What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's dedicated law for protecting personal data. It sets rules for how organisations handle your data and gives you enforceable rights. The DPDP Rules were notified in November 2025 and the framework is being rolled out in phases.

Before this law, India had no single, comprehensive statute protecting personal data — protection was scattered across the Information Technology Act, 2000 and various rules. The DPDP Act changes that. It focuses on digital personal data: information about an identifiable individual that is collected, stored or processed electronically — your name, phone number, email, photos, payment details and more.

The core idea is simple: your personal data is yours, and any organisation that wants to use it takes on legal duties to handle it responsibly, be transparent about it, and answer to you if things go wrong.

In plain language

The DPDP Act treats your personal data like something on loan. A company can use it for a stated purpose you agreed to — but it has to keep it safe, use it only for that purpose, and give it back or delete it when you ask. That is a big shift in your favour.

What rights do you have over your personal data?

As a Data Principal you have the right to access information about your data, the right to correction and erasure, the right to grievance redressal, and the right to nominate someone to exercise your rights. You can also withdraw consent you gave earlier.

Here is what each right means for you in everyday terms:

These rights are meaningful only if you use them. If a company keeps sending you marketing after you unsubscribed, or holds old data it no longer needs, you now have a legal basis to push back — not just a request it can ignore.

Good to know

Rights under the DPDP Act generally apply against the organisation processing your data. The exact way to exercise each right — and any conditions — follow the Act and the Rules being rolled out. When in doubt, start with the company's published grievance channel.

Worried about how your data is used?

Ask Legal Setu — free, no account needed.
Ask Legal AI — free

What is a Data Principal and a Data Fiduciary?

A Data Principal is you — the individual the personal data belongs to. A Data Fiduciary is the organisation, company or government body that decides how and why your personal data is processed. The Act places duties on the Fiduciary and gives rights to the Principal.

The word "fiduciary" is deliberate. It signals a relationship of trust: the organisation holding your data is expected to act responsibly towards you, not just in its own commercial interest. A Data Fiduciary could be your bank, a shopping app, a hospital, a social-media platform or a government department.

Some entities that handle very large volumes of data may be classified as "Significant Data Fiduciaries" and carry extra obligations. But for an ordinary person the key relationship is straightforward: you are the Principal, they are the Fiduciary, and the law sets the terms between you.

Can you ask a company to delete your data?

Generally yes. The DPDP Act gives you a right to erasure of your personal data, subject to conditions in the Act. Where a company no longer needs the data or you withdraw consent, you can ask it to correct or delete your data through its grievance channel.

In practice, the steps look like this:

  1. Find the company's privacy or grievance contact — usually in its privacy policy or app settings.
  2. Send a clear written request stating you want your personal data erased (or corrected), and why.
  3. Keep a copy of your request and any reply — screenshots and emails are useful evidence.
  4. If the company ignores you or refuses without a valid reason, escalate to the Data Protection Board.

Erasure is not absolute. A company may be allowed or required to keep some data — for example, to comply with another law, or to complete a purpose you are still using it for. But it cannot simply hold your data forever for no reason.

Everyday example

You signed up for a food-delivery app, used it once, and want out. You can withdraw consent, ask the app to stop processing your data and delete it. Once your legitimate purpose is over and no other law requires retention, it should erase your personal data.

How do you complain about misuse of your data?

First raise a grievance with the Data Fiduciary using its published grievance mechanism. If it does not respond, you can complain to the Data Protection Board of India, which handles complaints about mishandling of personal data and can impose penalties on companies.

The Data Protection Board of India is designed to work digitally — with online complaint filing and case tracking — so you do not necessarily need a lawyer or a courtroom to raise an issue. The Board can inquire into breaches and, where a company is found to have mishandled data, impose significant financial penalties. The penalties are meant to be large enough to make careless data handling genuinely costly for organisations.

Two-step approach

Almost always, complain to the company first and give it a chance to fix things — keep proof of what you sent and when. If that fails, or your data was leaked or misused, take it to the Data Protection Board of India.

Remember that the DPDP Act is about how organisations handle your data. It does not replace the criminal cyber-offence provisions of the IT Act — so if you are facing online fraud, hacking or abuse, that is dealt with separately. See our guide to the Information Technology Act, 2000 for online fraud and cyber-crime steps.

For a serious data-misuse issue, talk to a lawyer.

₹99* books a verified lawyer, briefed on your case before the call.
Book a Lawyer — ₹99*

In most cases, yes. Processing your personal data generally needs your consent, and the notice asking for it must be clear about what data is collected and why. Some legitimate uses are allowed without fresh consent. You can withdraw consent at any time.

The Act pushes back against the era of endless, unreadable terms and conditions. A consent notice is meant to be specific and understandable: which data, for what purpose, and how you can withdraw. Consent should be a genuine, informed choice — not something buried in fine print.

Crucially, withdrawing consent should be as easy as giving it. If you agreed to let an app use your location and later change your mind, you can withdraw that consent — and the app should stop using your location data for that purpose going forward.

Practical tip

Before you tap "I agree," look for what the notice actually asks for. If an app wants access to data it clearly does not need for its service, that is a red flag. Under the DPDP Act, consent is supposed to be tied to a specified purpose — not a blank cheque.

Is the DPDP Act in force yet?

The Act was passed in 2023 and the Digital Personal Data Protection Rules were notified in November 2025. The framework is being rolled out in phases, with a compliance window for organisations. As of August 2026 the rollout is still underway — check the latest official status.

This matters because the law is not a single switch that flips on one date. Different obligations take effect at different times, and organisations have been given a phased window to update their systems, consent flows and grievance mechanisms. That is why some companies may already be asking for clearer consent while others are still catching up.

Because implementation is still moving, treat this article as a plain-language explainer written on 1 August 2026, not as the final legal position. For the current status and exact dates, always check the official sources listed below.

Status check

The DPDP Act, 2023 exists and its Rules were notified in 2025, but the framework is being implemented in phases. Do not assume every provision is fully enforced today — verify the latest position on the official Government of India sources before you rely on a specific deadline.

DPDP Act — questions people actually ask

What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 is India's dedicated law for protecting personal data. It sets rules for how organisations handle your data and gives you enforceable rights. The DPDP Rules were notified in November 2025 and the framework is being rolled out in phases.
What rights do you have over your personal data?
As a Data Principal you have the right to access information about your data, the right to correction and erasure, the right to grievance redressal, and the right to nominate someone to exercise your rights. You can also withdraw consent you gave earlier.
What is a Data Principal and a Data Fiduciary?
A Data Principal is you — the individual the personal data belongs to. A Data Fiduciary is the organisation, company or government body that decides how and why your personal data is processed. The Act places duties on the Fiduciary and gives rights to the Principal.
Can you ask a company to delete your data?
Generally yes. The DPDP Act gives you a right to erasure of your personal data, subject to conditions in the Act. Where a company no longer needs the data or you withdraw consent, you can ask it to correct or delete your data through its grievance channel.
How do you complain about misuse of your data?
First raise a grievance with the Data Fiduciary using its published grievance mechanism. If it does not respond, you can complain to the Data Protection Board of India, which handles complaints about mishandling of personal data and can impose penalties on companies.
Does the DPDP Act require your consent?
In most cases, yes. Processing your personal data generally needs your consent, and the notice asking for it must be clear about what data is collected and why. Some legitimate uses are allowed without fresh consent. You can withdraw consent at any time.
Is the DPDP Act in force yet?
The Act was passed in 2023 and the Digital Personal Data Protection Rules were notified in November 2025. The framework is being rolled out in phases, with a compliance window for organisations. As of August 2026 the rollout is still underway — check the latest official status.