What is DPDP? India's data protection law, explained from the official text
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 12 min read
What is DPDP and what is its full form?
The short answer
DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act 2023, Act No. 22 of 2023, is India's law for processing digital personal data; it received the President's assent on 11 August 2023 and recognises both the individual's right to protect personal data and the need to process it for lawful purposes. The DPDP Rules 2025, notified on 13 November 2025, operationalise the Act. Both commence in phases: some provisions have been in force since 13 November 2025, Consent Manager registration is due on a computed date of 13 November 2026, and the main obligations are due on a computed date of 13 May 2027, both interpretation until officially confirmed. Once section 3 is in force with the main obligations, the law applies to digital personal data processed in India, and to processing abroad in connection with any activity related to offering goods or services to people in India, but not to personal or domestic processing or to data made publicly available by the individual or under a legal duty (section 3(c)).

DPDP stands for Digital Personal Data Protection. Depending on context, people use the abbreviation for the law itself, the DPDP Act 2023, or for the framework as a whole, the Act together with the DPDP Rules 2025. This page is the short, sourced version of both.
The DPDP Act 2023
The Digital Personal Data Protection Act, 2023 is Act No. 22 of 2023, enacted by Parliament with the President's assent on 11 August 2023. Its purpose fits in one sentence, its own:
"An Act to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto."
Long title of the DPDP Act 2023.
The Act has 44 sections and 1 Schedule of monetary penalties. In outline: it defines who is who, permits processing only on consent or certain legitimate uses, sets obligations for Data Fiduciaries such as notice, security safeguards, breach intimation and erasure, gives individuals rights of access, correction, erasure, grievance redressal and nomination, creates the Data Protection Board of India to enforce all of it, and caps penalties at amounts up to 250 crore rupees. Every section is on this site with its official Gazette text: start at the Act explorer.
Who is who: the 4 roles, and what each one owes
Almost every DPDP question turns into a question about which role you are in. Section 2 defines 3 of the 4 roles and section 18 creates the fourth, and those provisions have been in force since 13 November 2025. Almost nothing that attaches to the roles has: the duties, the rights and the Board's powers all sit in later commencement groups.
Data Principal, section 2(j)
The Data Principal is "the individual to whom the personal data relates", and the definition reaches further on its face: where she is a child it includes her parents or lawful guardian, and where she is a person with disability it includes her lawful guardian acting on her behalf.
Chapter III gives her 4 rights. Section 11 is a right to a summary of the personal data being processed and to the identities of the other Data Fiduciaries and Data Processors it has been shared with. Section 12 is a right to correction, completion, updating and erasure. Section 13 is a right to readily available means of grievance redressal, and its sub section (3) makes her exhaust that route before approaching the Board. Section 14 is a right to nominate another individual to exercise her rights in the event of her death or incapacity.
2 of those 4 are written narrowly, and the difference is the most misreported thing about Chapter III. Section 11(1) gives the right against "the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7", and section 12(1) attaches to personal data "for the processing of which she has previously given consent". Sections 13 and 14 carry no equivalent wording. What that means for a person whose data is processed on a legitimate use rather than on her consent is worked through on the individual rights page.
Chapter III is headed rights and duties, and the duties half is usually left out. Section 15 places 5 duties on the Data Principal herself: to comply with applicable law while exercising her rights, not to impersonate another person, not to suppress material information when providing personal data for a document, identifier or proof issued by the State, not to register a false or frivolous grievance or complaint, and to furnish only verifiably authentic information when exercising the right to correction or erasure. Entry 5 of the Schedule prices a breach of those duties at up to Rs 10,000, and it is the only entry in the Schedule that names a duty of the Data Principal.
Data Fiduciary, section 2(i)
A Data Fiduciary is "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data". Person is defined widely at section 2(s) and includes an individual, a company, a firm and the State, so nothing about size or sector settles the role. On this site's reading the test runs activity by activity: 1 organisation is routinely a Data Fiduciary for its own customer data and a Data Processor for a client's, which the role test works through in full.
Chapter II is where its duties live: a lawful ground for every purpose under section 4, a notice under section 5, consent that meets the section 6 standard, the certain legitimate uses of section 7 as the alternative to consent, and the general obligations of section 8, which run from the valid contract of section 8(2) through security safeguards and breach intimation to erasure.
2 of those sections do not attach to every Data Fiduciary, and a picture on this page said they did until 5 September 2026. Section 9 attaches only where the fiduciary processes the personal data of a child, or of a person with disability who has a lawful guardian. Section 10 attaches only where the Central Government notifies the fiduciary, or a class it belongs to, as a Significant Data Fiduciary under section 10(1); the status is never self declared, and no notification under section 10 has been located. Until one is made, no organisation owes the Data Protection Officer, independent data auditor and Data Protection Impact Assessment duties of section 10(2).
Data Processor, section 2(k)
A Data Processor is "any person who processes personal data on behalf of a Data Fiduciary". This site reads that as a role held towards 1 fiduciary for particular processing, not a status an organisation carries everywhere.
No duty in either instrument is addressed to a Data Processor by name, and that much is settled by enumeration rather than by argument. The Act names a Data Processor 9 times and the DPDP Rules 2025 name it 6, and every one of the 15 is a definition, an illustration, or a sentence whose subject is the Data Fiduciary. In the Act: section 2(k) defines the term, section 6(6) makes the fiduciary cease and cause its Data Processors to cease on withdrawal of consent, section 8(1) keeps the fiduciary responsible for processing done on its behalf irrespective of any agreement to the contrary, section 8(2) lets the fiduciary engage a processor only under a valid contract, section 8(5) makes the fiduciary protect the data including where a processor handles it, section 8(7)(b), which names it twice, makes the fiduciary cause the processor to erase, and section 11(1)(b) makes the fiduciary disclose which processors received the data, with the illustration to section 6(6) naming a processor as a contracting party. In the Rules: rule 6(1) with its clauses (b) and (f), rule 8(3) with its illustration, and item (f) of the Second Schedule, every one of them addressed to the Data Fiduciary.
So on this site's reading what binds a processor arrives through the contract section 8(2) requires, and what that contract has to carry is a drafting question rather than a statutory list. That reading is not settled. Section 4(1) is addressed to "a person" and not to a Data Fiduciary, section 27(2) binds "such person" to comply with a direction of the Board, and section 33(1) allows a penalty where a breach "by a person" is significant, with entry 7 of the Schedule as the residual head. Data Processor obligations under DPDP works the enumeration through mention by mention, sets out the argument each way and does not decide it.
Data Protection Board of India, section 2(c)
The Board is "the Data Protection Board of India established by the Central Government under section 18". It exists: notification G.S.R. 844(E) of 13 November 2025 established it, the companion notification G.S.R. 845(E) fixed its strength at 4 members, and sections 18 to 26 have been in force since the same day, so it is a body corporate that may hold property, contract, sue or be sued.
What it cannot do is act. Section 27, which sets out its powers and functions, is not in force, and neither are sections 28 to 34, which carry the procedure for an inquiry, appeal to the Appellate Tribunal, alternate dispute resolution, voluntary undertakings and penalties. No appointment of a Chairperson or of any Member has been located, and the search behind that negative has 2 dates rather than 1: MeitY's published document library, re run on 5 September 2026, and the wider search of official channels dated 28 August 2026. A published library is not the Gazette, so neither check is a certified negative. Is the Data Protection Board operational sets out both gaps, and why closing only the appointments one would change nothing for a person with a complaint.
The DPDP Rules 2025
The Act delegates the operational detail to rules. The DPDP Rules 2025 were notified as G.S.R. 846(E) on 13 November 2025 and answer the practical questions: what a notice must contain, what reasonable security safeguards include, how breach intimation works and on what clocks, how verifiable consent for children is obtained, and how the Board functions. The 23 rules and 7 Schedules are on the Rules explorer.
Who DPDP applies to
Section 3 sets the reach, and it is itself in the 18 month commencement group, computed as 13 May 2027 and interpretation until officially confirmed. The Act applies to digital personal data processed within India, whether collected digitally or digitised later, and it applies outside India where the processing is connected with any activity related to offering goods or services to Data Principals in India. It does not apply to personal data processed by an individual for personal or domestic purposes, or to data made publicly available by the Data Principal herself or by anyone required by law to publish it. Whether it applies to your organisation, and in what role, is what the applicability checker works out from the official criteria.
When DPDP applies
Neither the Act nor the Rules switched on all at once. Commencement notification G.S.R. 843(E) and Rule 1 phase them in 3 groups each:
- In force since 13 November 2025: the definitions, the Data Protection Board provisions and related machinery of the Act; Rules 1, 2 and 17 to 21, which set the Board up.
- Due at 1 year, computed as 13 November 2026: Consent Manager registration under section 6(9) and Rule 4, and the Board's power to act on intimation that a Consent Manager has breached a registration condition.
- Due at 18 months, computed as 13 May 2027: the main obligations, including notice, consent, security safeguards, breach intimation, individual rights, and the penalties chapter.
Both computed dates are interpretation until officially confirmed; the timeline tracks each milestone with its primary source and verification date.
Where to go next
If you handle other people's data, start with the applicability checker and the company action plan, then read the DPDP compliance requirements for businesses for the obligation by obligation map. If it is your own data you are thinking about, the individual rights assistant explains what you can ask for and how. And every legal claim in this article carries its exact official source below, which is the standard for everything on this site. If you would rather read this in Hindi, the same ground is covered in DPDP Act क्या है. For a quick answer to one question, the questions page collects the short answers, and every answer links to the article that sources it.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Individual Rights Assistant
Understand your rights as an individual and the channels a Data Fiduciary must offer.
Open
The DPDP Act 2023, section by section →The DPDP Rules 2025, rule by rule →DPDP timeline with verified milestones →