Frequently Asked Questions
Which organisations are required to comply with the Digital Personal Data Protection Act 2023, and when does it apply?
The Digital Personal Data Protection Act 2023 (DPDPA) applies to every 'Data Fiduciary' — any person who alone or in conjunction with others determines the purpose and means of processing digital personal data — as defined under Section 2(i) of the Act. The Act applies to processing of digital personal data within India where data is collected online or is digitised after collection offline, and also applies to processing outside India if it is in connection with offering goods or services to individuals in India under Section 3(b). The Act does not apply to personal data processed for personal or domestic purposes, or to publicly available personal data as carved out under the proviso to Section 3(a). The Act is notified but specific sections and rules are to be brought into force on dates notified by the Central Government — organisations should track the Ministry of Electronics and Information Technology (MeitY) notifications under Section 1(2) to determine applicable dates for each obligation, as some provisions may be phased.
What are the notice and consent requirements under the DPDPA 2023 before processing personal data?
Under Section 5 of the DPDPA 2023, a Data Fiduciary must give a notice to the Data Principal (the individual) before or at the time of collecting personal data, informing them of the personal data being processed, the purpose of processing, and the manner in which the Data Principal can exercise their rights. Section 6 requires that consent obtained must be free, specific, informed, unconditional, and unambiguous — given through a clear affirmative action — and must be limited to the specific purpose disclosed in the notice. Consent can be withdrawn at any time under Section 6(4) and the Data Fiduciary must provide a facility to withdraw consent as easily as it was given, ceasing processing upon withdrawal without affecting the lawfulness of prior processing. Section 7 provides legitimate uses (deemed consent) where consent is not required — such as processing for performance of a State function, compliance with law, or medical emergencies — but the Data Fiduciary bears the burden of establishing that its processing falls within a legitimate use category rather than relying on overly broad interpretations.
What obligations do Significant Data Fiduciaries have under the DPDPA 2023 that other companies do not?
Section 10 of the DPDPA 2023 empowers the Central Government to designate certain Data Fiduciaries as 'Significant Data Fiduciaries' (SDFs) based on factors including volume and sensitivity of data processed, risk to rights of Data Principals, national security implications, and potential impact on sovereignty. SDFs are subject to enhanced obligations under Section 10(2) including: appointment of a Data Protection Officer based in India who reports to the board, appointment of an independent data auditor to conduct periodic audits, and conducting Data Protection Impact Assessments (DPIAs) before undertaking new or high-risk processing activities. SDFs must also comply with any additional standards or restrictions notified by the Data Protection Board established under Section 18. Non-SDF companies must still comply with Sections 4–9 (notice, consent, data minimisation, accuracy, storage limitation, security) but are not subject to the enhanced SDF-specific obligations unless designated.
What data security obligations does the DPDPA 2023 impose, and what are the penalties for a data breach?
Section 8(5) of the DPDPA 2023 requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches, and the rules to be notified under the Act are expected to prescribe specific technical and organisational measures analogous to global standards. In the event of a personal data breach, Section 8(6) requires the Data Fiduciary to notify both the Data Protection Board and each affected Data Principal in the manner and within the timeframe prescribed by the forthcoming rules. The Schedule to the DPDPA 2023 sets out the penalty framework: failure to implement adequate security safeguards carries a penalty of up to ₹250 crore per breach, and failure to notify the Board of a breach carries a penalty of up to ₹200 crore. The Data Protection Board constituted under Section 18 has adjudicatory powers and may impose penalties after conducting an inquiry, and decisions of the Board are appealable to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29.
What rights do individuals (Data Principals) have under the DPDPA 2023, and how must companies handle these requests?
Sections 11 through 14 of the DPDPA 2023 confer four core rights on Data Principals: the right to access a summary of personal data being processed and the identities of all Data Fiduciaries with whom data has been shared (Section 11); the right to correction, completion, updating, and erasure of personal data that is no longer necessary for the specified purpose (Section 12); the right to grievance redressal with the Data Fiduciary before approaching the Board (Section 13); and the right to nominate another individual to exercise these rights in the event of death or incapacity (Section 14). Data Fiduciaries must provide a facility for Data Principals to exercise these rights under Section 8(7), and must respond within such period as prescribed by rules. Ignoring or denying rights requests without valid grounds exposes the Data Fiduciary to a penalty of up to ₹50 crore under the Schedule to the DPDPA 2023. Companies should establish a documented rights request management process, including identity verification of requestors and audit trails of responses, before the rules are notified to avoid remedial scrambling.
Ready to get DPDPA Compliance?
File a request in under 2 minutes. Our team contacts you within 24 hours.