Decoding India's Digital Personal Data Protection Act
A practical, operational reference guide for Data Fiduciaries, DPOs, and legal practitioners. Understand the law; automate the controls.
Every section summarised on this page is taken from the Gazette text of the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Summaries are ours; the Act's own words are the authority.
Map every statutory section to an operational control
Expand any section of the Act to see the obligations it imposes and the DPDPNiti control that operationalises it.
Every request for consent must be accompanied by a clear, itemised notice describing the personal data sought and the purpose of processing.
Key obligations
- Itemised description of personal data and processing purposes
- Notice available in English and any of the 22 Eighth Schedule languages
- Details of how to exercise rights and complain to the Data Protection Board
How DPDPNiti operationalises it
Notice obligations arrive as controls with an owner and an evidence requirement. Notice authoring across the 22 scheduled languages is on the roadmap, not in the product today.
The obligations that reshape day-to-day operations
22 Eighth Schedule Languages
Consent notices must be accessible in English and any of the 22 languages of the Eighth Schedule, ensuring Data Principals can understand what they agree to.
Grievance Redressal First
Data Principals must exhaust the Fiduciary’s grievance mechanism before approaching the Data Protection Board, making an accountable in-house process essential.
Verifiable Parental Consent
Processing a child’s data requires verifiable consent from a parent or lawful guardian, with robust identity and age verification standards.
Data Breach Triage Protocols
On a personal data breach, Fiduciaries must notify the Board and affected Data Principals, driving the need for disciplined incident triage and statutory timers.
Phased commencement
The Act commences in phases set by G.S.R. 843(E): some provisions on publication, more one year on, and the operative obligations — notice, consent, the Data Fiduciary duties, Data Principal rights — eighteen months from publication, on 13 May 2027.
Disclaimer: DPDPNiti provides enterprise governance software to operationalise compliance. This platform does not provide formal legal counsel or guarantees. Our regulatory summaries have not yet been reviewed by external legal counsel, and the product marks them as unreviewed for the same reason. Use them to orient, not to rely on.
See it against your own obligations
A walkthrough of the real product — the assessment, the controls, the evidence and the audit trail — with the roadmap shown as the roadmap.