Short Answer
The Digital Personal Data Protection Act, 2023 (DPDP) is India's first comprehensive data privacy law. It governs how organisations collect, store, process, and share digital personal data, and gives Indian citizens enforceable rights over their data.
The DPDP Act, 2023 is India's primary data protection law, enacted on 11 August 2023 and being operationalised through phased rules and the Data Protection Board. It applies to any business — Indian or foreign — that processes the digital personal data of individuals in India.
It defines two key roles: the Data Fiduciary (the organisation that decides why and how data is processed) and the Data Principal (the individual whose data is being processed). Every Fiduciary must obtain valid consent, provide clear notices, honour user rights (access, correction, deletion, nomination, grievance), protect data with reasonable safeguards, and notify breaches.
Non-compliance can attract penalties of up to ₹250 crore per violation, adjudicated by the Data Protection Board of India.
Law Reference
Sections 1–4 – Application & Definitions
Section 8 – Obligations of Data Fiduciary
DPDP is not an IT-only initiative — it touches marketing, CRM, HR, vendor management, and product. Every customer-data workflow must be re-examined against lawful basis, notice, and consent obligations.
An Indian D2C brand collecting emails via a website checkout becomes a Data Fiduciary the moment it stores that email, triggering DPDP notice, consent, security, and rights-handling duties.
Was this answer helpful?
Our team is here to help you with any questions about DPDP compliance.