Regulation · India

India's data protection law, in force.

India's landmark privacy legislation establishing comprehensive data protection rights for over 1.4 billion citizens. Neostra helps organisations achieve and maintain full DPDPA compliance with automated workflows and purpose-driven consent management.

2023
Year enacted
1.4B+
Citizens protected
₹250Cr
Maximum penalty
5
Data principal rights

What is the DPDPA?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's first comprehensive data protection law. It governs the processing of digital personal data, establishing clear obligations for Data Fiduciaries and rights for Data Principals.

The DPDPA applies to any organisation processing personal data of individuals in India, regardless of where the organisation is based, making it a truly extraterritorial regulation.

INDigital Personal Data Protection Act, 2023

Who must comply?

The DPDPA applies broadly to organisations processing digital personal data within India, as well as those outside India that process data in connection with offering goods or services to individuals in India.

  • Companies operating in India across all sectors
  • Foreign companies offering services to Indian residents
  • Government bodies processing citizen data
  • Data processors acting on behalf of Data Fiduciaries
  • Significant Data Fiduciaries, with additional obligations
Extraterritorial applicability
Obligations

What the law requires.

Lawful consent
Obtain free, specific, informed, unconditional and unambiguous consent before processing personal data. Consent must be purpose-specific and easily withdrawable.
Purpose limitation
Personal data can only be processed for the specific, lawful purpose for which consent was obtained. Processing beyond the stated purpose requires fresh consent.
Data principal rights
Individuals have the right to access, correct and erase their data, and to nominate representatives. Organisations must respond to these requests promptly.
Breach notification
Data Fiduciaries must notify the Data Protection Board and affected individuals of any personal data breach without delay, following prescribed timelines and formats.
Notice requirements
Organisations must provide clear, accessible privacy notices in plain language detailing what data is collected, the purpose of processing, and how to exercise rights.
Data Protection Officer
Significant Data Fiduciaries must appoint a Data Protection Officer based in India, conduct periodic data audits, and implement enhanced compliance measures.
Rights

Data principal rights under DPDPA

The DPDPA establishes fundamental rights for individuals regarding their personal data.

  1. 1
    Right to information
    Data Principals have the right to know what personal data is being processed, the purpose of processing, and the identity of all entities with whom data has been shared.
  2. 2
    Right to correction and erasure
    Individuals can request correction of inaccurate or misleading data and erasure of data that is no longer necessary for the stated purpose.
  3. 3
    Right to withdraw consent
    Data Principals can withdraw consent at any time with the same ease with which consent was given, and organisations must cease processing upon withdrawal.
  4. 4
    Right to grievance redressal
    Individuals have the right to register complaints with the Data Fiduciary and escalate to the Data Protection Board if not resolved satisfactorily.
  5. 5
    Right to nominate
    Data Principals can nominate another individual to exercise their rights in case of death or incapacity, ensuring continuity of data protection.
The platform

How Neostra covers DPDPA.

The platform automates the complex requirements of India's data protection regulation.

Consent lifecycle management
Capture, store and manage consent with full audit trails. Purpose-specific consent, easy withdrawal and automated re-consent workflows.
DSAR automation
Automate the entire rights request lifecycle: intake, identity verification, cross-department task routing and response delivery.
Data discovery and mapping
Discover and classify personal data across databases, cloud storage and SaaS applications to build comprehensive data inventories.
Readiness assessments
Evaluate your organisation's DPDPA readiness with structured assessments, gap analysis and actionable roadmaps with scoring frameworks.
Breach management
Streamline breach detection, assessment and notification workflows for timely reporting to the Data Protection Board and affected individuals.
Compliance dashboard
Monitor your compliance posture in real time: consent rates, DSAR response times and overall readiness scores.
Other regulationsGDPR → CCPA / CPRA →

Find out where you stand on DPDPA.

The free 33-point readiness check scores you across the six areas the law tests, in about ten minutes.