Back to Frameworks
Frameworks

Digital Personal Data Protection Act, 2023 (DPDPA) (India)

Framework Name

Digital Personal Data Protection Act (DPDPA)

Type

Mandatory

Region / Jurisdiction

India

Enforcing Body / Certifying Party

Data Protection Board of India

Penalty / Consequence of Non-Compliance

Financial penalties up to ₹250 crore (roughly $30 million USD) per instance, depending on the nature and severity of the violation

What It Is & Why It Matters

The Digital Personal Data Protection Act is India's national law for how organizations collect, store, and use personal data. It applies to any company processing digital personal data of individuals in India, whether the company is based in India or overseas. The law introduces defined roles: organizations that decide how data is used are called Data Fiduciaries, and the individuals whose data is collected are called Data Principals.

DPDPA matters because India is one of the largest digital markets in the world, and this law puts real obligations behind that scale. Companies must get clear consent before collecting personal data, explain why they need it, and let people access, correct, or delete their own information. Failing to meet these requirements can mean significant fines and reputational damage in a market few global companies can afford to ignore.

Who Needs It

  • You collect or process personal data from individuals located in India, regardless of where your company is headquartered
  • You offer goods or services to people in India, even without a local office
  • You handle Indian customer or employee data as part of a SaaS platform, app, or online service
  • You already comply with GDPR and want to understand how India's approach compares
Book A Demo