India's Digital Personal Data Protection Act explained in plain English: what each section requires, who it applies to, and which tracked enforcement actions cite it.
Personal data may be processed only for a lawful purpose, and only either with the Data Principal's consent or for a...
A request for consent must be preceded (or accompanied) by a clear notice stating what personal data is collected, the...
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to...
Lists the situations where processing is permitted without consent — including where the Data Principal voluntarily provided...
The core accountability section. The Data Fiduciary remains responsible for compliance even when a Data Processor acts on its...
Requires verifiable parental consent before processing a child's personal data, and prohibits tracking, behavioural monitoring...
Entities notified as Significant Data Fiduciaries carry heavier duties: appoint an India-based Data Protection Officer,...
Data Principals may request a summary of their personal data being processed, the processing activities, and the identities of...
Data Principals may require correction, completion, updating and erasure of their personal data.
Data Principals must have a readily available means of grievance redressal with the Data Fiduciary, which must be exhausted...
A Data Principal may nominate another individual to exercise their rights in the event of death or incapacity.
Places duties on individuals too, including not impersonating another person, not suppressing material information, and not...
Permits cross-border transfer of personal data except to countries restricted by the Central Government, and preserves...
Sets out exemptions, including for enforcement of legal rights, judicial functions, prevention and investigation of offences,...
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a breach | ₹250 crore |
| Failure to notify the Board or affected Data Principals of a breach | ₹200 crore |
| Breach of obligations relating to children's personal data | ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of the duties of a Data Principal | ₹10,000 |
| Breach of terms of a voluntary undertaking | As applicable to the breach |
| Residuary — breach of any other provision | ₹50 crore |
Summarised from the Schedule to the DPDP Act, 2023. Official text ↗