Digital Personal Data Protection Act, 2023: Key Provisions, Implications and Practical Takeaways for Professionals

Introduction

Data has become one of the most valuable assets of modern businesses. Companies routinely collect and process personal information relating to customers, employees, directors, shareholders, vendors and other stakeholders. Protecting such information is therefore not merely an IT responsibility—it is increasingly a corporate governance, legal and compliance responsibility.

India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a comprehensive framework for processing digital personal data while recognising the individual’s right to protect personal data and the legitimate need of organisations to process such data. The Act received Presidential assent on 11 August 2023.

The Digital Personal Data Protection Rules, 2025 were subsequently notified on 13 November 2025, bringing the country closer to an operational data-protection regime. The implementation, however, is phased, with different provisions of the Act and Rules coming into force at different stages.


1. What Does the DPDP Act Cover?

The Act applies to the processing of digital personal data in India and, in specified circumstances, to processing outside India where such processing is connected with offering goods or services to individuals in India.

The Act broadly regulates the relationship between:

  • Data Principal – the individual to whom the personal data relates;
  • Data Fiduciary – the person or entity determining the purpose and means of processing; and
  • Data Processor – a person processing personal data on behalf of a Data Fiduciary.

The framework is therefore relevant to virtually every organisation that collects or processes personal information digitally.


2. Lawful Processing and Consent

Personal data may generally be processed for a lawful purpose, based on the consent of the Data Principal or for specified legitimate uses recognised under the Act.

Where consent is relied upon, it must be:

  • Free;
  • Specific;
  • Informed;
  • Unambiguous; and
  • Given through clear affirmative action.

The Data Principal must also be able to withdraw consent, and the process for withdrawal should be as easy as the process of giving consent.

The 2025 Rules further require notices to be clear and understandable, including an itemised description of the personal data and the specific purpose of processing.

Practical implication

Organisations should move away from broad, generic privacy clauses and review their privacy notices, consent mechanisms and data-collection forms.


3. Rights of Data Principals

The Act gives individuals important rights concerning their personal data, including the right to:

  • Obtain information about processing of their personal data;
  • Seek correction and erasure of personal data;
  • Obtain grievance redressal; and
  • Nominate another individual to exercise their rights in specified circumstances.

These rights require organisations to have mechanisms for receiving, verifying, tracking and responding to requests from Data Principals.


4. Obligations of Data Fiduciaries

The Data Fiduciary bears significant responsibility under the Act.

Key obligations include:

  • Processing personal data in accordance with the Act;
  • Ensuring accuracy where required;
  • Implementing appropriate technical and organisational measures;
  • Taking reasonable security safeguards;
  • Notifying personal-data breaches as prescribed;
  • Deleting personal data when retention is no longer necessary, subject to applicable legal requirements; and
  • Providing effective grievance-redressal mechanisms.

The emphasis is therefore on responsible data lifecycle management—from collection to deletion.


5. Significant Data Fiduciaries

The Government may classify certain entities as Significant Data Fiduciaries (“SDFs”) based on factors such as the volume and sensitivity of personal data processed, risks to individuals, security of the State and other relevant considerations.

SDFs are subject to enhanced obligations, including:

  • Appointment of a Data Protection Officer based in India;
  • Appointment of an independent Data Auditor;
  • Periodic Data Protection Impact Assessments; and
  • Periodic data audits.

This is particularly relevant for large organisations and businesses handling substantial volumes of personal data.


6. Special Protection for Children

The Act provides enhanced protection for children’s personal data.

A Data Fiduciary is required to obtain verifiable parental consent before processing personal data of a child and is subject to restrictions concerning tracking, behavioural monitoring and targeted advertising directed at children, subject to the statutory framework and exemptions.

Businesses dealing with children or providing online services to them should therefore pay particular attention to their consent and age-verification mechanisms.


7. Data Security and Breach Management

Data security is a central component of the DPDP framework.

Organisations should have appropriate technical and organisational safeguards to prevent personal-data breaches. The Rules prescribe detailed requirements concerning security safeguards and breach-related notifications.

Accordingly, companies should maintain a documented Data Breach Response Plan covering:

Detection → Containment → Assessment → Internal Escalation → Regulatory/Stakeholder Notification → Remedial Action → Documentation

Data protection should therefore be integrated with the organisation’s broader cybersecurity and risk-management framework.


8. Significant Financial Penalties

One of the most important implications for businesses is the potential financial exposure.

The Act provides for monetary penalties that may extend to ₹250 crore for certain breaches, depending upon the nature and severity of the contravention.

The financial consequences make data protection a matter that should receive appropriate attention from the Board, senior management, Audit Committee, legal function and compliance professionals.


Practical Takeaways for CAs, CSs and Legal Professionals

The DPDP Act should not be viewed merely as an IT or cybersecurity law. It has significant implications for corporate governance and compliance.

1. Prepare a Personal Data Inventory

Identify what personal data the organisation collects, from whom, why it is collected, where it is stored and with whom it is shared.

2. Review Privacy Notices and Consent Forms

Ensure that customer, employee, vendor and website/app privacy notices comply with the applicable DPDP framework.

3. Review Contracts

Data-processing arrangements with vendors, cloud-service providers, payroll agencies, consultants and other processors should be reviewed from a data-protection perspective.

4. Establish a Data Retention Policy

Organisations should know how long personal data is retained and why. Unnecessary retention increases both compliance and security risks.

5. Create a Data-Breach Response Mechanism

A documented escalation mechanism should clearly identify responsibilities of IT, legal, compliance, management and other stakeholders.

6. Strengthen Board-Level Oversight

For larger organisations, data protection should form part of the organisation’s enterprise risk management and governance framework.

7. Monitor Significant Data Fiduciary Status

Entities handling large volumes or sensitive categories of personal data should assess whether they may fall within the SDF framework and plan for enhanced compliance requirements.


Why Professionals Need to Understand the DPDP Act

For Company Secretaries, the Act intersects with corporate governance, Board reporting, compliance management, contracts, risk management and regulatory disclosures.

For Chartered Accountants, it has implications for internal controls, audits, data security, financial-process information and third-party data handling.

For Legal Professionals, it creates an important new area involving contracts, consent, privacy notices, data-processing arrangements, regulatory proceedings and dispute resolution.

Accordingly, data protection should increasingly be viewed as a multi-disciplinary compliance function rather than a technology-only issue.


Conclusion

The Digital Personal Data Protection Act, 2023 represents an important milestone in India’s evolving data-governance framework. With the Digital Personal Data Protection Rules, 2025 now notified and implementation structured in phases, organisations should begin treating privacy and personal-data protection as an integral component of their compliance architecture.

For professionals, the key message is simple:

Personal data is not merely information—it is a compliance responsibility.

CAs, CSs and legal professionals have an important role to play in ensuring that organisations establish appropriate governance structures, contractual safeguards, internal controls and accountability mechanisms for responsible processing of personal data.

The transition from “data collection” to “responsible data governance” is likely to become one of the most important compliance developments for Indian businesses in the coming years.

Key Regulatory References

  • Digital Personal Data Protection Act, 2023
  • Digital Personal Data Protection Rules, 2025
  • Notification regarding commencement of DPDP Act provisions
  • Establishment of the Data Protection Board of India

Disclaimer: This article is intended for general informational and educational purposes and should not be construed as legal or professional advice. Readers should refer to the latest provisions of the DPDP Act, Rules, notifications and applicable regulatory directions before taking any compliance decision.