Digital Personal Data Protection Act, 2023 (India)

Asia-PacificPrivacy2023
ByDecipherU Editorial

India's DPDP Act is the country's first dedicated cybersecurity and data protection law, covering digital personal data processing. It establishes the Data Protection Board of India as the adjudicating body, requires notice and consent for data processing, and mandates 'reasonable security safeguards' for personal data. Rules under the Act are still being finalized as of 2026.

Quick Reference

EnactedAugust 11, 2023 (assented); rules pending as of April 2026
Enforcement BodyData Protection Board of India
PenaltiesUp to 250 crore INR (approximately $30 million USD) per violation; specific penalty amounts per category of violation
Applicable ToData fiduciaries (controllers) processing digital personal data in India or processing data of Indian individuals for offering goods/services

Key Requirements

Section 8 (Obligations of Data Fiduciary)

Data fiduciaries must implement appropriate technical and organizational measures to comply with the Act, including reasonable security safeguards to prevent data breaches

Section 8(6) (Breach notification)

Data fiduciaries must inform the Data Protection Board and each affected data principal about a personal data breach

Section 5 (Notice and consent)

Data fiduciaries must provide notice containing a description of personal data sought, the purpose of processing, and how to exercise rights, before obtaining consent

Section 16 (Cross-border data transfer)

Personal data may be transferred outside India except to countries restricted by the Central Government through notification

How Does India DPDP Act Affect Cybersecurity Careers?

India has one of the world's largest IT workforces, and the DPDP Act creates massive demand for cybersecurity and privacy professionals domestically. Security professionals at Indian IT services companies must implement DPDP compliance for their clients. The pending rules mean professionals must stay current as the regulatory framework evolves.

How Does India DPDP Act Affect Cybersecurity Sales?

India's digital economy and huge population make the DPDP Act a significant market opportunity for cybersecurity vendors. Consent management, data protection, and breach notification solutions all serve DPDP requirements. The rules are still being finalized, so vendors who prepare early can capture market share as enforcement begins.

Cybersecurity Roles That Work With India DPDP Act

Related Cybersecurity Certifications

Related Cybersecurity Laws

Frequently Asked Questions

India's DPDP Act is the country's first dedicated cybersecurity and data protection law, covering digital personal data processing. It establishes the Data Protection Board of India as the adjudicating body, requires notice and consent for data processing, and mandates 'reasonable security safeguards' for personal data. Rules under the Act are still being finalized as of 2026.

India has one of the world's largest IT workforces, and the DPDP Act creates massive demand for cybersecurity and privacy professionals domestically. Security professionals at Indian IT services companies must implement DPDP compliance for their clients. The pending rules mean professionals must stay current as the regulatory framework evolves.

Up to 250 crore INR (approximately $30 million USD) per violation; specific penalty amounts per category of violation

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?