A Simple and Practical Guide to India’s Digital Personal Data Protection Law

By Adv. Shridhar Patil

Advocate | Cyber Law | Data Protection | Technology Law | Digital Rights www.advshridharpatil.com

Your Data Is More Valuable Than You Think

Think about your normal day.

You wake up and check WhatsApp.

You open Instagram.

You order something online.

You make a UPI payment.

You book a cab.

You search something on Google.

You visit a hospital website.

You apply for a job.

You fill an online form.

You download an app.

In all these activities, we share some amount of personal information.

Sometimes we share our name.

Sometimes our mobile number.

Sometimes our email address.

Sometimes our photograph, location, financial information or identification documents.

We often click “I Agree” without thinking twice.

But have you ever stopped and asked:

Where is my data going?

Who is using it?

Why is it being collected?

How long will it be kept?

What happens if it is leaked?

This is where India’s Digital Personal Data Protection Act, 2023 (DPDP Act) becomes important.

The Act was enacted on 11 August 2023. Its basic objective is to regulate the processing of digital personal data while recognising both an individual’s interest in protecting personal data and the need for lawful processing.

What Exactly Is the DPDP Act?

Let us forget complicated legal language for a moment.

The simplest way to understand the DPDP Act is:

It creates a legal framework for how digital personal data should be collected, used, stored, protected and handled.

It tries to create a balance.

On one side:

Individuals want privacy and control over their personal information.

On the other side:

Businesses, governments and organisations need data to provide services and perform lawful activities.

The law tries to bring both interests together.

First Question: What Is Personal Data?

Personal data is information that relates to an identifiable individual.

For example:

  • Your name
  • Mobile number
  • Email address
  • Photograph
  • Address
  • Online account details
  • Certain financial information
  • Identification details
  • Other information that can identify you

A simple example:

Suppose an online shopping company has:

Name: Rahul Sharma Mobile: 98XXXXXX10 Email: rahul@example.com

This information relates to an identifiable person.

Therefore, it can be personal data.

What Does “Digital Personal Data” Mean?

The DPDP Act is focused on personal data in digital form.

For example:

You fill an online admission form.

The information goes into a computer system.

You create an account on a shopping website.

Your details are stored digitally.

You open a bank account through a mobile application.

Your information is processed electronically.

These are everyday examples of digital personal data processing.

The Act can also cover personal data that was collected offline and later digitised.

Who Am I Under the DPDP Act?

The law uses a term called “Data Principal.”

Don’t let the terminology confuse you.

In simple language:

If the personal data is about you, you are the Data Principal.

For example:

Your college has your student information.

You = Data Principal

Your employer has your employee information.

You = Data Principal

A bank has your customer information.

You = Data Principal

An online shopping company has your customer information.

You = Data Principal

Then Who Is a Data Fiduciary?

Another important term is “Data Fiduciary.”

In simple words, it generally means the person or organisation that decides why and how your personal data will be processed.

For example:

You purchase a product from an online company.

The company collects your name, address and phone number to deliver the product.

The company may be the Data Fiduciary for that processing.

So remember:

You → Data Principal

Organisation deciding why/how your data is processed → Data Fiduciary

Why Does the Law Call It a “Fiduciary”?

Because the organisation is expected to handle personal data responsibly.

Your data is not just another entry in a spreadsheet.

Behind every phone number is a person.

Behind every photograph is a person.

Behind every Aadhaar-related document is a person.

Behind every email address is a person.

That is why responsible handling of data matters.

Can a Company Collect My Data Whenever It Wants?

Not simply because it wants to.

The Act provides that personal data may be processed for a lawful purpose, generally based on the individual’s consent or certain legitimate uses recognised by the Act.

This is an important principle.

For example:

A delivery company needs your address to deliver your order.

That makes sense.

A school needs certain student information to administer education.

That makes sense.

A bank needs information for legally required banking and KYC purposes.

That makes sense.

But whenever an organisation asks for information, a basic question should be:

Why do you need this information?

Consent: What Does It Really Mean?

Most of us have developed a habit of clicking:

“I Agree.”

We rarely read the next 20 pages.

But under data protection law, consent is an important concept.

A person should be given appropriate information about what personal data is being requested and why it is being processed.

The Act also provides that a consent request should be accompanied or preceded by a notice explaining matters such as the personal data involved and the purpose of processing.

In simple words:

A person should have a reasonable understanding of what they are agreeing to.

Can I Withdraw My Consent?

The DPDP Act provides for withdrawal of consent.

But this does not mean that every service must continue exactly as before after consent is withdrawn.

For example:

If a service genuinely requires particular information to provide the service, withdrawing consent may affect the ability to continue that service.

Therefore, consent and withdrawal need to be understood within the complete legal framework.


What Rights Do I Have?

This is probably the most important part for an ordinary citizen.

The DPDP framework provides individuals with important rights, including rights relating to:

Access to information

You can seek information about your personal data and its processing, subject to the law.

Correction

If your personal information is inaccurate or incomplete, the law provides a mechanism to seek correction.

Erasure

In applicable circumstances, you can request erasure of your personal data.

Grievance redressal

You have a mechanism to raise a grievance regarding the processing of your personal data.

Nomination

The Act also provides a nomination mechanism for exercising rights in accordance with the law.

These rights are important because privacy should not be a concept that exists only inside a company’s privacy policy.

It should have practical meaning for individuals.

What If My Information Is Wrong?

Imagine your bank has your wrong mobile number.

Or your employer has the wrong address.

Or an online platform has incorrect personal information.

Incorrect data can cause real problems.

The DPDP framework therefore provides for correction of personal data in appropriate circumstances.

The simple message is:

If an organisation holds incorrect personal information about you, you should have a legal route to seek correction.

What About Deleting My Data?

This is where many people misunderstand data protection law.

People often say:

“DPDP gives me the right to delete everything about myself.”

That is too broad.

The law provides a right relating to erasure, but it operates within the statutory framework.

There can be situations where an organisation is legally required or permitted to retain information.

Therefore:

Right to erasure does not mean unlimited and immediate deletion in every situation.

The facts matter.

What Happens If My Data Gets Leaked?

Now we come to one of the biggest concerns in today’s digital world.

Imagine a company’s database gets hacked.

Thousands or millions of people’s information may be affected.

A personal data breach can involve unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability of personal data.

This is why cybersecurity and data protection are closely connected.

Privacy Is Not the Same as Cybersecurity

These two concepts are related, but they are not identical.

Privacy asks:

Should this information be collected and used?

Cybersecurity asks:

How do we protect the information from unauthorised access, misuse or loss?

For example:

A company may have a perfectly valid reason to collect your mobile number.

But if it stores that information without adequate security and the database is hacked, there can still be serious consequences.

Therefore:

Good data protection needs both responsible collection and proper security.

What Should Companies Do?

Data protection is not only the responsibility of Instagram, Google, banks or large technology companies.

A small business can also handle personal data.

A school can handle personal data.

A hospital can handle personal data.

An HR agency can handle personal data.

A lawyer’s office can handle personal data.

A digital marketing agency can handle personal data.

Therefore, organisations should start asking some basic questions:

1. What data are we collecting?

Don’t collect information simply because it may be useful someday.

2. Why are we collecting it?

Have a clear purpose.

3. Do we have a lawful basis?

Identify the applicable legal basis for processing.

4. Who can access it?

Not every employee needs access to every database.

5. How are we protecting it?

Use appropriate technical and organisational safeguards.

6. How long do we need it?

Do not treat personal data as something that should remain forever.

7. What happens if there is a breach?

Have a proper incident response plan.

8. How can a person raise a complaint?

Provide an effective grievance mechanism.

What About Children’s Data?

Children deserve special protection online.

Today, children use:

  • Online classes
  • Gaming applications
  • Social media
  • Educational platforms
  • Entertainment applications
  • Shopping platforms

Their personal information can be collected through these services.

The DPDP Act contains specific provisions relating to children’s data.

Therefore, organisations dealing with children’s personal data need to pay particular attention to the requirements applicable to children.

The basic principle is simple:

Children should not be left to manage complex privacy risks on their own.

What Is a Significant Data Fiduciary?

The Act provides for a category called a Significant Data Fiduciary.

These are Data Fiduciaries that may be designated by the Central Government based on factors provided in the Act.

Because such organisations can have greater data-related risks or impact, additional compliance obligations can apply.

These can include stronger governance and accountability requirements.

Who Will Enforce the Law?

The DPDP framework provides for the Data Protection Board of India.

This is important because a law needs an institutional mechanism for enforcement.

The Government published material concerning the establishment of the Board along with the 2025 implementation framework.

How Much Can a Company Be Fined?

The DPDP Act provides for significant financial penalties for specified breaches.

The maximum penalty in the Schedule can go up to ₹250 crore for certain breaches.

But one important point should be remembered:

A penalty is not automatically imposed simply because someone complains.

The applicable provision, facts, proceedings and legal requirements have to be considered.

What Changed in 2025?

This is particularly important today.

The DPDP Act was passed in 2023.

But the complete framework did not simply become operational in one single step.

On 14 November 2025, the Central Government notified the Digital Personal Data Protection Rules, 2025 and also issued an enforcement timeline for the Act.

The Government has provided a phased implementation period, with some provisions coming into force immediately, some after one year, and several substantive provisions after 18 months.

The Rules themselves also have a phased commencement structure.

This means that businesses should not look at the DPDP Act as merely a future law.

Data protection compliance needs to be treated as an ongoing business responsibility.

Does the DPDP Act Mean I Own Everything About Myself?

This is another common misunderstanding.

It is tempting to say:

“My data belongs to me.”

As a general public statement, this expresses the importance of personal control.

But legally, the DPDP Act is better understood as a law regulating the processing and protection of digital personal data.

It is not simply a declaration that every form of data is an item of property absolutely owned by an individual.

Different laws may apply to different situations.

For example:

Personal data → Data protection law

Creative work → Copyright law

Contractual relationship → Contract law

Online platform conduct → Applicable IT and other laws

These areas can overlap, but they should not be confused.

Does the DPDP Act Protect My Instagram Account?

This question is becoming increasingly important.

Suppose Instagram suspends your account.

Can you simply say:

“DPDP Act protects me, so Instagram cannot suspend my account.”

Not necessarily.

The DPDP Act primarily concerns the processing of digital personal data.

An account suspension may involve completely different issues, such as:

  • Copyright
  • Community standards
  • Platform terms
  • Intermediary rules
  • Fraud
  • Impersonation
  • Cybercrime
  • Other applicable laws

So:

DPDP Act is not a general law against every social media suspension.

However, where personal data processing is involved, the DPDP framework may become relevant depending on the facts.

This distinction is very important.

What About AI?

Now comes the biggest challenge for the future.

Artificial Intelligence can process enormous amounts of information.

AI can analyse:

  • Photos
  • Videos
  • Voice
  • Search behaviour
  • User preferences
  • Location-related information
  • Online activity
  • Communication patterns

The important legal question is no longer simply:

“Can technology process this data?”

The better question is:

“Should it process this data, why, on what legal basis, and with what safeguards?”

This is where data protection, cybersecurity, AI governance and digital rights will increasingly come together.

What Can Ordinary Indians Do to Protect Their Data?

The law is important.

But our own digital habits are equally important.

Use strong passwords.

Avoid using the same password everywhere.

Turn on two-factor authentication.

Especially for email, banking and social media.

Check app permissions.

Does a simple application really need access to your contacts, microphone or location?

Think before sharing.

Once information goes online, controlling it can become difficult.

Keep backups.

Do not keep your important photographs, documents or business data only on Instagram, Facebook or another platform.

Be careful with OTPs.

Never share OTPs with unknown persons.

Beware of phishing.

A message saying:

“Your account will be blocked today. Click here immediately.”

may be designed to steal your credentials.

Review your online accounts regularly.

Remove applications and services you no longer use.

What Should Content Creators Do?

For creators, digital data and digital accounts can be a livelihood.

Imagine losing:

  • 10 years of photographs
  • Thousands of followers
  • Brand contacts
  • Client conversations
  • Business enquiries
  • Advertising history
  • Original videos

Therefore, creators should maintain independent records.

Keep:

Original files

Copyright documents

Licensing agreements

Contracts

Account recovery information

Important platform communications

Backup copies

Your social media account should never be the only place where your digital work exists.

What Should Small Businesses Do?

You do not have to be a multinational company to start data protection compliance.

If your business has:

  • Customer phone numbers
  • Email addresses
  • Employee records
  • Leads
  • Enquiry forms
  • Website forms
  • WhatsApp customer information
  • Online payment information
  • HR records

you should start thinking about data governance.

A good first step is simply to make a list:

What personal data do we have?

Then ask:

Why do we have it?

Then:

Who has access to it?

And finally:

How are we protecting it?

These four questions can completely change how a business looks at privacy.

What Can Schools and Colleges Do?

Educational institutions handle a large amount of personal information.

For example:

  • Student details
  • Parent details
  • Contact numbers
  • Academic records
  • Attendance
  • Photographs
  • Identification documents
  • Fee information

Where children’s data is involved, additional care is particularly important.

Educational institutions should therefore treat student data as an important responsibility rather than merely administrative information.

What Can Employers Do?

Employers also handle personal data every day.

Think about your joining process.

You may submit:

  • Resume
  • Address
  • Mobile number
  • Identification documents
  • Bank details
  • Educational certificates
  • Photograph

This information should be handled responsibly.

A company should not allow unrestricted internal access simply because the information exists in its database.

DPDP Act and GDPR: Are They the Same?

No.

India’s DPDP Act and Europe’s GDPR have some common themes, such as:

  • Privacy
  • Accountability
  • Transparency
  • Responsible data processing
  • Individual rights

But they are different laws with different structures and requirements.

Therefore:

GDPR compliance does not automatically mean DPDP compliance.

Businesses operating internationally should examine both frameworks separately.

DPDP Act and OECD Privacy Principles

The OECD Privacy Guidelines of 1980 are among the important historical foundations of modern international privacy thinking.

They promoted principles such as:

  • Collection limitation
  • Data quality
  • Purpose specification
  • Use limitation
  • Security safeguards
  • Openness
  • Individual participation
  • Accountability

The world has changed dramatically since 1980.

But one idea remains relevant:

Personal information should be handled responsibly.

The Real Meaning of the DPDP Act

If I had to explain the entire DPDP Act to someone in one sentence, I would say:

“If you collect and use someone’s personal data, you must have a lawful reason to do so and you have responsibilities towards that data.”

And for an ordinary citizen:

“You should know what is happening with your personal data and have legal rights in relation to its processing.”

That is the heart of the law.

Five Things Every Indian Should Remember

1. Your data has value.

Your phone number, email, photograph and digital identity are valuable information.

2. Don’t share everything blindly.

Think before giving access to personal information.

3. Businesses have responsibilities.

Data should not be treated casually.

4. Know your rights.

The DPDP framework provides rights and grievance mechanisms for Data Principals.

5. Privacy is everyone’s responsibility.

Government, businesses, technology companies and citizens all have a role.

My Key Finding

The biggest challenge is not simply making another privacy law.

The real challenge is creating a privacy culture in India.

A culture where:

Businesses don’t collect unnecessary information.

Employees don’t misuse customer data.

Companies take data breaches seriously.

Users understand what they are agreeing to.

Children receive stronger protection online.

AI is developed responsibly.

Complaints are taken seriously.

And most importantly:

People understand that privacy is not something reserved for celebrities, lawyers or technology experts. Privacy belongs to everyone.

Best Way Forward

India is building one of the world’s largest digital economies.

Our future will involve:

UPI

Digital commerce

Artificial Intelligence

Cloud computing

Digital education

Digital healthcare

Smart services

Social media

Digital government services

All of these depend, to some extent, on data.

Therefore, India needs a digital environment where:

Innovation grows.

Businesses can operate.

Technology can develop.

Citizens remain protected.

Data is used responsibly.

Security is taken seriously.

Rights are respected.

Conclusion

The DPDP Act, 2023 may look like a complicated legal document.

But its basic idea is actually very human.

Every piece of personal data represents a person.

And every person deserves to know:

What data is being collected?

Why is it being collected?

Who is using it?

How is it being protected?

What happens if something goes wrong?

India’s data protection journey is still developing, particularly with the 2025 Rules and phased implementation of the Act.

The success of this law will ultimately depend not only on government enforcement, but also on how seriously businesses, institutions and citizens take data protection.

Because in today’s India:

Data is digital identity.

Privacy is dignity.

Security is responsibility.

And data protection is everyone’s business.

About the Author

Adv. Shridhar Patil

Advocate | Cyber Law | Data Protection | Technology Law | Digital Rights

www.advshridharpatil.com

“Protecting Rights in the Digital Age.”

Legal Disclaimer

This article is written for general awareness and educational purposes. It is not a substitute for legal advice. The application of the DPDP Act depends on the facts of each case, the relevant provisions, applicable rules, notifications and their commencement status.

Official reference: Digital Personal Data Protection Act, 2023 — Ministry of Electronics & IT

Current Rules: Digital Personal Data Protection Rules, 2025 — Ministry of Electronics & IT