DPDP Act 2023
Data Protection Act
India's first comprehensive data protection law. Applies to any digital processing of personal data. Establishes Data Principal rights and Data Fiduciary obligations.
The Digital Personal Data Protection Act, 2023 is India's principal statute on the processing of personal data. Notified in August 2023; rules and the Data Protection Board are being operationalised in phases. It repeals Section 43A of the Information Technology Act 2000 and overrides the SPDI Rules 2011 to the extent of inconsistency.
Applicability:
- Processing of digital personal data within India (including offline data subsequently digitised).
- Processing outside India if it relates to offering goods or services to Data Principals in India (extraterritorial reach).
- Does not apply to: personal data processed for personal/domestic purposes, data made publicly available by the Data Principal, or certain research/statistical processing.
Key actors:
- Data Principal — the individual to whom the data relates (the natural person).
- Data Fiduciary — any person who determines the purpose and means of processing (the entity, e.g., a startup).
- Data Processor — engaged by a Data Fiduciary to process data on its behalf.
- Significant Data Fiduciary (SDF) — class designated by the Central Government based on volume / sensitivity; SDFs have heavier obligations (DPO appointment, DPIA, audit).
Lawful grounds for processing: Consent of the Data Principal OR specified legitimate uses (employment, medical emergency, public interest, performance of a court order, etc.). Consent must be free, specific, informed, unconditional, and unambiguous, with clear plain-language notice.
Data Principal rights (Sections 11–14):
- Right to access information about personal data
- Right to correction and erasure
- Right of grievance redressal
- Right to nominate (in case of death/incapacity)
Penalties: Up to ₹250 crore per instance for failure to take reasonable security safeguards; ₹200 crore for breach of children's data; lesser amounts for other violations. Imposed by the Data Protection Board of India.
Children's data: Verifiable parental consent is mandatory for processing data of users under 18; behavioural monitoring and targeted advertising to children are prohibited.
For startups and AIFs: map your data inventory, refresh privacy notices, contract-flow with processors (DPAs), implement consent capture, and establish breach-notification SOPs to the DPB.
Anti-money-laundering statute. Drives KYC and reporting obligations for banks, AIFs, NBFCs, and now most VDA platforms and large startups.
Statutory regulator of Indian securities markets. Oversees listed companies, AIFs, mutual funds, intermediaries, takeovers, and insider-trading regimes.
Indian statute governing cross-border transactions. Administered by RBI. Two pillars: current account (free unless restricted) and capital account (regulated).