top of page

Understanding India's Digital Personal Data Protection Act: A General Overview

India's Digital Personal Data Protection Act, 2023 is the country's first comprehensive data protection law. It received presidential assent in 2023, and its implementing rules — the DPDP Rules, 2025 — were notified by the Ministry of Electronics and Information Technology in November 2025. Here's a general overview of how the framework is structured.

The Key Roles the Act Defines

The Act organises obligations around a few core roles: the Data Principal is the individual the personal data belongs to; the Data Fiduciary is the entity that determines why and how that data is processed; a Data Processor handles data on a fiduciary's behalf; and a Significant Data Fiduciary is a category subject to heightened obligations based on the volume or sensitivity of data it processes.

A Phased Rollout, Not a Single Effective Date

The Rules commenced in three notified phases. The Data Protection Board of India — the body responsible for enforcement and grievance redressal — became operational immediately upon notification in November 2025. The Consent Manager framework, which lets individuals manage consent across services through registered intermediaries, is scheduled to take effect by November 2026. The remaining substantive obligations, including the full penalty regime, are set to commence by May 2027.

Rights Given to Data Principals

Individuals are given a defined set of rights under the Act, including the right to obtain information about how their data is being processed, to seek correction or erasure of their data, to nominate another person to exercise these rights on their behalf, and to file grievances — first with the Data Fiduciary directly, and subsequently with the Data Protection Board if unresolved.

Obligations Placed on Data Fiduciaries

Data Fiduciaries are required to process personal data only on the basis of valid consent or another legally recognised ground, limit processing to the stated purpose, implement reasonable security safeguards, and notify both the Data Protection Board and affected individuals in the event of a data breach.

Enforcement and Penalties

The Data Protection Board of India has powers of inquiry and can impose financial penalties for non-compliance, with the framework providing for penalties that scale with the severity of the violation — reported to reach up to ₹250 crore for the most serious breaches, once the full penalty regime commences in 2027.

About This Firm

Blackridge Law Firm is an advocates' partnership practising before the High Court of Kerala and the courts and tribunals of Ernakulam. Practice areas, attorney credentials, and contact details are listed on the firm's website.

This article provides general legal information for educational purposes only, based on the DPDP Act, 2023 and DPDP Rules, 2025 as notified. It does not constitute legal advice and does not create an advocate-client relationship. For guidance on a specific compliance matter, consult a qualified legal professional.

 
 
 

Comments


bottom of page