Skip to content
Fri, 4 Sep 2026 Policies, schemes, jobs and law — tracked daily
Law

The Digital Personal Data Protection Act, 2023

Ministry of Electronics and Information Technology

Published 25 August 2026

In short

The Digital Personal Data Protection Act, 2023 is India's first standalone privacy law governing digital personal data processing in India and outside where services are offered to Indians. Data Fiduciaries must give clear notice and obtain free, informed, withdrawable consent. Rules notified 13 November 2025; main obligations start 12 May 2027. Penalties up to Rs 250 crore for breaches.

Key facts

Year
2023
Act number
Act No. 22 of 2023
Administered by
Ministry of Electronics and Information Technology
In force from
Phased. Rules notified 13 November 2025, with definitional and Data Protection Board provisions effective immediately, consent manager registration from 12 November 2026 and the main obligations from 12 May 2027
Replaces
Section 43A of the Information Technology Act, 2000 and the related 2011 sensitive personal data rules; it also amends the Right to Information Act, 2005

The Digital Personal Data Protection Act is India’s first standalone privacy law. It applies to digital personal data processed in India, and to processing outside India where goods or services are offered to people in India. Anyone who decides why and how personal data is processed is a Data Fiduciary; the individual whose data it is, is a Data Principal.

The core duty is notice and consent. A Data Fiduciary must give a clear, itemised notice in English or any of the Eighth Schedule languages, saying what data is collected and why, and must obtain free, specific, informed and unambiguous consent that can be withdrawn as easily as it was given. Certain legitimate uses, such as an individual voluntarily providing data or the State providing a benefit, do not need fresh consent. Children under eighteen require verifiable parental consent, and tracking or targeted advertising directed at children is prohibited.

Individuals get rights to access a summary of their data, to correction and erasure, to grievance redressal and to nominate someone to act on their behalf after death or incapacity. Enforcement runs through the Data Protection Board of India, which can impose the penalties listed above.

The critical practical point is timing. The Act was passed in August 2023 but sat unimplemented until the Digital Personal Data Protection Rules were notified on 13 November 2025. Definitions and Board provisions took effect at once, consent manager registration from 12 November 2026, and the substantive notice, consent and fiduciary obligations only from 12 May 2027.

Key penalties

  • Up to Rs 250 crore for failing to take reasonable security safeguards that results in a personal data breach
  • Up to Rs 200 crore for failing to notify the Data Protection Board and affected individuals of a breach
  • Up to Rs 200 crore for breaching the additional obligations owed in relation to children's data
  • Up to Rs 150 crore for breaching the additional obligations of a Significant Data Fiduciary
  • Up to Rs 10,000 on a data principal who breaches their own duties, such as filing a frivolous grievance or registering a false complaint

Frequently asked questions

When did the Digital Personal Data Protection Act come into force?

The Act was passed in August 2023 but implementation is phased. Rules were notified 13 November 2025. Definitions and Board provisions took effect immediately. Consent manager registration starts 12 November 2026. Main notice, consent and fiduciary obligations take effect 12 May 2027.

Who is a Data Fiduciary under the Act?

A Data Fiduciary is any person who decides why and how personal data is processed. The individual whose data is being processed is called a Data Principal. Data Fiduciaries must follow notice and consent rules.

What is the maximum penalty for data breach under the Act?

The maximum penalty is Rs 250 crore for failing to take reasonable security safeguards that results in a personal data breach. Penalties of Rs 200 crore apply for failure to notify breaches or for breaching children's data obligations.

What special protections apply to children's data?

Children under eighteen require verifiable parental consent for data processing. Tracking or targeted advertising directed at children is completely prohibited. Breaching children's data obligations carries a penalty up to Rs 200 crore.

What rights do individuals have under this Act?

Data Principals can access a summary of their data, request correction and erasure, lodge grievances, and nominate someone to act on their behalf after death or incapacity. Consent can be withdrawn as easily as it was given.

Does the Act apply outside India?

Yes. The Act applies to digital personal data processed in India and also to processing outside India where goods or services are offered to people in India.

Before you apply: confirm every date, fee and eligibility rule on the official website linked on this page. Public and Policy is an independent portal, not a government body, and details change without notice.