personal Data
Any data about an individual who is identifiable by or in relation to such data (s.2(t)). Includes name, address, email, phone, IP address, device ID.
A practical Act-level starting point for Indian startups handling personal data.
Assent: 11 August 2023
Enacted; DPDP Rules 2025 notified 13 Nov 2025 — obligations commence in phases (consent-manager registration, breach timelines and SDF criteria per the Rules schedule)
DPDP Rules 2025 were notified on 13 Nov 2025 with phased commencement dates. Confirm on the MeitY website WHICH obligations are in force on the date of advice — several tranches commence 12-18 months after notification.
Any data about an individual who is identifiable by or in relation to such data (s.2(t)). Includes name, address, email, phone, IP address, device ID.
Any person who alone or in conjunction with other persons determines the purpose and means of processing personal data (s.2(i)). Includes any startup or company collecting user data.
Any person who processes personal data on behalf of a Data Fiduciary (s.2(j)). E.g., cloud provider, analytics vendor.
The individual to whom the personal data relates (s.2(k)). The user/customer.
A body registered with the Data Protection Board that enables individuals to give, manage, review and withdraw consent (s.2(e)).
Whether 'sensitive personal data' as a distinct category remains under DPDP Act 2023 — the Act does NOT separately define sensitive personal data unlike earlier PDPB drafts. All personal data is treated uniformly. Only children's data gets heightened protection. Confirm with counsel whether this is still the position in the notified Rules.
DPDP Rules 2025 notified 13 Nov 2025 (phased commencement). Verify which retention periods, breach timelines (72-hour Board notification per the Rules) and consent-manager requirements are in force on the advice date.
Statutory basis: Digital Personal Data Protection Act 2023 (ss.2, 4-16, 33 r/w the Schedule) + DPDP Rules 2025 (notified 13 Nov 2025, phased commencement)
Common questions
Under s.5 of the Digital Personal Data Protection Act 2023, a data fiduciary must give the data principal a notice before or at the time of collecting personal data, stating the purpose, the data being collected, and the rights of the principal. The notice must be in clear and plain language and available in the languages of the Constitution (the DPDP Rules prescribe the notice format — check the notified text).
Consent under s.6 of the DPDP Act 2023 must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action — pre-ticked boxes do not count. The data principal must be able to withdraw consent as easily as it was given. Section 7 recognises deemed consent for specified purposes like employment and public services (see the notified DPDP Rules for the final list).
Section 8 of the DPDP Act 2023 gives the data principal the right to access and obtain a summary of their personal data, the right to correction and erasure, and the right to grievance redressal through the data fiduciary's grievance officer. These rights flow through the whole lifecycle of the data — a startup's privacy stack must be able to honour them on request.
Section 9 of the DPDP Act 2023 requires verifiable parental consent before processing a child's personal data (a child is under 18), and prohibits tracking or behavioural advertising directed at children. The parent's consent must be verifiable through a mechanism the Board prescribes (the notified DPDP Rules specify the mechanism).
Penalties under the DPDP Act 2023 run from ₹10,000 for breach of a data principal's duties up to ₹250 crore for failing to take reasonable security safeguards — all imposed under s.33 read with the Schedule to the Act. Startups below the significant-fiduciary threshold are still liable, which is why the checklist in this tool matters.