
The growing use of personal data in commercial activities, public administration and everyday digital interactions has made data protection an increasingly important component of India’s legal framework. The Digital Personal Data Protection Act, 2023 establishes a statutory framework for the processing of digital personal data, recognising both the right of individuals to protect their personal data and the need to process such data for lawful purposes. It sets out the responsibilities of entities that determine the purpose and means of processing and provides corresponding rights to individuals to whom the personal data relates.
The Digital Personal Data Protection Rules, 2025, notified in November 2025, supplement the Act by prescribing the detailed requirements for implementation. The Act and the Rules are being brought into force in phases. Institutional provisions took effect first, followed by provisions relating to Consent Managers and, subsequently, the principal obligations governing the processing of personal data. As of September 2026, the framework remains in a transitional phase, with the principal compliance requirements scheduled to take effect in May 2027 in accordance with the notified implementation timeline.
The Act applies to personal data collected in digital form as well as data collected in non-digital form and subsequently digitised, subject to the exclusions and exemptions prescribed under the law. Its application also extends to processing undertaken outside India where such processing is connected with the offering of goods or services to individuals within India. Consent is one of the principal grounds for processing, together with the “certain legitimate uses” recognised under the Act. Where processing is based on consent, such consent must satisfy the statutory requirements and must relate to personal data necessary for the specified purpose.
The framework introduces obligations intended to ensure accountability throughout the lifecycle of personal data, including requirements relating to notices, security safeguards, retention, erasure and grievance redressal. The Rules further prescribe measures for protecting personal data, including appropriate access controls, monitoring mechanisms, business continuity arrangements and contractual safeguards where processing is carried out on behalf of a Data Fiduciary. They also set out requirements for notifying personal data breaches to affected individuals and the Data Protection Board of India, including an initial intimation without delay and further reporting to the Board within the prescribed period.
The rights available to individuals form an important part of the framework and include the right to access information relating to the processing of personal data, seek correction and erasure, obtain grievance redressal and nominate another individual to exercise specified rights in certain circumstances. Additional safeguards apply to the processing of children’s personal data, and enhanced obligations may be imposed on entities designated as Significant Data Fiduciaries. The enforcement framework provides for inquiries into contraventions, remedial directions and monetary penalties, with the maximum penalty for failure to take reasonable security safeguards extending to INR 250 crore.
This booklet presents the principal provisions of the Act and the Rules in a frequently asked questions format. It covers the scope and application of the framework, consent and certain legitimate uses, obligations of Data Fiduciaries, individual rights, security safeguards, personal data breach reporting, cross-border processing and enforcement. The booklet is intended to serve as a clear and accessible reference for understanding the legal framework and its phased implementation.



