DPDP Act 2023 • Rules 2025 • Continuously Tracked

India's DPDP Law.
Made Practical.

Understand India's Digital Personal Data Protection framework, assess your readiness, and turn legal requirements into practical action with free tools, templates and source-backed guidance.

Free tools
No registration
Official-source references
DPDP Digital Compliance Manager
Hi! I can help you understand DPDP, check applicability and find the right compliance tools.
I'll Explore Myself
DPDP Digital Compliance Manager
DPDP Readiness
78%
Active Mode
Legal Basis Ready
Data Inventory Ready
Consent Management Review
Security Safeguards Ready
Next Recommended Action
Review Consent Workflow
16 Interactive Tools
Ready to use
Official Sources
Verified against Gazette
Explore your compliance journey
43
Legal Provisions
16
Interactive Tools
60
Practical Guides
40
Glossary Terms
22
Templates
Practical Workflows

Practical tools.
Not just explanations.

Turn complex DPDP statutory provisions into clear, guided operational workflows.

Structured Readiness

Replace compliance chaos with clarity.

Moving from fragmented spreadsheets to a structured, source-backed compliance foundation.

Without a Structured Approach
Fragmented & Reactive
  • Scattered compliance spreadsheets
  • Unclear departmental responsibilities
  • Disconnected and non-compliant privacy notices
  • Unknown third-party vendor risks
  • Zero retention schedule visibility
With Indian DPDP
Operational & Source-Backed
  • Mapped legal obligations across roles
  • Guided, step-by-step diagnostic workflows
  • Purpose-built interactive compliance tools
  • Reusable templates and policy generators
  • Direct cross-references to official Gazette text
The Legal Reader

Don't trust summaries.
Verify the law.

Official statutory text is permanently separated from our plain-language operational explanations.

General obligations of Data Fiduciary
Official Statutory Text • Gazette of India

8. (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.

(2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.

(3) Where personal data processed by a Data Fiduciary is likely to beΓÇö
(a) used to make a decision that affects the Data Principal; or
(b) disclosed to another Data Fiduciary,
the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency.

(4) A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder.

(5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.

(6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.

(7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,ΓÇö
(a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and
(b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor.

(8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does notΓÇôΓÇô
(a) approach the Data Fiduciary for the performance of the specified purpose; and
(b) exercise any of her rights in relation to such processing,
for such time period as may be prescribed, and different time periods may be prescribed for different classes of Data Fiduciaries and for different purposes.

(9) A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data.

(10) A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.

Plain-Language Operational Breakdown

What this means: This is the most critical section for companies, establishing their core responsibilities.

Company Obligations:
- They must use a legally binding contract when hiring third-party data processors.
- Data must be kept accurate and complete if it affects decisions about you.
- They must implement robust cybersecurity measures to protect your data.
- If a data breach happens, they must notify the government Data Protection Board and you.
- They must erase your data when it is no longer needed or when you withdraw consent.
- They must publish contact details for a person who will answer privacy-related questions and handle grievances.

Source Metadata
Official Source Verified
Related Tools
Platform Integrity

Built around the source.
Not around assumptions.

We believe data protection guidance must be grounded in official law. Every tool, checklist and article is continuously cross-referenced against Gazette notifications.

Official Text Kept Distinct
Statutory provisions are never merged or confused with plain-language explanations.
Cross-Referenced Provisions
Every tool outcome cites exact section numbers and gazetted rule schedules.
Tracked Legal Updates
Continuously updated as Ministry of Electronics & IT releases further notifications.
Educational Decision-Support
Purely independent decision support to empower privacy and technical teams without lock-in.
Legal Intelligence

DPDP Status Center

Full Timeline →
Primary Act Tracked
DPDP Act, 2023
Passed by Parliament of India and published in Gazette. Verified statutory base active.
Rules & Schedules Tracked
DPDP Rules, 2025
Implementation rules, consent manager parameters, and breach intimation guidelines actively mapped.
Monitoring Engine Active
Continuous Review
Our editorial desk continuously monitors MeitY notifications and Data Protection Board of India updates.
Manager Avatar

Still not sure where to begin?

Start with three quick questions and I'll point you in the right direction.

Educational Framework

Digital Personal Data Protection (DPDP) Act: A Comprehensive Guide to India's Privacy Law

The Digital Personal Data Protection (DPDP) Act, 2023 represents a milestone transformation in India's legal landscape, establishing the nation's first cross-sectoral statutory framework for the governance of digital personal data. Enacted by Parliament to balance the fundamental right to informational privacy with the legitimate processing needs of the digital economy, the DPDP framework replaces earlier fragmented provisions under the Information Technology Act.

Statutory Principle: The DPDP Act is built around principles of lawful processing, purpose specification, data minimisation, storage limitation, reasonable security safeguards, and accountability.

1. Scope and Territorial Applicability

The DPDP Act applies to the processing of digital personal data within India where such personal data is collected in digital form or collected offline and subsequently digitized. Crucially, the law incorporates extraterritorial jurisdiction: it applies to processing activities conducted outside the territory of India if such processing is in connection with any activity related to offering goods or services to Data Principals within India.

2. Key Stakeholders and Definitions

Understanding DPDP compliance requires familiarity with statutory roles defined under Section 2:

  • Data Principal: The individual to whom the personal data relates. In the case of a child (individual below 18 years), this includes the parent or lawful guardian.
  • Data Fiduciary: Any person, company, or state entity that alone or in conjunction with others determines the purpose and means of processing personal data.
  • Data Processor: Any person or entity that processes personal data on behalf of a Data Fiduciary under a binding contract.
  • Significant Data Fiduciary (SDF): High-impact entities designated by the Central Government based on factors such as data volume, sensitivity, national security risk, and systemic impact.

3. Core Obligations of Data Fiduciaries

Unlike frameworks where processors share statutory liability, the DPDP framework places the primary burden of legal compliance directly on the Data Fiduciary under Section 8:

  • Consent & Notice (Sections 5 & 6): Data processing must generally be grounded in valid, freely given, specific, informed, unconditional, and unambiguous consent with clear notice provided in 22 Eighth Schedule languages.
  • Reasonable Security Safeguards: Fiduciaries must implement appropriate technical and organizational measures to prevent personal data breaches.
  • Mandatory Breach Notification: In the event of a breach, the Fiduciary must give prompt intimation to both the Data Protection Board of India and every affected Data Principal.
  • Data Erasure & Retention Limits: Fiduciaries must erase personal data as soon as the specified purpose is no longer served or when consent is withdrawn.
  • Grievance Redressal: Organizations must provide an accessible mechanism for individuals to submit complaints before approaching the Board.

4. Rights of Data Principals

Chapter III of the Act grants actionable privacy rights to individuals, empowering them to maintain control over their digital footprint:

  • Right to Information: Access a summary of personal data being processed and the identities of all third-party Fiduciaries shared with.
  • Right to Correction & Erasure: Request correction of inaccurate data, completion of incomplete data, or erasure of unnecessary data.
  • Right of Grievance Redressal: Receive timely responses to privacy inquiries from the organization.
  • Right to Nominate: Nominate an individual to exercise rights in the event of death or incapacity.

5. Enforcement & Financial Penalties

The Data Protection Board of India (DPBI) serves as the adjudicatory body empowered to investigate non-compliance, direct remediation, and impose significant financial penalties under Schedule 1:

  • Failure to take reasonable security safeguards to prevent personal data breach: Up to &rupee;250 Crore.
  • Failure to notify the Board and affected principals of a breach: Up to &rupee;200 Crore.
  • Non-compliance with obligations in relation to children: Up to &rupee;200 Crore.
  • General non-compliance with other provisions or rules: Up to &rupee;50 Crore.

6. Frequently Asked Questions (FAQ)

Q: Does the DPDP Act apply to small businesses and startups?

A: Yes. The DPDP Act applies to any entity processing digital personal data. While the Central Government may notify certain exemptions for specific classes of research or startup entities, baseline principles of lawful processing and security remain essential.

Q: How does this platform assist with compliance?

A: The Indian DPDP provides free, source-verified tools, checklists, and templates to help organizations evaluate readiness and operationalize requirements without legal ambiguity.

Start Your Journey

Turn DPDP complexity
into a clear next step.

Explore verified statutory law, assess your organizational readiness, and use practical tools designed specifically for India's DPDP framework.

Compliance Manager Ready to Assist