RegulationIndia

DPDPA 2023

Ministry of Electronics and Information Technology, Government of India · Version 2023 · Presidential assent August 11, 2023

India's Digital Personal Data Protection Act — the primary legislation governing personal data in India.

Overview

The Digital Personal Data Protection Act 2023 received Presidential assent on August 11, 2023, making India the 137th country to enact comprehensive data protection legislation. The Act governs the processing of digital personal data within India and the processing of digital personal data outside India where such processing is in connection with offering goods or services to individuals within India. The Act adopts a consent-first model, requiring a Data Fiduciary to obtain free, specific, informed, unconditional, and unambiguous consent from a Data Principal before processing their personal data, except in cases where processing is permitted without consent under specific circumstances listed in the Act.

The Act introduces the concept of a Significant Data Fiduciary, a designation applied by the Central Government based on volume and sensitivity of data processed, risk to data principals, potential impact on national security and public order, and other factors. Significant Data Fiduciaries have additional obligations including the appointment of a Data Protection Officer who must be based in India, conducting periodic Data Protection Impact Assessments, and engaging an independent auditor. The Data Protection Board of India, established under the Act, will serve as an adjudicatory body for complaints and impose penalties. Penalties reach up to INR 250 crore per breach of the Act. The rules under the Act, which will specify technical and operational details, were under consultation as of 2024.

Who Needs This

Indian companies processing personal data of any Indian citizen in digital form

International companies offering goods or services to individuals located in India

Technology platforms, e-commerce companies, fintech firms, and healthtech companies operating in India

Companies with Indian employees whose HR data is processed digitally

Data processors handling personal data on behalf of Data Fiduciaries in India

Structure at a Glance

Grounds for processing, notice requirements, consent management, legitimate uses without consent, and obligations regarding children's data.

Right to information about personal data, right to correction and erasure, and right to grievance redressal.

Obligations on data principals not to impersonate others, suppress information, make frivolous complaints, or provide false particulars.

Designation criteria, additional obligations including DPO appointment, DPIA, and independent audit.

Establishment, powers, complaint procedure, appeals, and enforcement mechanisms.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

Consent Notice Drafting

Use this to draft compliant consent notices as required before data collection.

You are a DPDPA 2023 compliance specialist. I need to draft a consent notice under Section 5 of the DPDPA for the following data collection: [DESCRIBE WHAT DATA IS BEING COLLECTED]. Processing purpose: [DESCRIBE PURPOSE]. Goods or services provided in exchange: [DESCRIBE]. The consent notice must comply with DPDPA 2023 requirements and be: written in clear and plain language, available in English and such other language as the Data Principal may request, specific about each processing purpose, clear that consent can be withdrawn. Draft the notice in a format appropriate for [WEB CONSENT FORM / APP ONBOARDING / PAPER FORM].

Data Principal Rights Response

Use this when responding to rights requests from Indian data subjects.

I have received a DPDPA 2023 data principal rights request from [DESCRIBE DATA PRINCIPAL AND THEIR RELATIONSHIP TO OUR ORGANIZATION]. The request is for: [RIGHT TO ACCESS INFORMATION / RIGHT TO CORRECTION / RIGHT TO ERASURE / GRIEVANCE REDRESSAL]. Date received: [DATE]. Our relevant processing activities involving this data principal: [DESCRIBE]. Provide: (1) an acknowledgment response confirming receipt, (2) the timeline for response under the DPDPA, (3) an internal checklist of systems and records to query, (4) any grounds under the Act that may limit or exclude this right in this specific case, and (5) a draft final response.

Significant Data Fiduciary Assessment

Use this to assess whether your organization may be designated as a Significant Data Fiduciary.

Assess whether our organization is likely to be designated as a Significant Data Fiduciary under the DPDPA 2023. Organization details: [DESCRIBE TYPE, SIZE, AND SECTOR]. Volume of personal data processed: [ESTIMATE]. Categories of personal data: [LIST SENSITIVE CATEGORIES]. National security relevance: [DESCRIBE IF ANY]. Based on the criteria in Section 10 of the DPDPA, evaluate the likelihood of SDF designation, identify the additional obligations that would apply if designated, recommend the DPO appointment process and qualifications required, and outline the DPIA and audit requirements that would need to be operationalized.

Cross-Border Transfer Assessment

Use this to assess the legality of transferring personal data outside India.

I need to assess a personal data transfer outside India under the DPDPA 2023. Transfer details: personal data being transferred is [DESCRIBE DATA TYPES], sent to [DESTINATION COUNTRY AND ORGANIZATION]. Purpose: [DESCRIBE]. Number of data principals: [ESTIMATE]. Analyze: (1) whether the destination country is on the Central Government's blocklist restricting transfers, (2) the current transfer mechanism available under the DPDPA and any rules that have been issued, (3) contractual provisions that should be included in any data processing agreement with the overseas recipient, and (4) risks if the transfer is made before formal rules on cross-border transfers are issued.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Operating under the assumption that rules will clarify everything. The DPDPA is the primary legislation. Many obligations under Sections 5 through 12 apply regardless of whether implementing rules have been issued. Core obligations around consent, notice, and data principal rights are operative.

2

Equating DPDPA compliance with GDPR compliance. The two laws share philosophical similarities but differ in scope, definitions, lawful bases, and enforcement mechanisms. GDPR compliance does not substitute for DPDPA compliance for Indian operations.

3

Ignoring the duties of Data Principals in Section 13. Unlike GDPR, the DPDPA places explicit duties on individuals providing data. Organizations collecting data from individuals should ensure their processes do not inadvertently facilitate breaches of these duties.

4

Treating the Data Protection Board as a distant regulatory risk. The Board has powers to investigate on its own motion, not only on complaint. Organizations in high-volume consumer sectors should treat DPB oversight as an active regulatory risk, not a theoretical one.

5

Children's data processing without additional safeguards. Section 9 prohibits tracking, behavioral monitoring, or targeted advertising directed at children and requires verifiable parental consent. Platforms with any likelihood of child users must implement age verification and parental consent mechanisms.

Cross-Framework Mapping

GDPR

DPDPA draws significantly from GDPR architecture, including consent requirements, data principal rights, and controller-processor obligations. Organizations compliant with GDPR have a strong foundation but must adapt specifically for DPDPA's Indian legal context.

ISO 27001

ISO 27001 Annex A control A.5.34 addresses privacy and the protection of personal data. A certified organization has a security framework in place but must build a separate DPDPA compliance program covering legal obligations, consent management, and data principal rights.

CERT-In

DPDPA and CERT-In Directions operate as complementary regulations in India. CERT-In governs incident reporting and log retention. DPDPA governs personal data handling and breach notification to affected individuals. Both apply simultaneously to organizations processing Indian data.

All content sourced from official issuing body documentation.

Official source ↗

Regulation

DPDPA 2023