
The Act grants several important rights to the data principals (Individuals to whom data belongs) and impose certain obligations on the businesses and significant data fiduciaries.
The Act also provides enhanced protection for children under 18 years. It includes verifiable parental consent required before processing of data and businesses are prohibited from certain forms of tracking, behavioural monitoring, and targeted advertising involving children, subject to exemptions provided by the Rules.
The Act establishes the Data Protection Board of India, which is responsible for:
The DPDPA authorizes substantial financial penalties for non-compliance. Depending on the nature and seriousness of the contravention, penalties may extend to ₹250 crore for a single violation, including failures relating to reasonable security safeguards. Different contraventions attract different penalty limits under the Act.
Every Data Principal has the right to know how and why their personal data is being collected and processed. Before collecting any personal information, the Data Fiduciary must provide a clear, understandable, and easily accessible privacy notice explaining the purpose of data collection, the categories of data collected, the manner of processing, and the rights available under the Act. This ensures transparency and enables individuals to make informed decisions before sharing their personal information.
A Data Principal may request information regarding the processing of their personal data. Upon such a request, the Data Fiduciary must provide details such as the categories of personal data being processed, the processing activities undertaken, the identities of entities with whom the data has been shared (where applicable), and other information prescribed under the Act. This right enhances accountability and promotes openness in data handling practices.
Individuals have the right to request correction of inaccurate or misleading personal data, completion of incomplete information, and updating of outdated records. Furthermore, when the personal data is no longer required for the purpose for which it was collected, the Data Principal may seek its deletion, subject to any legal obligations requiring its retention. This right helps maintain accurate databases while reducing unnecessary data retention.
Consent is the foundation of lawful data processing under the Act. A Data Principal may withdraw consent at any time without providing any reason. Once consent is withdrawn, the Data Fiduciary must stop processing the personal data unless another legal ground exists for continuing such processing. The process for withdrawal must be as simple and accessible as the process through which consent was originally obtained.
If an individual believes that their rights under the Act have been violated or if the Data Fiduciary fails to address concerns regarding personal data processing, they have the right to file a grievance. Every organization must establish an effective grievance redressal mechanism and respond within the prescribed time. If the grievance remains unresolved, the individual may approach the Data Protection Board of India for further relief.
Recognizing the need for continuity of rights, the Act allows every Data Principal to nominate another individual who can exercise their rights in the event of death or incapacity. The nominated person may request access, correction, or deletion of personal data on behalf of the Data Principal. This provision ensures that digital rights remain protected even when the original individual is unable to exercise them personally.
Before collecting any personal data, businesses must provide a concise, plain-language privacy notice explaining the purpose of collection, the categories of personal data required, the rights available to the Data Principal, the grievance redressal mechanism, and the procedure for withdrawing consent. The notice should be easy to understand and should not contain misleading or ambiguous language. Transparent communication is the cornerstone of lawful data processing.
Businesses must obtain free, specific, informed, unconditional, and unambiguous consent before processing personal data, unless processing is permitted under legitimate uses recognized by the Act. Consent should be obtained through a clear affirmative action, and organizations should maintain proper records demonstrating that valid consent was obtained. Individuals should also be able to withdraw consent conveniently at any stage.
Where personal data is likely to be used for making decisions affecting individuals or disclosed to another Data Fiduciary, businesses must take reasonable steps to ensure that such data is accurate, complete, and up to date. Maintaining accurate records prevents unfair decisions, enhances customer confidence, and reduces the likelihood of disputes arising from incorrect information.
Every organization processing personal data must adopt appropriate technical and organizational measures to protect data against unauthorized access, accidental disclosure, loss, alteration, or cyberattacks. These safeguards may include encryption, multi-factor authentication, firewalls, regular vulnerability assessments, employee awareness training, secure cloud infrastructure, and periodic security audits. Strong cybersecurity practices are essential for preventing data breaches and ensuring regulatory compliance.
In the event of a personal data breach, businesses must promptly notify the Data Protection Board of India and, where required, inform the affected Data Principals. The notification should include details regarding the nature of the breach, its likely impact, remedial measures undertaken, and recommendations for mitigating potential harm. Timely reporting promotes transparency and enables swift corrective action to minimize risks.
Organizations should retain personal data only for as long as necessary to achieve the purpose for which it was collected or to comply with legal requirements. Once the purpose has been fulfilled and there is no statutory obligation to retain the information, businesses must securely erase or anonymize the personal data. Proper data retention and deletion practices reduce privacy risks and improve compliance with the Act.
Every business must create a robust mechanism for receiving, acknowledging, and resolving complaints from Data Principals regarding the processing of their personal data. Organizations should designate responsible officers, maintain complaint records, and ensure timely resolution of grievances. An efficient grievance redressal system strengthens consumer confidence and demonstrates the organization’s commitment to protecting privacy rights.
Businesses classified by the Central Government as Significant Data Fiduciaries are subject to enhanced compliance requirements due to the volume, sensitivity, or potential impact of the personal data they process. Such entities may be required to appoint a Data Protection Officer, conduct periodic Data Protection Impact Assessments, undergo independent data audits, and implement stronger governance mechanisms. These additional safeguards help address higher privacy risks associated with large-scale data processing.
Although the DPDP Act, 2023 itself has not undergone major statutory amendments, its implementation has significantly advanced through the Digital Personal Data Protection Rules, 2025. Key developments include: