What Is India's DPDP Act?

The Digital Personal Data Protection Act (DPDP Act), 2023 is India's national data protection law. It received presidential assent in August 2023, but its detailed compliance obligations stayed dormant until the Digital Personal Data Protection Rules, 2025 were finally notified on 14 November 2025 — with a phased rollout stretching to roughly mid-2027 before every obligation is fully live.

Key terms to know

  • Data Principal — the individual the data is about (India's equivalent of GDPR's "data subject").
  • Data Fiduciary — the entity that decides why and how personal data is processed (equivalent to GDPR's "controller").
  • Data Processor — an entity processing data on a Data Fiduciary's behalf.
  • Consent Manager — a concept GDPR doesn't have: a registered, India-incorporated intermediary through which a Data Principal can give, review, and withdraw consent on one interoperable platform.
  • Significant Data Fiduciary (SDF) — a Data Fiduciary the government designates based on the volume or sensitivity of data it processes, facing heightened obligations like an India-based DPO and mandatory data protection impact assessments.

The phased rollout

The Rules stage compliance obligations in roughly three steps: the Data Protection Board of India (DPBI) was established in law immediately on notification (November 2025); Consent Manager registration and parental/guardian consent mechanics take effect roughly a year later; and the core compliance obligations — consent architecture, notice standards, and full Significant Data Fiduciary duties — become fully applicable around 18 months out, roughly mid-2027. Exact dates vary slightly by source, but the staged, ~18-month runway is consistent across reporting.

Penalties

ViolationMaximum Penalty
Failure to take reasonable security safeguards₹250 crore
Failure to notify a breach to the Board/affected individuals₹200 crore
Breach of additional obligations around children's data₹200 crore
Breach of Significant Data Fiduciary obligations₹150 crore
Breach of any other provision of the Act/Rules₹50 crore
Breach of duties by a Data Principal (e.g. false complaints)₹10,000

Penalties go to the Consolidated Fund of India, not to affected individuals as compensation — a different model from GDPR's civil-damages routes. The Board weighs severity, sensitivity of data, and repeat behavior before setting the actual fine within these caps.

How DPDP differs from GDPR

DPDP has no broad "legitimate interest" basis — it relies on consent plus a narrow, statutorily enumerated list of "certain legitimate uses" (state benefits, legal compliance, medical emergencies, employment purposes). It requires breach notification for every breach regardless of severity, stricter than GDPR's risk-based notification threshold. And it takes a much lighter-touch, default-allow "blacklist" approach to cross-border transfers — permitted unless the government explicitly restricts a destination country — rather than GDPR's adequacy/SCC regime.

Enforcement status today

The Data Protection Board of India exists in law, but as of the most recent reporting, it isn't yet fully staffed — a chairperson and members have not been confirmed appointed. Treat this as a fast-moving fact worth re-checking rather than assuming it's already fully operational.

Common Questions

Is the DPDP Act actually in force yet?

Partially. The Act received assent in 2023, but the Rules that operationalize it were only notified in November 2025, and even then most core compliance obligations phase in over roughly 18 months from that date — full enforcement isn't expected until around mid-2027.

What's a "Significant Data Fiduciary" and why does it matter?

It's a category of Data Fiduciary the government designates based on factors like data volume, sensitivity, and risk. These organizations face extra obligations — an India-based Data Protection Officer, independent audits, and data protection impact assessments — on top of the baseline requirements everyone else has.

How is DPDP different from GDPR?

DPDP relies mainly on consent rather than GDPR's broader set of lawful bases, requires notifying every data breach regardless of severity (GDPR only requires notification above a risk threshold), and uses a more permissive default-allow approach to cross-border data transfers.

Want hands-on practice with compliance frameworks?

Try the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is GDPR?

The EU law that shaped much of DPDP's structure, and where the two differ.