DPDP Act
Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025
- Regulator
- Data Protection Board of India (Ministry of Electronics and Information Technology)
- Who it applies to
- Every data fiduciary processing digital personal data in India, and processing abroad that offers goods or services to people in India.
- If you fall short
- Up to INR 250 crore for failing to take reasonable security safeguards; other breaches carry penalties up to INR 200 crore.
- What it asks of you
- A clear notice and free, specific, informed consent — or another legitimate use
- Reasonable security safeguards to prevent personal data breaches
- Report a personal data breach to the Data Protection Board and to each affected person
- Answer data principals' rights and grievances, and erase data when its purpose is served
- Verifiable parental consent for children's data; a DPO in India, DPIAs and audits for Significant Data Fiduciaries
The DPDP Rules were notified in November 2025 with most obligations taking effect in phases over the following 18 months.