Insights

Digital Personal Data Protection Act, 2023 & Rules, 2025: FAQs

India's DPDP Act and the 2025 Rules reshape how businesses collect and handle personal data — consent, notices, breach reporting, and penalties up to ₹250 crore. A practical FAQ for businesses and individuals.

Published 3 December 2025 · Updated 14 August 2026 · Reviewed by Selvam & Selvam

India’s Digital Personal Data Protection Act, 2023 (with the 2025 Rules) changes how every business that touches Indian users’ personal data must operate — consent, notices, deletion, breach reporting, and penalties up to ₹250 crore. Here is what businesses (data fiduciaries) and individuals (data principals) need to know.

For businesses (data fiduciaries)

What data does the DPDP Act cover? Digital personal data — any information identifying a person, whether collected online or later digitised. It does not cover anonymous or non-personal data. The moment offline data is digitised, the Act applies.

Does it apply to foreign companies? Yes. If you process Indian users’ digital personal data to offer goods or services to people in India, the Act applies regardless of where you are incorporated.

What are the core new obligations?

  • Collect only necessary data (data minimisation).
  • Obtain clear, specific, informed, unconditional and express consent, preceded or accompanied by a specific notice.
  • Implement reasonable security safeguards.
  • Delete data once the purpose is met or consent is withdrawn.
  • Handle grievances in time, publish DPO/grievance-officer details, and keep records of consent and notices.

Is my existing click-wrap privacy policy enough? No. You need a separate, itemised, plain-language notice — stating what data is collected, the exact purpose, how users exercise their rights, and complaint/redressal details — distinct from your privacy policy and T&Cs.

Can I keep collecting the same data as before? Only if it was necessary for the service — and after sending customers a fresh, specific notice. Avoid excessive collection. For pre-Act data, send a fresh notice; you may keep processing unless the customer withdraws.

What about children and persons with disabilities? For children, obtain verifiable parental consent; for persons with disabilities, consent from their legal guardian. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited.

When is consent not required? For certain legitimate uses — voluntary provision of data, legal/state functions, compliance with law or court orders, medical/disaster emergencies, and specified employment purposes — but always subject to necessity and purpose limitation.

What are the breach-reporting rules? On a breach, notify each affected user and the Data Protection Board immediately, and give the Board a detailed account within 72 hours.

What are the penalties? Monetary penalties of up to ₹250 crore, depending on the nature, gravity, duration and repetition of the breach and whether you gained from it.

Do I need a Data Protection Officer or audits? Only if the Government notifies you as a Significant Data Fiduciary — which then also triggers independent audits and Data Protection Impact Assessments. You cannot self-declare that status.

Compliance timeline (from the Rules):

  • Data Protection Board provisions — already in force.
  • Data Fiduciary obligations — effective 13 May 2026.
  • Consent Manager provisions — effective 13 November 2026.

For individuals (data principals)

What rights do I have? To access your data (including pre-Act data), get a summary of processing, correct/update/delete it, withdraw consent anytime, know the purposes, and complain if your rights are violated. Any consent that waives these rights is invalid.

Can I refuse unnecessary data requests? Yes. A company cannot demand data not necessary for the service, nor deny the service just because you refuse unnecessary permissions.

Will my data be deleted when no longer needed? Yes — companies must delete it once the purpose is met (unless another law requires retention), and you can request deletion anytime.

How do I complain? Raise it with the company’s grievance officer (typically resolved within 30 days); escalate to the Data Protection Board, with a further appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

Practical guidance

  • Rebuild your consent flow and notices now — a generic policy will not satisfy the Act.
  • Map your data, minimise collection, and set deletion triggers.
  • Prepare a breach playbook for the immediate + 72-hour reporting duties.
  • Watch the 13 May 2026 deadline for data-fiduciary obligations.

Frequently asked questions

Does the DPDP Act apply to foreign apps serving Indian users? Yes — any business offering goods or services to people in India must comply, wherever it is incorporated.

Is a generic privacy policy enough under the DPDP Act? No. A separate, specific, itemised consent notice is required, distinct from the privacy policy and terms.

What is the maximum penalty under the DPDP Act? Up to ₹250 crore, depending on the breach’s nature, gravity, duration and repetition.

When must a data breach be reported? Affected users and the Data Protection Board must be notified immediately, with a detailed account to the Board within 72 hours.