Compliance

What Is the DPDP Act 2023? Plain-English Summary for Indian Businesses

India’s Digital Personal Data Protection Act explained without legal jargon — who it applies to, the core rules, and what your business must change.

Check your DPDP readiness — free More on the blog

What Is the DPDP Act 2023? Plain-English Summary for Indian Businesses

For years, Indian data privacy lived in Section 43A of the Information Technology Act, 2000 — a vague rule requiring "reasonable security practices" that resulted in almost zero public enforcement. That era ended with the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act). The DPDP Act is not merely a formality. It is an active compliance framework enforced by the Data Protection Board of India, equipped with statutory penalties reaching ₹250 crore per incident.

The vocabulary you need to know

  • Data Principal — the living individual whose personal data is collected (your customer, employee, website visitor, or vendor).
  • Data Fiduciary — the entity that determines the purpose and means of processing personal data (your company).
  • Data Processor — any service provider processing personal data on behalf of a Data Fiduciary (your cloud provider, payroll vendor, or CRM).
  • Data Protection Board of India (DPBI) — the adjudicatory body empowered to investigate breaches and levy penalties.

The five non-negotiable rules for every business

Regardless of whether you run a seed-stage SaaS product or an offline distributor with an online billing desk, five statutory duties apply immediately: Compliance is an engineering and operational inventory before it is a legal document. You cannot protect or delete data whose location you do not know.

  • Itemised Consent Notice — Section 5 requires you to present a clear, standalone notice before collecting any personal data, stating exactly what data is taken and for what specific purpose.
  • Unbundled Consent — Section 6 forbids pre-ticked boxes or burying consent inside long terms of service. Consent must be an unambiguous affirmative action.
  • Reasonable Security Safeguards — Section 8(5) commands businesses to implement technical and organisational measures to prevent breaches. Failing to do so carries the highest fine in Indian corporate law: up to ₹250 crore.
  • Mandatory Breach Notification — Section 8(6) requires immediate notification to both the Data Protection Board and every affected individual whenever a breach occurs.
  • Grievance Redressal Mechanism — Section 16 mandates publishing the contact details of a real person responsible for handling privacy complaints.

Where to begin your DPDP compliance

Start by mapping every entry point where personal data enters your systems: signup forms, checkout pages, employee onboarding packets, customer support inboxes, and CCTV systems. You can take our free DPDP readiness check to diagnose your statutory exposure across 21 risk factors in under 5 minutes. Then deploy our audited DPDP privacy policy template and sign a compliant vendor DPA with every external processor handling your customer records. For deep dives into the underlying statutory provisions, review our statute analyses for Section 5 consent notices, Section 6 consent validity, Section 8 fiduciary duties, Section 11 data principal rights, and Section 33 penalties.

Common questions

What is the DPDP Act 2023 in simple terms?

Passed in August 2023, the Digital Personal Data Protection Act (DPDP Act) is India's comprehensive data privacy legislation. It establishes rules for how organisations (Data Fiduciaries) collect, store, share, and delete digital personal data belonging to individuals (Data Principals), with statutory penalties up to ₹250 crore for non-compliance.

Does the DPDP Act apply to startups and small businesses?

Yes. The Act contains no turnover or employee threshold. Any business collecting digital personal data in India — including names, phone numbers, delivery addresses, or IP logs — is classified as a Data Fiduciary and must comply with consent notices, security safeguards, and breach reporting.

What are the main requirements of the DPDP Act 2023?

Core duties include: (1) giving a clear consent notice before data collection under Section 5; (2) obtaining unambiguous consent under Section 6; (3) taking reasonable security safeguards to prevent data breaches under Section 8(5); (4) mandatory breach reporting under Section 8(6); (5) erasing data when the purpose is served under Section 8(7); (6) publishing a grievance officer contact under Section 8(10) and Section 16; and (7) respecting Data Principal rights under Section 11.

What are the penalties under the DPDP Act?

Section 33 read with the Schedule prescribes monetary penalties up to ₹250 crore for failing to prevent a personal data breach, up to ₹200 crore for failing to report a breach to the Board and affected individuals, and up to ₹50 crore for other statutory lapses.

Related reading

  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
  • Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this