AMLEGALS — Strategic Lawyering
Insights & Answers

What practitioners and boards are asking

What is DPDPA 2023 and who does it apply to?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's comprehensive data privacy legislation. It applies to all entities processing digital personal data in India, and to foreign entities processing data of Indian residents under Section 3. There is no revenue or size threshold. every Data Fiduciary processing digital personal data is within scope.

What are the maximum penalties under DPDPA?

DPDPA prescribes penalties up to ₹250 Crore under Section 33 read with the Schedule. The penalty for failure to protect children's data is up to ₹200 Crore. The Data Protection Board of India determines penalties based on the nature, gravity, and duration of the breach.

What is the Vibe Data Privacy Framework by AMLEGALS?

Vibe Data Privacy™ is AMLEGALS' proprietary governance framework built from the DPDPA 2023 statutory text. It measures compliance across five operational layers. Signal (privacy frequency across consent records and data flows), Pulse (governance stance against all 44 Sections and 22 Rules), Drift (compliance entropy and deviations from baseline), Dividend (privacy ROI through trust metrics and audit readiness), and Culture (organisational privacy maturity). producing a single Board ready Vibe Pulse Score (VPS) from 0 to 100.

When will DPDPA be fully enforceable?

DPDPA received Presidential Assent in August 2023. The DPDP Rules, 2025 were notified on 21 March 2025. Full enforcement with operative penalties begins 13 May 2027. Organisations should achieve compliance before the enforcement deadline.

How does DPDPA compare to GDPR?

DPDPA and GDPR are structurally independent frameworks. Key differences: (1) DPDPA uses a negative list approach for cross border transfers under Section 16 versus GDPR's adequacy model; (2) No right to data portability under DPDPA; (3) Centralised Data Protection Board versus multiple supervisory authorities; (4) Fixed penalty amounts versus revenue percentages; (5) DPDPA applies only to digital personal data, not paper records.

What is a Significant Data Fiduciary under DPDPA?

Under Section 10, the Central Government may notify a Data Fiduciary as Significant based on volume and sensitivity of data processed, risk to Data Principals, and other prescribed factors. SDFs have enhanced obligations including mandatory DPO appointment (based in India), periodic audits by independent auditors, and Data Protection Impact Assessments.

Does DPDPA apply to foreign companies?

Yes. Section 3 of DPDPA extends its applicability to processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. This extraterritorial scope means foreign companies processing Indian residents' data must comply regardless of their physical location.

What are the DPDP Rules 2025 and when were they notified?

The Digital Personal Data Protection Rules, 2025 were notified on 21 March 2025 under Section 40 of DPDPA. They contain 22 Rules covering consent management (Rule 3), notice requirements (Rule 4), breach notification form and manner (Rule 7), children's data processing safeguards (Rule 10), Significant Data Fiduciary obligations (Rule 12), cross-border transfer procedures, and Data Protection Board constitution (Rules 16-22). Full enforcement begins 13 May 2027.

What are the consent requirements under DPDPA Section 6?

Section 6 of DPDPA requires consent that is free, specific, informed, unconditional, and unambiguous with clear affirmative action. Section 5 mandates an itemised notice before or at the time of data collection specifying the personal data to be processed and the purpose. Consent must be as easy to withdraw as to give under Section 6(6). Section 7 provides deemed consent grounds (legitimate uses) including employment purposes, public interest, and medical emergencies.

What is the data breach notification obligation under DPDPA?

Section 8(6) of DPDPA requires every Data Fiduciary to inform both the Data Protection Board of India and each affected Data Principal of a personal data breach. Rule 7 of DPDP Rules 2025 prescribes the specific form and manner of notification. The Act mandates notification without delay but does not prescribe a specific hourly time limit in the enacted statute. Failure to implement reasonable security safeguards attracting a breach carries penalties up to Rs 250 Crore under the Schedule.

How does DPDPA protect children's personal data?

Section 9 of DPDPA requires verifiable parental consent before processing any child's data (below 18 years). Data Fiduciaries must not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Rule 10 of DPDP Rules 2025 prescribes the manner of obtaining verifiable parental consent. Processing children's data that may cause detrimental effect is prohibited. Penalty for non-compliance is up to Rs 200 Crore under the Schedule.