The Digital Personal Data Protection Act, 2023 received presidential assent in August 2023, and the draft Digital Personal Data Protection Rules were released for public consultation in January 2025 — bringing India meaningfully closer to a functioning, enforceable data protection regime for the first time. For any organisation that collects, stores, or processes personal data of individuals in India, this is no longer a future compliance exercise. It is an active one.

Who the Act Actually Covers

The DPDP Act applies to the processing of digital personal data within India, and — critically for global businesses — to processing outside India where it relates to offering goods or services to individuals in India. The Act distinguishes between "Data Fiduciaries" (entities that determine the purpose and means of processing, roughly equivalent to "controllers" under the GDPR) and "Data Processors" acting on a fiduciary's instructions. A subset of fiduciaries handling especially large volumes of data will be designated "Significant Data Fiduciaries," attracting heightened obligations including mandatory Data Protection Officers and periodic data protection impact assessments.

Consent, Legitimate Uses, and Children's Data

Processing generally requires free, specific, informed, unconditional, and unambiguous consent, obtained through a notice that is meaningfully accessible — not buried in a wall of legalese. The Act also carves out a list of "legitimate uses" that do not require fresh consent, including employment-related processing, compliance with law, and certain voluntarily-disclosed data. For data of children under 18, the Act requires verifiable parental consent and prohibits behavioural monitoring, targeted advertising, and tracking directed at children — a provision that will require ed-tech, gaming, and consumer app businesses to rebuild significant parts of their data architecture.

Financial penalties under the Act can reach ₹250 crore for a single instance of non-compliance with reasonable security safeguards, making this one of the most consequential regulatory exposures on an Indian compliance calendar.

Building a Compliance Programme

  • Map your data flows. Identify every point at which personal data of Indian individuals is collected, the legal basis for that collection, and where it is stored or transferred.
  • Rebuild consent architecture. Notices must be clear, itemised, and available in a manner that lets a user withdraw consent as easily as they gave it.
  • Establish a grievance redressal mechanism. The Act requires fiduciaries to designate a contact point for data principals to raise concerns and exercise their rights.
  • Prepare breach-notification protocols. Both the Data Protection Board and affected individuals must be notified of personal data breaches, and the draft Rules propose tight notification windows.
  • Review cross-border transfer arrangements. Unlike the GDPR's adequacy-based model, the DPDP Act permits transfers to all countries except those specifically restricted by government notification — a materially different, and still-evolving, framework.

The Bottom Line

The Data Protection Board of India, the Act's principal enforcement authority, is being operationalised, and the final Rules are expected to bring the substantive provisions into force in phases. Businesses that wait for the Rules to be finalised before beginning implementation will find themselves compressing a multi-quarter compliance programme into a matter of weeks. The organisations best positioned are those already treating data mapping, consent redesign, and breach-response protocols as live workstreams.