What is DPDP? India's data protection law, explained from the official text
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act 2023, Act No. 22 of 2023, is India's law for processing digital personal data; it received the President's assent on 11 August 2023 and recognises both the individual's right to protect personal data and the need to process it for lawful purposes. The DPDP Rules 2025, notified on 13 November 2025, operationalise the Act. Both commence in phases: some provisions have been in force since 13 November 2025, Consent Manager registration is due on a computed date of 13 November 2026, and the main obligations are due on a computed date of 13 May 2027, both interpretation until officially confirmed. The law applies to digital personal data processed in India, and to processing abroad connected with offering goods or services to people in India.
DPDP stands for Digital Personal Data Protection. Depending on context, people use the abbreviation for the law itself, the DPDP Act 2023, or for the framework as a whole, the Act together with the DPDP Rules 2025. This page is the short, sourced version of both.
The DPDP Act 2023
The Digital Personal Data Protection Act, 2023 is Act No. 22 of 2023, enacted by Parliament with the President's assent on 11 August 2023. Its purpose fits in one sentence, its own:
"An Act to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto."
Long title of the DPDP Act 2023.
The Act has 44 sections and one Schedule of monetary penalties. In outline: it defines who is who (the Data Principal is the individual the data is about, the Data Fiduciary decides why and how data is processed, the Data Processor processes on a fiduciary's behalf), permits processing only on consent or certain legitimate uses, sets obligations for fiduciaries such as notice, security safeguards, breach intimation and erasure, gives individuals rights of access, correction, erasure, grievance redressal and nomination, creates the Data Protection Board of India to enforce all of it, and caps penalties at amounts up to two hundred and fifty crore rupees. Every section is on this site with its official Gazette text: start at the Act explorer.
The DPDP Rules 2025
The Act delegates the operational detail to rules. The DPDP Rules 2025 were notified as G.S.R. 846(E) on 13 November 2025 and answer the practical questions: what a notice must contain, what reasonable security safeguards include, how breach intimation works and on what clocks, how verifiable consent for children is obtained, and how the Board functions. The 23 rules and 7 Schedules are on the Rules explorer.
Who DPDP applies to
Section 3 sets the reach. The Act applies to digital personal data processed within India, whether collected digitally or digitised later, and it applies outside India where the processing is connected with any activity related to offering goods or services to Data Principals in India. It does not apply to personal data processed by an individual for personal or domestic purposes, or to data made publicly available by the Data Principal herself or by anyone required by law to publish it. Whether it applies to your organisation, and in what role, is what the applicability checker works out from the official criteria.
When DPDP applies
Neither the Act nor the Rules switched on all at once. Commencement notification G.S.R. 843(E) and Rule 1 phase them in three groups each:
- In force since 13 November 2025: the definitions, the Data Protection Board provisions and related machinery of the Act; Rules 1, 2 and 17 to 21, which set the Board up.
- Due at one year, computed as 13 November 2026: Consent Manager registration under section 6(9) and Rule 4, and the Board's power to act on intimation that a Consent Manager has breached a registration condition.
- Due at eighteen months, computed as 13 May 2027: the main obligations, including notice, consent, security safeguards, breach intimation, individual rights, and the penalties chapter.
Both computed dates are interpretation until officially confirmed; the timeline tracks each milestone with its primary source and verification date.
Where to go next
If you handle other people's data, start with the applicability checker and the company action plan. If it is your own data you are thinking about, the individual rights assistant explains what you can ask for and how. And every legal claim in this article carries its exact official source below, which is the standard for everything on this site.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Individual Rights Assistant
Understand your rights as an individual and the channels a Data Fiduciary must offer.
Open
The DPDP Act 2023, section by section →The DPDP Rules 2025, rule by rule →DPDP timeline with verified milestones →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), p. 1. Published 11 August 2023. Official source ↗ · Official requirement · Verified 18 August 2026The long title of the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). The Gazette print records assent on 11 August 2023.
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 3, p. 3. Published 11 August 2023. Official source ↗ · Official requirement · Verified 18 August 2026Section 3 sets the Act's application: processing of digital personal data within India, and processing outside India in connection with any activity related to offering goods or services to Data Principals within India, with stated exclusions.
- [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 18 August 2026The DPDP Rules 2025 were notified as G.S.R. 846(E) in Gazette issue No. 760, printed date 13 November 2025. Rule 1 commences the Rules in three groups.
- [4]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 18 August 2026Notification G.S.R. 843(E), Gazette issue No. 757, printed date 13 November 2025, commences the Act in three groups under paragraphs (a), (b) and (c).
- [5]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 18 August 2026The calendar dates 13 November 2026 and 13 May 2027 are computed from the printed publication date of 13 November 2025 plus one year and eighteen months and are presented as interpretation until officially confirmed.
- [6]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 18 August 2026For Rule 4 the same computed dates run from the printed publication date of Gazette issue No. 760, also 13 November 2025, and are likewise interpretation until officially confirmed.