On November 13, 2025, a law came into force that every Indian business collecting customer data must know about. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — commonly called the DPDP Act — is India's first comprehensive data protection legislation. Miss it, and you face penalties up to ₹250 Crore.
Quick Answer: What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) is India's first comprehensive data protection law, in force since November 13, 2025. It requires any business collecting personal data of individuals in India to obtain consent (Section 6), give notice (Section 5), honour data rights, and report breaches — with penalties up to ₹250 Crore. Most business obligations begin May 13, 2027.
The One-Line Summary
If you collect personal data from customers in India — name, phone, email, address, payment info — you now have legal obligations about how you collect it, use it, store it, and delete it.
That's it. It doesn't matter if you're a ₹10 crore company or a one-person Instagram seller. If you collect data, the law applies to you.
Where Did It Come From?
India has needed a data protection law for decades. The Supreme Court declared privacy a fundamental right in 2017 (Justice K.S. Puttaswamy case). What followed was a long drafting journey — the Justice Srikrishna Committee draft in 2018, the Personal Data Protection Bill introduced in 2019, a Joint Parliamentary Committee report in 2021, and a fresh Digital Personal Data Protection Bill in 2022 (when the 2019 bill was withdrawn) — before the DPDP Act was finally passed in 2023.
The DPDP Act 2023 was finally passed by Parliament in August 2023, received Presidential assent on August 11, 2023, and came into force on November 13, 2025 via notification G.S.R. 843(E).
The accompanying DPDP Rules 2025 were notified on November 13, 2025 (G.S.R. 846(E)), with most enforcement provisions taking effect on May 13, 2027.
Who Must Comply? (Section 3)
The Act applies to:
- Section 3(a)(i): Any business that collects personal data of individuals in India in digital form — websites, apps, WhatsApp, Instagram DMs, online checkouts.
- Section 3(a)(ii): Any business that collects data in non-digital form (paper forms, POS) and then digitises it — entering numbers into Excel, a phone, billing software, or any computer.
- Section 3(b): Businesses outside India that offer goods or services to individuals in India — a UK or US company with Indian customers must also comply.
The only businesses NOT covered are those that collect purely paper-based data that is never digitised. The moment you photograph a form, enter a number into a phone, or type anything into any software — you're covered.
Key Terms You Need to Know
- Data Principal: The individual whose data is being collected. Your customer.
- Data Fiduciary: The business that decides what data to collect and why. You.
- Data Processor: A third party that processes data on your behalf — Razorpay, Shiprocket, your email tool. You're still responsible for their compliance as the Data Fiduciary.
- Consent Manager: An entity registered with the government through which individuals can manage their consent across multiple fiduciaries.
- Data Protection Board (DPB): The government body that will hear complaints, investigate breaches, and impose penalties.
What Are Your Main Obligations?
As a Data Fiduciary, you must:
- Get consent before collecting data — free, informed, specific, and unconditional (Section 6). The customer must know exactly what you're collecting and why. See our DPDP consent requirements guide for what valid consent looks like.
- Publish a privacy notice (Section 5) — in clear language, listing what data, what purpose, how long, and how they can exercise rights. Our privacy notice guide with template walks through it.
- Respond to Data Subject Requests (DSRs) — customers can ask to see, correct, or delete their data. You must respond.
- Notify breaches within 72 hours — to the Data Protection Board and affected individuals under the 72-hour breach notification rule (Section 8(6)).
- Delete data when the purpose is fulfilled — you cannot keep customer data indefinitely (Section 8(7)).
When Do You Need to Be Compliant?
The Act is already in force (November 13, 2025). The DPDP Rules 2025 commence in phases: the Data Protection Board rules applied at once, the Consent Manager regime from November 13, 2026, and the core business-facing obligations (notice, consent, security, breach reporting, children's data and Data Principal rights) from May 13, 2027. This gives businesses roughly an 18-month window to build compliant systems.
Don't treat this as "I have 18 months to do nothing." Building consent management, DSR workflows, and breach notification systems takes time. The businesses that start now will be the ones that aren't scrambling in April 2027.
What Happens If You Don't Comply?
The Data Protection Board can impose penalties of up to:
- ₹250 Crore for failure to implement adequate data security / data breach (see our complete DPDP penalties guide)
- ₹200 Crore for failure to notify a data breach
- ₹200 Crore for violations involving children's data
- ₹50 Crore for other violations (consent, privacy notice, DSR)
These are maximums that apply per violation category, not a single overall cap. A business that both fails to get consent AND fails to notify a breach could, in principle, face penalties of up to ₹450 Crore in aggregate — though the Board sets the actual amount case by case using the factors in Section 33.
Bottom Line
The DPDP Act is not a bureaucratic formality. It represents a fundamental shift in how Indian businesses must treat customer data — as something that belongs to the customer, not the company. The 2027 deadline is real. Start building compliant systems now.
References & Sources
- Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Sections 3, 5, 6, 8; the Schedule).
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — commencement and phased implementation (core obligations from May 13, 2027).
This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; verify against the current notified version for your specific situation.