logo logo

Online Legal Advice from Insaaf99® Online Lawyer Consultation in India

INSAAF99

Book your Online meeting with our Legal Expert

Talk To Lawyer
Published Updated: September 04, 2026

DPDP Act 20203: A Practical, Ground-Level Breakdown for Businesses and Individuals

DPDP Act

Some laws come in subtle ways without many people noticing it. One such was the Digital Personal Data Protection Act, 2023. It was enacted in August 2023, but most people outside the legal profession did not really notice it in the beginning. Despite all this, the DPDP Act 2023 in India is one of the largest legislations for the digital world since the IT Act 2000 was enacted.

You may know some key points or the definition of this law during internal discussions. What is less readily available is a simple summary of what this law actually requires companies and individuals to do—and what it reveals about how Indian companies have been operating with personal data over these many years. And in this article, we will explain all these things in very simple language

The DPDP Act 2023: How this Act Changes Everything for Indian Businesses & Individuals

This law is not a compliance checklist. It alters the mindset of businesses when it comes to consumers' information. The person (known in the Act as the "Data Principal") now finds himself at the heart of the matter and not the company gathering the data. It is the first occasion that this has occurred in India.

The unspoken contract in the digital landscape of India for years has been as straightforward as this: You use our app for free and in return we can do whatever we want with your data. That deal is now over with the introduction of the DPDP Act 2023. Now, consent can only be free, specific, informed, unconditional and clear.

This is a long overdue law! It's based on the landmark Supreme Court judgment in Justice K.S. Puttaswamy v. Union of India in 2017, which held that privacy is a fundamental right under the Constitution's Article 21. The DPDP Act is the result of that judgment by Parliament; it needed years to get here and, thankfully, it did.

Also Read :- Transfer of Property Act In India: All You Need to Know

The true problem DPDP ACT 2023 Al ways trying to solve:

Most of the apps and websites gathered a lot more data than they required some years ago. Your date of birth, job, phone number — even if none of this information was required to operate the service. This information was kept indefinitely, passed along to marketing partners, and was not often communicated to users in human terms.

Sometimes it was because of the company's intent, sometimes it was because there was no law against it.

The DPDP Act 2023 brings an end to that. Only for a valid and real purpose, can companies now gather data. When this reason is satisfied, the data should be removed. You shouldn't be gathering 10 bits of information if three is sufficient. This concept is known as ‘purpose limitation' and ‘data minimization’ and is compelling companies that have been created to gather user data to re-evaluate their operations on how they are doing.

Who Actually Needs to Care — Beyond Big Tech

The DPDP Act is applicable to you if you are a SaaS business, a local ecommerce website, a Fintech app, a health portal or even a small HR software product company. The mistaken belief is that this law applies only to giants such as Google or Facebook but it isn't limited to big techs.

This law applies to any organisation that processes personal data of Indian citizens, regardless of where the processing occurs in a particular instance. Under this law, a small start-up company in Bangalore with 10,000 users is a "Data Fiduciary" as much as a company in the Fortune 500 with a global platform.

The size of your company might be a factor in determining the penalties imposed by the Data Protection Board, however, smaller companies are not necessarily exempt. All rules are for everyone.

This law applies to any product that comes into contact with personal data, which for every digital product is basically the case.

Now Let’s Understand Important Terms, In Everyday Language

Data Principal vs. Data Fiduciary

You are the Data Principal. The company you give your name, email, location, or health information to is the Data Fiduciary. If another company (such as a cloud provider, analytics service, payment gateway) is actually collecting your data, they are known as a Data Processor.

Under this law, the principal responsibility lies with the Data Fiduciary. But if your vendor gets it wrong, it's still the Fiduciary's responsibility to ensure that you don't.

Consent is not a one-off occurrence.

An individual's consent under the DPDP Act is not permanent. It must be clearly tailored to each use and a person must have the ability to terminate it at any time. The company has to stop using the data of an individual when they withdraw consent — in most circumstances, that means the company must delete it.

It is now important for businesses to have the correct systems in place to keep a record of and manage consent. It's no longer enough to have a simple ‘I agree’ box on the registration form.

Significant Data Fiduciaries

The government may classify some organisations as "Significant Data Fiduciaries" because of their volume of data, its sensitivity or impact on national security. These businesses are subject to additional regulations, such as conducting regular Data Protection Impact Assessments, designating a Data Protection Officer and undergoing more rigorous audits.

What is currently being lost by companies?

If you speak to most medium-sized Indian businesses today about compliance, you will most likely get one of two answers: panic or denial. Neither approach works.

The “panic” group changes their privacy policy, puts in a cookie notice, and that is done. However, they haven't determined if their systems can accommodate even the simplest request from a user to delete their information. They don't know what data they're collecting, where it's being stored, who's able to see it, or how long it's being stored.

The “denial” group is waiting for the law to be enforced before taking any action. They believe that the rules are not in full effect yet and do not need to take any immediate effect as of now.

Both sides are wrong. Compliance is not about paperwork, it's about the way a business operates. The companies that will be successful in this area are those who are aware of the data they are mapping out today, rather than those who are trying to catch up just before the enforcement starts.

Many people rarely talk about this, but a big part of the cost of complying with the DPDP Act 2023 is engineering time — not just legal fees.

Compliance is engineering work, not just legal work.

Things like letting users give specific consent, handling deletion requests, allowing data portability, and keeping proper records all require real changes to how systems are built — not just new paperwork. The tech team would be required to make all the necessary changes according to the law, so it will be done with the legal team guidance.

Old systems make this expensive.

Modern start-ups might need 2-3 months of dedicated work to get this right. Older SaaS platforms often need much bigger changes, sometimes even a full system overhaul.

Only engineers can really fix this

No consultant can fix your database or system architecture for you. Real compliance only happens through your own team's engineering work.

Why smaller companies may struggle more than big ones

Big companies have an advantage — they have legal teams and can afford compliance software, so they can move fast. Small start-ups usually don't have either.

There's no special treatment for start-ups. The law applies the same way to everyone, and it's hard to predict when or how strictly it will be enforced — so waiting and doing nothing isn’t a safe option.

The smartest approach is to start with "privacy by design": collect only what you truly need, document your practices from day one, since you are also responsible for data handling by vendors so work with vendors who are also compliant.

Penalties Are Real, Not Just Theory

The DPDP Act creates a Data Protection Board of India to enforce the law. This isn't just a symbolic body — it can investigate complaints and impose fines of up to ₹250 crore for certain violations.

To put that in perspective, ₹250 crore is a huge amount for most mid-sized Indian companies, and it could be enough to shut down a start-up entirely.

Penalties increase depending on the violation. Failing to put in place proper security measures, leading to a data breach, can bring fines of up to ₹250 crore. Not informing the Board or affected users about a breach quickly enough carries its own separate penalty. And breaking the extra rules that apply to Significant Data Fiduciaries can bring fines up to ₹200 crore.

These numbers aren't just for show. In Europe, GDPR enforcement has led to massive fines — Meta alone was fined more than €1.2 billion by Irish regulators in 2023. If India's enforcement follows a similar path once it picks up pace, companies should expect it to be taken just as seriously.

DPDP Rules 2025 and What's Coming Next

The DPDP Act 2023 lays the foundation, but the actual details of how it works will come from the DPDP Rules 2025 — this is where things get practical.

The Rules will spell out the details: Timelines for handling user requests, how consent systems should work, rules for data transfers, and how impact assessments should be done.
Cross-border data transfer is still uncertain: the government may limit which countries Indian companies can send data to, which could affect businesses using global tools and services.
Enforcement is getting closer: Full implementation is expected around 2026–2027, so companies don't have much time left to prepare.

Also Read :- What Is Posh Act 2013

What Most Articles About the DPDP Act 2023 Miss

Most discussions about this law skip over a key issue: who is actually responsible for making it happen inside a company. People talk about the rules, but not about who owns the job of following them. Legal teams see it as a tech issue, tech teams see it as a compliance issue, and leadership sees it as a business decision — and in the end, nobody clearly owns it.

This confusion — not a lack of awareness — is the real reason data protection often fails in practice. Since only some companies are required to appoint a Data Protection Officer, many operate without one, which leads to delays and weak systems. Smart companies solve this early by clearly assigning ownership before enforcement gets stricter.

 It's a Mindset Shift, Not Just a Checklist

The DPDP Act 2023 isn't meant to be treated as a checklist. It's meant to change how companies think about handling people's data.

Go beyond box-ticking: Updating a privacy policy or adding a consent banner isn't enough. Real compliance means thinking about privacy at every stage — in every feature, every integration, every data flow.

Treat data as a responsibility, not just an asset: Collect the minimum you need, delete more than you keep, and make sure any third-party apps you use also follow the rules. This reduces risk in the long run.

Trust becomes a competitive advantage: Strong, honest data practices are becoming something users actively look for, and that's turning into a real differentiator in India's growing digital market.

How Insaaf99 Helps You Navigate the DPDP Act 2023 with Confidence

At Insaaf99, we see many businesses that are unsure how to deal with the DPDP Act 2023. That's exactly where we step in. We help you move past the confusion — whether it is writing a proper privacy policy, setting up consent systems, or figuring out how to respond to user data requests. We not only help you with draft and implementation of the policy, we also explain the new law in easy to understand language

If you're a start-up or small business, you don't need a full legal team to get started. We connect you with experts who give you practical legal guidance, not just theory. The goal is simple: help you stay compliant without overcomplicating things or draining your resources.

Conclusion

The DPDP Act 2023 isn't just a change for companies — it changes things for users, creators, and start-ups too. With this law, users get back their rights: to access their data, correct it, delete it, and withdraw consent, as long as companies actually follow through properly.

Soon, how well a company handles data will start affecting things like funding and acquisitions. Not being compliant could become a serious business risk.