{"id":458,"date":"2024-02-21T15:57:16","date_gmt":"2024-02-21T14:57:16","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=33030"},"modified":"2025-06-25T07:48:48","modified_gmt":"2025-06-25T05:48:48","slug":"india-digital-personal-data-protection-act-dpdpa","status":"publish","type":"knowledge","link":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/","title":{"rendered":"India Digital Personal Data Protection Act (DPDP Act): An Overview"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-introduction-to-the-india-digital-personal-data-protection-act-dpdp-act\">Introduction to the India Digital Personal Data Protection Act (DPDP Act)<\/h2>\n\n\n<p>India\u2019s Digital Personal Data Protection Bill was tabled in 2022, and was finalized as <a href=\"https:\/\/www.meity.gov.in\/writereaddata\/files\/Digital%20Personal%20Data%20Protection%20Act%202023.pdf\" target=\"_blank\" rel=\"noopener\">India\u2019s Digital Personal Data Protection Act (DPDP Act)<\/a> when it received approval from both houses of Parliament and the assent of the President in August 2023. The law came into effect August 11, 2023 and covers personal data collected in digital format, or collected by other means and later digitized. The law is intended to protect personal information for citizens in the world\u2019s most populous country, and increase accountability for organizations that handle a lot of such data, including those with online operations and that run mobile apps.<\/p>\n<p>The law is in line with the standards of many global <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/data-privacy-in-2024-what-we-are-watching\/\">data privacy regulations<\/a>, taking influence from <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/china-personal-information-protection-law\/\">China\u2019s Personal Information Protection Law (PIPL)<\/a> and the <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/the-eu-general-data-protection-regulation\/\">European Union\u2019s General Data Protection Regulation (GDPR)<\/a>. We look at important requirements of the DPDP Act, key definitions, enforcement, and more. (Note: the state-level Delaware Personal Data Privacy Act in the United States also uses the initialism \u201cDPDPA\u201d, so we will mostly use \u201cthe DPDP Act\u201d.)<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-india-digital-personal-data-protection-act-dpdp-act\">What is the India Digital Personal Data Protection Act (DPDP Act)?<\/h2>\n\n\n<p>The DPDP Act is a federal law in India that regulates the processing of the digital personal data of its citizens. The law aims to strike a balance between the recognized need to process personal data for various purposes, and individuals\u2019 right to control and protect it.<\/p>\n<p>Like many data privacy laws around the world, the DPDP Act is extraterritorial, and so applies to organizations operating both inside and outside of India, if they are offering goods or services to Indian citizens, and in doing so processing personal data. The Act does allow for legal bases for data processing in addition to consent of the data principal, but consent is required for many processing purposes.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-key-definitions-in-the-indian-personal-data-privacy-law\">Key definitions in the Indian Personal Data Privacy Law<\/h2>\n\n\n<p>The definitions of key terms outlined in the DPDP Act are consistent with many data privacy laws, though some of the terms are different, e.g. \u201cdata fiduciary\u201d instead of \u201cdata controller\u201d. The definition of a person is also quite broad, as it can include the Indian State, a family, or a firm, for example.<\/p>\n<h4>What is a person under the DPDP Act?<\/h4>\n<p>A person covers a variety of entities, not just individual people, and refers to:<\/p>\n<ul>\n<li>an individual<\/li>\n<li>a Hindu undivided family<\/li>\n<li>a company<\/li>\n<li>a firm<\/li>\n<li>an association of persons or a body of individuals, whether incorporated or not<\/li>\n<li>the State<\/li>\n<li>every artificial juristic person, not falling within any of the preceding sub-clauses<\/li>\n<\/ul>\n<h4>What is personal data under the DPDP Act?<\/h4>\n<p>Personal data refers to any data about an individual who is identifiable by or in relation to such data. The personal data can be collected and processed in digital format, or collected in another format and later digitized. The Act does not provide a list of examples of personal data (e.g. name, phone number, financial information, etc.) like some data privacy laws do.<\/p>\n<h4>What is processing under the DPDP Act?<\/h4>\n<p>Processing in the context of personal data means<em> \u201ca wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction\u201d.<\/em><\/p>\n<h4>What is the definition of consent under the DPDP Act?<\/h4>\n<p>A data principal\u2019s consent must be: <em>\u201cfree, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose\u201d.<\/em><\/p>\n<h4>Who is defined as a child under the DPDP Act?<\/h4>\n<p>A child is defined as a person who is 18 years old or younger.<\/p>\n<h4>Who is a data principal under the DPDP Act?<\/h4>\n<p>This term refers to any individual to whom personal data being processed relates, and includes an individual who is a child (also, then, including the child\u2019s parents or lawful guardians) or an individual who has a disability (also, then, including the person\u2019s lawful guardian, acting on their behalf). Also known as a data subject under some other laws.<\/p>\n<h4>Who is a data fiduciary under the DPDP Act?<\/h4>\n<p>\u201cData fiduciary\u201d means any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data. Also known as a data controller under some other laws.<\/p>\n<p>A \u201cSignificant Data Fiduciary\u201d refers to any data fiduciary or class of data fiduciaries as may be notified by the Central Government.<\/p>\n<h4>Who is a data processor under the DPDP Act?<\/h4>\n<p>A data processor is any person who processes personal data on behalf of a data fiduciary.<\/p>\n<h4>What is a consent manager under the DPDP Act?<\/h4>\n<p>For the purposes of the Act, \u201cConsent Manager\u201d does not refer to software such as a consent management platform, but instead refers to a person or organization registered with the Data Protection Board. This entity acts as the point of contact to enable an individual, here the \u201cdata principal\u201d, to provide, manage, review, and\/or withdraw her consent via a platform that is \u201caccessible, transparent and interoperable\u201d. A consent manager serves as a middleman for businesses to help facilitate compliance with the DPDP Act.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-has-to-comply-with-the-indian-data-privacy-law\">Who has to comply with the Indian data privacy law?<\/h2>\n\n\n<p>The law applies to entities that collect and process digital personal data in India in the course of offering goods and services. It also applies to the processing of personal data outside of India if the processing is connected with an activity relating to offering goods or services to Indian citizens.<\/p>\n\n<div id=\"uc-cta_69d17dee4c0a5\" class=\"uc-cta uc-cta--button uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Find out how Usercentrics CMP can help you comply with India\u2019s DPDP Act. <\/div>\n                                                                                <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"39df60ea-4a81-47d7-ac14-075beedba7b8\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"https:\/\/usercentrics.com\/free-trial\/#app-cmp-trial?utm_source=blog_article&amp;utm_medium=content-distribution&amp;utm_campaign=in_dpdpa_blog_article_uc\" target=\"\"><span>Start your free trial today<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69d17dee4c0a5\"));\n    <\/script>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-consumers-rights-under-the-india-dpdpa\">What are consumers\u2019 rights under the India DPDPA?<\/h2>\n\n\n<p>Data principals have some of the rights common under other global data privacy laws, but not all of them. These include:<\/p>\n<ul>\n<li><strong>Right of access<\/strong> \u2013 to obtain information from the data fiduciary about their personal data, the processing of it, and identities of any third-party data fiduciaries or data processors with which it has been shared<\/li>\n<li><strong>Right to correction<\/strong> \u2013 to get errors or omissions corrected or personal data updated as quickly as is reasonable (with some exceptions)<\/li>\n<li><strong>Right to erasure<\/strong> \u2013 to have personal data deleted as quickly as is reasonable, including data held by and\/or processed by a third-party data processor, upon request (with some exceptions)<\/li>\n<li><strong>Right of grievance redressal<\/strong> \u2013 to have a readily available means to report a grievance, provided by the data fiduciary or consent manager, and have the grievance responded to within a reasonable amount of time from the date of receipt (with some exceptions)<\/li>\n<li><strong>Right to nominate an agent<\/strong> \u2013 to have someone represent the data principal to exercise their rights under the Act on their behalf in the event of death or incapacitation<\/li>\n<\/ul>\n<p>It should be noted that the right to erasure is not a full \u201cright to be forgotten\u201d as under the GDPR. Additionally, data principals do not have the right to data portability, to opt out of automated decision-making, or private right of action \u2014 the ability to sue a data fiduciary in the event of a breach \u2014 though they may seek compensation for a breach from responsible parties, and the Act does provide a schedule of penalties for different types and degrees of violation or negligence.<\/p>\n<h4>What are consumers\u2019 responsibilities under the DPDP Act?<\/h4>\n<p>Data principals have several duties under the DPDP Act, especially with regards to exercising their rights, including:<\/p>\n<ul>\n<li>complying with other applicable laws and their provisions<\/li>\n<li>not impersonating another person while providing personal data for a specific purpose<\/li>\n<li>not suppressing any material information while providing personal data for documents, proof of identity, proof of address, etc.<\/li>\n<li>issued by the State<\/li>\n<li>not registering any false or frivolous grievance or complaint with a data fiduciary or the Data Protection Board (the Board may issue<\/li>\n<li>a warning or impose costs on a complainant if a complaint brought by them is determined to be frivolous)<\/li>\n<li>providing only verifiably authentic information when exercising the right to correction or erasure<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-conditions-for-valid-consent-under-india-s-dpdp-act\">What are the conditions for valid consent under India\u2019s DPDP Act?<\/h2>\n\n\n<p>Requests made to a data principal for consent to process personal data must be preceded by or accompanied by a notice from the data fiduciary providing information about:<\/p>\n<ul>\n<li>the personal data requested<\/li>\n<li>the purpose for processing<\/li>\n<li>how the data principal can exercise their rights<\/li>\n<li>how the data principal can make a complaint to the Data Protection Board<\/li>\n<\/ul>\n<p>Valid consent must be \u201cfree, specific, informed, unconditional and unambiguous, with a clear affirmative action\u201d. Consent signifies an agreement for processing of personal data for a specified purpose, and is limited to the personal data that is necessary to fulfill that purpose.<\/p>\n<p>A data principal can withdraw their consent at any time, and it must be as easy to do so as to give consent. At the point when consent is withdrawn, the data fiduciary (or data processor) must stop processing their personal data. If requested, and if legally possible, that personal data must also be deleted.<\/p>\n<h4>Consent for marketing or advertising purposes<\/h4>\n<p>The DPDP Act does not contain specific clauses outlining requirements for or prohibiting the processing of personal data for marketing or advertising purposes for adults, including data use for targeted advertising or profiling. Targeted advertising to children is prohibited, however.<\/p>\n<h4>What protections are there for children\u2019s data under the Indian personal data protection law?<\/h4>\n<p>A data fiduciary must obtain verifiable consent from a parent or guardian before processing any personal data from a child or person with a disability. Additionally, data fiduciaries must not track or engage in behavioral monitoring of children or targeted advertising directed at children.<\/p>\n\n<div class=\"uc-notice\">\n    <div class=\"uc-notice__icon\">\n        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M10.8177 17.0093H12.8177V11.0093H10.8177V17.0093ZM11.8177 9.00928C12.1011 9.00928 12.3386 8.91344 12.5302 8.72178C12.7219 8.53011 12.8177 8.29261 12.8177 8.00928C12.8177 7.72594 12.7219 7.48844 12.5302 7.29678C12.3386 7.10511 12.1011 7.00928 11.8177 7.00928C11.5344 7.00928 11.2969 7.10511 11.1052 7.29678C10.9136 7.48844 10.8177 7.72594 10.8177 8.00928C10.8177 8.29261 10.9136 8.53011 11.1052 8.72178C11.2969 8.91344 11.5344 9.00928 11.8177 9.00928ZM11.8177 22.0093C10.4344 22.0093 9.13442 21.7468 7.91775 21.2218C6.70108 20.6968 5.64275 19.9843 4.74275 19.0843C3.84275 18.1843 3.13025 17.1259 2.60525 15.9093C2.08025 14.6926 1.81775 13.3926 1.81775 12.0093C1.81775 10.6259 2.08025 9.32594 2.60525 8.10928C3.13025 6.89261 3.84275 5.83428 4.74275 4.93428C5.64275 4.03428 6.70108 3.32178 7.91775 2.79678C9.13442 2.27178 10.4344 2.00928 11.8177 2.00928C13.2011 2.00928 14.5011 2.27178 15.7177 2.79678C16.9344 3.32178 17.9928 4.03428 18.8927 4.93428C19.7927 5.83428 20.5052 6.89261 21.0302 8.10928C21.5552 9.32594 21.8177 10.6259 21.8177 12.0093C21.8177 13.3926 21.5552 14.6926 21.0302 15.9093C20.5052 17.1259 19.7927 18.1843 18.8927 19.0843C17.9928 19.9843 16.9344 20.6968 15.7177 21.2218C14.5011 21.7468 13.2011 22.0093 11.8177 22.0093Z\" fill=\"black\"\/>\n<\/svg>\n    <\/div>\n    <div class=\"uc-notice__content\">\n                <p><strong>India\u2019s mobile market is huge:<\/strong> <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/2024-privacy-challenges-for-apps-and-games-publishers\/\">Top 5 privacy challenges for Apps and Games publishers in 2024<\/a><\/p>\n            <\/div>\n<\/div>\n\n\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-companies-responsibilities-under-the-indian-privacy-law\">What are companies\u2019 responsibilities under the Indian privacy law?<\/h2>\n\n\n<p>Entities have responsibilities on several fronts under the Act, including to data principals, with regards to the data itself, and if they engage the services of any third-party data processor, which can only be done under contract. The data fiduciary is ultimately responsible under the law for actions taken on its behalf by any data processor contracted to it, or in the event of a data breach involving the data processor. Data fiduciaries must also keep records of processing activities, including the purposes of processing, categories of data principals, and data transfers.<\/p>\n<h4>Legal processing of personal data<\/h4>\n<p>Personal data may be processed only when the data principal has given consent, or for certain legitimate uses (\u201clegitimate interest\u201d under the GDPR). Applications of legitimate use are significantly restricted. They include, under current Indian law:<\/p>\n<ul>\n<li>personal data voluntarily provided by the data principal to the data fiduciary for a specified purpose (and they have not indicated that they do not consent to the use of the data)<\/li>\n<li>processing by the state to enable issuing benefits, services, licenses, etc. when the data principal\u2019s consent has been received before or the personal data is already available digitally in a database or other repository maintained by the State.<\/li>\n<li>fulfillment of a legal obligation, judgment, or order<\/li>\n<li>compliance with legal judgment or order relating to contractual or civil claims<\/li>\n<li>providing lifesaving medical care or in responding to a life-threatening medical emergency<\/li>\n<li>providing medical treatment or health services during an epidemic, disease outbreak, or other threat to public health<\/li>\n<li>ensuring the safety of or providing assistance or services to any individual during a disaster or breakdown of public order<\/li>\n<li>for employment or to safeguard employers from loss or liability resulting from the actions of a data principal who is an employee<\/li>\n<\/ul>\n<h4>Data fiduciaries\u2019 responsibilities for personal data<\/h4>\n<p>Entities that collect and process personal data have several responsibilities, including:<\/p>\n<ul>\n<li>maintaining the completeness, accuracy, and consistency of the data<\/li>\n<li>taking reasonable technical and security measures to protect the data<\/li>\n<li>deletion of the data once the purpose for which it was collected and processed is complete<\/li>\n<\/ul>\n<p>In conjunction with data principals\u2019 rights, data fiduciaries also need to:<\/p>\n<ul>\n<li>provide information about personal data in their possession and about processing to data principals upon reasonable request<\/li>\n<li>correct or delete personal data when notified (with some exceptions)<\/li>\n<li>address complaints levied by data principals regarding issues relating to the data processing and the stipulations of the law<\/li>\n<\/ul>\n<h4>Data fiduciary notified as a Significant Data Fiduciary (SDF)<\/h4>\n<p>The Central Government, upon assessment, may notify a data fiduciary that they have been determined to be \u201csignificant\u201d. This is based on factors like:<\/p>\n<ul>\n<li>volume and sensitivity of personal data processed<\/li>\n<li>risk to the rights of data principals<\/li>\n<li>potential impact on the sovereignty and integrity of India<\/li>\n<li>risk to electoral democracy<\/li>\n<li>security of the State<\/li>\n<li>public order<\/li>\n<\/ul>\n<p>There are a number of requirements for data fiduciaries determined to be Significant Data Fiduciaries, including:<\/p>\n<ul>\n<li>appointing a Data Protection Officer who will represent the SDF under provisions of the DPDP Act and who is:\n<ul>\n<li>based in India<\/li>\n<li>responsible to the SDF\u2019s Board of Directors or comparable governing body<\/li>\n<li>the point of contact for the SDF\u2019s grievance redressal mechanism under the Act<\/li>\n<\/ul>\n<\/li>\n<li>appointing an independent audit to carry out data audits to evaluate the SDF\u2019s compliance with the Act<\/li>\n<li>undertaking periodic data protection impact assessments (DPIA), which include:\n<ul>\n<li>describing the rights of data principals<\/li>\n<li>purposes of personal data processing<\/li>\n<li>assessment and management of risks to data principals\u2019 rights, etc.<\/li>\n<\/ul>\n<\/li>\n<li>undertaking periodic data audits<\/li>\n<li>other prescribed measures consistent with provisions of the Act<\/li>\n<\/ul>\n<h4>International data transfers<\/h4>\n<p>The DPDP Act allows for transfers of personal data outside of India, except to countries that have been notified by the Central Government. Concerns have been expressed that this mechanism may not ensure adequate evaluation standards for data protection in the countries where data transfers are allowed.<\/p>\n<p>The Central Government may notify a data fiduciary to restrict transfers of personal data for processing to a country or territory outside of India. Any Indian law currently in force will supersede the Act if it allows for a higher degree of protection for personal data, or restriction on transfers of personal data.<\/p>\n<h4>Privacy notice or privacy policy requirement<\/h4>\n<p>The Act requires that requests for data principals\u2019 personal data be preceded by or accompanied by a notice about the personal data requested, the purpose of processing, how the data principal can exercise their rights, and how they can make a complaint to the Data Protection Board.<\/p>\n<p>The Act specifies that every consent request or other notice to data principals must be presented in \u201cclear and plain language\u201d, and accessible in English or any constitutionally recognized language. Where applicable, contact details for a Data Protection Officer must be included, or for any other person authorized by the data fiduciary to respond to communications from data principals to exercise their rights under the DPDP Act.<\/p>\n<p>The Act does not specifically reference a <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/what-is-a-privacy-policy-and-why-do-you-need-one\/\">privacy policy<\/a> or notice, e.g. as can be found on many websites.<\/p>\n<h4>Data Protection Officer<\/h4>\n<p>When required, data fiduciaries must appoint a Data Protection Officer and must publish business contact information for this person in a prescribed manner. Or they must be able to provide contact details for a person who can provide answers to inquiries and information on behalf of the data fiduciary if data principals inquire about the processing of their personal data.<\/p>\n<h4>Contracts with data processors<\/h4>\n<p>Data fiduciaries can engage data processors to process personal data on their behalf for any activity related to offering goods or services to data principals. However, this can only be done under a valid contract. Data fiduciaries are ultimately responsible for the actions of any data processors they engage.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-exemptions-to-the-dpdp-act\"> What are the exemptions to the DPDP Act?<\/h2>\n\n\n<p>The Central Government may exempt government agencies from DPDP Act provisions in the interest of national security, public order, and prevention of offenses. This option includes quite a few agencies. It is possible that exempt agencies could collect, process, and retain personal data beyond what is necessary in such cases. The government can also exclude categories of organizations in the future, like startups, which raises concerns about privacy oversight.<\/p>\n<p>Exemptions also include processing publicly available personal data, processing data for research purposes, and in some circumstances, processing personal data of non-Indian citizens.<\/p>\n<h4>Personal data exemptions<\/h4>\n<p>The Act does not apply to personal data processed by an individual for personal or domestic purposes, for journalistic purposes or artistic expression, or to personal data that is made or caused to be made publicly available by the data principal to whom the data relates, or any other person with an obligation under current Indian law to make that personal data publicly available.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-enforcement-and-penalties-under-india-s-digital-personal-data-protection-act\">Enforcement and penalties under India\u2019s Digital Personal Data Protection Act<\/h2>\n\n\n<p>The Central Government is the ultimate authority, though management and enforcement of the DPDP Act will fall to the Data Protection Board they appoint. The Act also makes it very clear what mechanisms data principals have to register complaints about personal data processing or breaches, how those must be handled and by whom, and what the potential penalties are for confirmed violations.<\/p>\n<p>The DPDP Act defines a personal data breach as <em>\u201cany unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability <\/em><em>of personal data\u201d.<\/em><\/p>\n<h4>DPDP Act enforcement authorities<\/h4>\n<p>India\u2019s Central Government will establish a Data Protection Board to adjudicate on issues of noncompliance with the DPDP Act. Board members and the Chairperson will be appointed by the Central Government for two-year terms and are eligible for re-appointment.<\/p>\n<p>Board members will be individuals who possess <em>\u201cspecial knowledge or practical experience in the fields of data governance, administration or implementation of laws related to social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation or techno-regulation, or in any other field which in the opinion of the Central Government may be useful to the Board, and at least one among them shall be an expert in the field of law\u201d<\/em>.<\/p>\n<p>With approval from the Central Government, the Board may appoint officers and employees necessary to perform its functions under the Act. The text of the DPDP Act also notes that, the Board and the Appellate Tribunal (which handles data principal appeals of Board decisions) shall function as an independent body, and, as far as practicable, as a digital office, meaning functions like receiving complaints, making inquiries, announcing decisions, etc. should be set up digitally by design.<\/p>\n<h4>Submitting complaints under the India DPDPA<\/h4>\n<p>In addition to publishing contact information for a representative of the data fiduciary or a Data Protection Officer, data fiduciaries must establish an \u201ceffective mechanism to redress the grievances of data principals\u201d. Typically this includes a phone number, email address, online form, etc.<\/p>\n<p>A data principal can make a complaint regarding a personal data breach by a data fiduciary to the Board or to a Consent Manager (which will then liaise with the Board), which will make inquiries regarding the breach and impose penalties where relevant. The Board will make decisions regarding whether there are sufficient grounds with a complaint to proceed with an inquiry. For the purposes of inquiries, the Board will have the same powers as a civil court regarding summoning people, receiving evidence, inspecting documents, etc.<\/p>\n<h4>Voluntary undertaking during a complaint investigation<\/h4>\n<p>An entity under investigation relating to a compliance complaint under the DPDP Act can offer a voluntary undertaking at any stage of the inquiry. This is a voluntarily offered commitment to achieve compliance with DPDP Act provisions. The undertaking can include specific actions to be taken, not taken, or ceased. The data fiduciary makes this offer to the Data Protection Board, which has the authority to accept, modify, or reject it, and to make it publicly known if the entity will commence with the undertaking.<\/p>\n<p>If accepted, a voluntary undertaking provides legal protection from penalties related to the alleged violation of the Act, as long as they do not fail to meet the terms of the undertaking. If they do fail to achieve compliance, the Board can impose penalties.<\/p>\n<h4>Appealing decisions by the Data Protection Board<\/h4>\n<p>If a complainant is unsatisfied with a decision by the Board, they can file an appeal within 60 days of receiving the Board\u2019s decision. A fee may be charged for this filing. Appeals are handled by the Appellate Tribunal, and must be dealt with within six months under most cases, and if this is not possible, the reasons must be recorded.<\/p>\n<h4>Data breach notifications<\/h4>\n<p>Data fiduciaries are responsible for appropriate technical, organization, and security measures to ensure compliance with the DPDP Act and protection of any personal data in their possession. The data fiduciary is also responsible for the actions of third-party data processors contracted to it, or in the event of a data breach occurring with such a third party.<\/p>\n<p>In the event of a personal data breach, the data fiduciary must notify the Data Protection Board and each affected data principal in a way determined by the Board. Upon notification of a breach or alleged breach, the Board will direct urgent remedial or mitigation measures, as well as performing inquiries regarding the breach and imposing penalties.<\/p>\n<h4>Penalties and fines<\/h4>\n<p>The Data Protection Board will have responsibility for determining penalties for violations and amounts of those penalties. Considerations for the severity of penalties imposed upon a data fiduciary will include:<\/p>\n<ul>\n<li>nature, gravity, and duration of the breach<\/li>\n<li>type and nature of the personal data affected by the breach<\/li>\n<li>repetitive nature of the breach<\/li>\n<li>whether the person, as a result of the breach, has realized a gain or avoided loss<\/li>\n<li>whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action<\/li>\n<li>whether the monetary penalty to be imposed is proportionate and effective (particularly regarding the need to enforce compliance with the Act and deter other violations)<\/li>\n<li>likely impact of the imposition of the monetary penalty on the person<\/li>\n<\/ul>\n<p>Sums received as penalties will be credited to the Consolidated Fund of India. The schedule of monetary penalties for a breach as outlined in the DPDP Act are as follows:<\/p>\n<table>\n<tbody>\n<tr>\n<th>Type of Breach<\/th>\n<th>Penalty<\/th>\n<\/tr>\n<tr>\n<td>Breach in observing the obligation to take reasonable security safeguards to prevent personal data breaches<\/td>\n<td>May extend to two hundred and fifty crore* rupees<\/td>\n<\/tr>\n<tr>\n<td>Breach in observing the obligation to give the Data Protection Board or affected data principal notice of a personal data breach<\/td>\n<td>May extend to two hundred crore rupees<\/td>\n<\/tr>\n<tr>\n<td>Breach in observance of additional obligations concerning children<\/td>\n<td>May extend to two hundred crore rupees<\/td>\n<\/tr>\n<tr>\n<td>Breach in observance of additional obligations of a Significant Data Fiduciary<\/td>\n<td>May extend to one hundred and fifty crore rupees<\/td>\n<\/tr>\n<tr>\n<td>Breach in observance of the duties regarding responsibilities to data principals<\/td>\n<td>May extend to ten thousand rupees<\/td>\n<\/tr>\n<tr>\n<td>Breach of any term of voluntary undertaking accepted by the Data Protection Board<\/td>\n<td>Up to the extent applicable for the breach in respect of which the proceedings of the Board were instituted<\/td>\n<\/tr>\n<tr>\n<td>Breach of any other provision of the DPDP Act or the rules made thereunder<\/td>\n<td>May extend to fifty crore rupees<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>*crore = 10,000,000, so 250 crore rupees equals 2.5 billion rupees, equivalent to ~US $30 million or ~\u20ac27.7 million.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-achieve-compliance-with-the-indian-data-privacy-law\">How to achieve compliance with the Indian data privacy law?<\/h2>\n\n\n<p>India\u2019s Digital Personal Data Protection Act brings data protections to over 17% of the world\u2019s population, and introduces compliance requirements to businesses wanting access to very large markets since it applies extraterritorially.<\/p>\n<h4>Understand the law and its business applications<\/h4>\n<p>For organizations familiar with or already compliant with established data privacy laws like the GDPR, the DPDP Act does not bring too many diversions or surprises. However, organizations should consult with qualified legal counsel and\/or a data privacy expert to ensure compliance needs are met.<\/p>\n<h4>The importance of consent for DPDP Act compliance<\/h4>\n<p>In many cases, organizations can achieve compliance by requesting data principals\u2019 consent before collecting or processing personal data. This must be done with clear and simple language, and explain what data would be collected, for what purpose(s), what the data principal\u2019s rights are, and how they can lodge complaints. The data must also be deleted once the purpose for processing is completed in most cases.<\/p>\n<h2><span style=\"font-weight: 400\">India\u2019s DPDP Act draft rules released<\/span><\/h2>\n<p><span style=\"font-weight: 400\">On January 3, 2025 the draft Digital Personal Data Protection Act (DPDPA) rules were released, and, shortly after, the AI Governance Guidelines Development Report was also released on January 6, 2025.<\/span><\/p>\n<p><span style=\"font-weight: 400\">These are some of the areas that include significant updates to India\u2019s data privacy framework in the draft rules.<\/span><\/p>\n<p><b>Consent:<\/b><span style=\"font-weight: 400\"> Requirements to inform individuals about personal data being processed, processing purpose, and services that will be enabled, and obtaining explicit written consent to collect sensitive personal data.<\/span><\/p>\n<p><b>Security measures: <\/b><span style=\"font-weight: 400\">Companies must implement detailed security measures via programs and policies to protect personal data and prevent breaches. Contracts must also be in place between data controllers and third-party processors.<\/span><\/p>\n<p><b>Data breach notices: <\/b><span style=\"font-weight: 400\">If a breach occurs the data controller must notify the Data Protection Board and affected individuals within 72 hours of discovery (unless the DPB grants an extended deadline).<\/span><\/p>\n<p><b>Data deletion:<\/b><span style=\"font-weight: 400\"> When an individual withdraws consent or the legal purpose for data collection and processing has been completed, personal data must be deleted. Data controllers must notify data subjects 48 hours in advance before deleting data.<\/span><\/p>\n<p><b>Officers:<\/b><span style=\"font-weight: 400\"> Specific requirements regarding appointing a Data Protection Officer, or, where not legally required, a professional responsible for addressing data subjects\u2019 concerns about personal data use. Information on appointed individuals must be included on companies\u2019 websites.<\/span><\/p>\n<p><b>Children\u2019s personal data and consent: <\/b><span style=\"font-weight: 400\">Verifiable consent must be obtained from a parent or legal guardian before processing a child\u2019s personal data. Processing of personal data is banned if it is likely to cause detrimental effects to a child\u2019s well-being, tracks or monitors their behavior, or uses advertising that targets them.<\/span><\/p>\n<p><b>Individuals with disabilities and consent: <\/b><span style=\"font-weight: 400\">Verifiable consent must be obtained from a parent or guardian before processing personal data of an individual with a disability if they cannot provide it personally.<\/span><\/p>\n<p><b>Cross-border data transfers: <\/b><span style=\"font-weight: 400\">The government may restrict or impose additional requirements for the transfer of personal data outside of India.<\/span><\/p>\n<p><b>Consent managers:<\/b><span style=\"font-weight: 400\"> Entities registered with the Data Protection board to assist companies and data controllers with consent management for personal data processing. Consent managers must be incorporated in India and have a net worth of at least 2 crore Indian rupees (approximately USD 230,000).<\/span><\/p>\n<p><span style=\"font-weight: 400\">No official timeline for implementation of the draft rules has been released, however, the Union Minister for Electronics and Information Technology has indicated a timeframe of two years. India\u2019s budget for 2025-2026 increased funding for the country\u2019s Data Protection Board.<\/span><\/p>\n<h3><span style=\"font-weight: 400\">AI Governance Guidelines Development Report<\/span><\/h3>\n<p><span style=\"font-weight: 400\">Given the current state of AI development in India, the AI Governance report recommended a regulatory approach that is principles-based and activity-focused, i.e. regulating specific AI applications, such as those relating to consumer safety, employment, and taxation rather than the entities creating and implementing such AI functions.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Generally, the subcommittee suggested a combination of voluntary commitments and standards combined with sectoral and\/or risk-based regulation of AI.<\/span><\/p>\n<p><span style=\"font-weight: 400\">India\u2019s 2025-2026 budget also provided funding for a proposed Centre of Excellence for AI to reinforce its focus on governance and digital infrastructure.<\/span><\/p>\n<h2>Know what your organization needs to do to achieve DPDP Act compliance<\/h2>\n<p>Organizations aiming to use legitimate interest as a legal basis for data processing need to be very careful and consult legal counsel, as the use of this option is quite restricted. Some organizations will also need to engage a Data Protection Officer, and others will just need to ensure there is an easily accessible contact person for data principals to engage with regarding exercising their rights. Organizations should also ensure they have a robust data breach response process in place.<\/p>\n<h3>The DPDP Act and consent management<\/h3>\n<p>A consent manager can help with achieving and maintaining compliance, and a consent management platform like <a href=\"https:\/\/usercentrics.com\/website-consent-management\/\">Usercentrics CMP<\/a> could be a valuable tool administered by a consent manager for enabling obtaining and managing consent from data principals. The DPDP Act does apply to the use of cookies and other tracking technologies on websites and apps.<\/p>\n<p>Organizations need to ensure contractual agreements are in place before engaging data processors. They need to be aware that they are responsible for the actions of third parties they have contracted, so data processing partners should be selected carefully after due diligence.<\/p>\n<p>If you have questions about how India\u2019s Digital Personal Data Protection Act may affect your business, or more generally about consent management for websites and apps, we\u2019re happy to help. <a href=\"https:\/\/usercentrics.com\/book-a-consultation\/?utm_source=blog_article&amp;utm_medium=content-distribution&amp;utm_campaign=in_dpdpa_blog_article_uc\">Contact one of our experts<\/a>!<\/p>\n<p><em>Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>The India Digital Personal Data Protection Act (DPDP Act or DPDPA) was passed and came into effect in August 2023. It bears similarities to the European Union\u2019s General Data Protection Regulation (GDPR) in scope, though there are some concerns about gaps and volume of exemptions.<\/p>\n","protected":false},"featured_media":8955,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[14,13],"class_list":["post-458","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>India Digital Personal Data Protection Act (DPDP Act) Overview<\/title>\n<meta name=\"description\" content=\"Learn about the data privacy implications and impact of the India DPDP Act on consumers and businesses with Usercentrics.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"India Digital Personal Data Protection Act (DPDP Act) Overview\" \/>\n<meta property=\"og:description\" content=\"Learn about the data privacy implications and impact of the India DPDP Act on consumers and businesses with Usercentrics.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-25T05:48:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"India Digital Personal Data Protection Act (DPDP Act): An Overview\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"22 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/\",\"url\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/\",\"name\":\"India Digital Personal Data Protection Act (DPDP Act) Overview\",\"isPartOf\":{\"@id\":\"https:\/\/usercentrics.com\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg\",\"datePublished\":\"2024-02-21T14:57:16+00:00\",\"dateModified\":\"2025-06-25T05:48:48+00:00\",\"description\":\"Learn about the data privacy implications and impact of the India DPDP Act on consumers and businesses with Usercentrics.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#primaryimage\",\"url\":\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg\",\"contentUrl\":\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg\",\"width\":1000,\"height\":1000,\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics.com\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"India Digital Personal Data Protection Act (DPDP Act): An Overview\",\"item\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/usercentrics.com\/us\/#website\",\"url\":\"https:\/\/usercentrics.com\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/usercentrics.com\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"India Digital Personal Data Protection Act (DPDP Act) Overview","description":"Learn about the data privacy implications and impact of the India DPDP Act on consumers and businesses with Usercentrics.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"India Digital Personal Data Protection Act (DPDP Act) Overview","og_description":"Learn about the data privacy implications and impact of the India DPDP Act on consumers and businesses with Usercentrics.","og_url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-25T05:48:48+00:00","og_image":[{"width":1000,"height":1000,"url":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"India Digital Personal Data Protection Act (DPDP Act): An Overview","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"22 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/","url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/","name":"India Digital Personal Data Protection Act (DPDP Act) Overview","isPartOf":{"@id":"https:\/\/usercentrics.com\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg","datePublished":"2024-02-21T14:57:16+00:00","dateModified":"2025-06-25T05:48:48+00:00","description":"Learn about the data privacy implications and impact of the India DPDP Act on consumers and businesses with Usercentrics.","breadcrumb":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#primaryimage","url":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg","contentUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/02\/India-Digital-Personal-Data-Protection-Act-DPDP-Act-min.jpg","width":1000,"height":1000,"copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics.com\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"India Digital Personal Data Protection Act (DPDP Act): An Overview","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics.com\/us\/#website","url":"https:\/\/usercentrics.com\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics.com\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/458\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media\/8955"}],"wp:attachment":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media?parent=458"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/tags?post=458"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_issue?post=458"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_tag?post=458"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/resource_tag?post=458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}