DPDP Act (Digital Personal Data Protection Act)
The Digital Personal Data Protection Act, 2023 is India's main law on personal data. It requires businesses to collect personal data for clear purposes with valid consent or another lawful basis, keep it secure, and let people access, correct and erase their data. The rules were notified in November 2025 with a phased timeline.
Key Facts
| Covers | Digital personal data of individuals in India, collected online or digitised later |
|---|---|
| Key duties | Notice and consent, purpose limitation, security safeguards, breach reporting, erasure when no longer needed |
| Software impact | Consent records, access controls, audit logs, retention and deletion features |
| Penalties | Up to ₹250 crore for certain failures, such as inadequate security safeguards |
What to build into software
- Clear notices and recorded consent where consent is the basis.
- Role-based access so staff see only what they need.
- Logs of who accessed or changed personal data.
- Retention periods and automatic deletion.
- A way to handle access, correction and erasure requests.
See the DPDP Act and your software. This is general information, not legal advice; confirm obligations with a lawyer.
Frequently Asked Questions
Does the DPDP Act apply to small businesses?
Yes, it applies broadly, though some obligations are heavier for businesses designated as Significant Data Fiduciaries.
Do I need consent for every piece of data?
Consent is one basis; the Act also allows certain legitimate uses. Map each data use to its basis with legal advice.
Related Glossary
Need help implementing this in your business?
Turbo Bytes Consulting helps businesses streamline operations and build custom software architectures that scale without chaos.