Decode Explains

What Is the DPDP Act and Why It Matters

India’s long-pending data protection law, the parts that matter most, in plain language.

What Is the DPDP Act and Why It Matters

Photo illustration — file image. · Photo: BOOM

Editorial Note: Why read this

The DPDP Act 2023 changes what companies can do with your personal data. A plain-language explainer on what it covers, what it doesn't, and why enforcement is still missing.

India's Digital Personal Data Protection Act became law in 2023. The implementing rules — the bit that decides what actually gets enforced — are still being drafted. Until they're notified, the law exists on paper but has almost no teeth.

What the law says

In the simplest terms: any company processing your personal data needs your consent to do so, must tell you what they'll use it for, must let you ask for a copy or deletion, and must report serious breaches. There are higher protections for children's data and for "significant" data fiduciaries — large platforms.

What the law does not say

The Act does not include a right to compensation for ordinary data subjects. It does not include any meaningful restriction on government processing. It does not explicitly address surveillance.

Why it still matters

For companies, the rules — when notified — will require real changes to how consent screens, audit trails, and breach disclosure work. For citizens, even an under-powered law is better than the previous patchwork. The next milestone to watch: when the Data Protection Board is staffed, the regime starts being enforced.

Edited by Kabir Singh

About the author
Adrija Bose

Adrija covers digital rights, surveillance, and the systems that determine who gets to belong. She joined Decode after seven years at India's national press, where her reporting on the Aadhaar identity programme won the Red Ink Award for human rights journalism.