DPDP Act 2023
The Digital Personal Data Protection Act, 2023 is India’s principal data protection statute, governing how organisations collect, process and store the digital personal data of individuals in India.
In plain English
The Act is built around consent and purpose limitation. It defines the entity determining the purpose and means of processing as the Data Fiduciary, and the individual as the Data Principal. It requires clear notice, lawful grounds for processing, reasonable security safeguards, breach notification, and grants individuals rights of access, correction and erasure. Significant Data Fiduciaries carry additional obligations including appointing a Data Protection Officer.
Why it matters
The Act applies to essentially any organisation processing digital personal data in India, and to processing outside India connected with offering goods or services to individuals in India. Contractual data-protection clauses drafted against GDPR alone will not map cleanly onto its requirements.
Example
A SaaS company serving Indian customers must be able to show a lawful basis for each processing activity, provide notice in clear language, honour correction and erasure requests, and have a breach response process — regardless of where its servers sit.
Under Indian law
The Act received Presidential assent in August 2023. Its provisions are being brought into force alongside subordinate rules, so organisations should confirm the current commencement and compliance timelines rather than assuming the whole Act is already fully operative.
How LexVio handles it
LexVio is built with DPDP Act 2023 in mind — AES-256 encryption at rest, TLS 1.3 in transit, and no training on customer data.
LegalTech & Compliance AICommon questions
Who does the DPDP Act 2023 apply to?
It applies to processing of digital personal data within India, and to processing outside India where it is connected with offering goods or services to individuals in India.
Is the DPDP Act the same as GDPR?
No. They share concepts such as consent, purpose limitation and data subject rights, but differ in terminology, in the grounds for lawful processing, and in enforcement structure. Compliance mapping between them is not one-to-one.
What is a Significant Data Fiduciary?
A Data Fiduciary or class of Data Fiduciaries notified by the Central Government based on factors such as volume and sensitivity of data processed and risk to Data Principals. They carry additional obligations, including appointing a Data Protection Officer.
