Security Awareness

DPDP Act 2023: Key Rules, Rights, and Penalties You Must Know

Pawan Panwar
April 22, 2026

Featured previewDo you know how amazing the DPDP Act 2023 is? If not, then you are at the right place. Here, we will talk about this Legal Act in detail and explain how it can help organizations and keep consumers’ data safe online.

Moreover, we will introduce you to a reliable phishing simulation platform offered by a reputable VAPT service provider. What are we waiting for? Let’s get straight to the topic!

What is the DPDP Act 2023?

India's historic Digital Personal Data Protection (DPDP) Act 2023 was created to control the processing of digital personal data while striking a balance between the need to process data for legitimate purposes and an individual's right to privacy.

It creates a thorough set of rights for "Data Principals" and stringent requirements for "Data Fiduciaries," requiring explicit consent and openness in data processing. In order to maintain a safe and responsible digital ecosystem, the Act, which is enforced by the Data Protection Board of India, levies severe financial penalties for non-compliance.

Let’s take a look at what the DPDP Act 2023 is and how you can run your business while complying with it!

Key Objectives of the Digital Personal Data Protection Act

S.No.

Objectives

What?

1.

Protecting Individual Autonomy

To protect people's rights by giving them control over their personal information and its use.

2.

Ensuring Lawful and Transparent Processing

To require that personal data be processed only with the user's express consent and for certain, acceptable reasons.

3.

Accountability and Security

To make data-handling organizations accountable for putting strong security measures in place and preserving the accuracy of the data they gather.

4.

Balancing Rights with Innovation

To establish a framework that permits the lawful flow of data while safeguarding individual privacy to promote the expansion of the digital economy.

5.

Establishing Enforcement Mechanisms

To establish the Data Protection Board of India to monitor adherence to the Act and penalize companies that do not comply.

Scope and Applicability: Who Does the DPDP Act Cover?

DPDP Act covers the following things:

Scope and Applicability Who Does the DPDP Act Cover

  1. Digital Personal Data: The Act particularly covers personal information that is either physically (on paper) or digitally gathered.
  2. Territorial Jurisdiction (Within India): Regardless of the location of the company's headquarters, it encompasses any processing of digital personal data that occurs within Indian territory.
  3. Extra-Territorial Reach (Outside India): It covers data processing outside of India if it has to do with providing products or services to people (Data Principals) in India.
  4. Exclusion of Personal/Domestic Use: Data processed by an individual for strictly personal or domestic purposes (such as your personal phone contact list or family photos) is exempt from the Act.
  5. Publicly Available Data: It does not include personal information that has been made public by the person themself (for example, through a public social media post) or that is required by law.

Exemptions

The following are some exemptions:

     State and National Security: In order to protect India's sovereignty, integrity, security, and public order, the Central Government may exempt government agencies from the Act.

     Legal and Judicial Processes: When processing is required to uphold legal rights or claims, or when it is carried out by a court or tribunal in the performance of judicial duties, it is exempt.

     Operational & Legitimate Uses: When data is handled for statistical, research, archiving, or criminal prevention and investigation reasons, several restrictions are not applicable.

     Cross-Border & Foreign Data: When an Indian entity enters into a contract with a foreign person or entity and processes their personal data, there are exemptions.

     Mergers & Acquisitions: When data processing takes place as part of a court-approved plan for company mergers, amalgamations, or asset transfers, it is exempt.

Important Definitions You Must Understand (Data Principal, Data Fiduciary, etc.)

S.No.

Factors

What?

1.

Data Principal

The person to whom the personal information pertains; this includes the parents or legal guardians of minors (under the age of eighteen) or people with disabilities.

2.

Data Fiduciary

The primary responsibility for compliance rests with any individual, business, or governmental body that decides how and why to process personal data.

3.

Data Processor

Any individual or organization that handles personal data on behalf of a Data Fiduciary (such as a third-party payroll company or cloud service provider).

4.

Significant Data Fiduciary (SDF)

A particular group of fiduciaries is required to designate a Data Protection Officer and conduct audits after receiving notification from the government based on variables such as the amount of data processed or the risk to national security.

5.

Consent Manager

A recognized organization that serves as the Data Principals' single point of contact for granting, managing, reviewing, and withdrawing consent via an easily accessible and transparent portal.

Principles of Data Protection Under DPDP Act 2023

The following are the principles of data protection under the DPDP Act 2023:

Principles of Data Protection Under DPDP Act 2023

a)    Lawfulness, Transparency, and Consent: Legal processing of personal data is required, and notices must be sent to individuals in simple language (available in English and 22 Indian languages).

b)    Purpose Limitation: Only the precise purpose for which the person provided consent at the time of collection should be utilized.

c)    Data Minimisation: It is forbidden for organizations to gather "excess" data; they should only gather the bare minimum required to accomplish the declared goal.

d)    Accuracy: Data fiduciaries are in charge of making sure that the personal information they handle is correct, comprehensive, and consistent, especially if it's used to make judgments about the individual.

e)    Storage Limitation: Unless its keeping is mandated by law, personal data must be erased or anonymized once the precise purpose for its acquisition has been fulfilled.

f)     Integrity and Confidentiality: To stop unwanted access, data breaches, or unintentional disclosure, reasonable security measures must be put in place.

g)    Accountability: The Data Protection Board is in charge of enforcement and fines, and organizations are legally liable for any violations or non-compliance.

Consent Management and Data Processing Rules

The following are some consent management and data processing rules:

  1. Standard of Consent: Free, specific, informed, unconditional, and provided by the individual through a clear affirmative action are all requirements for consent.
  2. The "Notice" Requirement: A Data Fiduciary shall give a notification outlining the data gathered, the reason for processing, and how to exercise rights before or at the time of requesting consent.
  3. Ease of Withdrawal: A person has the right to revoke consent at any moment, and doing so must be as simple as providing it.
  4. The Consent Manager Framework: When it comes to giving, managing, reviewing, and withdrawing consent for various services, a certified "Consent Manager" can serve as a single point of contact.
  5. Legitimate Uses (Processing without Consent): For "legitimate uses," such as medical crises, state functions (subsidies/benefits), employment purposes, or legal/judicial demands, data may be used without express consent.

Rights of Individuals (Data Principals) Under the DPDP Act

Data principals are entitled to information about their processed data as well as the identities of any third parties that may have received it. Additionally, individuals have the authority to request the erasure of data that is no longer required for its original purpose, the completeness of missing elements, or the correction of erroneous information.

Duties of Data Principals

The following are the duties of data principals:

     Compliance with Laws: When exercising their rights under the Act, people must make sure they abide by the terms of all applicable legislation.

     Prohibition of Impersonation: When giving their personal information for any defined reason, data principals are prohibited from posing as anybody else.

     Duty of Truthfulness: When submitting personal information or asking for updates and corrections, you must only give true and verified information.

     No Suppression of Material Information: When supplying personal information for any document or service that the state requires, people are not allowed to withhold any significant information.

     Preventing Frivolous Grievances: Data Principals are not allowed to file frivolous or false complaints or grievances with the Data Protection Board or the Data Fiduciary.

Responsibilities of Data Fiduciaries and Data Processors

The following are the responsibilities of Data Fiduciaries and Data Processors:

a)    Vicarious Liability of the Fiduciary: Regardless of any agreement to the contrary with a Data Processor, the Data Fiduciary is nonetheless legally liable for any processing done on its behalf.

b)    Mandatory Data Processing Contracts: A legitimate contract outlining the nature and extent of the activity is required before a Data Fiduciary can hire a Data Processor to handle personal data.

c)    Reasonable Security Safeguards: To stop breaches of personal data, Fiduciaries and Processors must put in place the proper organizational and technical safeguards.

d)    Duty of Erasure and Deletion: When the designated purpose is fulfilled, or the Data Principal withdraws their consent, fiduciaries are required to make sure that personal data is erased.

e)    Breach Notification Protocol: The Data Fiduciary is required by law to notify the Data Protection Board and any impacted Data Principal in the case of a personal data breach.

Protection of Children’s Data

Before processing any child's personal information, data fiduciaries must gain verifiable parental consent. They are also not allowed to track children, monitor their conduct, or show them customized ads.

Additionally, they are prohibited from performing any data processing that could negatively impact a child's well-being, guaranteeing a "safety-by-design" approach for users under the age of eighteen.

The Data Protection Board of India (DPB)

The main independent regulatory authority in charge of overseeing compliance, instructing data fiduciaries to take corrective action, and making decisions about data breaches is the Data Protection Board of India (DPB).

It has the ability of a civil court to call witnesses, hold investigations, and, in the end, impose heavy fines for Act infractions.

Cross-border Data Transfers

The DPDP Act 2023 takes a "negative list" or "blacklist" approach, which by default allows the transmission of personal data to any foreign nation or territory unless a government notification expressly prohibits it.

But this flexibility is subject to more stringent sector-specific requirements (like RBI's data localization for payments), which nonetheless supersede the Act's general provisions.

Penalties, Fines, and Enforcement Mechanisms Explained

The Data Protection Board may impose fines of up to ₹250 crore for a single case of failing to prevent a breach of personal data under the tiered penalty structure outlined in the DPDP Act 2023.

To guarantee rigorous corporate accountability, these sanctions are based on the type, severity, and duration of the breach, with a focus on financial deterrent rather than criminal jail.

How Businesses Can Ensure Compliance with the DPDP Act 2023?

In the following ways, businesses can ensure compliance with the DPDP Act 2023:

  1. Conduct Data Inventory and Mapping: Determine what personal information is being gathered, where it is kept, and who may access it to make sure each piece of information has a specific, legitimate purpose.
  2. Implement a Consent Management Framework: Install technological mechanisms that can record, capture, and make it simple for consumers to revoke their "clear and affirmative" consent.
  3. Update Privacy Notices and Policies: As mandated by the Act, update all customer-facing papers to be understandable, succinct, and accessible in several Indian languages.
  4. Establish a Data Breach Response Plan: Establish a formal internal procedure for locating, containing, and promptly reporting data breaches to the Data Protection Board and impacted parties.
  5. Appoint a Data Protection Officer (DPO): A DPO located in India must be appointed by Designated Significant Data Fiduciaries as the main point of contact for regulatory oversight and grievance settlement.

Grievance Redressal Mechanisms

To address complaints about data processing or rights abuses, people must first use the Data Fiduciary's internal grievance redressal method. The person may then take the case to the Data Protection Board of India for official adjudication and possible enforcement action if the problem is not remedied or if the response is inadequate.

Conclusion

Now that we have talked about what the DPDP Act 2023 is and why you need to comply with it, you might want to know how you can protect yourself against phishing scams & attacks. For that, you can get in contact with Craw Security, offering a dedicated phishing simulation platform “Phish Next” to the IT Aspirants and organizations.

Practitioners will be able to test their knowledge & skills on this phishing simulation and will get trained to evade such attacks in the future. What are you waiting for? Contact, Now!