Plain-language guide

The DPDP Act, 2023, explained simply

India's Digital Personal Data Protection Act gives people real rights over their personal data — and gives businesses real duties. Here's what it means and how to comply.

This guide is for general understanding and is not legal advice.

The basics

Four principles at its core

The Act rests on a handful of ideas. Get these right and most of the obligations follow naturally.

Lawful purpose & consent

Personal data may only be processed for a lawful purpose with the data principal's free, informed and specific consent.

Notice & transparency

A clear notice must accompany every request for consent, describing what data is collected and why.

Purpose limitation

Data can only be used for the purposes it was collected for — and must be erased once that purpose is met.

Accountability

Data fiduciaries are responsible for compliance and must be able to demonstrate it to the Data Protection Board.

Your rights

What the Act gives data principals

The Act puts individuals back in control of their personal data, with clear, enforceable rights they can exercise at any time.

See how we power these rights

Right to access

Know what personal data is held about you and how it's being processed.

Right to correction & erasure

Have inaccurate data corrected and request deletion when it's no longer needed.

Right to grievance redressal

Raise concerns and have them addressed within the statutory timeline.

Right to nominate

Nominate someone to exercise your rights in the event of death or incapacity.

Getting compliant

A four-step path to readiness

01

Map your data

Inventory what personal data you collect, for which purposes, and where it flows.

02

Fix your notices & consent

Show clear, purpose-level notices and capture verifiable consent at the point of collection.

03

Enable rights & grievances

Give data principals an easy way to access, correct, erase and raise concerns.

04

Keep proof

Maintain a tamper-evident record of consent and actions to demonstrate compliance.

Quick compliance checklist

  • Clear, purpose-level consent notices
  • Verifiable consent capture & storage
  • Easy withdrawal of consent
  • Data-principal rights portal
  • Grievance channel with SLAs
  • Tamper-evident audit trail
FAQ

DPDP Act, frequently asked

Common questions about India's data protection law.

It applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to data principals in India. Both 'data fiduciaries' (who decide how data is processed) and their processors are covered.

A data principal is the individual the personal data relates to. A data fiduciary is the entity that determines the purpose and means of processing that data — broadly, the organisation collecting it.

The Act provides for significant financial penalties — up to ₹250 crore for certain failures, such as not taking reasonable security safeguards to prevent a data breach. Penalties are determined by the Data Protection Board.

Consent is the primary basis, but the Act also recognises 'certain legitimate uses' where data can be processed without explicit consent (for example, where a person voluntarily provides data for a clearly intended purpose). Consent management remains central for most use cases.

ConsentVault gives you compliant notices, verifiable consent capture, a rights and grievance portal, and a tamper-evident audit trail — turning the Act's obligations into a repeatable workflow you can prove.

Background

Ready to give your users consent they can trust?

Register your organization or sign in to your portal to get started with DPDP-compliant consent management.

Already have an account?