All acts
Cyber Law

The Digital Personal Data Protection Act, 2023

India's data protection law — consent, notice, the duties of anyone processing personal data, and the rights of the people it belongs to. A curated selection; not the complete text.

Share

Provided for study purposes. Cross-check against the official source (India Code / the relevant government gazette) before citing or relying on this text — amendments and corrections may not be reflected here.

PRELIMINARY

Section 2. Definitions

A Data Principal is the individual to whom the personal data relates, and where that individual is a child, includes the parents or lawful guardian. A Data Fiduciary is any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. Personal data means any data about an individual who is identifiable by or in relation to such data.

OBLIGATIONS OF DATA FIDUCIARIES

Section 4. Grounds for processing personal data

A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose for which the Data Principal has given their consent, or for certain legitimate uses. A lawful purpose means any purpose which is not expressly forbidden by law.

Section 5. Notice

Every request made to a Data Principal for consent shall be accompanied or preceded by a notice informing them of the personal data proposed to be processed and the purpose of the processing, the manner in which they may exercise their rights to withdraw consent and to grievance redressal, and the manner in which they may make a complaint to the Board. The Data Principal shall be given the option to access the notice in English or in any language specified in the Eighth Schedule to the Constitution.

Section 6. Consent

The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and shall signify agreement to the processing of their personal data for the specified purpose and be limited to such personal data as is necessary for that purpose. The Data Principal has the right to withdraw their consent at any time, and the ease of doing so shall be comparable to the ease with which consent was given.

Section 8. General obligations of Data Fiduciary

A Data Fiduciary is responsible for complying with this Act in respect of any processing undertaken by it or on its behalf by a Data Processor. It shall implement appropriate technical and organisational measures to ensure effective observance of the Act, protect personal data in its possession by taking reasonable security safeguards to prevent a personal data breach, and in the event of a breach give notice to the Board and to each affected Data Principal. It shall erase personal data on the Data Principal withdrawing consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, and shall publish the business contact information of a Data Protection Officer or a person able to answer questions about the processing.

Section 9. Processing of personal data of children

Before processing any personal data of a child or of a person with a disability who has a lawful guardian, a Data Fiduciary shall obtain verifiable consent of the parent or the lawful guardian. A Data Fiduciary shall not undertake processing of personal data that is likely to cause any detrimental effect on the well-being of a child, and shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

Section 10. Additional obligations of Significant Data Fiduciary

The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary on the basis of the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, the security of the State and public order. A Significant Data Fiduciary shall appoint a Data Protection Officer based in India who shall be responsible to the Board of Directors, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessments and periodic audits.

RIGHTS AND DUTIES OF DATA PRINCIPALS

Section 11. Right to access information about personal data

The Data Principal has the right to obtain from the Data Fiduciary to whom they have previously given consent a summary of the personal data being processed and the processing activities undertaken, the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared along with a description of the data so shared, and any other information related to the personal data and its processing as may be prescribed.

Section 12. Right to correction and erasure of personal data

A Data Principal has the right to correction, completion, updating and erasure of their personal data for the processing of which they have previously given consent. On receiving such a request the Data Fiduciary shall correct inaccurate or misleading personal data, complete incomplete personal data, update the personal data, and erase the personal data unless retention is necessary for the specified purpose or for compliance with any law.

Section 13. Right of grievance redressal

A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or a Consent Manager in respect of any act or omission regarding the performance of their obligations. The Data Fiduciary or Consent Manager shall respond to any grievance within the period prescribed, and the Data Principal shall exhaust the opportunity of redressing their grievance under this section before approaching the Board.

Section 14. Right to nominate

A Data Principal shall have the right to nominate, in the manner prescribed, any other individual who shall, in the event of the death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act.

PENALTIES

Section 33. Penalties

Where the Board determines on the conclusion of an inquiry that a breach of the provisions of this Act or the rules made under it by a person is significant, it may, after giving the person an opportunity of being heard, impose a monetary penalty as specified in the Schedule. In determining the amount the Board shall have regard to the nature, gravity and duration of the breach, the type and nature of the personal data affected, the repetitive nature of the breach, whether the person realised a gain or avoided a loss, whether the person took any action to mitigate the effects, and the likely impact of the penalty on the person.

Post your matter

What do you need help with? Pick the closest one — you can explain in your own words next.