Disclaimer & Confirmation of User
As per the rules of the Bar Council of India, advocates and law firms are not permitted to solicit work or advertise. By clicking “I Agree” below, the user acknowledges and confirms that:
- there has been no advertisement, personal communication, solicitation, invitation or inducement of any kind from Anshul Dutt & Co. or its members to solicit any work through this website;
- the user wishes to gain information about the firm for his or her own information and use;
- the information is made available only at the user’s request and is for informational purposes only, and should not be construed as advertising or solicitation;
- no information on this website is to be construed as legal advice, and the firm is not liable for any action taken in reliance on it;
- nothing on this website creates a lawyer–client relationship.
IP & Technology
The Digital Personal Data Protection Act, 2023: What It Means for Businesses
Consent, data fiduciary duties, and penalties under India’s new data protection law.

This article is general information only, not legal advice, and not solicitation of work. It should not be relied upon as a substitute for advice on your specific facts.
What the DPDP Act Covers
The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India, applying to organisations, termed data fiduciaries, that determine the purpose and means of processing such data, whether they are based in India or process data of individuals in India in connection with offering goods or services here.
Consent and Notice Obligations
Processing generally requires clear, specific consent from the individual, termed the data principal, given after a notice describing what data is collected and why. Consent must be as easy to withdraw as it was to give, and certain limited processing, such as for specified legitimate uses set out in the Act, does not require consent at all.
Obligations on Businesses as Data Fiduciaries
Businesses must implement reasonable security safeguards, report data breaches to the Data Protection Board and affected individuals, and, for significant data fiduciaries as notified by the government, appoint a data protection officer and undertake periodic audits. Certain uses, particularly those involving children’s data, carry additional restrictions, including a general bar on tracking or targeted advertising directed at children.
Penalties and What Businesses Should Do Now
Non-compliance can attract significant financial penalties, running into hundreds of crores of rupees for serious breaches such as failure to implement reasonable safeguards. Businesses handling personal data are well advised to map what data they collect and why, review consent mechanisms and privacy notices, and put a breach response plan in place well before enforcement intensifies.
This note is prepared by our IP & Technology team. If you are dealing with a related situation, get in touch with us.
← Back to all Insights