The Digital Personal Data Protection Act, 2023
Prelims and MainsCurrent affairs on this: Cyber security and data protection
The Digital Personal Data Protection Act, 2023 is India's first general law on personal data, six years after Puttaswamy (2017) made privacy a fundamental right. It covers digital personal data, including abroad when goods or services are offered to people in India. The person the data is about is the data principal, the body deciding why and how it is processed is the data fiduciary, and a processor acts for a fiduciary. Processing needs consent that is free, specific, informed, unconditional and unambiguous, or a listed "legitimate use". The Data Protection Board of India adjudicates breaches and imposes penalties, with appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT); the rules were notified on 13 November 2025 in three phases.
Who does what under the Act
- Rights: access, correction and erasure, grievance redress, and nominating someone to act after death; duties on the principal too, such as no false complaints. Children under 18 need verifiable parental consent, and tracking and targeted advertising directed at them are barred; Rule 10 of the 2025 Rules lets a fiduciary verify the parent as an identifiable adult from details it holds, details provided, or a virtual token issued by a Digital Locker provider. The Centre may exempt notified fiduciaries or set a lower age where processing is verifiably safe.
- The Board is adjudicatory only and appointed by the Centre. The Schedule sets ceilings, not fixed fines: Rs 250 crore for failing to take reasonable security safeguards, Rs 200 crore for failing to notify a breach and for the children's data duties, Rs 150 crore for a significant data fiduciary's additional duties, Rs 50 crore residual, and Rs 10,000 on a data principal. Appeal to TDSAT within 60 days.
- Larger fiduciaries can be declared significant, with a resident data protection officer and audits; consent managers are a registered intermediary through which consent can be given and withdrawn.
- Cross border transfer is allowed except to countries the Centre lists (a blacklist, not a whitelist), and Rule 15 lets the Centre add conditions by order.
- The contested parts: Section 17(2)(a) lets the Centre disapply the whole Act to any notified instrumentality of the State on security or public order grounds, with no procedure or oversight prescribed; and Section 44(3) widens the Right to Information (RTI) Act's privacy exemption, replacing Section 8(1)(j) with a bare bar on "information which relates to personal information" and deleting the public interest override, which is the basis of the demand for its repeal.
The 2025 Rules and their phasing
Notified as G.S.R. 846(E) on 13 November 2025. The definitions and the Board provisions took effect on notification; consent manager registration takes effect on 13 November 2026; the substantive core, which is notice, consent, security safeguards, breach intimation, retention, children's data, significant fiduciary duties, data principal rights, cross border transfer and exemptions, takes effect on 13 May 2027.
Mains: The Act gives individuals rights and firms obligations but keeps the State largely outside its reach, and by widening the RTI exemption it reduces what citizens can ask of the State, so it protects privacy against companies far better than against the government, which was the harm Puttaswamy was decided on.
UPSC has asked
- Mains 2024: the context and salient features of the Digital Personal Data Protection Act, 2023
Further reading: The Digital Personal Data Protection Bill, 2023 (PRS India)
See also: Safe harbour and the Meta takedown · CERT-In and AI driven threats · Sanchar Saathi, ASTR and Chakshu · Consumer Protection (E-Commerce) Rules, 2020