Who does the DPDP Act apply to?
It applies to anyone processing digital personal data in India, and to processing outside India where goods or services are offered to people in India. It does not cover personal data processed for a purely personal or domestic purpose, or data made publicly available by the person themselves or under a legal obligation.
What is the penalty for a data breach in India?
Failing to take reasonable security safeguards carries a penalty of up to ₹250 crore. Failing to notify the Data Protection Board or affected Data Principals of a breach carries up to ₹200 crore. Penalties are set by the Board after an inquiry, weighing the nature, gravity, and duration of the breach.
What must a consent notice contain?
It must describe the personal data being sought, the purpose of processing, how a Data Principal may exercise their rights, and how to complain to the Board. It must be standalone, itemised, and written in plain language, and be available in English or any of the 22 languages in the Eighth Schedule.
What is a Significant Data Fiduciary?
A class the Central Government may notify based on the volume and sensitivity of data processed, risk to Data Principals, and impact on sovereignty, electoral democracy, and public order. Additional obligations follow: appointing a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments.
How is children's data treated under the DPDP Act?
Anyone under 18 is a child. Verifiable consent from a parent or lawful guardian is required before processing. Tracking, behavioural monitoring, and targeted advertising directed at children are prohibited, though the Government may exempt certain classes of Data Fiduciary.
When do the DPDP Rules come into force?
The Act received assent in August 2023 and is being brought into force in stages through notification. The Rules published in 2025 set out the operational detail — consent manager registration, breach intimation, and verifiable consent for children. Check the changes feed for the current commencement position.
Do I need a Data Protection Officer?
Only Significant Data Fiduciaries must appoint a Data Protection Officer, who has to be based in India and answerable to the board of directors or equivalent. Every Data Fiduciary must nevertheless publish the contact details of someone able to answer questions about processing.
What rights do individuals have?
A Data Principal can obtain a summary of the personal data being processed and the identities of others it has been shared with, ask for correction or erasure, nominate someone to act on their behalf in the event of death or incapacity, and use a grievance redressal route before approaching the Board.