India's first standalone data protection law, which regulates the processing of digital personal data through consent, fiduciary duties and penalties of up to Rs 250 crore.
The Digital Personal Data Protection Act, 2023 is India's first dedicated law on personal data. It received presidential assent on 11 August 2023 and gives statutory shape to the right to informational privacy that the Supreme Court recognised as a fundamental right in the Puttaswamy judgment of 2017. The Act applies to personal data in digital form - data collected digitally, or collected on paper and later digitised - and deliberately leaves out purely offline records. It works through three actors: the data principal, the individual to whom the data relates; the data fiduciary, who decides the purpose and means of processing; and the data processor, who processes on a fiduciary's behalf. Its operating rules were notified as the Digital Personal Data Protection Rules, 2025 on 13 November 2025, which set a phased compliance timetable rather than switching the whole Act on at once.
Type: LawConsent as the default basis for processing - consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and it may be withdrawn as easily as it was given.
Legitimate uses - a limited set of situations where processing is allowed without consent, such as when the data principal voluntarily provides data for a specified purpose, for state benefits and services, for medical emergencies, and for employment-related purposes.
Rights of the data principal - access to information about processing, correction and completion, updating and erasure, grievance redressal, and the right to nominate another person to exercise the rights in the event of death or incapacity.
Duties of the data principal - a rarity in data protection law. A person must not register a false or frivolous complaint or furnish false particulars, and can be penalised up to Rs 10,000 for breaching these duties.
Children's data - processing the data of anyone below eighteen requires verifiable consent of a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.
Significant Data Fiduciary - entities notified by the Centre on criteria such as volume and sensitivity of data and risk to electoral democracy or public order, who must appoint a Data Protection Officer based in India, an independent data auditor, and conduct periodic Data Protection Impact Assessments.
Data Protection Board of India - the adjudicating body that inquires into breaches and imposes penalties, functioning as a digital office; its orders are appealable to the Telecom Disputes Settlement and Appellate Tribunal.
Consent Managers - a platform registered with the Board through which an individual can give, manage, review and withdraw consent across many data fiduciaries from a single interface. This framework takes effect from 13 November 2026.
Frequency: High salience since 2023 and rising through the 2025-27 implementation window; appears in Prelims through its terminology and in Mains through the privacy-versus-transparency debate.
India had no general data protection statute for the whole period in which it built the world's largest biometric identity system and one of its largest digital payments markets. The gap was filled only partially by Section 43A of the Information Technology Act, 2000 and the rules made under it. The nine-judge bench in Justice K.S. Puttaswamy v. Union of India in August 2017 held privacy to be a fundamental right under Article 21 and expressly asked the government to bring in a data protection law. A committee under Justice B.N. Srikrishna was constituted the same year and submitted a draft in 2018; a Personal Data Protection Bill introduced in 2019 went to a Joint Parliamentary Committee, was withdrawn in August 2022, and was replaced by a shorter, principles-based draft that became the 2023 Act.
Information Technology Act; Section 43A and the 2011 rules provide the only data protection cover
Puttaswamy judgment - a nine-judge bench holds privacy to be a fundamental right under Article 21
Justice B.N. Srikrishna Committee constituted on data protection
The Committee submits its report and a draft Personal Data Protection Bill
Personal Data Protection Bill introduced and referred to a Joint Parliamentary Committee
The 2019 Bill is withdrawn
Digital Personal Data Protection Act receives presidential assent
DPDP Rules, 2025 notified, with a phased implementation timetable
The Consent Manager framework takes effect
The Act is built around a notice-and-consent transaction between the individual and the entity that wants their data.
Step 1 - Notice: before or along with seeking consent, the data fiduciary gives an itemised notice stating what personal data will be processed, for what purpose, how the individual may exercise their rights, and how to complain to the Board.
Step 2 - Language: the notice must be available in English or any of the languages listed in the Eighth Schedule of the Constitution, at the individual's option.
Step 3 - Consent: consent must be free, specific, informed, unconditional and unambiguous, and limited to the personal data necessary for the stated purpose. Any part of it that goes further is void to that extent.
Step 4 - Withdrawal: the individual may withdraw consent at any time, with the same ease as giving it. The fiduciary must then stop processing within a reasonable time unless another law requires retention.
Step 5 - Erasure: once consent is withdrawn or the purpose is no longer being served, the fiduciary must erase the data and cause its processors to do the same, unless retention is legally required.
Step 6 - Consent Manager: from 13 November 2026, an individual may route all of this through a Board-registered Consent Manager and manage consents across services from one place.
11 August 2023
13 November 2025 (Digital Personal Data Protection Rules, 2025)
13 November 2026
Up to Rs 250 crore for failure to take reasonable security safeguards
Up to Rs 200 crore each
Up to Rs 150 crore
Up to Rs 50 crore
Up to Rs 10,000
Below 18 years; verifiable parental consent required
Data Protection Board of India; appeals to the TDSAT
The Act converts a constitutional right into an enforceable set of obligations on every business, hospital, school and government department that handles personal data digitally, backed by penalties large enough to change behaviour. Its design choices are what make it contested. By covering only digital personal data it avoids the enforcement problem of paper records but leaves them unprotected. By dropping the 'sensitive personal data' category it simplifies compliance but treats a health record and a shopping preference alike at the level of the statute. Its broad exemptions for the State - which may exempt its own instrumentalities in the interests of sovereignty, security, public order and similar grounds - have drawn the sharpest criticism, since the Puttaswamy judgment was itself about limiting state surveillance. And the amendment to the RTI Act sets privacy against transparency in a way information commissioners and activists continue to challenge.
Assent 11 August 2023; India's first standalone data protection law; flows from the Puttaswamy judgment of 2017 and the Srikrishna Committee.
Applies to digital personal data only; not to offline non-digitised records, personal or domestic use, or publicly available data.
Data principal (individual), data fiduciary (decides purpose and means), data processor (processes for a fiduciary), Significant Data Fiduciary (notified, with DPO, auditor and impact assessments).
Consent must be free, specific, informed, unconditional, unambiguous and withdrawable; legitimate uses allow processing without consent in defined situations.
Children are under 18; verifiable parental consent is required and tracking and targeted advertising at children are barred.
Data Protection Board of India adjudicates; appeals go to the TDSAT.
Penalties: Rs 250 crore (security safeguards), Rs 200 crore (breach notification and children's data), Rs 150 crore (SDF obligations), Rs 50 crore (other), Rs 10,000 (data principal).
Section 44(3) amended Section 8(1)(j) of the RTI Act, removing the public-interest override for disclosure of personal information.
DPDP Rules 2025 notified 13 November 2025; Consent Manager framework from 13 November 2026.
Only if they are digitised. The Act covers personal data in digital form, and personal data collected in non-digital form and subsequently digitised. Purely offline records that are never digitised fall outside it.
Up to Rs 250 crore, imposed on a data fiduciary that fails in its obligation to take reasonable security safeguards. Failure to notify a personal data breach and breach of children's-data obligations attract up to Rs 200 crore each.
No. It does not impose a general data localisation requirement. It allows the Central Government to restrict transfers of personal data to countries it notifies, and sectoral regulators may still impose stricter localisation rules of their own.
Section 44(3) amended Section 8(1)(j) of the RTI Act so that personal information is exempt from disclosure without the earlier qualification permitting disclosure where a larger public interest warranted it. This is the most contested provision of the Act.
A data fiduciary or class of fiduciaries notified by the Central Government on criteria such as the volume and sensitivity of data processed and the risk to electoral democracy, security or public order. They must appoint an India-based Data Protection Officer and an independent data auditor and carry out periodic Data Protection Impact Assessments.