DPDP Act 2023: India’s Privacy Law in Force, Exam-Ready Notes

CommerceCommerce10 min read

On 11 August 2023, India finally enacted a dedicated data protection law — the Digital Personal Data Protection Act, 2023, or DPDP Act — twenty-three years after the IT Act first touched electronic data and six years after the Supreme Court declared privacy a fundamental right. Then the statute went quiet for more than two years, before switching on in phases from 13 November 2025 and receiving its operational rulebook, the DPDP Rules, 2025, the very next day.

The Act belongs to the same recodification season as the four labour codes now in force, the BNS–BNSS–BSA criminal-law overhaul and the welfare-employment statute mapped in our VB-G RAM-G explainer — one parliament, many rewires. This brief compresses the whole DPDP story — the six-year legislative slog, the cast of fiduciaries and principals, the rights pack, the ₹50-crore penalty floor, the 2025 Rules and the exam angles — into one revision card.

What the DPDP Act Actually Does

Four lines before the detail — the what, the reach, the philosophy and the switch-on.

  1. The headliner. The DPDP Act, 2023 creates India’s first comprehensive framework for the protection of digital personal data — collected online, or offline and later digitised.
  2. The reach. It binds every Data Fiduciary processing an Indian resident’s data — startups, big tech platforms and government departments alike.
  3. The philosophy. Consent-led processing: your data moves only with your informed, unambiguous and freely given permission, with narrow listed exemptions.
  4. The switch-on. Phased commencement from 13 November 2025 through 13 May 2027, with the Data Protection Board of India live from day one.

From Puttaswamy to the President: The Six-Year Slog

Every exam set-piece on this law begins with the case and ends with the timetable — learn the ladder.

  1. The verdict. On 24 August 2017, a nine-judge Constitution Bench in Justice K. S. Puttaswamy v. Union of India held privacy to be a fundamental right under Article 21 and Part III of the Constitution.
  2. The committee. MeitY constituted a committee of experts under Justice B. N. Srikrishna in December 2017; it released a draft Personal Data Protection Bill in July 2018 with its report.
  3. The 2019 Bill. The Personal Data Protection Bill, 2019 was cleared by Cabinet on 4 December and tabled on 11 December 2019, then sent to a Joint Parliamentary Committee chaired by Meenakshi Lekhi.
  4. The long pause. The JPC reported on 16 December 2021 — and the Bill was finally withdrawn on 3 August 2022 after broad criticism.
  5. The critiques. Justice Srikrishna himself warned the 2019 Bill could turn India into an “Orwellian State”; critics flagged blanket government powers to access citizens’ data.
  6. The 2022 draft. MeitY released the draft DPDP Bill, 2022 on 18 November 2022 for public consultation, with the comment deadline extended from 17 December 2022 to 2 January 2023.
  7. The sprint. Cabinet approved the revised Bill on 5 July 2023; Ashwini Vaishnaw introduced it on 3 August; Lok Sabha passed it on 7 August; Rajya Sabha on 9 August; President Droupadi Murmu assented on 11 August 2023.

The Statute at a Glance

The identification card every prelims paper can ask for — numbers, names and dates.

  1. The citation. The Digital Personal Data Protection Act, 2023 is Act No. 22 of 2023, introduced as Bill No. 113 of 2023 by the Minister of Electronics and Information Technology.
  2. The first. It is the first Act of the Indian Parliament drafted using “she” and “her” for all individuals, in place of the usual “he” and “him”.
  3. The scope limit. It covers digital personal data alone — including offline data later digitised — leaving purely offline personal data outside its net.
  4. The administrator. The Union Ministry of Electronics and Information Technology (MeitY) administers the Act and notified its Rules.
  5. The commencement ladder. 13 November 2025 brought the core machinery into force (including sections 18 to 26 establishing the Board); 13 November 2026 adds two further provisions; 13 May 2027 switches on the remainder.
  6. The status. In force — a phased roll-out, with the DPDP Rules, 2025 notified on 14 November 2025 to operationalise it.

The Cast: Fiduciaries, Principals and the Board

Three defined actors run the entire statute — match each to its role.

  1. The fiduciary. The Data Fiduciary is any person, company or government entity that decides why and how personal data is processed — the obligation-bearer of the Act.
  2. The principal. The Data Principal is the individual whose data it is — the rights-holder, who also carries duties such as furnishing only authentic information.
  3. The board. The Data Protection Board of India, created under section 18, adjudicates disputes between principals and fiduciaries and enforces compliance.
  4. The design choice. The Board is an adjudicator, not a day-to-day regulator — government clarified this distinction at enactment itself.
  5. The working style. Under the 2025 Rules the Board runs digital-first proceedings, with its composition and appointment process set out in detail.

The Rights Pack

Seven rights and shields every Data Principal carries — the heart of the statute.

  1. The access right. A principal is entitled to know what personal data a fiduciary holds and how it is being processed.
  2. The correction and erasure right. Errors can be corrected and data can be erased — the right to be forgotten in Indian statutory form.
  3. The consent switch. Consent, once given, can be revoked at any time through the same ease with which it was granted.
  4. The grievance lane. Every fiduciary must offer grievance redressal before a principal can escalate to the Board.
  5. The nominee. A principal may nominate a consent manager to exercise data rights on her behalf — including in the event of death or incapacity.
  6. The child shield. For children under 18, processing detrimental to well-being is banned outright — no tracking, no behavioural monitoring, no targeted advertising; the Rules add verifiable guardian consent.
  7. The language guarantee. Data-collection notices and terms must be available in all 22 languages of the Eighth Schedule — accessibility written into the statute.

Duties, Penalties and the ₹50-Crore Floor

Obligations on one side, money on the other — the compliance engine of the Act.

  1. The penalty floor. The minimum penalty for breach of the Act’s obligations is ₹50 crore — a figure designed to concentrate corporate boards’ attention.
  2. The notice duty. Fiduciaries must present clear, concise notices stating the purpose of processing, the categories of data, retention periods and how to withdraw consent.
  3. The breach alarm. Personal data breaches must be reported to the Data Protection Board and to every affected principal within prescribed timelines.
  4. The paperwork. Record-keeping and audit obligations — including annual audits for significant fiduciaries — keep enforcement evidence ready.
  5. The principal’s duties too. Data Principals must not furnish false information or impersonate others — the statute disciplines both sides of the bargain.
  6. The breathing room. Phased compliance timelines let startups and small enterprises adapt without the full burden landing on day one.

The Rules of 2025: The Act Gets Operational

The Act waited two years for its rulebook; the Rules arrived one day after commencement.

  1. The date. MeitY notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025 — the day after the Act’s first commencement tranche.
  2. The route taken. The final Rules followed draft releases and stakeholder consultation, and were presented as the last step to operationalise India’s data-protection framework.
  3. The consent code. The Rules spell out informed, unambiguous and freely given consent — with withdrawal mechanisms guaranteed alongside.
  4. The vulnerable-groups cover. Enhanced protections extend to children’s data and to persons with disabilities, with lawful guardian oversight where appropriate.
  5. The border question. Cross-border transfers proceed under conditions and safeguards, with the Central Government retaining the power to specify permitted countries and mechanisms.
  6. The quiet rider. Reporting on the notification day also flagged a consequential amendment to the Right to Information Act — worth one prepared line in mains.

The GDPR Mirror

India’s statute consciously converses with Europe’s — similarities and departures both are exam material.

  1. The family resemblance. The DPDP Act and the EU’s General Data Protection Regulation share core principles: consent, transparency, breach response and enforceable individual rights.
  2. The reach difference. GDPR protects personal data in every form; the DPDP Act protects digital personal data only — the most cited contrast.
  3. The taxonomy difference. The DPDP Act declines to create a separate category of sensitive personal data, which GDPR singles out for stricter handling.
  4. The legal-bases difference. Both grant similar rights but differ in their approach to the lawful bases for processing — GDPR lists six, the DPDP Act leans on consent plus exemptions.
  5. The exam hook. Three differences — scope, sensitivity, legal bases — and one similarity — rights — answer every comparison question set on this pair.

Exemptions and Criticism

Six lawful gateways out of the consent regime — and the critiques that shadow the statute.

  1. The rights-enforcement gateway. Processing necessary to enforce any legal right or claim is exempt from the consent architecture.
  2. The courts gateway. Courts, tribunals and other judicial or quasi-judicial bodies may process data needed for their functions.
  3. The investigations gateway. Processing for prevention, detection, investigation or prosecution of offences stands outside the consent net.
  4. The offshore-contract gateway. Data of principals outside India, processed under a contract with an India-based person, is exempt.
  5. The two niche gateways. Court-approved mergers and reconstructions, and ascertaining the financial position of loan defaulters, complete the exemption list.
  6. The offline gap. Critics point out that personal data never digitised — paper forms, manual records — enjoys no protection framework at all.
  7. The RTI shave. The Act’s consequential amendment to the RTI Act is read by transparency advocates as narrowing the disclosure regime — a mains-ready critique.

How Exams Probe This Topic

Match the actors, climb the date ladder, count the money — and prepare one mains essay on digital rights.

  1. The date ladder. Puttaswamy 24 August 2017 → 2019 Bill withdrawn 3 August 2022 → Act passed 7–9 August 2023 → assent 11 August 2023 → commencement 13 November 2025 → Rules 14 November 2025.
  2. The actors match. Fiduciary to obligations, Principal to rights, Board to adjudication — the most bankable matching set of the data-law syllabus.
  3. The number card. Act 22 of 2023, Bill 113 of 2023, ₹50 crore minimum penalty, 22 notice languages, children under 18 — five numbers, five statements.
  4. The case law. Puttaswamy is the doctrinal foundation — pair the 2017 verdict with Article 21 and Part III in any prelims framing.
  5. The comparison. Expect one GDPR-versus-DPDP question: digital-only scope, no sensitive-data category, divergent legal bases.
  6. The mains frame. Place the Act inside the reform season — data protection here, the four labour codes now in force at work, the BNS–BNSS–BSA criminal-law overhaul in the courts — and ask what a rights-first digital state requires.

Quick Revision: One-Glance Facts

Carry these into the hall — the entire DPDP story folds into one card.

  1. The citation. Digital Personal Data Protection Act, 2023 = Act No. 22 of 2023, from Bill No. 113 of 2023, introduced by Ashwini Vaishnaw.
  2. The dates. Passed 7 and 9 August 2023; assent 11 August 2023; first tranche in force 13 November 2025; Rules notified 14 November 2025; full force 13 May 2027.
  3. The actors. Data Fiduciary, Data Principal, Data Protection Board of India (section 18) — obligations, rights, adjudication.
  4. The rights. Access, correction and erasure, consent revocation, grievance redressal, consent-manager nomination, child protections.
  5. The money. Minimum penalty for breach: ₹50 crore.
  6. The shields. Children under 18: no tracking, no behavioural monitoring, no targeted advertising; notices in 22 Eighth-Schedule languages.
  7. The firsts. India’s first she/her-drafted Act; first dedicated data-protection statute; Board live from 13 November 2025.

Conclusion: The Long Game Paid Off

The DPDP Act is best read as India’s slowest and steadiest digital reform: one verdict, two bills, six years and one pandemic-era rewrite produced a consent-first, Board-enforced, penalty-backed framework that switched on in deliberate phases. For prelims, the topic is pure goldmine arithmetic — Act 22, Bill 113, ₹50 crore, 22 languages, under-18, 13 November. For mains, the richer question is architectural: a digital-only statute, an adjudicating rather than regulating Board, and six exemption gateways leave plenty to argue about. Learn the card, watch the Rules roll out through 2027, and this topic is banked.

Quick revision

  • The headliner.: The DPDP Act, 2023 creates India’s first comprehensive framework for the protection of digital personal data — collected online, or offline…
  • The reach.: It binds every Data Fiduciary processing an Indian resident’s data — startups, big tech platforms and government departments alike.
  • The philosophy.: Consent-led processing: your data moves only with your informed, unambiguous and freely given permission, with narrow listed exemptions.
  • The switch-on.: Phased commencement from 13 November 2025 through 13 May 2027, with the Data Protection Board of India live from day one.
  • The verdict.: On 24 August 2017, a nine-judge Constitution Bench in Justice K.
  • The committee.: MeitY constituted a committee of experts under Justice B.