Skip to content

Digital Personal Data Protection (DPDP) Act, 2023

Key Objectives and Scope

  • Applicability: Applies to the processing of digital personal data within India, whether collected online or digitized offline. It also applies to processing outside India if it involves offering goods or services to individuals in India.
  • Consent: Personal data can only be processed for a lawful purpose for which the individual (Data Principal) has given or is deemed to have given consent. Consent must be free, specific, informed, unconditional, and unambiguous.

Key Stakeholders & Definitions

TermDefinition / Role
Data PrincipalThe individual to whom the personal data relates (includes parents/lawful guardians if the individual is a child or a person with disability).
Data FiduciaryThe entity (individual, company, or state) that determines the purpose and means of processing personal data.
Significant Data Fiduciary (SDF)Classified by the Government based on factors like volume of data, risk to electoral democracy, state security, and public order. Subject to stricter audit requirements.
Data Protection Board of India (DPBI)The regulatory body established by the Central Government to monitor compliance, direct mitigation measures, and impose penalties.

Rights and Duties of the Data Principal

  • Right to Access: Request summary of personal data being processed and the identities of all Data Fiduciary partners with whom the data is shared.
  • Right to Correction and Erasure: Correct inaccurate data, complete incomplete data, and update or erase data no longer necessary for the purpose it was collected.
  • Right to Grievance Redressal: Access readily available means of registering a grievance with the Data Fiduciary.
  • Duties: Must not register false or frivolous complaints, impersonate others, or provide false information.

Obligations of the Data Fiduciary

  • Security Safeguards: Must implement reasonable security safeguards to prevent personal data breaches.
  • Breach Notification: Must notify the Data Protection Board of India (DPBI) and the affected Data Principals in the event of a data breach.
  • Data Erasure: Must delete personal data once the specified purpose is fulfilled or when consent is withdrawn.
  • Special Obligations for Children's Data: Must obtain verifiable parental consent before processing data of children (under 18) and must not track, monitor, or target advertisements at children.

Exemptions from the Act

  • State Instrumentalities: The government can exempt specific state agencies in the interest of national security, public order, and sovereignty of India.
  • Research & Statistics: Processing for research, archiving, or statistical purposes is exempted if the data is not used to make decisions concerning specific individuals.
  • Legal Rights: Processing necessary for enforcing legal rights or defending claims.

Penalty Structure for Non-Compliance

[Non-Compliance Event]

       ├─► Failure to take security safeguards to prevent data breach ──► Up to ₹250 Crore

       ├─► Failure to notify DPBI or users of a breach ─────────────────► Up to ₹200 Crore

       └─► Non-fulfillment of obligations related to children's data ──► Up to ₹150 Crore