AMLEGALS — Strategic Lawyering
Insights & Answers

What practitioners and boards are asking

What is DPDPA 2023 and who does it apply to?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's comprehensive data privacy legislation. It applies to all entities processing digital personal data in India, and to foreign entities processing personal data in connection with offering goods or services to Data Principals within India under Section 3. There is no revenue or size threshold. every Data Fiduciary processing digital personal data is within scope.

What are the maximum penalties under DPDPA?

DPDPA prescribes penalties up to ₹250 Crore under Section 33 read with the Schedule. The penalty for failure to protect children's data is up to ₹200 Crore. The Data Protection Board of India determines penalties based on the nature, gravity, and duration of the breach.

What is the Vibe Data Privacy Framework by AMLEGALS?

Vibe Data Privacy™ is AMLEGALS' proprietary governance framework built from the DPDPA 2023 statutory text. It measures compliance across five operational layers. Signal (privacy frequency across consent records and data flows), Pulse (governance stance against all 44 Sections and 23 Rules), Drift (compliance entropy and deviations from baseline), Dividend (privacy ROI through trust metrics and audit readiness), and Culture (organisational privacy maturity). producing a single Board ready Vibe Pulse Score (VPS) from 0 to 100.

When will DPDPA be fully enforceable?

DPDPA received Presidential Assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: the institutional provisions, including the Data Protection Board, commenced on 13 November 2025; the Consent Manager framework (Rule 4) commences on 13 November 2026; and the substantive obligations on notice, consent, breach reporting, children data, Significant Data Fiduciaries, rights and cross-border transfers commence on 13 May 2027. Organisations should treat the current period as the build window.

How does DPDPA compare to GDPR?

DPDPA and GDPR are structurally independent frameworks. Key differences: (1) DPDPA uses a negative list approach for cross border transfers under Section 16 versus GDPR's adequacy model; (2) No right to data portability under DPDPA; (3) Centralised Data Protection Board versus multiple supervisory authorities; (4) Fixed penalty amounts versus revenue percentages; (5) DPDPA applies only to digital personal data, not paper records.

What is a Significant Data Fiduciary under DPDPA?

Under Section 10, the Central Government may notify a Data Fiduciary as Significant based on volume and sensitivity of data processed, risk to Data Principals, and other prescribed factors. SDFs have enhanced obligations including mandatory DPO appointment (based in India), periodic audits by independent auditors, and Data Protection Impact Assessments.

Does DPDPA apply to foreign companies?

Yes. Section 3 of DPDPA extends its applicability to processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. This extraterritorial scope means foreign companies offering goods or services to Data Principals within India must comply regardless of their physical location.

What are the DPDP Rules 2025 and when were they notified?

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)) under Section 40 of DPDPA. They contain 23 Rules and 7 Schedules covering notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), breach notification form and manner (Rule 7), children's data processing safeguards (Rule 10), Significant Data Fiduciary obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), cross-border transfer requirements (Rule 15), and the Data Protection Board (Rules 17 to 22). Commencement is phased, with the substantive obligations commencing on 13 May 2027.

What are the consent requirements under DPDPA Section 6?

Section 6 of DPDPA requires consent that is free, specific, informed, unconditional, and unambiguous with clear affirmative action. Section 5 mandates an itemised notice before or at the time of data collection specifying the personal data to be processed and the purpose. Consent must be as easy to withdraw as to give under Section 6(6). Section 7 provides certain legitimate uses (historically termed deemed consent) including employment purposes, public interest, and medical emergencies.

What is the data breach notification obligation under DPDPA?

Section 8(6) of DPDPA requires every Data Fiduciary to inform both the Data Protection Board of India and each affected Data Principal of a personal data breach. Rule 7 of DPDP Rules 2025 prescribes a staged model: affected Data Principals must be intimated without delay; the Data Protection Board must receive an initial intimation without delay; and a detailed report must follow within 72 hours, or such longer period as the Board may allow on request. Failure to implement reasonable security safeguards attracting a breach carries penalties up to Rs 250 Crore under the Schedule.

How does DPDPA protect children's personal data?

Section 9 of DPDPA requires verifiable parental consent before processing any child's data (below 18 years). Data Fiduciaries must not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Rule 10 of DPDP Rules 2025 prescribes the manner of obtaining verifiable parental consent. Processing children's data that may cause detrimental effect is prohibited. Penalty for non-compliance is up to Rs 200 Crore under the Schedule.