What the DPDP Act covers
the DPDP Act, the Digital Personal Data Protection Act, 2023, governs the collection, use and disclosure of personal information by private-sector organizations in the course of commercial activity. 'Personal information' is broadly defined: any information about an identifiable individual, including IP addresses in many contexts.
Where the DPDP Act applies (and where state laws take over)
the DPDP Act applies federally across India, except in states that have substantially similar laws (Maharashtra, Karnataka and Tamil Nadu). In those states, local privacy law applies for intra-state activity, while the DPDP Act still applies for federally regulated businesses and cross-border transfers.
The ten fair information principles
the DPDP Act is built on ten principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Every the DPDP Act obligation maps back to one of these, internalize them and the law becomes intuitive.
Meaningful consent
Consent must be 'meaningful', the individual must understand what they are agreeing to. Pre-checked boxes, buried terms, or vague catch-all statements don't constitute meaningful consent under the Data Protection Board's guidelines. Plain language, layered notice (summary plus full policy), and just-in-time disclosures are the modern best practice.
Free Compliance Health Check
Get a confidential 30-min review of your privacy and compliance posture, no obligation.
Purpose limitation
You can only use personal information for the purposes you identified at collection. Adding new purposes later requires fresh consent. This is the principle most often breached in practice, a marketing team starts using CRM data for a use case the privacy policy never covered.
Safeguards proportionate to sensitivity
the DPDP Act requires safeguards proportionate to the sensitivity of the data. Financial and health information warrants stronger controls than marketing list data. The Data Protection Board has been increasingly active on encryption-at-rest, access controls, and vendor due diligence.
Breach reporting and record-keeping
Since 2018, organizations must report breaches of security safeguards involving real risk of significant harm to both the Data Protection Board and affected individuals, as soon as feasible. You must also maintain records of every breach for 24 months, even if not reportable.
Individual rights
Individuals have the right to access their personal information held by your organization, correct inaccuracies, and challenge how you handle their data. You generally have 30 days to respond to access requests. This is one of the most operationally demanding parts of the DPDP Act, most organizations under-prepare.
Cross-border transfers
If you transfer Indian personal data to processors outside India (e.g., US-based SaaS), the transferring organization remains responsible for protection under the DPDP Act. Best practice: vendor due diligence, data processing agreements, and disclosure in your privacy policy.
The CPPA on the horizon
The Consumer Privacy Protection Act, working its way through Parliament, would replace the DPDP Act with a more GDPR-like regime, explicit consent emphasis, higher penalties, and stronger individual rights. Building to GDPR-style practices today futureproofs you.
the DPDP Act compliance is the floor, not the ceiling, of how a modern Indian business should treat data. Organizations that go beyond minimum compliance and treat privacy as a competitive asset win trust at scale, and avoid the costly remediation that follows enforcement.
Frequently asked questions
Quick answers to common questions on this topic. Have a specific situation? Talk to our team.
What does the DPDP Act cover?
the DPDP Act, the Digital Personal Data Protection Act, 2023, governs the collection, use and disclosure of personal information by private-sector organizations in the course of commercial activity. 'Personal information' is broadly defined: any information about an identifiable...
Where the DPDP Act applies (and where state laws take over)?
the DPDP Act applies federally across India, except in states that have substantially similar laws (Maharashtra, Karnataka and Tamil Nadu). In those states, local privacy law applies for intra-state activity, while the DPDP Act still applies for federally regulated businesses and cross-border transfers.
What is the ten fair information principles?
the DPDP Act is built on ten principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Every the DPDP Act obligation maps back to one of these, internalize them and the law becomes intuitive.
What is meaningful consent?
Consent must be 'meaningful', the individual must understand what they are agreeing to. Pre-checked boxes, buried terms, or vague catch-all statements don't constitute meaningful consent under the Data Protection Board's guidelines. Plain language, layered notice (summary plus full policy), and just-in-time...
Ready to put this into practice?
Tell us about your business and we will scope a starter engagement or recommend a better starting point, typically within one business day. No obligation, no high-pressure sales call.