India’s new Digital Personal Data Protection Act, introduced in 2023 and fully operational from 2025, establishes comprehensive rules for personal data processing, impacting businesses and organisations nationwide while aligning with global privacy standards.
India’s Digital Personal Data Protection Act is now the country’s main law for digital privacy, giving businesses a clearer set of rules for collecting, storing and sharing personal information. Introduced in 2023 and fully operational from 2025, it applies to digital personal data and also to information first gathered offline and later digitised. The law is designed to match India’s rapidly expanding online economy with stronger safeguards for individuals whose names, contact details, financial records and other identifiers move through websites, apps and online services.
At the centre of the framework are three core roles. A data principal is the individual whose personal data is being processed. A data fiduciary is the person or organisation deciding why and how that data is used. Larger or higher-risk entities can be designated significant data fiduciaries and face tighter compliance duties. According to summaries of the law, these obligations are overseen by the Data Protection Board of India, which handles complaints, compliance and penalties.
The Act is built around consent, accountability and limited use of personal data. The Press Information Bureau said the Bill was intended to support lawful, transparent processing while also improving ease of doing business. It also introduced key principles such as purpose limitation, data minimisation, storage limitation and reasonable security safeguards. Individuals can ask for access to their data, request corrections, seek erasure once a purpose is met or consent is withdrawn, raise grievances and nominate another person to act on their behalf if they die or lose capacity.
The law reaches far beyond large technology firms. It applies to companies, government departments, public authorities and foreign organisations that process the personal data of people in India while offering goods or services to them. In practical terms, that includes banks, hospitals, schools, telecoms groups, e-commerce platforms and payment providers. Some exemptions remain, including for certain government functions and specific public-interest uses. But for most organisations handling customer or employee data in digital form, the central message is clear: privacy compliance is now a legal obligation, not an optional policy choice.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





