Overview

The Digital Personal Data Protection (DPDP) Act, 2023 is India's first standalone law for the protection of personal data. Enacted in August 2023, it governs how digital personal data may be collected and used, gives individuals rights over their own data, and places duties on the organisations that handle it. The Act was brought into operation by the DPDP Rules, 2025, notified on 14 November 2025, which fill in the working detail and set a phased window of about eighteen months for compliance. The law rests on the Supreme Court's recognition of the right to privacy as a fundamental right, creates a Data Protection Board of India to enforce it, and is built around consent: data may be processed only for a lawful purpose with the individual's permission or for certain legitimate uses.

India Notifies the DPDP Rules and Operationalises the 2023 Act

The DPDP Rules, 2025 bring the Act into force

India has brought its first standalone data-protection law into operation. On 14 November 2025 the Government notified the Digital Personal Data Protection (DPDP) Rules, 2025, the detailed regulations that put the Digital Personal Data Protection Act, 2023 into effect. The Act had been passed two years earlier, in August 2023, but a law of this kind needs working rules before it can bite, and those rules have now arrived.

The Rules followed an extended public consultation. A draft set of Rules was released in January 2025, and the Ministry of Electronics and Information Technology then gathered views in cities across the country, from Delhi and Mumbai to Guwahati, Kolkata, Hyderabad, Bengaluru and Chennai. In all, about 6,915 inputs were received from startups, smaller firms, industry bodies, civil-society groups and government departments before the final Rules were settled.

Rather than switch on every obligation at once, the Rules provide for a phased commencement. Some provisions take effect immediately, while organisations are given a window of about eighteen months to put in place the systems the law requires, such as consent notices, security safeguards and breach reporting. The figure below sets out the framework at a glance.

Figure 1. India's data-protection law at a glance.

Why the DPDP Law Is in the News: From Statute to Working Regime

A two-year wait and a digital-first Board

Why it matters now is that the law has moved from the statute book to a working regime. For two years the DPDP Act existed on paper without the rules needed to apply it, so its rights and duties could not be enforced. The notification of the Rules on 14 November 2025 closes that gap and starts the clock on compliance for the many organisations that hold personal data.

The Rules also stand up the institution that will run the system. They establish the Data Protection Board of India as a digital-by-design body, with a small membership, through which a person can file a complaint online and track it on a dedicated portal and mobile app. A law that promises individuals control over their data only becomes real once there is a regulator they can approach, which is why the start of this regime is so closely watched.

Understanding the Significance of the DPDP Law for India

A right to control one's data and a duty on those who hold it

What is the significance of the DPDP law lies first in the right it gives the individual. For the first time, an Indian has a clear legal claim to know what personal data an organisation holds, to have it corrected or erased, and to withdraw the consent on which its use rests. In a country with one of the world's largest populations of internet and smartphone users, that shift of control towards the individual is a substantial change.

Its second significance is the duty it places on those who handle data. Every organisation that decides why and how personal data is processed now carries enforceable obligations: to seek genuine consent, to keep the data secure, to report breaches, and to erase data when it is no longer needed.

Backed by a Data Protection Board and by penalties, these duties turn data protection from good practice into law. They also align India with the global move, led by Europe's data-protection regime, towards treating personal data as something the law must actively guard.

How the DPDP Act Works: Data Principal, Fiduciary, Consent and the Board

Data Principal, Data Fiduciary, Data Processor and Consent Manager

The law is built around a few defined actors, and the whole scheme is easier to follow once they are clear. At the centre is the Data Principal, the individual to whom the personal data relates, the person the law is meant to protect. Where the data is of a child, the Data Principal includes the parent or lawful guardian.

Opposite the individual stands the Data Fiduciary, defined as any person or organisation that, alone or with others, decides the purpose and the means of processing personal data. The choice of the word fiduciary is deliberate: it signals that the organisation holds the data in a position of trust and owes duties to the individual, not merely a commercial relationship. A Data Processor is a separate party that processes data on behalf of a Data Fiduciary, under its instructions.

A distinctive feature is the Consent Manager, a platform, which must be an Indian company registered with the Board, through which an individual can give, review, manage and withdraw consent across different services from a single point. It is meant to make consent something a person can actually control rather than a forgotten click. The figure below names the main actors.

Actor Who they are Core role
Data Principal The individual the data is about Gives consent and exercises rights over the data
Data Fiduciary Decides the purpose and means of processing Owes duties of consent, security and erasure
Data Processor Processes data for a Data Fiduciary Acts on the Fiduciary's instructions
Consent Manager An Indian company registered with the Board Lets a person manage consent in one place

Reading the rows together shows the design: the individual sits at the centre with rights, those who handle the data carry the duties, and a Consent Manager and the Board sit between them to make the system work.

Figure 3. The key actors under the DPDP Act.

The engine of the Act is consent. As a rule, a Data Fiduciary may process personal data only for a lawful purpose for which the individual has given consent, and that consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The individual may withdraw consent at any time, and withdrawal must be as easy as giving it was.

Consent has to be informed, so the Act requires an itemised notice. Before or at the time of seeking consent, the Data Fiduciary must tell the individual, in plain language and with the option of English or any language in the Eighth Schedule of the Constitution, what personal data will be collected and for what purpose, how the person may exercise their rights, and how they may complain to the Board.

Consent is not the only basis for processing. The Act also allows certain legitimate uses, for instance where a person voluntarily shares data for a service, or for the State to provide a benefit, subsidy or licence, or to respond to a medical emergency or a disaster. These narrow grounds let essential and emergency functions continue without separate consent, while consent remains the default everywhere else.

Significant Data Fiduciaries and the Data Protection Board of India

The Act recognises that not all data handlers carry the same risk, so it creates the category of the Significant Data Fiduciary. The Government may classify an organisation as significant by looking at factors such as the volume and sensitivity of the data it handles and the risk to the rights of individuals or to the security of the State.

A Significant Data Fiduciary carries extra obligations. These include appointing a Data Protection Officer based in India, commissioning independent audits, and carrying out data-protection impact assessments before deploying high-risk processing.

Enforcement rests with the Data Protection Board of India. It is designed as a digital-by-design adjudicatory body, with four members, that an individual can approach online to complain about a breach of their rights or a failure to protect their data.

The Board investigates breaches, can direct urgent remedial or mitigation measures, and imposes the financial penalties the Act provides. Appeals from its orders lie to the Telecom Disputes Settlement and Appellate Tribunal, so the Board sits within a wider structure of adjudication rather than acting as the final word.

Rights of the Data Principal, Duties of Fiduciaries, Children and Penalties

What the individual can demand from a Data Fiduciary

The Act gives the Data Principal a set of enforceable rights against the organisations that hold their data. The first is the right to access information: an individual can ask a Data Fiduciary for a summary of the personal data it is processing and of the activities it has carried out on that data, and for the identities of others with whom it has been shared.

Alongside access sit the rights to correction and erasure. A person may have inaccurate or incomplete data corrected, completed or updated, and may have their data erased once the purpose is served or consent is withdrawn, unless the law requires it to be kept.

There is also a right to grievance redressal, first to the Data Fiduciary and then to the Board, and a right of nomination, by which a person can name someone to exercise these rights on their behalf in the event of death or incapacity. Data Fiduciaries are expected to respond to such requests within a set period, of up to ninety days.

  1. (a) Right to access. A summary of the personal data held and processed, and of the parties it has been shared with.
  2. (b) Right to correction and erasure. To correct or complete the data, and to have it erased when no longer needed or once consent is withdrawn.
  3. (c) Right to grievance redressal. A readily available means to complain, first to the Fiduciary and then to the Board.
  4. (d) Right to nominate. To name another person to exercise these rights in the event of death or incapacity.

Read together, these rights are what give the individual real control: not just a promise that data will be handled carefully, but specific demands an organisation must answer. The figure below pairs the rights with the penalties that back them.

Figure 4. Data Principal rights and the penalty schedule.

The duties of a Data Fiduciary

Against those rights stand the obligations of the Data Fiduciary. It must process data only for the consented purpose, give the itemised notice described above, and ensure the completeness and accuracy of data used to make a decision about a person or shared with another fiduciary.

Two duties are central to data security. A Data Fiduciary must put in place reasonable security safeguards to prevent a personal data breach, and, if a breach does occur, must notify both the Data Protection Board and each affected individual.

It must also practise data minimisation in time: once the purpose is met and the data is no longer needed for legal reasons, it must be erased, and it must erase data when an individual withdraws consent. These obligations turn the abstract idea of protection into concrete operational duties.

Children's data and cross-border transfer

The Act gives special protection to children's data, treating anyone below eighteen years as a child. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. The Act further forbids any processing likely to cause a detrimental effect on a child's well-being, and bars the tracking, behavioural monitoring and targeted advertising of children, with limited exemptions the Government may allow for purposes such as healthcare and education.

On cross-border transfer, the Act takes a permissive default. Personal data may be transferred outside India for processing, except to any country or territory that the Government specifically restricts by notification. This blacklist approach, where transfer is allowed unless a destination is barred, is lighter than schemes that allow transfer only to approved countries, and it is one of the features that distinguishes the Indian law from stricter regimes abroad.

The graded schedule of financial penalties

The law is enforced through a graded schedule of financial penalties, which the Board may impose after an inquiry. The penalties are tied to the seriousness of the failure rather than levied at a single flat rate, so the cost of a breach scales with the harm it risks.

Nature of the breach Penalty up to
Failure to maintain reasonable security safeguards Rs 250 crore
Failure to notify the Board or individuals of a data breach Rs 200 crore
Breach of obligations relating to children Rs 200 crore
Any other breach of the Act or the Rules Rs 50 crore

The ceiling of Rs 250 crore for a security-safeguards failure signals how seriously the law treats the protection of personal data: the largest penalty attaches to the duty to keep data safe, the failure most likely to expose ordinary people to harm. The penalties give the Board the teeth it needs to make the rights and duties more than words.

Backdrop and Journey: From the Privacy Judgment to the 2025 Rules

The Puttaswamy judgment and the right to privacy

The law has a clear constitutional root. In August 2017, in K.S. Puttaswamy v. Union of India, a nine-judge bench of the Supreme Court unanimously held that the right to privacy is a fundamental right, intrinsic to the right to life and personal liberty under Article 21 and to the freedoms in Part III of the Constitution.

The judgment expressly recognised informational privacy, a person's control over their own data, as part of this right, and it called on the State to put in place a dedicated data-protection law.

That judgment created both the duty and the design space for the present statute. Because privacy is now a fundamental right, any law touching personal data must meet the tests the Court set, of a legitimate aim, a basis in law and proportionality. The DPDP Act is, in large part, the legislature's answer to the Court's call, which is why its rationale begins with privacy rather than with commerce.

The Srikrishna Committee and the bills that came before

Between the judgment and the Act lay several years of drafting. Soon after Puttaswamy, the Government set up an expert committee under Justice B.N. Srikrishna, a retired Supreme Court judge, which submitted its report and a draft Personal Data Protection Bill in July 2018. The report framed the basic vocabulary of data principals and data fiduciaries that the final law would keep.

The road from that draft to the Act was not straight. A Personal Data Protection Bill, 2019 was introduced in Parliament and sent to a joint committee, but after long deliberation it was withdrawn in August 2022.

The Government then released a fresh, simpler draft, which became the Digital Personal Data Protection Bill, 2023, and was enacted as the DPDP Act in August 2023. The draft Rules of January 2025 and the final Rules of November 2025 completed the journey. The timeline below traces these steps.

Figure 2. India's journey to a data-protection law, year by year.

The DPDP Law in Context: Global Comparison, the Data Economy and Criticisms

How the Indian law sits beside global practice and the data economy

Contemporary linkages place the DPDP law within a worldwide movement. The clearest comparison is with the European Union's General Data Protection Regulation, the GDPR, which set the global template of consent, individual rights and heavy penalties.

India's law shares that architecture, but is deliberately lighter in places: it relies on broad rule-making by the Government, takes a blacklist rather than a whitelist approach to cross-border transfer, and does not, unlike the GDPR, create a separate category of specially sensitive personal data.

The law also belongs to the wider story of India's digital economy and governance. The same population that powers digital payments, online services and Aadhaar-linked benefits generates vast quantities of personal data, and a trusted legal framework for that data is meant to support both individual rights and the growth of a data-driven economy.

It connects to live debates on data localisation, on the governance of artificial intelligence, which is trained on personal data, and on cyber security and data breaches. The framework is therefore read as much as an enabler of the data economy as a shield for the individual.

  • The Information Technology Act, 2000: The earlier, general framework that governed data and cyber matters before the dedicated DPDP law.
  • Cross-border data and localisation: Debates on where data may be stored and processed, on which the Act takes a permissive negative-list stance.
  • Artificial-intelligence governance: Concerns over training models on personal data, which the consent and purpose rules touch directly.
  • Sectoral regulators: Bodies in banking, health and telecom that already handle personal data, alongside which the Board now sits.

It sits, too, within India's evolving institutional architecture for the digital world. The DPDP Act adds a dedicated data regulator, the Board, to that landscape, and overlaps with the sectoral regulators that already handle personal data in banking, health and telecom.

The Main Criticisms and Concerns Around the DPDP Law

A balanced reading must weigh the criticisms the law has drawn, since UPSC questions reward this balance. The most debated concern is the breadth of the exemptions for the State, which the Act allows on grounds such as the security of the State, public order and the prevention of offences.

Critics argue these grounds are wide and could weaken privacy protection against the very State whose surveillance the privacy judgment was meant to check. The fear is that broad executive exemptions hollow out the right the law is supposed to deliver.

A second concern is the law's effect on the Right to Information. The DPDP Act amended Section 8(1)(j) of the Right to Information Act, 2005, which governs the disclosure of personal information. Transparency advocates fear the change could be used to deny information that was earlier available in the public interest, while the Government maintains that it only balances privacy with the right to information rather than restricting disclosure that serves the public good.

Critics also question the independence of the Data Protection Board, because its members are appointed and its terms are largely set by the Government, which raises concerns about how freely it can act against the State. A further worry is the extent of delegated legislation: a great deal of the law's substance is left to rules the Government may frame, change and bring into force, which gives the executive broad latitude over how the regime actually works.

  • Wide State exemptions: Government agencies can be exempted on broad grounds such as the security of the State, raising surveillance concerns.
  • The RTI amendment: A change to Section 8(1)(j) of the RTI Act is feared by transparency advocates to narrow access to information.
  • Board independence: Government control over appointments and terms raises doubts about how independently the Board can act.
  • Heavy delegation: Much of the law’s detail is left to executive rule-making, giving the Government broad discretion.

Set against these concerns are the law's real gains: a first enforceable right over personal data, a dedicated regulator, strong protections for children, and graded penalties. The fair assessment, and the one an answer should reach, is that the DPDP framework is a significant step forward whose value will depend on how independently it is enforced and how the exemptions are used in practice.

UPSC Relevance and Exam Focus

Where this fits in the UPSC-CSE syllabus

This topic maps most directly to General Studies Paper II: governance, government policies and interventions, and statutory bodies, with strong links to fundamental rights and the right to privacy. It also reaches into General Studies Paper III, where data security and the protection of personal data sit within the science-and-technology and internal-security syllabus.

For Prelims, hold the high-yield facts: the DPDP Act, 2023 is India's first standalone data-protection law; the DPDP Rules, 2025 were notified in November 2025; the law creates the Data Protection Board of India; it is built on consent and the Puttaswamy right to privacy; and it defines the Data Principal, the Data Fiduciary and the Consent Manager.

For Mains, the recurring framing is to describe the law's context and salient features, and to weigh its strengths against its criticisms, the wide State exemptions, the RTI amendment and the Board's independence. A strong answer treats data protection as a balance between the individual's right to privacy and the State's and the economy's need to process data.

Recurring linked concepts an aspirant should keep in working memory:

  • Right to privacy (Puttaswamy, 2017): The Supreme Court holding that privacy is a fundamental right under Article 21, the basis of the DPDP Act.
  • Data Principal and Data Fiduciary: The individual whose data it is, and the entity that decides the purpose and means of processing it.
  • Consent and itemised notice: The free, informed permission, and the plain-language notice, on which lawful processing rests.
  • Data Protection Board of India: The digital adjudicatory body that hears complaints and imposes penalties under the Act.

A common Prelims trap is to confuse the DPDP Act with the Information Technology Act, 2000. The IT Act and its rules earlier governed data through a general framework; the DPDP Act is the dedicated, standalone law on personal data, with its own regulator and rights.

A common Mains trap is to praise the law without testing it. Its exam value lies in a balanced judgment: the genuine advance of an enforceable privacy right and a regulator, set honestly against the concerns over State exemptions, the RTI change and the Board's independence.

Previous Year UPSC-CSE Questions By the end you will be able to draft model answers for the following UPSC questions. Each question carries a collapsible framework showing how to approach it in the exam.

  1. UPSC Mains 2024 GS-IIIDescribe the context and salient features of the Digital Personal Data Protection Act, 2023.
    How to structure the answer in the exam

    Approach: First set the context, the right-to-privacy judgment and the years of drafting that produced the Act, then describe its salient features, the actors, consent and notice, the rights and duties, the Board and the penalties, closing with a brief, balanced note on its significance and concerns.

    Body (sub-themes to develop):

    • Context: the Puttaswamy 2017 judgment made privacy a fundamental right under Article 21 and called for a data-protection law; the Justice Srikrishna Committee (2018) and the withdrawn 2019 and 2022 bills preceded the 2023 Act and the 2025 Rules.
    • Core actors and consent: the Data Principal, the Data Fiduciary, the Data Processor and the Consent Manager; processing rests on free, informed consent and an itemised notice, with limited legitimate uses.
    • Rights of the individual: to access a summary of their data, to correct and erase it, to grievance redressal and to nominate another to act for them.
    • Duties and safeguards: Data Fiduciaries must keep reasonable security safeguards, notify breaches and erase data; Significant Data Fiduciaries face audits and impact assessments; children's data needs verifiable parental consent.
    • Enforcement and concerns: the Data Protection Board of India adjudicates and imposes penalties up to Rs 250 crore, while critics flag wide State exemptions, the RTI amendment and the Board's independence.

Sources and Further Reading

Editorial Disclaimer

This briefing is for UPSC preparation. Verify the figures and provisions against the official MeitY and PIB sources and the bare Act and Rules before relying on them.