DPDP Act: When Your Data Tells Your Story
Imagine this.
You wake up in the morning and check your phone.
You open a shopping app.
You search for a pair of shoes.
A few hours later, you receive an advertisement for the exact kind of shoes you were looking at.
Then you book a doctor's appointment online. You enter your name, phone number, age, and medical details.
Later, you order food. You share your address.
At work, you log in to an online platform using your email address.
By the end of the day, dozens of pieces of information about you have travelled through different apps, websites, companies, and systems.
But who is keeping all this information?
And more importantly:
Who decides what happens to it?
This is where India's Digital Personal Data Protection Act, 2023 (DPDP Act) enters the story.
Meet Aarav
Let's take a simple example.
Aarav is 28 years old and lives in Bengaluru.
One Monday morning, he downloads a new fitness application.
The app asks for:
His name
Email address
Phone number
Age
Location
Fitness information
Aarav quickly clicks "I Agree" and starts using the application.
He doesn't think much about it.
Most of us don't.
But behind that single click, something important has happened.
A company now has access to information about Aarav.
The company needs to answer some basic questions:
Why is this data being collected?
How will it be used?
Who will have access to it?
How long will it be kept?
What happens if Aarav wants it corrected or deleted?
The DPDP Act is designed to create rules around questions like these.
First, Let's Meet the Two Main Characters
The DPDP Act uses two important terms.
The Data Principal
That's Aarav.
In simple language, the Data Principal is the individual to whom the personal data relates.
If your name, phone number, email address, or other personal information is being processed, you are the Data Principal.
So whether you are a customer, employee, student, patient, or user of an online service, you may be a Data Principal.
The Data Fiduciary
Now meet the fitness application.
The company decides:
"We need Aarav's information to provide our service."
It decides what information to collect and why it should be processed.
Under the DPDP Act, this organization may be a Data Fiduciary.
In simple terms, the Data Fiduciary is the organization that determines the purpose and means of processing personal data.
And that's where responsibility begins.
The Story Gets Interesting: Consent
Aarav opens the app again.
This time, instead of simply clicking "Accept," he notices something different.
The application explains what information it wants and why.
This is important.
Under the DPDP framework, where consent is the basis for processing, consent needs to be free, specific, informed, unconditional and unambiguous, and involve a clear affirmative action.
In other words, consent shouldn't be hidden behind confusing language or designed to trick someone into agreeing.
And there's another important principle.
If Aarav can give consent easily, withdrawing that consent should also be reasonably easy.
The DPDP Rules, 2025 provide additional requirements around notices and consent mechanisms.
Then Aarav Asks a Simple Question
A few months later, Aarav becomes curious.
He thinks:
"What information does this company actually have about me?"
This is where individual rights become important.
The DPDP Act gives Data Principals rights relating to their personal data, including rights concerning:
Access to information
Correction
Erasure
Grievance redressal
Nomination
So Aarav isn't simply handing over his information and losing all control over it.
The law creates a framework through which he can exercise certain rights regarding his personal data.
Then Something Goes Wrong
Now imagine the company's database is attacked.
Hackers gain unauthorized access to customer information.
Aarav receives a message:
"We have detected a security incident that may have affected your personal data."
This is no longer just an IT problem.
It can become a data-protection issue.
The DPDP framework requires Data Fiduciaries to implement reasonable security safeguards and establishes requirements relating to personal data breaches.
The 2025 Rules provide more detailed requirements concerning security measures and breach notifications.
For businesses, this means cybersecurity and privacy can no longer be treated as completely separate conversations.
What Happens to Aarav's Data After He Leaves?
A year later, Aarav stops using the fitness application.
But the company still has his information.
Should it keep everything forever?
That's where data retention and erasure become important.
The DPDP framework creates obligations concerning the erasure of personal data when it is no longer necessary for the relevant purpose, subject to applicable legal requirements and exceptions.
The 2025 Rules also introduce specific requirements for certain classes of Data Fiduciaries concerning retention and erasure.
For organizations, this means:
"Store everything forever" is not a sensible privacy strategy.
Companies need to understand what data they hold, why they hold it, and when it should be deleted.
What About Children?
Now imagine Aarav's younger sister, Siya, who is 15.
She downloads an educational application.
Children receive additional protection under the DPDP framework.
The Act defines a child as an individual who has not completed 18 years of age.
The framework contains additional requirements concerning children's personal data, including requirements around verifiable parental consent and restrictions on certain processing activities.
The objective is to provide additional protection to children in the digital environment.
Not Every Company Has the Same Responsibilities
Now let's move from Aarav's story to the business world.
Imagine a small online store processing a limited amount of customer information.
Now compare that with a massive digital platform processing information about millions of people.
The risks aren't necessarily the same.
That's why the DPDP Act creates the concept of a Significant Data Fiduciary.
The Central Government may designate an organization as a Significant Data Fiduciary based on factors including the volume and sensitivity of personal data processed and potential risks to areas such as the sovereignty and integrity of India, electoral democracy, security of the State, and public order.
Significant Data Fiduciaries have additional obligations, including requirements relating to data protection officers, independent data audits, and assessments.
And Then Comes the Regulator
Every story needs someone responsible for enforcing the rules.
Enter the Data Protection Board of India.
The Board was formally established by the Central Government in November 2025.
Its role includes dealing with matters under the DPDP framework, including certain breaches of obligations and associated penalties.
This is significant because the DPDP framework is not simply a set of voluntary privacy guidelines.
It establishes a statutory regulatory structure.
And Yes, There Can Be Serious Penalties
Let's return to the company that suffered the security breach.
Suppose it failed to implement the required security safeguards.
The financial consequences under the DPDP Act can be significant.
The Act's Schedule provides for penalties of up to ₹250 crore for certain breaches, including failure to take reasonable security safeguards to prevent personal data breaches.
The applicable penalty depends on the specific breach and circumstances.
But the lesson for businesses is straightforward:
Data protection is no longer something organizations can afford to treat as an afterthought.
So, What Should a Business Do?
Imagine you're the founder of a growing company.
You have customer data in your website.
Employee information in your HR system.
Customer support conversations in your CRM.
Payment information handled through third-party providers.
Marketing databases.
Cloud storage.
Mobile applications.
Now ask yourself:
Do I know where all this personal data is?
If the answer is "not completely," that's where the DPDP compliance journey should begin.
A practical approach is to:
1. Map your data
Find out what personal data you collect, where it comes from, where it is stored, and who processes it.
2. Understand why you collect it
Every piece of personal information should have a clear purpose.
3. Review your privacy notices
Make them understandable rather than filling them with complicated legal language.
4. Review consent
Make sure consent mechanisms meet applicable requirements and that withdrawal can be handled appropriately.
5. Build processes for individual rights
Have a system for handling requests relating to access, correction, erasure, and grievances.
6. Strengthen security
Review access controls, authentication, monitoring, backups, incident response, and other safeguards.
7. Review vendors
Your organization may not be the only one handling customer data.
Cloud providers, technology vendors, consultants, and other partners may also be involved.
8. Create a retention policy
Know when information should be retained and when it should be deleted, subject to applicable legal requirements.
The Bigger Picture
The DPDP Act is not just another compliance document sitting in a company's legal department.
It represents a broader change in how organizations think about personal information.
For years, the digital economy operated around a simple idea:
Collect more data.
The emerging privacy mindset asks a different set of questions:
Why do you need it?
Did the individual understand what was happening?
Can they exercise their rights?
Is the information secure?
Do you still need it?
Those questions are at the heart of modern data protection.
The Story Isn't Over
Remember Aarav?
He started his day by downloading a fitness app.
He clicked "I Agree."
He shared his information.
He later asked what data the company held.
Then a security incident occurred.
Finally, he stopped using the service.
That small story represents something much bigger.
Every day, millions of people in India interact with digital services and share pieces of their personal lives.
The Digital Personal Data Protection Act, 2023, together with the DPDP Rules, 2025, provides the legal framework for how digital personal data is to be handled within its scope.
For individuals, it provides a framework of rights and protections.
For businesses, it creates new responsibilities around privacy, security, governance, and accountability.
And for India's digital economy, it marks an important step toward building trust around the way personal data is collected and used.
Because ultimately, data isn't just information sitting inside a database.
Behind every name is a person.
Behind every phone number is a person.
Behind every customer ID is a person.
And behind every piece of personal data is a story.
The DPDP Act is about making sure that story is handled responsibly.
Sources
India Code — Digital Personal Data Protection Act, 2023
Ministry of Electronics and Information Technology (MeitY) — Digital Personal Data Protection Rules, 2025
MeitY — Notifications concerning commencement of the DPDP Act and Rules
MeitY — Notification establishing the Data Protection Board of India
This article is for educational purposes and does not constitute legal advice. Organizations should review the DPDP Act, applicable Rules, notifications and other relevant laws and obtain professional legal advice for their specific circumstances.
No comments:
Post a Comment