DPDP Act 2023 Explained: India’s Data Protection Law & What It Means for Careers
The DPDP Act (Digital Personal Data Protection Act 2023) is India’s first comprehensive data privacy law. It requires organisations to obtain explicit consent before collecting personal data of Indian residents, store it only as long as needed, and delete it once the purpose is fulfilled. Penalties for non-compliance reach up to 250 crore rupees per violation.
The DPDP Act sets rules for how organisations collect, store, and use personal data of Indian citizens. Passed by Parliament in August 2023, it applies to any entity processing digital personal data in India, with penalties reaching up to 250 crore rupees for serious violations.
- Key Takeaway 1: The DPDP Act covers all digital personal data collected in India, plus data collected outside India if it is used to offer goods or services to Indian residents.
- Key Takeaway 2: Consent is the foundation of the law. Companies must get free, specific, and informed consent before processing personal data.
- Key Takeaway 3: A new government body, the Data Protection Board of India, will investigate complaints and impose penalties.
- Key Takeaway 4: Non-compliance penalties go up to 250 crore rupees per instance, making this law impossible for large businesses to ignore.
- Key Takeaway 5: The DPDP Act is already creating demand for Data Protection Officers, privacy analysts, and GRC professionals across Indian industries.
What the DPDP Act Actually Says (Plain-English Summary)
Think of the DPDP Act as India’s answer to Europe’s GDPR, but built specifically for the Indian context. The law uses two core terms you will see everywhere: data fiduciary (the company or person who decides why and how data is processed) and data principal (the individual whose data is being processed).
Before a company can collect your name, phone number, email, or health information, it must give you a clear notice in plain language and get your explicit consent. You can withdraw that consent later. The company must then delete your data once the purpose for collecting it is done.
The DPDP Act covers digital personal data only. Paper records are not directly covered unless they are digitised. It applies to processing that happens inside India, plus processing outside India if the goal is to offer products or services to people in India.
DPDP Act vs GDPR: Key Differences
The GDPR is older (2018) and more granular. The DPDP Act borrows from it but takes a lighter-touch approach in several areas. There is no explicit right to data portability in the Indian law, and the grounds for processing are narrower. The GDPR allows multiple lawful bases for processing; the DPDP Act centres almost entirely on consent and a limited set of legitimate uses.
One significant difference: the DPDP Act does not yet have a mandatory data breach notification timeline baked into the primary legislation. The DPDP Rules 2025, still being finalised by the Ministry of Electronics and Information Technology (MeitY), are expected to specify that timeline along with other procedural details.
| Feature | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Year enacted | 2023 | 2018 |
| Right to data portability | Not included | Included |
| Lawful bases for processing | Primarily consent plus limited legitimate uses | Six lawful bases |
| Breach notification timeline | To be specified in DPDP Rules 2025 | 72 hours |
| Maximum penalty | Up to 250 crore rupees | 20 million euros or 4% of global turnover |
| Dedicated regulator | Data Protection Board of India | National Data Protection Authorities |
DPDP Act vs the IT Act: Why This Is Different
India already had Section 43A of the IT Act 2000, which dealt with sensitive personal data. But that provision only applied to companies, used vague standards, and had no dedicated enforcement body. The DPDP Act replaces that framework with a dedicated law, a dedicated regulator, and specific penalty slabs. It is a proper upgrade, not a patch.
Who the DPDP Act Applies To and What Compliance Looks Like
If your organisation collects any digital personal data from Indian residents, the DPDP Act applies to you. That includes startups, banks, hospitals, e-commerce platforms, SaaS companies, and even non-profits. There are some exemptions, including personal or domestic use, and certain government processing activities notified by the Central Government.
Significant data fiduciaries face extra obligations under the DPDP Act. MeitY will notify specific companies as significant based on the volume of data they process, sensitivity of that data, and potential national security risk. These entities must appoint a Data Protection Officer based in India, conduct regular data protection impact assessments, and submit to audits.
The Practical DPDP Act Compliance Checklist
Getting compliant with the DPDP Act is not a one-day job. Here is what most organisations need to work through:
- Data mapping: Identify every category of personal data you collect and document why you collect it.
- Consent management: Build or buy a system that records when consent was given, for what purpose, and allows users to withdraw it easily.
- Privacy notice update: Rewrite your privacy policy in plain language (the Act specifically requires notices to be clear and plain).
- Grievance mechanism: Every data fiduciary must have a published contact point for users to raise data-related complaints.
- Vendor contracts: If you share data with third parties (data processors), update your contracts to include DPDP-aligned obligations.
- DPO appointment: Significant data fiduciaries must appoint a DPO; others should consider it as a risk management measure.
A 2023 survey by KPMG India found that over 60% of Indian organisations had not started any formal data protection compliance programme. That gap is both a business risk and a career opportunity. Separately, a 2023 report by NASSCOM estimated that India would need over 50,000 trained data privacy professionals within three years of the DPDP Act coming into full force, underscoring the scale of the skills shortage.
If you are working in IT governance or risk management, understanding how to build an enterprise cybersecurity framework is the logical complement to DPDP Act compliance work. The two disciplines overlap more than most teams realise.
The Data Protection Board of India
The Data Protection Board is the DPDP Act’s enforcement arm. It is a digital-first body, meaning complaints can be filed online. The Board has powers to investigate, call for information, and impose penalties. It is not a court, but its decisions can be appealed to the High Court.
The Board’s structure and appointment process drew criticism during the Bill’s passage, particularly because the Central Government has significant influence over who sits on it. That is a genuine governance concern worth watching as the institution matures.
Penalties Under the DPDP Act and Why They Matter
This is where most compliance teams pay attention. The DPDP Act penalty structure is tiered based on the type of violation. Here is the full breakdown:
| Violation Type | Maximum Penalty |
|---|---|
| Failure to protect children’s data or process it without verifiable parental consent | Up to 200 crore rupees |
| Failure to notify the Data Protection Board and affected individuals of a data breach | Up to 200 crore rupees |
| Non-fulfilment of obligations by significant data fiduciaries | Up to 150 crore rupees |
| Violation of data principal rights (e.g., ignoring erasure requests) | Up to 10,000 rupees per instance |
| Any other violation of the Act or Rules | Up to 50 crore rupees |
| Breach by a significant data fiduciary causing widespread harm | Up to 250 crore rupees |
The 250 crore rupee ceiling is significant. For context, that is roughly $30 million USD. It is lower than GDPR’s maximum (20 million euros or 4% of global turnover), but it is still large enough to be material for mid-sized Indian companies. The IAMAI and several industry bodies lobbied for lower caps during the Bill’s drafting, and this is what came out the other side.
One thing worth noting: the DPDP Act includes a good-faith defence. If an organisation can show it took reasonable security safeguards and acted promptly after discovering a breach, the Board has discretion to reduce penalties. That makes your security posture directly relevant to your legal exposure.
Timeline: From Bill to Rules
The Digital Personal Data Protection Bill was passed by both Houses of Parliament in August 2023 and received Presidential assent on 11 August 2023. The Act’s operative sections, however, come into force only when notified by the Central Government. As of mid-2025, MeitY had released draft DPDP Rules 2025 for public comment, with the final rules expected to be notified before the end of 2025. Until the Rules are notified, full enforcement has not formally begun, but smart organisations are not waiting.
The Careers the DPDP Act Is Creating Right Now
Privacy law creates privacy jobs. That is not speculation; it is what happened in Europe after GDPR came into force. The International Association of Privacy Professionals (IAPP) reported that GDPR created over 500,000 new DPO positions globally within two years of enforcement. India’s market is different in scale, but the direction is identical.
The roles emerging right now in India under the DPDP Act include:
- Data Protection Officer (DPO): Required by law for significant data fiduciaries. Expected salaries range from 15 lakh to 40 lakh rupees per annum depending on company size and sector, based on current job listings on LinkedIn and Naukri.com.
- Privacy Analyst / Privacy Counsel: Handles consent management, privacy notices, and data subject requests. Strong demand in BFSI, health-tech, and e-commerce sectors.
- GRC (Governance, Risk and Compliance) Analyst: Broader role that includes DPDP Act compliance alongside ISO 27001, SOC 2, and other frameworks.
- Privacy Engineer: Builds privacy-by-design into product architecture. High demand in SaaS and fintech companies.
- Data Breach Response Specialist: Manages incident response from a legal and regulatory notification standpoint.
Certifications that employers are already asking for include the IAPP’s CIPP/A (Certified Information Privacy Professional/Asia), CIPM, and ISO 27701 Lead Implementer. If you are coming from a technical background, pairing one of these with hands-on security skills makes you genuinely rare in the Indian job market.
The hiring wave is most visible in BFSI right now. The Reserve Bank of India has been pushing data localisation and governance requirements for years, so banks and NBFCs already had compliance infrastructure. They are now expanding it to meet DPDP Act requirements. Health-tech is next, given the sensitivity of medical data.
If you want to see how wide this hiring wave actually runs, the detailed breakdown in our guide to cybersecurity job demand in India puts the numbers in context. Privacy roles are one of the fastest-growing sub-categories.
For professionals looking to pivot into this space, 3.0 University’s GRC and cybersecurity programmes are built specifically around frameworks like the DPDP Act, ISO 27001, and enterprise risk management. Getting structured training now, before the rules are fully notified, puts you ahead of the compliance hiring rush that is coming.
There is also a strong parallel with how the EU’s DORA regulation is reshaping compliance roles in financial services. The skills overlap is real: if you are building expertise for DORA compliance and cybersecurity training, DPDP Act expertise fits naturally alongside it, especially for multinational firms operating in both markets.
Frequently Asked Questions
What is the DPDP Act in simple terms?
The DPDP Act (Digital Personal Data Protection Act 2023) is India’s main data privacy law. It requires companies to get your consent before collecting your personal data, tell you why they are collecting it, and delete it when they no longer need it. It applies to any organisation handling digital personal data of Indian residents.
Who does the DPDP Act apply to?
The DPDP Act applies to any entity that processes digital personal data in India, regardless of where the company is headquartered. It also applies to companies outside India if they process data of Indian residents to offer goods or services. Small personal or domestic use is exempt, as are certain notified government activities.
What are the penalties under the DPDP Act?
Penalties under the DPDP Act range from 10,000 rupees for minor individual violations up to 250 crore rupees for the most serious breaches, such as mishandling children’s data or failing to report a major data breach. The Data Protection Board of India decides penalties after investigation. Good-faith efforts to comply can reduce the penalty amount.
How do companies comply with the DPDP Act?
Companies need to map the personal data they collect, build a consent management system, update privacy notices in plain language, set up a user grievance mechanism, review vendor contracts, and, if classified as a significant data fiduciary, appoint a Data Protection Officer. Most organisations will also need to run employee awareness training on DPDP Act requirements.
Does the DPDP Act create new cybersecurity jobs?
Yes, directly. The DPDP Act requires DPOs, privacy analysts, GRC specialists, and privacy engineers. Based on post-GDPR trends reported by IAPP, hundreds of thousands of privacy roles were created in Europe. India’s compliance hiring wave is already visible in BFSI, health-tech, and e-commerce, and it will accelerate once the DPDP Rules 2025 are formally notified.
When does the DPDP Act come into full effect?
The DPDP Act received Presidential assent on 11 August 2023, but its operative sections come into force only when notified by the Central Government. As of mid-2025, MeitY was finalising the DPDP Rules 2025, with full enforcement expected once those rules are notified, likely before the end of 2025.
Last updated: June 2025. Reviewed by the 3University editorial team.


