Every app that asks for your phone number, address or Aadhaar now sits under a new law. The Digital Personal Data Protection Act, 2023 (the DPDP Act) decides what it may do with that information.
What is the DPDP Act, 2023?
It is India’s first general law on personal data. It covers data collected in digital form, and data collected on paper and then digitised. It applies inside India. It also applies to processing outside India when the aim is to offer goods or services to people here.
Two terms matter. The Data Principal is the person the data is about. The Data Fiduciary is the business or body that decides why and how the data is used.
Your rights as a Data Principal
- Access. You can ask what personal data is held about you and who it has been shared with (section 11).
- Correction and erasure. You can ask for wrong data to be corrected and for data no longer needed to be erased (section 12).
- Grievance redressal. You must first complain to the company. If it does not respond, you can go to the Data Protection Board (section 13).
- Nomination. You can name someone to exercise your rights if you die or cannot act (section 14).
You also have duties. You must not make false or frivolous complaints (section 15).
What businesses must do
- Give a clear notice in plain language when asking for consent (section 5).
- Take free, specific and informed consent. Let people withdraw it as easily as they gave it (section 6).
- Collect only what the stated purpose needs. Erase the data when the purpose ends.
- Keep reasonable security safeguards. Report a personal data breach to the Board and to affected people (section 8).
- Obtain verifiable parental consent before using a child’s data. Do not track children or target advertising at them (section 9).
- Larger “significant data fiduciaries” have extra duties, such as audits and an India-based data protection officer (section 10).
The DPDP Rules, 2025 and the timeline
The Rules were notified on 13 November 2025. They start in phases. The rules on the Data Protection Board took effect at once. The rules on consent managers follow after one year. Most duties for businesses follow after 18 months, in about May 2027.
In January 2026 MeitY proposed a shorter period. Check the latest position before you plan your timetable. Our regulatory update on the timeline tracks it.
What are the penalties?
The Schedule to the Act sets ceilings. Failing to keep reasonable security safeguards can attract up to ₹250 crore. Failing to report a breach, or breaching the rules on children’s data, can attract up to ₹200 crore.
What to do now
- Individuals: read privacy notices, and use the erasure and correction requests when a service no longer needs your data.
- Businesses: list the personal data you hold, update notices and consent screens, set retention periods, and write a breach response plan.
Key takeaway
Start with a data map. If you cannot say what personal data you hold, and why, you cannot meet the Act’s core duties.