Reference
The DPDP Act 2023
The Digital Personal Data Protection Act 2023 (Act No. 22 of 2023) was enacted on 11 August 2023 and commences in three phases under notification G.S.R. 843(E) of 13 November 2025. Pick a section from the contents list to read its official Gazette text, its commencement status and the exact source behind every claim.
44 of 44 sections currently publish with verified Gazette text, alongside the Schedule of monetary penalties. Every entry in the contents list opens the official text with its commencement status and the exact source behind it.
Original document: the official Act PDF (Gazette print) ↗ · all official documents with verification dates are on the documents page.
How the Act commences
Notification G.S.R. 843(E), published in Gazette issue No. 757 with printed date 13 November 2025, brings the Act into force in three groups. Computed future dates are presented as interpretation until officially confirmed.
13 November 2025· official
Sections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) of the Act
13 November 2026· computed date, interpretation until officially confirmed
Section 6(9) and section 27(1)(d) of the Act
13 May 2027· computed date, interpretation until officially confirmed
Sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 other than section 27(1)(d), sections 28 to 34, sections 36 and 37, and section 44(2) of the Act
A guide to the Act, chapter by chapter
Chapter I, Preliminary (sections 1 to 3). The short title, the phased commencement power, and the definitions everything else builds on: section 2 defines the Data Principal, Data Fiduciary, Data Processor, personal data breach and the rest, and section 3 sets where the Act applies.
Chapter II, Obligations of Data Fiduciary (sections 4 to 10). The operational core: the two grounds of lawful processing, notice, consent, the certain legitimate uses, the general obligations including security safeguards and breach intimation, children's data and Significant Data Fiduciaries.
Chapter III, Rights and Duties of Data Principal (sections 11 to 15). The individual's side: access, correction and erasure, grievance redressal, nomination and the duties of Data Principals.
Chapter IV, Special Provisions (sections 16 and 17). Cross border transfer and the exemptions, including the startup exemption power.
Chapters V and VI, the Board (sections 18 to 28). Establishment and composition of the Data Protection Board of India, and its powers and functions and inquiry procedure.
Chapters VII and VIII, appeals and penalties (sections 29 to 34). Appeals to the Appellate Tribunal, voluntary undertakings, penalties and the Schedule of monetary penalty caps.
Chapter IX, Miscellaneous (sections 35 to 44). Protection of good faith action, the Central Government's power to call for information and rule making power, and consequential amendments to other laws.
For the full history from the Puttaswamy judgment to the latest notification, see the DPDP timeline. For a rule by rule cross reference, see the Act to Rules map. To check what applies to your organisation, start with the applicability checker.