.png)
.png)

Digital Personal Data Protection Act, 2023 (DPDPA) (India)
Framework Name
Digital Personal Data Protection Act (DPDPA)
Type
Mandatory
Region / Jurisdiction
India
Enforcing Body / Certifying Party
Data Protection Board of India
Penalty / Consequence of Non-Compliance
Financial penalties up to ₹250 crore (roughly $30 million USD) per instance, depending on the nature and severity of the violation
What It Is & Why It Matters
The Digital Personal Data Protection Act is India's national law for how organizations collect, store, and use personal data. It applies to any company processing digital personal data of individuals in India, whether the company is based in India or overseas. The law introduces defined roles: organizations that decide how data is used are called Data Fiduciaries, and the individuals whose data is collected are called Data Principals.
DPDPA matters because India is one of the largest digital markets in the world, and this law puts real obligations behind that scale. Companies must get clear consent before collecting personal data, explain why they need it, and let people access, correct, or delete their own information. Failing to meet these requirements can mean significant fines and reputational damage in a market few global companies can afford to ignore.
Who Needs It
- You collect or process personal data from individuals located in India, regardless of where your company is headquartered
- You offer goods or services to people in India, even without a local office
- You handle Indian customer or employee data as part of a SaaS platform, app, or online service
- You already comply with GDPR and want to understand how India's approach compares