AMLEGALSDPDPAVibe Data Privacy
Return to India Hub
Legal Memorandum

The Digital Personal Data
Protection Act, 2023

Consolidated with DPDP Rules, 2025 • Published 13 November 2025 • Full Enforcement 13 May 2027

Enforcement Status
In Force
Act No. 22 of 2023 • Ministry of Electronics & IT

Practitioner\'s Summary

Practice Analysis • Updated January 2026

The Digital Personal Data Protection Act, 2023 ("DPDPA" or "Act"), read with the Digital Personal Data Protection Rules, 2025 ("DPDP Rules" or "Rules"), establishes India\'s first comprehensive horizontal data protection regime. The framework adopts a principles-based approach with prescriptive operational requirements delivered through subordinate legislation.

Key structural features include: (i) a binary consent/legitimate use framework eschewing GDPR-style legitimate interests; (ii) fiduciary terminology imposing trust-law duties; (iii) a tiered SDF regime for high-risk processors; (iv) extraterritorial application with a negative-list cross-border transfer model; and (v) the unprecedented imposition of duties on Data Principals.

CHAPTER IPRELIMINARY

Key Definitions

Data Fiduciary
Section 2(i)

Any person who alone or in conjunction determines the purpose and means of processing

Data Principal
Section 2(j)

The individual to whom the personal data relates; includes guardian for minors

Data Processor
Section 2(k)

Person processing personal data on behalf of a Data Fiduciary

Consent Manager
Section 2(g)

Person registered with the Board to enable consent lifecycle management

Rule 2(b)
Significant Data Fiduciary
Section 2(x)

Data Fiduciary notified under Section 10 based on prescribed factors

Rule 13
Personal Data Breach
Section 2(u)

Unauthorized processing, disclosure, acquisition, or loss of personal data

Rule 7
Counsel's Note

Counsel's Note: The Act deliberately eschews the controller/processor nomenclature of GDPR, adopting fiduciary terminology to impose heightened duties of care reflective of trust-based relationships under Indian jurisprudence.

CHAPTER IIOBLIGATIONS OF DATA FIDUCIARY
CHAPTER IIIRIGHTS AND DUTIES OF DATA PRINCIPAL
CHAPTER IVSIGNIFICANT DATA FIDUCIARIES
CHAPTER VTRANSFER & EXEMPTIONS
CHAPTER VIDATA PROTECTION BOARD OF INDIA
CHAPTER VIIPENALTIES & ENFORCEMENT
CHAPTER VIIIMISCELLANEOUS
THE RULESDPDP RULES, 2025

Legal Disclaimer

This memorandum is prepared for informational purposes and does not constitute legal advice. The Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 continue to be subject to interpretation by the Data Protection Board of India. Organizations should obtain jurisdiction-specific counsel before implementing compliance programs.

Last Updated: January 2026 • AMLEGALS DPDPA Advisory