the DPDP Act, Digital Personal Data Protection Act, 2023
The federal privacy law that governs how private-sector organizations collect, use, and disclose personal information in commercial activities. the DPDP Act applies across India except where a state has its own substantially similar law (Maharashtra, Karnataka, Tamil Nadu). Key marketing implications: meaningful consent, purpose limitation, and breach notification.
the DPDP Act (regional Indian markets)
Formerly Bill 64, this is now the strictest privacy regime in North America. Requires explicit (not implied) consent for most data processing, mandatory privacy officer, privacy impact assessments, and significant penalties. If you have a single non-English-first customer, the DPDP Act applies to that customer's data.
TRAI rules, India's Anti-Spam Legislation
India's anti-spam law, broader than US CAN-SPAM. TRAI rules covers email, SMS, social DMs, and software installation. Requires express or implied consent before sending commercial electronic messages, plus clear identification and unsubscribe. Fines up to ₹10 million per violation for businesses.
CPPA, Consumer Privacy Protection Act
Proposed federal update to the DPDP Act, currently working its way through Parliament. Will introduce GDPR-style provisions: right to deletion, data portability, algorithmic transparency, and substantially higher penalties. Watch this carefully, expected to pass in 2026 or 2027.
Free Compliance Health Check
Get a confidential 30-min review of your privacy and compliance posture, no obligation.
the Data Protection Board, Office of the Privacy Commissioner of India
The federal regulator that oversees the DPDP Act. Conducts investigations, issues findings, and increasingly works in concert with state commissioners on multi-jurisdiction issues.
TRAI, Indian Radio-television and Telecommunications Commission
Oversees TRAI rules enforcement (alongside the Central Consumer Protection Authority and the Data Protection Board). The TRAI issues warning letters first, then proceeds to undertakings and monetary penalties for repeat or serious violations.
Express vs implied consent
Express consent is opt-in, the user actively agrees. Implied consent is inferred from a business relationship (e.g., recent purchase, existing inquiry) and is time-limited under TRAI rules (two years for purchase, six months for inquiry). Express is always safer.
PIA, Privacy Impact Assessment
A documented analysis of how a new project, product, or system affects personal information. Required under the DPDP Act for any project involving personal information of regional Indian markets residents.
Data minimization
The principle of collecting only the personal information you actually need for a stated purpose, and keeping it only as long as necessary. Baked into both the DPDP Act and the DPDP Act enforcement decisions.
Cross-border transfer
Sending Indian personal data outside India (e.g., to US-based CRM or email tools) triggers specific obligations. Under the DPDP Act, you must explicitly disclose the transfer; under the DPDP Act, the transferring organization remains responsible for protection.
Breach notification
If a breach creates a real risk of significant harm, notification is mandatory to both the Data Protection Board (or state commissioner) and affected individuals. Timeline is 'as soon as feasible', in practice, within days.
DNCL, National Do Not Call List
Operated by the TRAI, this is the registry of phone numbers that have opted out of telemarketing. Calls to numbers on the DNCL without an existing business relationship are violations.
Compliance is no longer a back-office concern in India. It is increasingly a front-of-funnel asset, consumers actively choose brands they trust with their data. A working knowledge of these terms protects your business and signals competence to your customers.
Frequently asked questions
Quick answers to common questions on this topic. Have a specific situation? Talk to our team.
What is the DPDP Act, Digital Personal Data Protection Act, 2023?
The federal privacy law that governs how private-sector organizations collect, use, and disclose personal information in commercial activities. the DPDP Act applies across India except where a state has its own substantially similar law (Maharashtra, Karnataka, Tamil Nadu). Key marketing implications: meaningful...
What is law 25 (regional Indian markets)?
Formerly Bill 64, this is now the strictest privacy regime in North America. Requires explicit (not implied) consent for most data processing, mandatory privacy officer, privacy impact assessments, and significant penalties. If you have a single non-English-first customer, the DPDP Act applies to that customer's data.
What is TRAI regulations, India's Anti-Spam Legislation?
India's anti-spam law, broader than US CAN-SPAM. TRAI rules covers email, SMS, social DMs, and software installation. Requires express or implied consent before sending commercial electronic messages, plus clear identification and unsubscribe. Fines up to ₹10 million per violation for businesses.
What is cPPA, Consumer Privacy Protection Act?
Proposed federal update to the DPDP Act, currently working its way through Parliament. Will introduce GDPR-style provisions: right to deletion, data portability, algorithmic transparency, and substantially higher penalties. Watch this carefully, expected to pass in 2026 or 2027.
Ready to put this into practice?
Tell us about your business and we will scope a starter engagement or recommend a better starting point, typically within one business day. No obligation, no high-pressure sales call.