This article is general information, not legal advice. It summarises the published text of the Act and Rules as of the date above. For decisions about your own organisation, consult a qualified lawyer and check the official sources for later notifications or amendments.
The law in one paragraph
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) received Presidential assent on 11 August 2023. It governs how organisations collect and use digital personal data, gives individuals enforceable rights, and sets up the Data Protection Board of India to handle complaints and impose penalties. The detail sits in the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), published in the Gazette of India dated 13 November 2025. The Press Information Bureau’s backgrounder gives the notification date as 14 November 2025 and describes an eighteen-month period for phased compliance.
If your website or app collects names, phone numbers, email addresses or any other data that identifies a person, read on.
Key terms
The Act uses its own vocabulary (section 2):
- Data Principal: the individual the data is about. For a child, this includes the parent or lawful guardian.
- Data Fiduciary: whoever decides why and how personal data is processed. If you run the website or app, this is usually you.
- Data Processor: anyone processing data on the fiduciary’s behalf, such as a hosting provider, email platform or CRM vendor.
- Child: anyone under 18.
When it applies, and when it starts
Under section 3, the Act covers digital personal data processed in India, and data that was collected on paper and later digitised. It also reaches processing outside India if it is connected with offering goods or services to people in India. It does not apply to purely personal or domestic use, or to data the person has chosen to make public themselves.
The Rules commence in three stages (rule 1):
| Stage | What commences | Timing |
|---|---|---|
| On publication | Rules 1, 2 and 17 to 21: definitions and the Data Protection Board | 13 November 2025 |
| One year later | Rule 4: registration and obligations of Consent Managers | November 2026 |
| Eighteen months later | Rules 3, 5 to 16, 22 and 23: notice, security, breach intimation, retention, children’s data, rights, cross-border transfer and appeals | May 2027 |
Most day-to-day obligations arrive in the final stage. That is months away, and reworking consent flows, logging and deletion takes engineering time. Dates can be changed by later notification. Press reports during 2026 have said the government may revise parts of this framework, including the timeline, but at the date above we could not find any amending notification published on MeitY’s website. Before relying on these dates, check the MeitY site and the e-Gazette for later notifications.
Lawful grounds: consent or “certain legitimate uses”
Section 4 allows processing only for a lawful purpose and on one of two grounds: the person’s consent, or one of the legitimate uses listed in section 7. The legitimate uses include data a person voluntarily provides for a specific purpose without objecting, legal compliance, medical emergencies, disasters and certain employment purposes. For marketing, analytics, personalisation and most “nice to have” processing, consent is the ground you will rely on.
Notice: what you must tell people
Every request for consent must come with, or be preceded by, a notice (section 5). Rule 3 sets the standard. The notice must:
- stand on its own and be understandable independently of any other information you provide;
- use clear and plain language;
- give an itemised description of the personal data you collect;
- state the specific purpose and describe the goods, services or uses that the processing enables; and
- give a link and describe any other means by which the person can withdraw consent, exercise their rights and complain to the Board.
The person must be able to read the notice in English or any language in the Eighth Schedule to the Constitution (section 5(3)). If you collected data with consent before the Act commenced, section 5(2) requires you to send a notice to those people as soon as reasonably practicable.
Consent: how to ask for it
Section 6 sets a high bar. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose. In practice:
- Designs that assume consent, such as pre-ticked boxes, sit poorly with the need for a clear affirmative action.
- Consent extends only to data needed for the purpose. In the Act’s illustration, a telemedicine app’s consent covers the telemedicine service, not access to the user’s contacts.
- Any part of a consent that waives rights under the law is invalid.
- Withdrawal must be as easy as giving consent (section 6(4)).
- After withdrawal you must stop processing, and make your processors stop, within a reasonable time unless the law requires otherwise (section 6(6)).
- If there is a dispute, you must prove that notice was given and consent obtained (section 6(10)). Keep timestamped consent records.
Consent Managers
People can give and withdraw consent through a registered Consent Manager instead of dealing with each business separately (section 6(7)). Under the First Schedule to the Rules, a Consent Manager must be a company incorporated in India with net worth of at least ₹2 crore. It must not be able to read the personal data it routes, and must keep consent records for at least seven years. Registration opens when rule 4 commences in November 2026. Plan for your systems to accept consent signals from these platforms.
Rights you must support
Chapter III gives individuals the right to:
- Access a summary of their personal data and processing, and the identities of other fiduciaries and processors it was shared with (section 11).
- Correct, complete, update and erase their data (section 12). Erasure can be refused only where retention is needed for the specified purpose or by law.
- Grievance redressal from you before going to the Board (section 13).
- Nominate another person to act for them on death or incapacity (section 14).
Rule 14 requires you to publish prominently on your website or app how people can make these requests and what identifier you need (for example, a username or customer ID). You must also publish the period within which you will respond to grievances, which cannot exceed 90 days. Rule 9 requires you to publish the business contact details of a Data Protection Officer, or of a person who can answer questions about processing, and to include them in every reply to a rights request.
Security and breach intimation
Section 8(5) requires “reasonable security safeguards”, and rule 6 sets a minimum. That includes encryption, obfuscation, masking or tokenisation; access control; logging and monitoring that can detect unauthorised access; backups for continuity; and security clauses in your contracts with processors. Logs and the relevant personal data must be retained for one year to support investigation, unless another law requires otherwise.
If a personal data breach occurs, rule 7 requires two sets of notifications:
- Each affected person, without delay, through their account or registered contact channel, in plain language: what happened and when, the likely consequences, what you are doing about it, what they can do to protect themselves, and who to contact.
- The Data Protection Board, without delay, with an initial description, followed within 72 hours of becoming aware with a detailed report: causes, mitigation, any findings about who caused it, remedial steps and a report on the notifications sent to individuals. The Board can allow more time on a written request.
The Act’s definition of a breach (section 2(u)) includes accidental disclosure and loss of access, not only hacking.
Retention and deletion
You must erase personal data once consent is withdrawn or the purpose is no longer being served, and make your processors do the same, unless the law requires you to keep it (section 8(7)). For large e-commerce, social media and online gaming platforms (thresholds are in the Third Schedule), the purpose is deemed to have ended three years after the user last engaged, with 48 hours’ warning before erasure (rule 8). Separately, rule 8(3) requires fiduciaries to keep personal data, traffic data and processing logs for at least one year from the processing, for purposes listed in the Seventh Schedule.
Children’s data
For anyone under 18, section 9 and rule 10 require verifiable consent from a parent before processing. You must also check that the person claiming to be the parent is an identifiable adult, using identity and age details you already hold or details provided voluntarily, including through a virtual token issued by an authorised entity or made available through a Digital Locker service provider. Beyond consent, you must not process children’s data in a way likely to harm their well-being, and you must not track, behaviourally monitor or target advertising at children (section 9(3)).
The Fourth Schedule exempts some cases, under conditions, such as healthcare providers, educational institutions, creating an email-only account, and confirming that a user is not a child.
Significant Data Fiduciaries
Fiduciaries the government designates as significant, based on factors such as data volume and sensitivity, must appoint an India-based Data Protection Officer and an independent data auditor (section 10), and carry out a Data Protection Impact Assessment and audit every twelve months (rule 13).
Penalties
The Board can impose penalties after an inquiry (section 33). Maximum amounts are set in the Act’s Schedule:
| Breach | Maximum penalty |
|---|---|
| Failing to take reasonable security safeguards (s. 8(5)) | ₹250 crore |
| Failing to notify the Board or affected people of a breach (s. 8(6)) | ₹200 crore |
| Breaching the additional obligations for children (s. 9) | ₹200 crore |
| Breaching Significant Data Fiduciary obligations (s. 10) | ₹150 crore |
| Breach of any other provision of the Act or Rules | ₹50 crore |
| Data Principal breaching their own duties (s. 15) | ₹10,000 |
In setting the amount, the Board must weigh factors including the gravity and duration of the breach, the data affected, repetition, mitigation and proportionality.
A practical checklist for website and app owners
- Map your data. List every form, SDK, tag, log and integration that touches personal data, with its purpose.
- Pick a ground for each purpose. Consent or a section 7 legitimate use. Drop anything you cannot justify.
- Rewrite notices as standalone, itemised, plain-language statements, available in English and the Eighth Schedule languages your users need.
- Rebuild consent flows. Use unticked, purpose-level choices and a visible “withdraw” option that is as easy as opting in. Store timestamped consent records.
- Gate non-essential tags (analytics, ads, session replay) behind consent where consent is your ground.
- Publish a rights page explaining how to request access, correction, erasure and nomination, your grievance response period (90 days at most) and a named contact.
- Build the back end for rights requests: export, correction and deletion across your database, backups policy and processors.
- Review processor contracts for security, deletion and breach-notification terms.
- Harden security against the rule 6 list and keep access logs for at least a year.
- Write a breach runbook covering detection, decision-makers, user notification templates and the 72-hour Board report.
- Check for children. If minors can use your service, add age screening and verifiable parental consent, and turn off behavioural tracking and targeted ads for them.
- Set retention schedules and automate deletion.
- Track dates: Consent Manager registration from November 2026, and the main obligations from May 2027, subject to any amendment.
Sources
- The Digital Personal Data Protection Act, 2023 (Gazette of India, via MeitY)
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) (Gazette of India, via MeitY)
- Press Information Bureau backgrounder: DPDP Rules, 2025 Notified (17 November 2025)
- Ministry of Electronics and Information Technology
- The Gazette of India (e-Gazette)