The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive federal data protection legislation, enacted in August 2023. It establishes the framework for how personal data of Indian residents may be collected, processed, stored, and transferred — by both Indian and foreign entities that process such data.
Key provisions
Consent as the primary lawful basis. Personal data may generally be processed only with the free, specific, informed, and unambiguous consent of the data principal (the individual whose data is being processed). Consent must be obtained before processing, must be as easy to withdraw as to give, and must be maintained in a verifiable form.
Data Fiduciary obligations. Entities that determine the purpose and means of processing (Data Fiduciaries — equivalent to GDPR's "controllers") must maintain data accuracy, implement security safeguards, delete data when no longer necessary, and establish a grievance redressal mechanism. Significant Data Fiduciaries (to be notified by the government) face additional obligations including data protection impact assessments and audits.
Data Principal rights. Individuals have the right to access a summary of their data, correct inaccurate data, erase data (right to be forgotten), nominate a person to exercise rights on their behalf, and raise grievances with both the Data Fiduciary and the Data Protection Board of India.
Cross-border transfer restrictions. The Central Government may restrict transfer of personal data to certain countries or territories. The specific list of permitted and restricted countries has not yet been notified as of early 2026, but the framework is in place.
Penalties. The DPDP Act establishes significant financial penalties — up to ₹250 crore per instance of personal data breach, and up to ₹200 crore for failure to notify breaches. The Data Protection Board has adjudicatory powers.
DPDP and infrastructure choices
The DPDP Act's data localisation provisions — combined with the practical need to demonstrate control over personal data processing — make on-premise infrastructure significantly easier to comply with than cloud-based alternatives. When data resides on hardware you control, the Data Fiduciary relationship is straightforward. When data is processed on a third-party cloud, the Fiduciary/Processor relationship must be contractually established, audited, and maintained for every processing activity.
