DPDP Act 2023: ₹250 Crore Penalties Are Coming Is Your Business Ready Before 13 May 2027?

India finally has a dedicated data protection law. The Digital Personal Data Protection Act, 2023 (DPDPA) was passed by Parliament in August 2023 and received Presidential assent on 11 August 2023. The full enforcement, including the penalty regime begins on 13 May 2027. The regulator and the Data Protection Board of India, is functioning.

If any business collects customer data in any digital form, this law applies to you. Here is what you need to know, in plain language.

What Does the DPDP Act Cover?

The DPDP Act governs the collection, processing, storage, and protection of digital personal data, any data about an individual who can be identified by it (Section 2(t)). It covers data collected digitally, and data collected on paper and later digitised (Section 3).

It also reaches foreign companies that process personal data to offer goods or services to people in India. Two things fall outside the Act, data processed for purely personal or domestic use, and data the individual has themselves made public.

The Three Key Players

RoleWho they areExample
Data PrincipalThe individual the data belongs to (s. 2(j))Individual, the customer
Data FiduciaryThe entity deciding why and how data is processed (s. 2(i))An e-commerce company deciding what customer data to collect for orders
Data ProcessorA vendor processing data on the fiduciary’s instructions (s. 2(k))A courier company using addresses for delivery

A “person” here is broad individuals, HUFs, companies, firms, associations, the State, and any other juristic person.

What Must a Data Fiduciary Do?

The Data Fiduciary carries the main compliance burden. In sequence:

  1. Lawful purpose – process data only for a lawful purpose (s. 4)
  2. Notice – tell the individual what data is collected and why, before or at collection (s. 5)
  3. Consent – obtain free, specific, informed consent, fresh consent is needed for any new purpose (s. 6)
  4. Protect -implement reasonable security safeguards, the fiduciary remains liable for its processors (s. 8)
  5. Notify breaches – report every personal data breach to the Board and affected individuals
  6. Erase -delete data once the purpose is over or consent is withdrawn, unless law requires retention
  7. Redress – publish contact details and run an effective grievance mechanism

Children’s data: processing a child’s data requires verifiable parental consent (s. 9), and behavioural tracking or targeted advertising aimed at children is prohibited.

Consent Managers (s. 2(g)) are Board-registered platforms that let individuals give, review, and withdraw consent in one place. 

Your Rights as a Data Principal

Under Sections 11–14, every individual can:

  • Know how their data is being used and access it
  • Correct or erase inaccurate or outdated data
  • Complain -first through the fiduciary’s grievance system, then to the Data Protection Board
  • Nominate someone to exercise these rights on death or incapacity

Duties apply too-do not impersonate anyone, do not suppress material information, and do not file false or frivolous complaints.

Penalties: Up to ₹250 Crore Per Breach

The Data Protection Board can impose penalties of up to ₹250 crore for a single violation – the ceiling applies to failure to maintain security safeguards (Schedule read with s. 33). The Board weighs the gravity, duration, data sensitivity, repetition, and mitigation efforts. Repeat offenders can even have their platforms blocked in public interest (s. 37). Appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days (s. 29), which functions digitally and must decide within six months. Civil courts are barred from these matters (s. 39), the Board and Tribunal have exclusive jurisdiction.

What Should Businesses Do Now?

The waiting of date 13 May 2027 is no longer an option. Businesses typically need:

  • A DPDP Act compliance audit – mapping what data you hold and why
  • Consent notices and privacy policies drafted to the statutory standard
  • Data processing agreements reviewed for processor obligations
  • A breach response plan covering Board notification
  • Representation before the Data Protection Board and TDSAT

Frequently Asked Questions

Is the DPDP Act 2023 in force?
Partially, the Data Protection Board and core machinery are live, full obligations and penalties apply from 13 May 2027.

What is the maximum penalty under the DPDP Act?
₹250 crore per violation, for failing to maintain reasonable security safeguards.

Does the DPDP Act apply to foreign companies?
Yes, if they process personal data to offer goods or services to individuals in India.

Who enforces the DPDP Act?
The Data Protection Board of India,  appeals lie to the TDSAT.

Talk to a Lawyer Before the Deadline Does the Talking

Ajit Kakkar and Associates advises businesses, startups, and institutions on DPDPA compliance from audits and policy drafting to representation before the Data Protection Board. Book an Initial Consultation today.

💬 +91-9958006409

Leave a Reply

Your email address will not be published. Required fields are marked *