Digital Personal Data Protection Act, 2023 (DPDP Act)
India's law on the processing of digital personal data, which sets obligations for organisations that decide how personal data is processed, grants rights to individuals and establishes the Data Protection Board of India.
The DPDP Act applies to digital personal data processed within India, whether collected digitally or digitised later, and to processing outside India connected with offering goods or services to individuals in India. It uses its own terms: the Data Principal is the individual, the Data Fiduciary determines the purpose and means of processing, and a Data Processor processes data on a fiduciary's behalf. Processing generally requires notice and consent, or must fall within a limited set of legitimate uses defined in the Act.
Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches, inform the Data Protection Board and affected individuals of breaches, erase data when its purpose has been served and honour individuals' rights to information, correction, erasure and grievance redressal. Processing children's data requires verifiable parental consent, and organisations notified by the government as Significant Data Fiduciaries carry additional duties, such as appointing a Data Protection Officer and conducting periodic data protection impact assessments and audits.
The Act leaves detailed procedures, such as the form of notices, breach reporting and the registration of consent managers, to rules made by the central government. The Board can impose substantial monetary penalties for non-compliance. Because the Act uses its own definitions and exemptions, organisations familiar with GDPR should not assume the requirements are identical, and they rely on qualified legal advice for interpretation.
Key points
- Covers digital personal data processed in India and some processing abroad.
- Defines Data Principals, Data Fiduciaries and Data Processors.
- Requires reasonable security safeguards and notification of breaches.
- Enforced by the Data Protection Board of India.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.