The Digital Personal Data Protection Act (DPDP Act) is India's landmark legislation governing the processing of personal digital data. It establishes a legal framework designed to balance an individual's right to protect their personal data with the need to process data for lawful purpose.
Key Terminology
Data Principal: The individual to whom the personal data belongs (the user/consumer).
Data Fiduciary: The entity (company, startup, or government body) that determines the purpose and means of processing personal data.
Data Processor: An entity that processes personal data on behalf of a Data Fiduciary.
Significant Data Fiduciary (SDF): Entities categorized by the central government based on data volume, sensitivity, or risk factors, facing stricter regulatory mandates.
Core Principles
Lawful & Transparent Processing: Personal data can only be processed for legitimate, stated purposes with clear user notices.
Purpose Limitation: Data must be collected solely for specified operational purposes; fresh consent is required for new uses.
Data Minimization: Organizations must collect only the minimum amount of data strictly necessary for the service.
Storage Limitation: Personal data should be deleted once the intended purpose has been served or consent is withdrawn, unless legally mandated otherwise.
Key Rights of Data Principals
Right to Information & Access: Request summaries of personal data processed and third-party sharing details.
Right to Correction & Erasure: Update inaccurate details or request deletion of personal data.
Right to Grievance Redressal: Access clear channels to resolve complaints directly with the entity.
Right to Nominate: Name a representative to exercise privacy rights in the event of death or incapacity.
Organizational Compliance Obligations
┌───────────────────────────────┐
│ Consent & Transparency │
│ • Clear, itemized notices │
│ • Multilingual accessibility │
│ • Easy consent withdrawal │
└──────────────┬────────────────┘
│
▼
┌───────────────────────────────┐
│ Security Safeguards │
│ • Technical & admin controls │
│ • Mandatory breach notices │
│ • Vendor/Processor oversight │
└──────────────┬────────────────┘
│
▼
┌───────────────────────────────┐
│ Special Safeguards │
│ • Children's data rules │
│ • SDF audit & DPO roles │
└───────────────────────────────┘
Explicit Consent: Processing relies on free, specific, informed, and unambiguous consent via affirmative action. Privacy notices must be provided in English and all 22 scheduled Indian languages.
Security Safeguards & Breach Notification: Reasonable security measures (e.g., encryption, access controls) are required. Breaches must be promptly reported to both the Data Protection Board of India (DPBI) and affected individuals.
Children’s Data Protection: Processing data of minors requires verifiable parental consent, with restrictions on behavioral tracking and targeted advertising.
SDF Governance: Significant Data Fiduciaries must appoint an India-resident Data Protection Officer (DPO), conduct independent data protection impact assessments, and complete periodic audits.
Enforcement & Financial Penalties
The Act is enforced by the Data Protection Board of India (DPBI). It focuses on substantial monetary penalties rather than criminal sanctions:
Violation / Non-Compliance Maximum Penalty
Failure to implement reasonable security safeguards to prevent data breach Up to ₹250 Crore
Failure to notify DPBI or individuals of a personal data breach Up to ₹200 Crore
Non-compliance with obligations regarding children's data Up to ₹200 Crore
Failure to comply with Significant Data Fiduciary obligations Up to ₹150 Crore