What the DPDP Act means for companies handling personal data in 2026

The Digital Personal Data Protection (DPDP) Act, 2023 is India's principal law governing how personal data of individuals is collected, processed and stored by organizations. It applies to any entity processing digital personal data within India, and in certain cases, to entities outside India that process the data of individuals located in the country.
The law defines the individual whose data is being processed as the "Data Principal," while the entity determining the purpose and means of processing that data is the "Data Fiduciary" — roughly equivalent to concepts like "data subject" and "data controller" in other global privacy frameworks.
Organizations must obtain clear, informed consent before processing personal data, with consent requests required to be presented in plain, understandable language rather than buried in lengthy legal terms.
Personal data collected for one specified purpose generally cannot be repurposed for unrelated uses without fresh consent from the individual.
Individuals are granted rights including access to their data, correction of inaccurate data, and the ability to withdraw consent and request erasure of their data in many circumstances.
Data Fiduciaries are required to implement appropriate technical and organizational measures to prevent data breaches.
Organizations must notify both the Data Protection Board of India and affected individuals in the event of a personal data breach.
Entities designated as "Significant Data Fiduciaries" — typically those processing large volumes of sensitive data — face additional obligations, including appointing a Data Protection Officer based in India.
The law imposes stricter requirements around processing children's personal data, including obtaining verifiable parental consent.
The Act empowers the Data Protection Board of India to impose significant financial penalties on organizations found non-compliant, with penalty amounts scaled based on the nature and severity of the violation, including failures to implement adequate security safeguards or properly notify data breaches.
Does the DPDP Act apply to foreign companies?
Yes, in certain circumstances — the law can apply to entities outside India that process personal data of individuals located within the country in connection with offering goods or services to them.
What counts as personal data under the Act?
Personal data broadly includes any data about an individual who is identifiable by or in relation to that data.
Is there a grace period for compliance?
Implementation timelines and specific compliance deadlines are set out through rules and notifications issued under the Act, and businesses should monitor official government notifications for applicable dates.
The DPDP Act represents a significant step in aligning India's data protection framework with global privacy standards. For businesses, compliance is not merely a legal formality but an operational necessity — requiring updated consent processes, stronger security practices and clear accountability structures. This article provides a general overview and should not be treated as personalized legal advice; organizations should consult qualified legal counsel for compliance specific to their operations.