Digital Personal Data Protection Act 2023 (India)
India's comprehensive data-protection regulation, enacted August 2023. Applies to processing of digital personal data within India + cross-border processing of data principals in India. Penalty up to ₹250 crore per violation. The dominant privacy regulation for the world's most populous market.
Lawful Processing of Personal Data
Personal data may be processed only for lawful purposes consented to by the data principal or for legitimate uses.
Notice to Data Principals
Data fiduciary must provide notice in clear and plain language at or before processing.
Consent Management
Consent must be free, specific, informed, unconditional, unambiguous, and revocable.
Data Accuracy
Data fiduciary must take reasonable steps to ensure data is accurate, complete, and consistent.
Data Retention Limitation
Personal data must not be retained beyond purpose or contractual period; deleted when consent withdrawn.
Security Safeguards
Data fiduciary must implement reasonable security safeguards to protect personal data.
Breach Notification
Data fiduciary must notify Data Protection Board + affected data principals of personal data breach.
Data Principal Rights
Data principals have rights to access, correction, erasure, grievance redressal.
Cross-Border Transfer
Cross-border transfers permitted only to countries notified by Central Government.
Children's Data Protection
Verifiable parental consent required before processing data of children (under 18 in India per DPDP).
Significant Data Fiduciary Obligations
Companies designated as Significant Data Fiduciary have additional obligations: DPIA, audits, DPO.
Grievance Officer
Data fiduciary must designate grievance officer + publish contact information.
Data Protection Board Cooperation
Data fiduciaries must cooperate with DPB investigations + provide requested information.
Reasonable Security Safeguards Documentation
Document the security safeguards deployed; serves as DPB defense in breach investigations.
Employee Data Lawful Use
Employee personal data may be processed only for legitimate employment purposes.
Data Retention Compliance
Data must be retained only as long as necessary; deleted promptly when no longer required.
Easy Consent Withdrawal
Withdrawal of consent must be as easy as giving it.
Penalty Awareness
Awareness of DPDP penalty structure: up to ₹250 crore per violation.
Verifiable Consent Records
Consent records must be verifiable: timestamp, scope, mechanism, withdrawal log.
Cross-Border Transfer Restrictions
Maintain ability to suspend transfers per Central Government notification.