The Digital Personal Data Protection Act (DPDP Act), 2023 is India's national data protection law. It received presidential assent in August 2023, but its detailed compliance obligations stayed dormant until the Digital Personal Data Protection Rules, 2025 were finally notified on 14 November 2025 — with a phased rollout stretching to roughly mid-2027 before every obligation is fully live.
Key terms to know
- Data Principal — the individual the data is about (India's equivalent of GDPR's "data subject").
- Data Fiduciary — the entity that decides why and how personal data is processed (equivalent to GDPR's "controller").
- Data Processor — an entity processing data on a Data Fiduciary's behalf.
- Consent Manager — a concept GDPR doesn't have: a registered, India-incorporated intermediary through which a Data Principal can give, review, and withdraw consent on one interoperable platform.
- Significant Data Fiduciary (SDF) — a Data Fiduciary the government designates based on the volume or sensitivity of data it processes, facing heightened obligations like an India-based DPO and mandatory data protection impact assessments.
The phased rollout
The Rules stage compliance obligations in roughly three steps: the Data Protection Board of India (DPBI) was established in law immediately on notification (November 2025); Consent Manager registration and parental/guardian consent mechanics take effect roughly a year later; and the core compliance obligations — consent architecture, notice standards, and full Significant Data Fiduciary duties — become fully applicable around 18 months out, roughly mid-2027. Exact dates vary slightly by source, but the staged, ~18-month runway is consistent across reporting.
Penalties
| Violation | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify a breach to the Board/affected individuals | ₹200 crore |
| Breach of additional obligations around children's data | ₹200 crore |
| Breach of Significant Data Fiduciary obligations | ₹150 crore |
| Breach of any other provision of the Act/Rules | ₹50 crore |
| Breach of duties by a Data Principal (e.g. false complaints) | ₹10,000 |
Penalties go to the Consolidated Fund of India, not to affected individuals as compensation — a different model from GDPR's civil-damages routes. The Board weighs severity, sensitivity of data, and repeat behavior before setting the actual fine within these caps.
How DPDP differs from GDPR
DPDP has no broad "legitimate interest" basis — it relies on consent plus a narrow, statutorily enumerated list of "certain legitimate uses" (state benefits, legal compliance, medical emergencies, employment purposes). It requires breach notification for every breach regardless of severity, stricter than GDPR's risk-based notification threshold. And it takes a much lighter-touch, default-allow "blacklist" approach to cross-border transfers — permitted unless the government explicitly restricts a destination country — rather than GDPR's adequacy/SCC regime.
Enforcement status today
The Data Protection Board of India exists in law, but as of the most recent reporting, it isn't yet fully staffed — a chairperson and members have not been confirmed appointed. Treat this as a fast-moving fact worth re-checking rather than assuming it's already fully operational.