Digital Personal Data Protection Act 2023 — Overview
Reading module · approx 12 min
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection legislation. It replaces the IT Act's Section 43A data protection provisions and introduces a new statutory framework governing how personal data of Indian residents may be collected, processed, stored, and transferred.
The DPDP Act received Presidential assent on 11 August 2023. It applies to the processing of digital personal data — that is, personal data collected in digital form, or digitised after collection. The Act applies both to processing within India and to processing outside India if it involves personal data of Data Principals in India.
Key definitions
Personal data means any data about an identifiable individual. Unlike GDPR, the DPDP Act does not create a separate category of sensitive personal data in the main Act — special category provisions are anticipated in the DPDP Rules, which are being notified separately.
Data Principal means the individual to whom the personal data relates. Children under 18 (or an age specified by the government, which may be lower for certain contexts) are a special category of Data Principal whose data requires verifiable parental consent.
Data Fiduciary means any person or entity that determines the purpose and means of processing personal data. This is functionally equivalent to the GDPR "data controller." Data Fiduciaries bear the primary compliance obligations under the Act.
Data Processor means any person who processes data on behalf of a Data Fiduciary. Data Processors have limited direct obligations under the DPDP Act — they process data under the instructions of the Data Fiduciary and must assist the Fiduciary in meeting its obligations.
Territorial scope
The DPDP Act applies to the processing of digital personal data within India, regardless of whether the Data Fiduciary is incorporated in India. It also applies to processing outside India if the processing is "in connection with any activity related to offering of goods or services to Data Principals within the territory of India." This extraterritorial scope is similar to GDPR's Article 3(2) and means that foreign companies with Indian customers are subject to the Act.
Legal bases for processing
Unlike GDPR, the DPDP Act has a simpler structure: the two primary legal bases for processing are (1) consent of the Data Principal, and (2) legitimate uses specified in the Act. Legitimate uses include processing for purposes related to state functions, compliance with legal obligations, medical emergencies, employment purposes, and certain public interest functions.
Module 2 covers the specific obligations that apply to Data Fiduciaries under the Act.