Understanding consent, data fiduciary duties, cross-border transfer rules, and compliance deadlines under India's Digital Personal Data Protection Act

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's comprehensive law governing how organizations collect, process, and store the personal data of individuals in India. Passed by Parliament in 2023, the Act is being brought into force in phases, with major compliance obligations landing through November 2026 and May 2027. For any business that collects personal data from Indian users — from e-commerce platforms to SaaS companies to local service providers — understanding what the law requires, and by when, has become a practical necessity rather than a legal afterthought.
This guide covers the Act's core provisions as currently enacted and notified, distinguishing them clearly from rules and mechanisms still being finalized.
This article is for general informational purposes only and is not legal advice. Businesses should consult a qualified data protection or technology lawyer for guidance specific to their operations.
The Act applies to the processing of digital personal data — data about an identifiable individual, processed digitally — within India, and in certain cases to processing outside India if it relates to offering goods or services to individuals in India. It replaces the more limited data-protection provisions that previously existed under India's IT Act and associated rules.
Two core roles are defined by the Act:
A special category, the Significant Data Fiduciary (SDF), applies to organizations the government designates based on factors like volume and sensitivity of data processed, risk to individual rights, and potential impact on India's sovereignty and security — SDFs face additional obligations, including mandatory data protection officer appointments and periodic audits.
The Act requires that personal data generally be processed only with the free, specific, informed, unconditional, and unambiguous consent of the individual (called the "Data Principal"), given through a clear affirmative action. Consent requests must be presented in plain language, and individuals must be able to withdraw consent as easily as they gave it.
The Act also recognizes certain "legitimate uses" where consent is not required — for example, when an individual voluntarily provides data for a specified purpose, for compliance with law, medical emergencies, or employment-related purposes — though these carve-outs are narrower than a general "legitimate interest" basis found in some other privacy frameworks.
The Act introduces a novel mechanism: Consent Managers, registered intermediary platforms through which individuals can give, manage, and withdraw consent across multiple data fiduciaries from one place. Consent Managers owe a fiduciary duty to the individual, not to businesses, and are required to be data-blind — unable to read the personal data flowing through their consent infrastructure. This framework becomes operative from November 2026.
Organizations acting as Data Fiduciaries must:
Individuals are granted specific rights under the Act, including the right to:
Unlike some privacy regimes that require case-by-case approval for international transfers, the DPDP Act takes a "blocklist" approach: personal data can generally be transferred outside India to any country, except those specifically restricted by the central government through official notification. As of the Act's current framework, businesses should watch for government notifications identifying restricted destination countries rather than assuming a default prohibition.
The Act sets a higher protection standard for processing children's personal data (defined as under 18), requiring verifiable parental consent before processing and prohibiting tracking, behavioral monitoring, or targeted advertising directed at children, subject to specific exemptions the government may notify.
| Phase | Date | What It Covers |
|---|---|---|
| Phase 1 | November 2025 | Institutional groundwork — Data Protection Board establishment and definitional provisions take effect |
| Phase 2 | November 2026 | Consent Manager registration framework becomes operative |
| Phase 3 | May 2027 | Full substantive obligations enforceable — notice requirements, consent standards, security safeguards, and data-principal rights |
Important caveat: As of this writing, the Data Protection Board of India has not been fully constituted, and several implementation mechanisms tied to the Consent Manager framework remain under development. Businesses should treat these dates as the government's stated schedule while monitoring official notifications for any changes, since operational readiness of supporting institutions can affect actual enforcement timing.
The DPDP Act sets substantial financial penalties, calibrated to the nature of the violation:
Penalties are imposed by the Data Protection Board of India following an inquiry, and the Act does not currently provide for imprisonment as a penalty for these corporate violations, distinguishing it from some cybercrime provisions elsewhere in Indian law.
For Indian businesses, and for foreign companies serving Indian users, the DPDP Act represents the first comprehensive, dedicated data protection statute in India — replacing a patchwork of IT Act rules that offered comparatively limited and less structured privacy obligations. The financial penalties are large enough to be a genuine board-level risk, and the phased timeline means businesses have a defined but finite runway to build compliant consent flows, breach-response processes, and data governance practices before enforcement of the full obligations in May 2027.
While specific implementation will vary by organization, common preparatory steps include:
Does the DPDP Act apply to businesses outside India?
Yes, in certain circumstances — the Act can apply to processing of personal data outside India if it is connected to offering goods or services to individuals within India.
Is the DPDP Act similar to the EU's GDPR?
There are conceptual similarities (data fiduciary/controller roles, consent requirements, individual rights), but the DPDP Act's approach to legitimate-use exemptions, cross-border transfers, and enforcement structure differs meaningfully from the GDPR. Businesses already GDPR-compliant should not assume automatic DPDP compliance.
When do businesses actually need to be compliant?
The most significant substantive obligations become enforceable from May 2027, with the Consent Manager framework operative from November 2026. However, businesses should not wait until the deadline, since building compliant systems typically takes considerable lead time.
What counts as "personal data" under the Act?
Any data about an individual who is identifiable by or in relation to that data, when processed in digital form.
Is this article a substitute for legal advice?
No. This guide summarizes publicly available provisions of the DPDP Act for general informational purposes. Businesses should consult a qualified lawyer for advice specific to their data processing activities, as rules and notifications continue to be finalized.
The DPDP Act establishes India's first dedicated, comprehensive framework for personal data protection, built around consent, defined obligations for data fiduciaries and processors, individual rights, and a blocklist-style approach to cross-border transfers. With the Consent Manager framework arriving in November 2026 and full enforcement in May 2027, businesses handling Indian users' personal data have a defined but narrowing window to build compliant systems — while key institutional pieces, including the Data Protection Board's full constitution, are still being put in place. Treat the Act's provisions as the baseline, and stay alert to official notifications that will fill in remaining operational details.