The DPDP Act 2023 changes what companies can do with your personal data. A plain-language explainer on what it covers, what it doesn't, and why enforcement is still missing.
India's Digital Personal Data Protection Act became law in 2023. The implementing rules — the bit that decides what actually gets enforced — are still being drafted. Until they're notified, the law exists on paper but has almost no teeth.
What the law says
In the simplest terms: any company processing your personal data needs your consent to do so, must tell you what they'll use it for, must let you ask for a copy or deletion, and must report serious breaches. There are higher protections for children's data and for "significant" data fiduciaries — large platforms.
What the law does not say
The Act does not include a right to compensation for ordinary data subjects. It does not include any meaningful restriction on government processing. It does not explicitly address surveillance.
Why it still matters
For companies, the rules — when notified — will require real changes to how consent screens, audit trails, and breach disclosure work. For citizens, even an under-powered law is better than the previous patchwork. The next milestone to watch: when the Data Protection Board is staffed, the regime starts being enforced.
Edited by Kabir Singh
