Skip to main content
Glossary

DPDP Act (Digital Personal Data Protection Act)

The Digital Personal Data Protection Act, 2023 is India's main law on personal data. It requires businesses to collect personal data for clear purposes with valid consent or another lawful basis, keep it secure, and let people access, correct and erase their data. The rules were notified in November 2025 with a phased timeline.

Key Facts

CoversDigital personal data of individuals in India, collected online or digitised later
Key dutiesNotice and consent, purpose limitation, security safeguards, breach reporting, erasure when no longer needed
Software impactConsent records, access controls, audit logs, retention and deletion features
PenaltiesUp to ₹250 crore for certain failures, such as inadequate security safeguards

What to build into software

  • Clear notices and recorded consent where consent is the basis.
  • Role-based access so staff see only what they need.
  • Logs of who accessed or changed personal data.
  • Retention periods and automatic deletion.
  • A way to handle access, correction and erasure requests.

See the DPDP Act and your software. This is general information, not legal advice; confirm obligations with a lawyer.

Frequently Asked Questions

Does the DPDP Act apply to small businesses?

Yes, it applies broadly, though some obligations are heavier for businesses designated as Significant Data Fiduciaries.

Do I need consent for every piece of data?

Consent is one basis; the Act also allows certain legitimate uses. Map each data use to its basis with legal advice.

Take the next step

Need help implementing this in your business?

Turbo Bytes Consulting helps businesses streamline operations and build custom software architectures that scale without chaos.

Chat with us