Skip to content
Regulatory Intelligence Hub

Decoding India's Digital Personal Data Protection Act

A practical, operational reference guide for Data Fiduciaries, DPOs, and legal practitioners. Understand the law; automate the controls.

Every section summarised on this page is taken from the Gazette text of the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Summaries are ours; the Act's own words are the authority.

Clause-to-Control Explorer

Map every statutory section to an operational control

Expand any section of the Act to see the obligations it imposes and the DPDPNiti control that operationalises it.

Every request for consent must be accompanied by a clear, itemised notice describing the personal data sought and the purpose of processing.

Key obligations

  • Itemised description of personal data and processing purposes
  • Notice available in English and any of the 22 Eighth Schedule languages
  • Details of how to exercise rights and complain to the Data Protection Board

How DPDPNiti operationalises it

Notice obligations arrive as controls with an owner and an evidence requirement. Notice authoring across the 22 scheduled languages is on the roadmap, not in the product today.

Key Operational Mandates

The obligations that reshape day-to-day operations

Sec 5 & 6

22 Eighth Schedule Languages

Consent notices must be accessible in English and any of the 22 languages of the Eighth Schedule, ensuring Data Principals can understand what they agree to.

Sec 13

Grievance Redressal First

Data Principals must exhaust the Fiduciary’s grievance mechanism before approaching the Data Protection Board, making an accountable in-house process essential.

Sec 9

Verifiable Parental Consent

Processing a child’s data requires verifiable consent from a parent or lawful guardian, with robust identity and age verification standards.

Sec 8(6)

Data Breach Triage Protocols

On a personal data breach, Fiduciaries must notify the Board and affected Data Principals, driving the need for disciplined incident triage and statutory timers.

G.S.R. 843(E)

Phased commencement

The Act commences in phases set by G.S.R. 843(E): some provisions on publication, more one year on, and the operative obligations — notice, consent, the Data Fiduciary duties, Data Principal rights — eighteen months from publication, on 13 May 2027.

Disclaimer: DPDPNiti provides enterprise governance software to operationalise compliance. This platform does not provide formal legal counsel or guarantees. Our regulatory summaries have not yet been reviewed by external legal counsel, and the product marks them as unreviewed for the same reason. Use them to orient, not to rely on.

See it against your own obligations

A walkthrough of the real product — the assessment, the controls, the evidence and the audit trail — with the roadmap shown as the roadmap.