India's DPDP Act, explained: what it is and who it binds
India's Digital Personal Data Protection Act, 2023 (DPDP) is India's first comprehensive, cross-sectoral personal-data law. Read together with the Digital Personal Data Protection Rules, 2025, it is enforced by a new regulator, the Data Protection Board of India. If you process the digital personal data of individuals in India — or offer them goods or services from anywhere in the world — it applies to you.
The whole Act turns on one idea: the organisation that decides why and how personal data is processed (the 'Data Fiduciary') is accountable for it. Not the vendor, not the individual — you.
The roles
- Data Fiduciary — decides the purpose and means of processing. Accountable for everything, including what its processors do.
- Data Processor — processes on a Fiduciary's behalf, only under a valid contract.
- Data Principal — the individual; for a child, the parent or lawful guardian.
- Significant Data Fiduciary — a high-impact Fiduciary the government designates, with extra duties (a DPO, audits, DPIAs, localisation).
- Consent Manager — a Board-registered platform through which people give, manage and withdraw consent.
Two lawful bases — and no third
You may process personal data only (1) with consent, preceded by a clear, itemised notice, or (2) for one of a closed list of 'certain legitimate uses' — employment, legal obligations, medical emergencies and a handful of others. Crucially, there is no open-ended 'legitimate interests' balancing test as in the GDPR. If it is not consent and not on the s.7 list, you cannot do it.
The deadline
The Board provisions are already in force. Consent Manager registration opens in November 2026. The core obligations and individual rights take effect on 13 May 2027. That sounds far away until you count the consent flows, notices, rights workflows and breach procedures you have to build first.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.