What is the Digital Personal Data Protection Act (DPDPA)?
Also known as: DPDPA, DPDP Act, DPDP Act 2023, Digital Personal Data Protection Act 2023, India's Data Protection Law
The law defines the responsibilities of organisations that determine why and how personal data is processed, known as Data Fiduciaries, and gives rights to individuals, known as Data Principals.
The DPDPA establishes requirements around notice, consent, withdrawal of consent, children's data, data security, personal-data breaches, Data Principal rights, grievance handling, and other obligations.
The DPDP Rules, 2025 provide additional operational requirements for implementing the framework.
What does DPDPA mean?
DPDPA stands for the Digital Personal Data Protection Act.
It is commonly referred to as the DPDP Act 2023 or simply DPDPA.
The law establishes a framework for processing digital personal data in India while giving individuals greater control over how their personal data is collected and used.
For organisations, this means privacy cannot be treated only as a policy document. Businesses need processes and technical controls that support lawful data processing, meaningful consent where required, security, user rights, and accountability.
Who does the DPDPA apply to?
The DPDPA applies to the processing of digital personal data within the scope defined by the Act, including processing by organisations that operate in India.
It can also apply to certain processing outside India when it is connected with offering goods or services to Data Principals in India.
The law is therefore relevant to a wide range of organisations, including:
- SaaS companies
- E-commerce websites
- Mobile applications
- Financial services businesses
- Healthcare platforms
- Educational technology companies
- Marketing and advertising businesses
- Online marketplaces
- Technology companies
- Websites collecting personal information
Organisations should assess their specific processing activities and legal obligations rather than assuming that every processing activity is treated identically.
What is personal data under DPDPA?
Personal data is data about an individual who is identifiable by or in relation to that data.
Under the DPDPA, the framework focuses on digital personal data.
Examples can include information such as:
- Name
- Email address
- Phone number
- Account information
- Online identifiers
- Location-related information
- Customer records
- Information submitted through online forms
- Other information that can identify an individual
The actual applicability of the Act depends on the nature of the data and the processing activity.
What is a Data Fiduciary?
A Data Fiduciary is a person who, alone or together with other persons, determines the purpose and means of processing personal data.
In simple terms, a Data Fiduciary is generally the organisation that decides:
Examples can include an online business collecting customer information, a SaaS platform processing user account data, or an e-commerce company using customer information to provide its services.
The concept is broadly comparable to a data controller under the GDPR, although the legal frameworks are different.
What is a Data Principal?
A Data Principal is the individual to whom the personal data relates.
For example, if a customer creates an account on an e-commerce website, the customer is the Data Principal and the organisation determining how that customer's personal data is processed may be the Data Fiduciary.
The DPDPA gives Data Principals certain rights and provides mechanisms for exercising those rights.
What are the key requirements of DPDPA?
The DPDPA introduces several important privacy and data-protection requirements.
These include:
- Providing appropriate notice about personal-data processing
- Obtaining valid consent where consent is the applicable ground
- Making consent specific and informed
- Making withdrawal of consent possible
- Protecting personal data with reasonable security safeguards
- Notifying certain personal-data breaches as required
- Providing Data Principal rights
- Providing grievance redressal mechanisms
- Implementing additional protections for children's data
- Meeting additional obligations where applicable to Significant Data Fiduciaries
The exact obligations depend on the organisation, processing activity, and provisions applicable to it.
What does DPDPA say about consent?
Consent is one of the central concepts under the DPDPA.
Where consent is relied upon, the Act requires consent to be free, specific, informed, unconditional and unambiguous, with a clear affirmative action.
Consent should relate to a specified purpose rather than functioning as unrestricted permission to process personal data.
Organisations should also provide an effective mechanism for Data Principals to withdraw consent.
This makes the consent experience an important part of DPDPA compliance.
What is DPDPA consent management?
DPDPA consent management is the process of collecting, recording, enforcing, and managing consent in accordance with the requirements of the DPDP Act.
A consent management system can help businesses:
- Present clear consent notices
- Explain processing purposes
- Capture affirmative consent
- Record consent decisions
- Manage consent withdrawal
- Maintain evidence of consent
- Apply different consent rules to different processing purposes
- Support privacy requests and audits
Consent management should be connected to the systems that actually process personal data so that a user's decision can be respected in practice.
DPDPA and cookie consent
The DPDPA is particularly relevant to websites and applications that use cookies, analytics tools, advertising technologies, and other tracking mechanisms where these involve processing of personal data.
A cookie banner by itself does not automatically make a website DPDPA compliant.
Businesses should understand:
- What personal data their trackers collect
- Why the data is collected
- Which third parties receive or process the data
- What consent or other lawful basis applies
- How users can withdraw consent
- How tracking technologies respond to the user's choice
For websites serving users in multiple countries, DPDPA requirements may need to operate alongside GDPR, UK GDPR, CCPA/CPRA, or other applicable privacy frameworks.
DPDPA and children's data
The DPDPA provides specific protections for children's personal data.
A child is an individual who has not completed 18 years of age under the Act.
Section 9 establishes requirements around verifiable parental consent and places restrictions on processing involving children, including restrictions concerning tracking, behavioural monitoring, and targeted advertising directed at children, subject to applicable provisions and exemptions.
Businesses serving children should therefore consider age determination, parental-consent mechanisms, and technical controls that prevent prohibited processing.
What rights do Data Principals have?
The DPDPA provides Data Principals with rights that can include:
- Access to information about personal data
- Correction of personal data
- Erasure of personal data
- Grievance redressal
- The ability to nominate another individual in certain circumstances
- Withdrawal of consent where processing is based on consent
Organisations need processes for receiving, authenticating, tracking, and responding to applicable Data Principal requests.
What is a Consent Manager under DPDPA?
A Consent Manager is a registered entity designed to provide an interoperable platform through which a Data Principal can give, manage, review, and withdraw consent.
The Consent Manager model is an important part of India's approach to consent management.
Businesses should distinguish between a Consent Manager as defined by the DPDPA framework and ordinary website consent-management software used to operate banners, preferences, and tracking controls.
What are DPDPA Rules?
The Digital Personal Data Protection Rules, 2025 provide detailed requirements supporting implementation of the DPDPA framework.
The Rules address operational areas such as notices, consent mechanisms, security safeguards, breach-related obligations, children's data, Data Fiduciaries, Consent Managers, and other compliance requirements.
The Rules were notified on 13 November 2025 and include phased commencement provisions. Businesses should therefore track the applicable commencement dates rather than treating every requirement as effective on the same day.
What are the penalties under DPDPA?
The DPDPA provides for significant financial penalties for certain breaches.
Penalties can reach ₹250 crore for specified breaches, depending on the applicable provision and circumstances.
The Data Protection Board of India is responsible for enforcement under the framework.
Because penalties and enforcement requirements can change as regulations and rules develop, organisations should verify the current requirements before relying on a compliance interpretation.
DPDPA compliance checklist
Businesses preparing for DPDPA compliance should consider:
- Identify the personal data being collected and processed
- Document the purposes for processing
- Review privacy notices
- Review consent mechanisms
- Make consent clear and purpose-specific where required
- Provide an effective consent-withdrawal mechanism
- Review cookie and tracking technologies
- Implement appropriate security safeguards
- Establish personal-data breach procedures
- Prepare processes for Data Principal requests
- Review children's-data processing
- Assess whether Significant Data Fiduciary obligations apply
- Maintain appropriate records and evidence
- Review third-party processors and service providers
- Monitor applicable DPDPA Rules and commencement dates
DPDPA compliance for websites
Websites should pay particular attention to consent and tracking because online forms, analytics platforms, advertising tools, cookies, pixels, and third-party scripts can involve personal-data processing.
A practical website compliance workflow includes:
- Discover
- Classify
- Inform
- Obtain Consent
- Enforce
- Record
- Allow Withdrawal
This approach helps ensure that privacy choices are reflected not only in the website's privacy notice but also in its technical behaviour.
DPDPA in ConsentX
ConsentX provides DPDPA-focused consent management designed to help businesses implement and demonstrate privacy choices across websites.
ConsentX supports:
Purpose-based consent
DPDPA-aware consent experiences
Consent withdrawal
Tamper-evident consent records
Region-specific privacy rules
Prior-script blocking
Cookie and tracker discovery
Data Principal request workflows
Age-gate and parental-consent flows
Audit-ready consent evidence
This helps businesses move from a static privacy notice to an enforced and provable consent process.
ConsentX also supports other privacy frameworks, allowing businesses serving international users to manage consent requirements through a single platform.
Put DPDPA compliance into practice
ConsentX helps businesses implement purpose-based consent, manage privacy preferences, block applicable trackers before consent, and maintain audit-ready consent records. Start free with ConsentX.
Related Terms
A Data Fiduciary is the person or organisation that determines the purpose and means of processing personal data under the DPDPA.
A Data Principal is the individual to whom the personal data relates.
A Consent Manager is a registered platform through which a Data Principal can give, manage, review, and withdraw consent.
DPDPA consent is consent that meets the requirements of the DPDP Act, including being free, specific, informed, unconditional and unambiguous with clear affirmative action.
Section 9 establishes specific requirements and protections relating to the processing of children's personal data.
Personal data is data about an individual who is identifiable by or in relation to that data.
A consent management platform helps organisations collect, manage, enforce, and document user consent across websites and applications.
Cookie consent is the process of obtaining and managing a user's permission for applicable non-essential cookies and tracking technologies.