The DPDP Act in plain language

India’s Digital Personal Data Protection Act, 2023 sets rules for how organisations handle digital personal data. This page is a short map of the ideas your product, ops, and legal teams use in the same conversation — not a substitute for professional advice.

Who the law speaks to

If your organisation decides why and how personal data is processed — and that processing happens digitally — you are usually in scope. There are statutory exceptions and nuances; your counsel confirms fit for your case.

  • Applies to processing of digital personal data where it relates to individuals in India (subject to how the Act and rules apply).
  • “Personal data” means data about an identifiable person — name, phone, email, IDs, and much more.

Two roles to remember

Almost every workflow boils down to the relationship between the person and the organisation that controls their data.

Data Principal and Data Fiduciary The person shares data with the organisation; the organisation must meet duties under the law. Data Principal The individual Data Fiduciary Your organisation

You owe that person clarity, lawful handling, and a way to exercise their rights.

Four things to operationalise

Teams move faster when they group work into four buckets (same framing as elsewhere on this site):

  • Tell Be transparent — notices, purposes, and who you share with.
  • Permission Where the law requires it, get valid consent and honour withdrawal.
  • Control Make rights requests (access, correction, erasure, grievance, etc.) workable and traceable.
  • Report Be ready for incidents and scrutiny — evidence, not panic.

Notice (being upfront)

Before or at collection, people should understand what you collect, why, how long you keep it, and how they can exercise rights. Notices should be easy to find — not buried in links nobody opens.

Rights of the individual

The Act recognises several rights in principle — such as access, correction, erasure, grievance redressal, and nomination — with details and limits in the statute and rules. Operationally: define who handles requests, how fast you respond, and how you prove what you did.

A minimal discipline loop for any rights channel.

Security & data breaches

You are expected to take reasonable security safeguards. If a breach hurts individuals, the law contemplates notification to the Data Protection Board of India and, in some situations, to affected people — timelines and content follow regulatory rules. Have a playbook before you need it.

Penalties & urgency

The Act allows for significant penalties for serious failures (including up to ₹250 crore per incident in the statute’s upper range for certain violations). Boards and regulators care whether you can show process and records, not only policy PDFs.

Industry talk often cites May 2027 as a milestone for fuller compliance readiness — verify what applies to your sector; this page does not set your legal deadline.

Disclaimer: Kavach is not a law firm. This guide summarises common talking points only. For obligations, contracts, and regulator engagement, work with qualified Indian legal counsel.