Emergency Legal Support: +91 90070 00603 | Chamber: 14 Hare Street, Kolkata
PANCHANAND SHAW Advocate • Calcutta High Court
Call Now
Cyber Law July 16, 2025 8 min read

Digital Personal Data Protection Act 2023 – Complete Guide for Businesses and Individuals

Complete guide to the Digital Personal Data Protection Act 2023. Learn about data fiduciary obligations, data principal rights, consent requirements, penalties, and compliance for businesses in India.

PS

Advocate Panchanand Shaw

Practicing Advocate, Calcutta High Court | 15+ years | 14 Hare Street, Kolkata

Technology Law July 12, 2025

Complete guide to the Digital Personal Data Protection Act 2023. Learn about data fiduciary obligations, data principal rights, consent requirements, penalties, and compliance for businesses in India.

Overview of the Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection legislation, passed by Parliament in August 2023. The Act establishes a framework for the processing of digital personal data in a manner that recognizes both the right of individuals to protect their personal data and the need to process such data for lawful purposes. The Act has been hailed as a significant step towards aligning India's data protection regime with global standards like the EU's General Data Protection Regulation (GDPR).

The DPDP Act applies to the processing of digital personal data within India, where such data is collected online or collected offline and subsequently digitized. It also applies to processing outside India if it involves offering goods or services to individuals in India. This extraterritorial application is similar to the GDPR and ensures that foreign companies processing data of Indian citizens are also subject to the Act. The Act covers personal data — defined as any data about an individual who is identifiable by or in relation to such data — and does not distinguish between sensitive and non-sensitive categories of personal data, unlike the GDPR or the earlier Personal Data Protection Bill.

In Kolkata, the impact of the DPDP Act is far-reaching. From IT companies in Sector V and New Town to healthcare providers, educational institutions, e-commerce platforms, and small businesses — virtually every entity that collects, stores, or processes personal data is affected. The Act creates new rights for individuals, imposes significant obligations on data fiduciaries (entities that determine the purpose and means of data processing), and provides for penalties of up to Rs. 250 crore for non-compliance.

The Act establishes the Data Protection Board of India (DPBI) as the regulatory authority responsible for enforcement, grievance redressal, and imposition of penalties. The DPBI will have its headquarters at a place to be determined by the Central Government and will have regional offices, possibly including one in Kolkata given the city's importance as an IT and business hub.

Key Definitions Under the DPDP Act

Understanding the key definitions under the DPDP Act is essential for compliance. Here are the most important terms:

Data Principal: The individual to whom the personal data relates. In simple terms, the data principal is the person whose data is being processed. If you are a customer of a business that collects your name, phone number, email, and other details, you are the data principal. The Act also recognizes the parent or lawful guardian as the data principal for children (individuals below 18 years). A "child" is defined as an individual who has not completed the age of 18 years, which is a higher threshold than many other jurisdictions (GDPR defines a child as below 16, with member states having the option to lower it to 13).

Data Fiduciary: Any person who alone or in conjunction with others determines the purpose and means of processing of personal data. This includes companies, government bodies, partnership firms, LLPs, trusts, and any other entity that collects and processes personal data. In Kolkata, this covers a wide range of entities — from large IT companies like TCS and Cognizant in Sector V, to hospitals like AMRI and Belle Vue, to educational institutions like Jadavpur University and Presidency College, and small businesses across the city.

Data Processor: Any person who processes personal data on behalf of a data fiduciary. For example, a cloud service provider that hosts customer data for an e-commerce company, or a payroll processing company that handles employee data for an organization, would be a data processor. Data processors are not directly regulated by the Act (unlike the GDPR) but are bound by the contract with the data fiduciary. The primary responsibility for compliance rests with the data fiduciary.

Processing: A wholly or partially automated operation or set of operations performed on digital personal data. This includes collection, recording, organization, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, dissemination, restriction, erasure, or destruction of personal data. This broad definition covers virtually every activity related to personal data.

Significant Data Fiduciary: The Central Government may notify certain data fiduciaries or classes of data fiduciaries as "Significant Data Fiduciaries" based on factors such as: the volume and sensitivity of personal data processed, risk to the rights of data principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, and security of the state. Significant data fiduciaries have additional obligations, including appointing a Data Protection Officer (DPO) and an independent data auditor.

Consent Manager: A person registered with the Data Protection Board who acts as a single point of contact to enable a data principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. The concept of consent managers is innovative and unique to the Indian framework, designed to simplify consent management for individuals dealing with multiple data fiduciaries.

Have questions about this topic?

Call +91 90070 00603 for a Consultation

Rights of Data Principals (Individuals)

The DPDP Act confers several rights on data principals (individuals) to give them control over their personal data. These rights are enforceable against the data fiduciary:

Right to Information (Section 11): The data principal has the right to request information about: (a) what personal data is being processed, (b) the processing activities undertaken, (c) the identities of all data fiduciaries and data processors with whom the data has been shared, and (d) any other prescribed information. The data fiduciary must respond to such requests within the prescribed time and manner. This right enables individuals to know who has their data and how it is being used.

Right to Correction and Erasure (Section 12): The data principal has the right to request correction of inaccurate or misleading personal data, completion of incomplete personal data, and erasure of personal data. Upon receiving such a request, the data fiduciary must correct, complete, or erase the data, and must also take reasonable steps to notify all other data fiduciaries and data processors to whom the data has been disclosed about the correction or erasure. The right to erasure is subject to exceptions where retention of data is required for legal or regulatory compliance.

Right to Grievance Redressal (Section 13): The data principal has the right to readily available grievance redressal mechanisms provided by the data fiduciary or consent manager. If the data fiduciary does not respond within the prescribed period (7 days as proposed in the rules), or if the grievance is not resolved satisfactorily, the data principal can approach the Data Protection Board.

Right to Nominate (Section 14): The data principal has the right to nominate another individual who will exercise the data principal's rights in the event of the data principal's death or incapacity. This right ensures continuity in the exercise of rights and is particularly important for elderly individuals or those with serious medical conditions.

Right to Withdraw Consent (Section 6(4)): The data principal has the right to withdraw consent at any time. The withdrawal of consent must be as easy as giving consent. Upon withdrawal, the data fiduciary must cease processing the data within a reasonable time, unless the processing is required or authorized under the Act or any other law. Withdrawal of consent does not affect the legality of processing done before the withdrawal.

Right Against Automated Decision-Making: While not explicitly included as a separate right in the Act, the DPDP Act empowers the Central Government to prescribe rules regarding processing that involves risk of harm to data principals. Automated decision-making is expected to be regulated under these rules, providing some protection against decisions made solely by automated means without human intervention.

Obligations of Data Fiduciaries

Data fiduciaries bear the primary responsibility for compliance under the DPDP Act. Here are the key obligations:

Consent-Based Processing (Section 4-6): Personal data may be processed only for a lawful purpose and with the consent of the data principal. The consent must be: (a) free — given without coercion or undue influence, (b) specific — related to the specific purpose for which the data is being collected, (c) informed — the data principal must be provided with a notice containing details about the data being collected, the purpose of processing, the rights of the data principal, and the grievance redressal mechanism, and (d) unconditional — not bundled with conditions that are not necessary for the service. The request for consent must be presented in clear and plain language, and the data principal must be given the option to access the notice in English or any language specified in the Eighth Schedule of the Constitution (including Bengali for users in Kolkata and West Bengal).

Legitimate Uses (Section 7): The Act also permits processing of personal data without consent for certain "legitimate uses," including: (a) the specified purpose for which the data principal has voluntarily provided their personal data and has not indicated objection, (b) performance of any function under any law or providing any service or benefit to the data principal by the State, (c) compliance with any judgment or order of a court, (d) responding to a medical emergency involving a threat to life or immediate threat to the health of the data principal or any other individual, and (e) taking measures to provide medical treatment or health services during an epidemic or outbreak of disease.

Notice Requirement (Section 5): Before or at the time of seeking consent, the data fiduciary must give the data principal a notice containing: (a) the personal data to be collected, (b) the purpose for which it is to be processed, (c) the manner in which the data principal may exercise their rights, and (d) the manner in which the data principal may make a complaint to the Data Protection Board. The notice must be made available in clear and plain language.

Data Quality and Purpose Limitation (Section 8): The data fiduciary must ensure the completeness, accuracy, and consistency of personal data when it is likely to be used to make a decision that affects the data principal, or when the data is likely to be disclosed to another data fiduciary. Personal data must not be retained beyond the purpose for which it was collected, and must be deleted once the purpose is fulfilled, unless retention is required under any law.

Security Safeguards (Section 9): The data fiduciary must implement reasonable security safeguards to prevent personal data breaches. This includes taking appropriate technical and organizational measures. In the event of a personal data breach, the data fiduciary must notify the Data Protection Board and each affected data principal in the prescribed form and manner. The rules are expected to specify a timeline (likely 72 hours) for breach notification, similar to the GDPR.

Additional Obligations for Significant Data Fiduciaries (Section 10): Significant data fiduciaries must: (a) appoint a Data Protection Officer (DPO) based in India, who will represent the significant data fiduciary and be responsible for compliance, (b) appoint an independent data auditor to evaluate compliance with the Act, and (c) undertake Data Protection Impact Assessments (DPIAs) and periodic audits as prescribed.

Have questions about this topic?

Call +91 90070 00603 for a Consultation

Penalties and Enforcement Mechanism

The DPDP Act establishes a robust enforcement mechanism with substantial penalties for non-compliance:

Data Protection Board of India (DPBI): The Central Government will establish the DPBI, which will function as an independent regulatory body. The Board will have the power to: (a) inquire into complaints from data principals regarding violations of the Act, (b) inquire into personal data breaches reported by data fiduciaries, (c) issue directions to data fiduciaries, (d) impose financial penalties, and (e) refer complaints to alternative dispute resolution mechanisms. The Board will be composed of a Chairperson and members appointed by the Central Government, and will have the power to summon witnesses, receive evidence, and conduct proceedings.

Penalties (Schedule): The Act prescribes specific penalties for different violations: (a) breach of obligations regarding processing of children's data — up to Rs. 200 crore, (b) failure to take reasonable security safeguards to prevent personal data breach — up to Rs. 250 crore, (c) failure to notify the Board and affected data principals about a personal data breach — up to Rs. 200 crore, (d) non-fulfillment of additional obligations by significant data fiduciaries — up to Rs. 150 crore, (e) non-compliance with duties by data principals — up to Rs. 10,000 per violation, (f) breach of any other provision of the Act or rules — up to Rs. 50 crore. The total penalty cannot exceed Rs. 500 crore for each "significant contravention." The Board has the discretion to determine the quantum of penalty considering factors such as the nature, gravity, and duration of the breach, and whether the breach was intentional or negligent.

Appeal Mechanism: Any person aggrieved by an order of the DPBI can file an appeal before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days. Further appeals lie before the Supreme Court. The TDSAT has the power to hear appeals on questions of fact and law, providing a robust judicial review mechanism.

Voluntary Undertaking: The DPBI may accept a voluntary undertaking from a data fiduciary at any stage of the proceedings. A voluntary undertaking is a commitment by the data fiduciary to take specified actions to remedy the contravention. If the Board accepts the undertaking and the data fiduciary complies, the Board cannot impose further penalties for the same contravention.

Steps for Businesses in Kolkata to Comply with the DPDP Act

Compliance with the DPDP Act requires a systematic approach. Here is a step-by-step plan for businesses in Kolkata:

Step 1: Data Mapping and Audit. Identify all personal data that your organization collects, stores, processes, and shares. Map the data flows — where does the data come from, where is it stored, what processing happens, and with whom is it shared. This includes customer data, employee data, vendor data, and data from website visitors and app users. In Kolkata, businesses should pay particular attention to paper-based data that is digitized (customer forms, job applications, medical records), as the Act applies to data collected offline but digitized.

Step 2: Review and Update Privacy Notices. Prepare or update your privacy notice to comply with the requirements of Section 5 of the Act. The notice must be clear, concise, and available in English and the local language (Bengali, for businesses serving Kolkata and West Bengal). The notice must be provided before or at the time of seeking consent.

Step 3: Implement Consent Mechanisms. Design and implement consent mechanisms that are compliant with the Act. Consent forms (online or physical) must be free, specific, informed, and unconditional. Implement a mechanism for data principals to withdraw consent as easily as they gave it. For businesses that serve customers in Kolkata through websites and mobile apps, the consent mechanism must be integrated into the user interface.

Step 4: Strengthen Data Security. Review and upgrade data security measures. Implement technical measures such as encryption, access controls, firewalls, intrusion detection systems, and regular security audits. Implement organizational measures such as data protection policies, employee training, and incident response plans. The data security measures should be proportionate to the nature and volume of personal data processed.

Step 5: Appoint a Data Protection Officer (DPO). If your organization is or is likely to be designated as a significant data fiduciary, appoint a DPO based in India. Even if not mandatory, having a designated person responsible for data protection is a good practice. The DPO should have expertise in data protection law and should report directly to the board or top management.

Step 6: Prepare Breach Response Plans. Develop and document a personal data breach response plan. The plan should include procedures for detecting, investigating, containing, and reporting breaches. Identify the key individuals responsible for breach response and establish communication channels with the Data Protection Board and affected data principals.

Step 7: Review Contracts with Data Processors. Review and update contracts with data processors (cloud service providers, IT vendors, payroll processors, marketing agencies) to include data protection obligations. While the DPDP Act does not directly regulate data processors, the data fiduciary is responsible for ensuring that the data processor complies with the Act through contractual obligations.

Frequently Asked Questions

When will the DPDP Act come into full force in India?
The DPDP Act was passed by Parliament and received Presidential assent in August 2023. However, the Act will come into force on dates notified by the Central Government, and different provisions may be notified on different dates. The rules under the Act are currently being drafted, and the Data Protection Board is yet to be established. Businesses should monitor notifications and be prepared to comply within the transition period (likely 12-18 months from notification).
Does the DPDP Act apply to small businesses in Kolkata?
Yes, the DPDP Act applies to all data fiduciaries regardless of size, with a few exceptions for startups and small businesses that may be notified by the government. Unlike the GDPR, which has exemptions for small-scale processing, the DPDP Act does not have a blanket exemption based on the number of employees or revenue. However, the obligations of small businesses may be less onerous in practice, and the rules may provide some relaxations.
What is the penalty for non-compliance with the DPDP Act?
Penalties range from Rs. 50 crore to Rs. 250 crore depending on the nature of the violation, with a maximum of Rs. 500 crore for each significant contravention. The Data Protection Board has the discretion to determine the quantum of penalty based on factors such as the nature, gravity, and duration of the breach.
Can individuals sue companies for violation of their data privacy rights?
The DPDP Act does not create a private right of action (i.e., individuals cannot directly sue data fiduciaries for damages). However, individuals can file complaints with the Data Protection Board, which can investigate and impose penalties. Civil suits under the common law of torts for breach of privacy or negligence may still be possible, and a class action may be filed under the Code of Civil Procedure.
How does the DPDP Act protect children's data?
The Act provides enhanced protection for children (individuals below 18 years). Data fiduciaries must obtain verifiable parental consent before processing the personal data of a child. They must not engage in tracking, behavioral monitoring, or targeted advertising directed at children. Processing that is likely to cause any detrimental effect on the well-being of a child is prohibited.
PS

Advocate Panchanand Shaw

Practicing Advocate, Calcutta High Court

With a distinguished career spanning decades in the legal profession, Advocate Panchanand Shaw leads Panchanand & Associates, a premier law firm based at 14 Hare Street, Kolkata 700001. Our firm handles a comprehensive range of legal matters including civil litigation, criminal defense, family law, property disputes, corporate law, and more. We are committed to providing accessible, transparent, and result-oriented legal services to clients across West Bengal and beyond.

Calcutta High Court Supreme Court of India Sessions Court Family Court NCLT / NCLAT

Need Legal Assistance?

Contact Advocate Panchanand Shaw for expert legal guidance. With decades of experience practicing at Calcutta High Court, we provide dedicated representation tailored to your case.

Related Articles

Need Legal Assistance in Kolkata?

Advocate Panchanand Shaw specializes in legal matters at the Calcutta High Court and all Kolkata courts. Get professional legal counsel from an experienced advocate with 15+ years of practice.

Need urgent legal advice? Chat with us!