Featured Article

India’s Digital Personal Data Protection Act, 2023: Privacy Becomes a Business Responsibility

Appreciation

0

Introduction

Data has become the most valuable asset in the digital economy. Every business, whether an e-commerce platform, fintech startup, healthcare company, ed-tech platform, or social media application, collects personal information from customers. Until recently, India lacked comprehensive legislation governing how such data should be collected, processed, stored, and protected. To address this gap, Parliament enacted the Digital Personal Data Protection Act, 2023, which received Presidential assent on 11 August 2023. The Act establishes India’s first comprehensive framework for protecting digital personal data. The law has since been operationalised through the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology, introducing phased compliance requirements for businesses. The Rules prescribe procedures relating to consent notices, breach reporting, rights of individuals, obligations of data fiduciaries, and the functioning of the Data Protection Board of India. For entrepreneurs, founders, and companies planning to start operations in India, compliance with the DPDPA is no longer optional; it is a fundamental legal obligation and a competitive advantage that builds consumer trust. The Digital Personal Data Protection Act seeks to: 1. Protect individuals’ personal data. 2. Regulate lawful processing of digital personal data. 3. Promote responsible data governance. 4. Increase trust in India’s digital economy. 5. Encourage innovation while ensuring privacy. 6. Establish accountability for organizations processing personal data.

Core Principles of the Act

The Act grants several important rights to the data principals (Individuals to whom data belongs) and impose certain obligations on the businesses and significant data fiduciaries.

The Act also provides enhanced protection for children under 18 years. It includes verifiable parental consent required before processing of data and businesses are prohibited from certain forms of tracking, behavioural monitoring, and targeted advertising involving children, subject to exemptions provided by the Rules.

The Act establishes the Data Protection Board of India, which is responsible for:

  1. Investigating violations
  2. Hearing complaints
  3. Imposing penalties
  4. Issuing directions
  5. Encouraging compliance

The DPDPA authorizes substantial financial penalties for non-compliance. Depending on the nature and seriousness of the contravention, penalties may extend to ₹250 crore for a single violation, including failures relating to reasonable security safeguards. Different contraventions attract different penalty limits under the Act.

RIGHTS OF DATA PRINCIPALS

  • RIGHT TO INFORMATION

Every Data Principal has the right to know how and why their personal data is being collected and processed. Before collecting any personal information, the Data Fiduciary must provide a clear, understandable, and easily accessible privacy notice explaining the purpose of data collection, the categories of data collected, the manner of processing, and the rights available under the Act. This ensures transparency and enables individuals to make informed decisions before sharing their personal information.

  • RIGHT TO ACCESS

A Data Principal may request information regarding the processing of their personal data. Upon such a request, the Data Fiduciary must provide details such as the categories of personal data being processed, the processing activities undertaken, the identities of entities with whom the data has been shared (where applicable), and other information prescribed under the Act. This right enhances accountability and promotes openness in data handling practices.

  • RIGHT TO CORRECTION, COMPLETION, UPDATING AND ERASURE

Individuals have the right to request correction of inaccurate or misleading personal data, completion of incomplete information, and updating of outdated records. Furthermore, when the personal data is no longer required for the purpose for which it was collected, the Data Principal may seek its deletion, subject to any legal obligations requiring its retention. This right helps maintain accurate databases while reducing unnecessary data retention.

  • RIGHT TO WITHDRAW CONSENT

Consent is the foundation of lawful data processing under the Act. A Data Principal may withdraw consent at any time without providing any reason. Once consent is withdrawn, the Data Fiduciary must stop processing the personal data unless another legal ground exists for continuing such processing. The process for withdrawal must be as simple and accessible as the process through which consent was originally obtained.

  • RIGHT TO GRIEVANCE REDRESSAL

If an individual believes that their rights under the Act have been violated or if the Data Fiduciary fails to address concerns regarding personal data processing, they have the right to file a grievance. Every organization must establish an effective grievance redressal mechanism and respond within the prescribed time. If the grievance remains unresolved, the individual may approach the Data Protection Board of India for further relief.

  • RIGHT TO NOMINATE

Recognizing the need for continuity of rights, the Act allows every Data Principal to nominate another individual who can exercise their rights in the event of death or incapacity. The nominated person may request access, correction, or deletion of personal data on behalf of the Data Principal. This provision ensures that digital rights remain protected even when the original individual is unable to exercise them personally.

OBLIGATIONS OF BUISNESSES

  • DUTY TO PROVIDE A CLEAR PRIVACY NOTICE

Before collecting any personal data, businesses must provide a concise, plain-language privacy notice explaining the purpose of collection, the categories of personal data required, the rights available to the Data Principal, the grievance redressal mechanism, and the procedure for withdrawing consent. The notice should be easy to understand and should not contain misleading or ambiguous language. Transparent communication is the cornerstone of lawful data processing.

  • DUTY TO OBTAIN VALID CONSENT

Businesses must obtain free, specific, informed, unconditional, and unambiguous consent before processing personal data, unless processing is permitted under legitimate uses recognized by the Act. Consent should be obtained through a clear affirmative action, and organizations should maintain proper records demonstrating that valid consent was obtained. Individuals should also be able to withdraw consent conveniently at any stage.

  • DUTY TO ENSURE DATA ACCURACY

Where personal data is likely to be used for making decisions affecting individuals or disclosed to another Data Fiduciary, businesses must take reasonable steps to ensure that such data is accurate, complete, and up to date. Maintaining accurate records prevents unfair decisions, enhances customer confidence, and reduces the likelihood of disputes arising from incorrect information.

  • DUTY TO IMPLEMENT REASONABLE SECURITY SAFEGUARDS

Every organization processing personal data must adopt appropriate technical and organizational measures to protect data against unauthorized access, accidental disclosure, loss, alteration, or cyberattacks. These safeguards may include encryption, multi-factor authentication, firewalls, regular vulnerability assessments, employee awareness training, secure cloud infrastructure, and periodic security audits. Strong cybersecurity practices are essential for preventing data breaches and ensuring regulatory compliance.

  • DUTY TO REPORT PERSONAL DATA BREACHES

In the event of a personal data breach, businesses must promptly notify the Data Protection Board of India and, where required, inform the affected Data Principals. The notification should include details regarding the nature of the breach, its likely impact, remedial measures undertaken, and recommendations for mitigating potential harm. Timely reporting promotes transparency and enables swift corrective action to minimize risks.

  • DUTY TO DELETE PERSONAL DATA AFTER PURPOSE IS FULFILLED

Organizations should retain personal data only for as long as necessary to achieve the purpose for which it was collected or to comply with legal requirements. Once the purpose has been fulfilled and there is no statutory obligation to retain the information, businesses must securely erase or anonymize the personal data. Proper data retention and deletion practices reduce privacy risks and improve compliance with the Act.

  • DUTY TO ESTABLISH AN EFFECTIVE GRIEVANCE REDRESSAL MECHANISM

Every business must create a robust mechanism for receiving, acknowledging, and resolving complaints from Data Principals regarding the processing of their personal data. Organizations should designate responsible officers, maintain complaint records, and ensure timely resolution of grievances. An efficient grievance redressal system strengthens consumer confidence and demonstrates the organization’s commitment to protecting privacy rights.

  • ADDITIONAL OBLIGATIONS OF SIGNIFICANT DATA FIDUCIARIES

Businesses classified by the Central Government as Significant Data Fiduciaries are subject to enhanced compliance requirements due to the volume, sensitivity, or potential impact of the personal data they process. Such entities may be required to appoint a Data Protection Officer, conduct periodic Data Protection Impact Assessments, undergo independent data audits, and implement stronger governance mechanisms. These additional safeguards help address higher privacy risks associated with large-scale data processing.

Recent Developments and Amendments

Although the DPDP Act, 2023 itself has not undergone major statutory amendments, its implementation has significantly advanced through the Digital Personal Data Protection Rules, 2025. Key developments include:

  1. Notification of detailed operational rules by MeitY.
  2. Phased implementation schedule allowing organizations time to achieve compliance.
  3. Procedures for consent notices and consent management.
  4. Mandatory breach reporting processes.
  5. Operational framework for the Data Protection Board of India.
  6. Clarification of obligations relating to retention, deletion, grievance handling, and children’s data.

Conclusion

The Digital Personal Data Protection Act, 2023, together with the Digital Personal Data Protection Rules, 2025, marks a significant shift in India’s digital regulatory landscape. It places individuals at the center of data governance while requiring organizations to adopt transparent, secure, and accountable data practices. For companies planning to commence business in India, integrating privacy into product design, internal governance, and operational processes from the outset is essential. Organizations that embed data protection into their culture are likely to enjoy greater consumer trust, stronger investor confidence, and sustainable long-term growth in India’s rapidly expanding digital economy. Privacy compliance should therefore be viewed as a strategic business investment rather than merely a regulatory burden.

Appreciation

0

Latest News And Updates