Everything you need to know about DPDP Act compliance, data security requirements, and secure data disposal.
India's Digital Personal Data Protection Act, 2023 (DPDP Act) is the country's first comprehensive, dedicated data protection law. Enacted in August 2023 and now moving through phased implementation following the notification of its supporting rules in late 2025, the DPDP Act represents a major shift in how organizations operating in India must handle digital personal data.
Background
The DPDP Act was passed by Parliament and received presidential assent in August 2023, following years of deliberation dating back to draft bills first proposed in 2018 and 2019. Unlike earlier attempts, the final Act deliberately narrowed its scope to digital personal data specifically, rather than personal data in all forms.
Implementation has proceeded in structured phases. The Digital Personal Data Protection Rules, 2025, were notified on November 13, 2025, along with enforcement timelines and the formal establishment of the Data Protection Board of India (DPBI). The Ministry of Electronics and Information Technology set out a staggered rollout across three broad phases: initial governance and Board setup (effective November 2025), a second phase centered on the Consent Manager framework (effective November 2026), and full substantive enforcement (effective May 2027).
Who Must Comply
The DPDP Act applies to the processing of digital personal data within India, and — notably — also applies to processing outside India if it relates to offering goods or services to individuals (Data Principals) in India. Entities that determine the purpose and means of processing are termed "Data Fiduciaries," while individuals whose data is processed are termed "Data Principals."
Consent as the Foundation
The DPDP Act is built around a consent-centric model. Data Fiduciaries must obtain clear, specific, informed, and unambiguous consent before processing personal data, accompanied by an itemized notice describing the personal data being collected and the purpose of processing. Consent must be as easy to withdraw as it was to give. The Act also recognizes a limited set of "legitimate uses" that permit processing without consent in specific circumstances, such as for purposes voluntarily provided by an individual for a specified purpose, or compliance with a legal obligation.
Significant Data Fiduciaries
The Act creates a category of "Significant Data Fiduciary" for organizations designated by the government based on factors such as the volume and sensitivity of data processed, and the risk to Data Principals' rights. These entities face heightened obligations, including appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, and independent data audits.
Children's Data
The DPDP Act sets a strict, uniform threshold of 18 years for defining a child, one of the strictest globally, and requires verifiable parental consent before processing a child's personal data. It also prohibits tracking, behavioral monitoring, and targeted advertising directed at children.
Data Principal Rights
Individuals under the DPDP Act have the right to obtain a summary of personal data being processed and the processing activities undertaken, the right to correction and erasure of personal data, the right to grievance redressal, and the right to nominate another individual to exercise these rights on their behalf in the event of death or incapacity.
Breach Notification
The DPDP Act requires Data Fiduciaries to notify the Data Protection Board and affected Data Principals in the event of a personal data breach — notably, without the materiality or risk threshold found in many other laws such as GDPR, meaning notification obligations under the DPDP framework can apply more broadly than under comparable international laws.
Enforcement and Penalties
The Data Protection Board of India is empowered to investigate breaches and impose financial penalties, which can reach up to INR 250 crore (roughly USD 30 million) for the most serious violations, such as failure to implement reasonable security safeguards or failure to notify a data breach. Enforcement is expected to intensify gradually as the phased implementation timeline progresses toward full substantive enforcement in mid-2027.
Secure Data Erasure Under the DPDP Act
The Act requires Data Fiduciaries to erase personal data once the specified purpose is no longer being served and retention is not otherwise required by law, and requires reasonable security safeguards to prevent personal data breaches — including in relation to data on devices being decommissioned. For organizations handling digital personal data in India, this means retired laptops, servers, and mobile devices need to go through standards-based, verifiable data erasure rather than simple deletion, with documentation retained to demonstrate that "erasure" obligations were genuinely fulfilled, especially as the Data Protection Board ramps up enforcement scrutiny through 2026 and 2027.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
The DPDP Act marks a foundational shift for data protection in India, moving the country toward a structured, consent-driven, and increasingly enforced privacy regime. With phased implementation continuing through 2027, organizations should treat 2026 as the critical window to build compliant consent flows, breach response processes, and secure, verifiable data lifecycle management well ahead of full enforcement.
No comments yet. Be the first to comment.