Explainer 7 min read 15 November 2025

What is the DPDP Act? A Plain English Guide for Indian Businesses

The Digital Personal Data Protection Act 2023 is India's first comprehensive data law. What it means for your business — in plain language.

On November 13, 2025, a law came into force that every Indian business collecting customer data must know about. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — commonly called the DPDP Act — is India's first comprehensive data protection legislation. Miss it, and you face penalties up to ₹250 Crore.

Quick Answer: What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) is India's first comprehensive data protection law, in force since November 13, 2025. It requires any business collecting personal data of individuals in India to obtain consent (Section 6), give notice (Section 5), honour data rights, and report breaches — with penalties up to ₹250 Crore. Most business obligations begin May 13, 2027.

The One-Line Summary

If you collect personal data from customers in India — name, phone, email, address, payment info — you now have legal obligations about how you collect it, use it, store it, and delete it.

That's it. It doesn't matter if you're a ₹10 crore company or a one-person Instagram seller. If you collect data, the law applies to you.

Where Did It Come From?

India has needed a data protection law for decades. The Supreme Court declared privacy a fundamental right in 2017 (Justice K.S. Puttaswamy case). What followed was a long drafting journey — the Justice Srikrishna Committee draft in 2018, the Personal Data Protection Bill introduced in 2019, a Joint Parliamentary Committee report in 2021, and a fresh Digital Personal Data Protection Bill in 2022 (when the 2019 bill was withdrawn) — before the DPDP Act was finally passed in 2023.

The DPDP Act 2023 was finally passed by Parliament in August 2023, received Presidential assent on August 11, 2023, and came into force on November 13, 2025 via notification G.S.R. 843(E).

The accompanying DPDP Rules 2025 were notified on November 13, 2025 (G.S.R. 846(E)), with most enforcement provisions taking effect on May 13, 2027.

Who Must Comply? (Section 3)

The Act applies to:

The only businesses NOT covered are those that collect purely paper-based data that is never digitised. The moment you photograph a form, enter a number into a phone, or type anything into any software — you're covered.

Key Terms You Need to Know

What Are Your Main Obligations?

As a Data Fiduciary, you must:

When Do You Need to Be Compliant?

The Act is already in force (November 13, 2025). The DPDP Rules 2025 commence in phases: the Data Protection Board rules applied at once, the Consent Manager regime from November 13, 2026, and the core business-facing obligations (notice, consent, security, breach reporting, children's data and Data Principal rights) from May 13, 2027. This gives businesses roughly an 18-month window to build compliant systems.

Don't treat this as "I have 18 months to do nothing." Building consent management, DSR workflows, and breach notification systems takes time. The businesses that start now will be the ones that aren't scrambling in April 2027.

What Happens If You Don't Comply?

The Data Protection Board can impose penalties of up to:

These are maximums that apply per violation category, not a single overall cap. A business that both fails to get consent AND fails to notify a breach could, in principle, face penalties of up to ₹450 Crore in aggregate — though the Board sets the actual amount case by case using the factors in Section 33.

Bottom Line

The DPDP Act is not a bureaucratic formality. It represents a fundamental shift in how Indian businesses must treat customer data — as something that belongs to the customer, not the company. The 2027 deadline is real. Start building compliant systems now.

The DPDP Act is also not the only rulebook you are subject to. The IT Act and its SPDI Rules still bind you until May 2027, the CERT-In directions impose a six-hour breach report today, and your sector regulator may add more. Our guide comparing data privacy and compliance laws in India and globally lays out which frameworks are actually law for you and which are optional certifications.

References & Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Sections 3, 5, 6, 8; the Schedule).
  2. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
  3. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — commencement and phased implementation (core obligations from May 13, 2027).

This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; verify against the current notified version for your specific situation.

DPDP ActIndiaData ProtectionBasics

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts