DPDP Act 2023 & Rules 2025

DPDP Act 2023 — Frequently Asked Questions for Indian Businesses

Clear, authoritative answers to statutory obligations, fiduciary responsibilities, citizen rights, penalties, and compliance tools.

Fundamental Concepts

1. What is DPDPA 2023?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India’s principal data privacy law enacted in August 2023. It establishes a comprehensive legal framework for processing digital personal data within India, as well as extraterritorial processing where goods or services are offered to individuals in India. It aims to protect citizen privacy while enabling lawful data processing for legitimate business purposes.

2. Who is a Data Fiduciary?

Under Section 2(i) of the Act, a 'Data Fiduciary' is any person, company, startup, NGO, educational institution, or government body that alone or in conjunction with others determines the purpose and means of processing personal data. This is analogous to a 'Data Controller' under the European Union GDPR.

3. Who is a Data Principal?

Under Section 2(j), a 'Data Principal' is the individual to whom the personal data relates. Where the individual is a child (under 18 years) or a person with disability, the Data Principal includes their parents or lawful guardian.

4. When does DPDPA come into force?

The DPDP Act was enacted in August 2023 and the DPDP Rules 2025 were officially notified on November 13, 2025. Full statutory enforcement and statutory audits across India take effect on May 13, 2027. Organizations must have all technical and operational compliance safeguards active before this deadline.

Statutory Modules & Obligations

5. What are the penalties under the DPDP Act?

Penalties under the Schedule to the Act are structured per violation rather than global turnover percentages. Failure to implement reasonable security safeguards to prevent data breaches incurs up to ₹250 Crore (Section 8(5)). Failure to notify the Data Protection Board and affected users of a breach carries up to ₹200 Crore (Section 8(6)). Violations concerning children’s data carry up to ₹200 Crore (Section 9).

6. What is a Grievance Desk under Section 13?

Section 13 mandates that every Data Fiduciary must establish an accessible, prompt grievance redressal mechanism for Data Principals. Fiduciaries must acknowledge complaints, track a 90-day statutory SLA countdown, and inform citizens of their statutory right to escalate to the Data Protection Board of India under Section 13(3).

7. What is the Right to Nominate under Section 14?

Under Section 14 and Rule 14(4), every Data Principal has the right to designate a nominee who can exercise their data protection rights (such as access, correction, and erasure) in the event of their death or medical incapacity. DPDP Shield provides an automated nomination portal with OTP authentication and proof-of-authority storage.

8. What is Data Retention under Section 8(7)?

Section 8(7) requires Data Fiduciaries to securely erase personal data once the specified purpose of collection is fulfilled or upon withdrawal of consent, unless retention is required by another applicable Indian law (e.g. Companies Act accounting rules). DPDP Shield’s Retention Engine automates 30-day proactive deletion alerts and generates tamper-proof SHA-256 Legal Erasure Certificates (PDF).

Compliance Execution & DPDP Shield

9. Who needs DPDPA compliance in India?

Any entity operating in India or offering goods/services to Indian citizens that processes digital personal data — including early-stage startups, SaaS providers, e-commerce stores, healthcare clinics, schools, colleges, and fintech companies — must achieve DPDPA compliance.

10. What is a Data Protection Impact Assessment (DPIA)?

A DPIA is a structured assessment required for Significant Data Fiduciaries (SDFs) and high-risk processing activities under Section 10(2)(c). It evaluates systemic risks to privacy, processing proportionality, and technical security mitigations prior to launching data-intensive features.

11. What is the Data Protection Board of India (DPBI)?

The DPBI is the digital statutory body established under Section 18 of the DPDP Act 2023. It operates as a digital-first tribunal with powers to summon records, conduct forensic inquiries, order data remediation, and impose financial penalties for statutory violations.

12. How does DPDP Shield help with compliance?

DPDP Shield by Kryptasys is India’s first evidence-driven DPDPA platform. It eliminates guesswork by providing: (1) a guided 61-point compliance scoring engine, (2) in-browser LEAP v2 PII forensic scanner for logs and databases, (3) Section 13 Grievance Desk, (4) Section 14 Nominee Management, (5) Section 8(7) Data Retention Engine, and (6) immutable SHA-256 audit logs with board-ready PDF dossiers.

Ready to Prove DPDPA Compliance?

Run your first compliance scan in 30 seconds. Generate an instant gap report with statutory rule citations and forensic PII validation.