The Digital Personal Data Protection Act is India’s first standalone privacy law. It applies to digital personal data processed in India, and to processing outside India where goods or services are offered to people in India. Anyone who decides why and how personal data is processed is a Data Fiduciary; the individual whose data it is, is a Data Principal.
The core duty is notice and consent. A Data Fiduciary must give a clear, itemised notice in English or any of the Eighth Schedule languages, saying what data is collected and why, and must obtain free, specific, informed and unambiguous consent that can be withdrawn as easily as it was given. Certain legitimate uses, such as an individual voluntarily providing data or the State providing a benefit, do not need fresh consent. Children under eighteen require verifiable parental consent, and tracking or targeted advertising directed at children is prohibited.
Individuals get rights to access a summary of their data, to correction and erasure, to grievance redressal and to nominate someone to act on their behalf after death or incapacity. Enforcement runs through the Data Protection Board of India, which can impose the penalties listed above.
The critical practical point is timing. The Act was passed in August 2023 but sat unimplemented until the Digital Personal Data Protection Rules were notified on 13 November 2025. Definitions and Board provisions took effect at once, consent manager registration from 12 November 2026, and the substantive notice, consent and fiduciary obligations only from 12 May 2027.