← Back to blog

DPDP Act: the complete guide to India's data protection law

DPDP Act: the complete guide to India's data protection law

India's Digital Personal Data Protection Act (DPDP Act) is the law that now governs how every organisation collects, stores and uses the personal data of people in India. With the DPDP Rules notified in November 2025 and enforcement rolling out through 2027, compliance is no longer optional. This guide explains what the DPDP Act is, who it applies to, what it requires, the penalties for getting it wrong, and how to comply — with deep-dive links to each topic. It pairs with our guide to AI governance in India.

AramGRC Team·Regulatory Readiness·September 10, 2026·14 min read

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (the “DPDP Act”) is India's first comprehensive data protection law. It governs the processing of digital personal data — any information about an identifiable individual, held in digital form — and gives people in India enforceable rights over how their data is collected and used. The Act was passed in 2023, and its operational rulebook, the DPDP Rules 2025, was notified on 14 November 2025, starting a phased rollout toward full enforcement in 2027.

The DPDP Act at a glance

  • Full name:Digital Personal Data Protection Act, 2023.
  • What it covers:the processing of digital personal data of individuals (“Data Principals”) in India, including by companies outside India that offer goods or services to Indian users.
  • Regulator:the Data Protection Board of India (DPBI).
  • Rules:the DPDP Rules 2025, notified 14 November 2025.
  • Penalties:monetary penalties up to ₹250 crore per instance.
  • Enforcement:phased, with full enforcement expected around May 2027.

Why the DPDP Act matters

Almost every organisation processes personal data — customer records, employee data, marketing lists, and increasingly, data used to train and run AI systems. The DPDP Act makes the organisation that decides how that data is used legally responsible for protecting it and using it only for the purpose the individual agreed to. For businesses that run on data and AI, the Act reshapes how you collect consent, how long you keep data, how you honour deletion requests, and how you prove all of it — with financial penalties large enough to reach the balance sheet.

Key definitions

Five terms unlock the whole Act:

  • Data Principalthe individual whose personal data is being processed (your customer, user or employee).
  • Data Fiduciarythe organisation that decides why and how personal data is processed. If you run the systems that use the data, you are a Data Fiduciary.
  • Significant Data Fiduciary (SDF)a Data Fiduciary handling large volumes or sensitive categories of data, notified by the government and subject to stricter obligations (a Data Protection Officer, audits and Data Protection Impact Assessments).
  • Consent Managera registered platform through which individuals give, manage and withdraw consent across services.
  • Data Protection Board of India (DPBI)the regulator that investigates breaches and imposes penalties.

What the DPDP Act requires

Every Data Fiduciary must, in broad terms:

  • Collect valid consentclear, specific, informed and freely given, with notice in English and India's scheduled languages, and an easy way to withdraw it.
  • Limit purpose and retentionuse data only for the stated purpose and delete it when that purpose is met.
  • Honour Data Principal rightsaccess, correction, erasure and grievance redress.
  • Protect the dataimplement reasonable security safeguards to prevent breaches.
  • Report breachesnotify the Board and affected individuals.
  • Handle children's data carefullyobtain verifiable parental consent and avoid tracking or targeted advertising to children.
  • Appoint accountabilitya grievance officer for all, and for SDFs a Data Protection Officer based in India.

The DPDP Rules 2025

The DPDP Rules, notified on 14 November 2025, turn the Act's principles into operational obligations — on consent notices, Consent Managers, security safeguards, breach notification, retention and children's data — with a phased implementation window. We cover them in detail in DPDP Rules 2025.

Who does the DPDP Act apply to?

The Act applies to any organisation processing the digital personal data of people in India — of any size, and including foreign companies serving Indian users. Some processing (purely personal, or certain government functions) is exempt. See the full breakdown in who does the DPDP Act apply to.

DPDP Act penalties

The DPDP Act carries some of the largest data-protection penalties in Asia — up to ₹250 crore per instance for failing to prevent a data breach, with a graded schedule for other violations, imposed by the Data Protection Board. We break down the full penalty schedule in DPDP Act penalties.

The enforcement timeline

The DPDP framework is being switched on in phases: the Rules were notified in November 2025, Consent Manager and core obligations follow through 2026, and full enforcement — including penalties — is expected around May 2027. If you're asking “is the DPDP Act in force yet?”, the honest answer is “in stages, and the window to prepare is now” — see DPDP Act enforcement date and timeline.

The DPDP Act and AI

AI makes DPDP compliance harder, not easier. AI systems reuse data across purposes, learn from it, and make automated decisions — which strains the Act's rules on purpose limitation, consent withdrawal and the right to erasure. A model trained on personal data collected for another purpose is a compliance gap most organisations don't realise they have, and “deleting” a Data Principal's data from a trained model is a genuine engineering problem. This is where data protection and AI governance meet — and why treating DPDP as a purely legal exercise fails for AI-driven businesses.

DPDP Act vs GDPR

The DPDP Act is often compared to the EU's GDPR, and they share DNA — consent, purpose limitation, data-subject rights, breach notification and large fines. But the DPDP Act is deliberately simpler and more consent-centric: it covers only digital personal data, leans heavily on consent (via Consent Managers) as the basis for processing, does not create GDPR-style categories of “sensitive” data in the same way, and its penalties are fixed-amount rather than turnover-linked. Organisations already GDPR-compliant have a strong head start, but should not assume GDPR compliance equals DPDP compliance.

How to comply with the DPDP Act

Compliance is a programme, not a policy update: map your personal data, fix your consent and notices, rework data used for AI training, build deletion and retention workflows, appoint a grievance officer (and a DPO if you're an SDF), and keep auditable evidence of all of it. Work through the full DPDP compliance checklist.

DPDP and India's wider AI law

The DPDP Act is the data-protection foundation, but India's approach to AI spans more: MeitY's India AI Governance Guidelines, RBI's FREE-AI framework for financial services, and sector rules from SEBI and IRDAI. We map the whole landscape in AI regulation in India.

Key takeaways

  • The DPDP Act, 2023 is India's first comprehensive data protection law; its Rules were notified in November 2025 and enforcement runs to 2027.
  • It applies to any organisation processing the personal data of people in India, including foreign companies.
  • Penalties reach ₹250 crore per instance, imposed by the Data Protection Board of India.
  • AI-driven businesses face the sharpest compliance challenge, because models reuse and retain personal data.
  • The transition window is open now — the organisations that prepare early won't be scrambling in 2027.

How AramGRC helps

AramGRC is India-first by design. Our Regulatory Readiness service maps your personal data across your AI and IT footprint, identifies the gaps between your systems and the DPDP Rules, and gives you a sector-ready compliance roadmap — covering DPDP alongside RBI, SEBI and IRDAI expectations.

Frequently asked questions

What is the DPDP Act?+

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection law. It governs how organisations process the digital personal data of people in India and gives individuals enforceable rights over their data.

When was the DPDP Act passed and when does it come into force?+

The Act was passed in 2023; the DPDP Rules were notified on 14 November 2025, and enforcement is phased, with full enforcement expected around May 2027.

Who does the DPDP Act apply to?+

Any organisation processing the digital personal data of people in India — of any size — including foreign companies that offer goods or services to Indian users.

What are the penalties under the DPDP Act?+

Monetary penalties up to ₹250 crore per instance for failing to prevent a data breach, with a graded schedule for other violations, imposed by the Data Protection Board of India.

What is a Data Fiduciary?+

The organisation that decides why and how personal data is processed. If you run the systems that use the data, you are almost certainly a Data Fiduciary under the DPDP Act.

What is the difference between the DPDP Act and GDPR?+

Both protect personal data with consent, rights and fines, but the DPDP Act is simpler and more consent-centric, covers only digital personal data, and uses fixed-amount penalties rather than turnover-linked ones.

Is the DPDP Act in force?+

It's being switched on in phases — the Rules were notified in November 2025 and full enforcement, including penalties, is expected around May 2027.

What is DPDP compliance?+

The set of measures — consent, notices, data mapping, retention and deletion, security, breach reporting and accountability — that a Data Fiduciary must implement to meet the DPDP Act's requirements.

DPDP ActData ProtectionIndiaCompliance
WhatsApp