Concept Page
Digital Personal Data Protection Act 2023
The Digital Personal Data Protection Act, 2023 is India’s first comprehensive statute regulating how private and government bodies collect, store, process and transfer personal data. It creates a Data Protection Authority, gives individuals rights such as consent and correction, and penalises violations up to 4% of global turnover; for instance, social‑media platforms must obtain explicit consent before profiling Indian users.
India's Digital Personal Data Protection Act, 2023 (DPDPA) is the country's first horizontal statute dedicated to the protection of personal data, replacing the sectoral patchwork that previously governed information privacy under the Information Technology Act, 2000, and the SPDI Rules, 2011. Enacted on 11 August 2023 after receiving Presidential assent, and notified for staggered implementation beginning in 2023–24, the law applies to digital personal data processed within India and to data of individuals located outside India if the processing is connected with offering goods or services to them. What sets the Act apart is its remarkably wide territorial reach combined with a comparatively streamlined obligation regime: rather than enumerating categories of sensitive data, it treats most personal data under a single framework while carving out specific protections for children.
Origins and Constitutional Antecedents
The DPDPA is the legislative culmination of a constitutional promise. In K.S. Puttaswamy v. Union of India (2017), a nine-judge bench of the Supreme Court unanimously held that the right to privacy is a fundamental right under Article 21 of the Constitution. The judgment expressly directed Parliament to enact a comprehensive data protection regime. Earlier, the Justice B.N. Srikrishna Committee submitted a draft Personal Data Protection Bill in 2018, followed by the Personal Data Protection Bill, 2019, which lapsed with the dissolution of the 17th Lok Sabha. After further consultation, the revised Digital Personal Data Protection Bill, 2022 was withdrawn and replaced by the present Act.
Key Provisions
The Act's architecture rests on a few central obligations. Section 4 requires personal data to be processed only for a lawful purpose with the consent of the Data Principal, or for certain permitted uses defined in Section 7, including medical emergencies, employment-related obligations, and disaster response. Section 8 obliges Data Fiduciaries (controllers) to issue a clear notice describing the purpose of and manner of processing. Sections 10–14 grant Data Principals rights of access, correction, erasure, grievance redressal, and the right to nominate another individual to exercise rights after death.
For children, Section 9 prohibits processing that causes detrimental effect and bars tracking or behavioural monitoring directed at users under 18 without verifiable parental consent. Section 17 obliges Significant Data Fiduciaries—designated by the government based on the volume and sensitivity of data processed—to conduct periodic Data Protection Impact Assessments, audits, and appoint a Data Protection Officer based in India.
Penalties and Enforcement
The enforcement regime is notable for its scale. Section 33 read with the Schedule specifies financial penalties of up to ₹250 crore for failure to take reasonable security safeguards, and up to ₹500 crore for breaches involving children's data or certain other categories. For other non-compliances, the Schedule sets tiered penalties calibrated to the nature of the violation. The Data Protection Board of India, constituted under Section 18, adjudicates complaints and imposes penalties, with appeals lying to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Implementation and Early Concerns
Although the Act received Presidential assent in August 2023, the central government issued the Digital Personal Data Protection Rules, 2025 on 3 January 2025, with most operational provisions taking effect later that year. Section 44(2), which had drawn criticism for exempting State agencies from large parts of the Act in the interest of sovereignty, public order, and security, was held constitutionally suspect by the Bombay High Court in October 2025, though appeals remain pending.
Significance
The DPDPA positions India among a growing club of jurisdictions—alongside the European Union's GDPR and Brazil's LGPD—with comprehensive data protection legislation. Yet by replacing draft-stage proportionality tests with a binary consent model and granting the government broad exemption powers, it reflects a distinctive Indian calibration between individual autonomy and administrative access, the long-term trajectory of which will depend on litigation before the Supreme Court and the evolving jurisprudence of the Data Protection Board.