The Digital Personal Data Protection (DPDP) Act, 2023
Context: In its first major compliance push, the Centre directed ministries, States and UTs to prepare time-bound plans and appoint nodal officers to implement the DPDP Act, 2023.
- Government Data Fiduciaries must audit data, strengthen cybersecurity and embed privacy-by-design in digital platforms.

About The Digital Personal Data Protection (DPDP) Act, 2023:
What It Is?
- The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s principal statutory data privacy legislation enacted to regulate the processing of digital personal data. Built on the SARAL approach (Simple, Accessible, Rational, and Actionable), the law establishes rights for individuals (Data Principals), legal obligations for data collectors (Data Fiduciaries), and enforcement powers under the Data Protection Board of India (DPBI).
Aim: To establish a comprehensive legal regime that protects individual privacy rights and safeguards digital personal data while recognizing the necessity to process such data for lawful, legitimate, and national development purposes.
Key Features of the DPDP Act, 2023:
- Broad Territorial and Extra-Territorial Scope: Applies to digital personal data processed within India, as well as foreign processing of personal data linked to offering goods or services to Data Principals in India.
- Consent-Centric & Legitimate Use Processing: Personal data can only be processed after giving clear prior notice and securing free, specific, and informed consent.
- Specified exceptions include voluntary provision of data, government subsidies/services, medical emergencies, and employment purposes.
- Robust Data Principal Rights with Civic Duties: Empowers individuals with the right to access processing summaries, seek correction and erasure, register grievances, and nominate legal representatives upon death/incapacity. It balances these rights with statutory duties.
- Child Safety and Special Protections: Prohibits behavioral tracking, targeted advertising, and processing of data that causes harm to children, mandating verifiable parental or legal guardian consent prior to data collection.
- Independent Oversight & Graded Financial Penalties: Establishes the Data Protection Board of India (DPBI) as the adjudicatory body (with appellate jurisdiction under TDSAT). It imposes strict non-criminal penalties:
- Up to ₹250 crore for failing to maintain reasonable security safeguards to prevent data breaches.
- Up to ₹200 crore for failing to report data breaches or violating child-data protection norms.
- Up to ₹50 crore for general statutory violations.
Significance:
- Gives statutory effect to the Puttaswamy (2017) privacy principle and strengthens personal data protection.
- Allows cross-border data transfers unless specifically restricted, supporting IT exports, cloud services and investment in India’s digital economy.






