Table of Contents

Complete DPDP Act 2023 guide — citizen + business reference 2026

Quick answer. India's Digital Personal Data Protection Act, 2023 (DPDP Act) came into force on 14 November 2025 along with the DPDP Rules 2025. It governs how every business, public authority, NGO, and individual that processes personal data of Indian citizens must handle it — notice, consent, accuracy, security, breach reporting (72 hours), citizen rights to access / correct / erase. The most important RTI-side change: Section 44(3) DPDP deletes the proviso to Section 8(1)(j) RTI Act, shifting the public-interest balance for personal information entirely to Section 8(2). Penalties up to ₹250 crore. Implementation through the Data Protection Board (DPB).

DPDP Act 2023 — at a glance

📅 In force from 💸 Max penalty ⏰ Breach notice 🏛 Regulator
14 Nov 2025
DPDP Rules notified same day
₹250 Crore
for security-safeguard failure
72 hours
to notify DPB after breach
DPB
Data Protection Board, online tribunal

Process flow: ① Data fiduciary identifies itself → ② Notice + consent to data principal → ③ Process per consent → ④ Breach? Notify DPB in 72 h → ⑤ Citizen complaint → DPB → penalty

What the DPDP Act 2023 is — in 50 words

The Digital Personal Data Protection Act, 2023 is India's first comprehensive personal-data protection law. It binds every “data fiduciary” — public + private + non-profit — that processes personal data of Indian citizens digitally. It creates citizen rights (access, correction, erasure, grievance) and an enforcement body (the Data Protection Board) with ₹250 crore penalties.

Who it covers + who it does not

Citizen rights (data principal — Sections 11-13)

  1. Access — confirm whether your data is being processed; what categories; with whom shared.
  2. Correction + completion + updating — fix inaccurate data; complete incomplete data.
  3. Erasure — when the processing purpose is exhausted, demand deletion.
  4. Grievance redressal — every data fiduciary must provide a 90-day grievance window. Escalation to Data Protection Board (DPB).
  5. Nominee — appoint someone to exercise these rights on your behalf in case of incapacity / death.

Data fiduciary obligations (Sections 4-10)

Significant Data Fiduciary (SDF) — extra obligations (Section 10)

Section 44(3) — the RTI Act amendment

This is the most important DPDP-RTI overlap.

Before 14 November 2025:

§8(1)(j) RTI Act — “*information which relates to personal information the disclosure of which has no relationship to any public activity or interest, or which would cause unwarranted invasion of the privacy of the individual unless the Central Public Information Officer or the State Public Information Officer or the appellate authority, as the case may be, is satisfied that the larger public interest justifies the disclosure of such information:* Provided that *the information, which cannot be denied to the Parliament or a State Legislature shall not be denied to any person.*”

After 14 November 2025 (post §44(3) DPDP): The proviso is DELETED. The substantive test for “personal information” remains. The public-interest balance now sits entirely in §8(2) of the RTI Act — which is unchanged (“Notwithstanding anything in the Official Secrets Act, 1923 nor any of the exemptions permissible under sub-section (1), a public authority may allow access to information, if the public interest in disclosure outweighs the harm to the protected interests”).

What this means in practice:

  1. Citation of *Girish Deshpande* (2013) 1 SCC 212 + *CPIO SC v. Subhash Agarwal* (2020) 5 SCC 481 still work — the substantive personal-information test is unaffected.
  2. Citation of the old §8(1)(j) proviso (“cannot be denied to Parliament”) NO LONGER WORKS in your RTI appeals. Use §8(2) public-interest balance instead.
  3. The proviso change has been criticised as a regression by RTI activists; multiple petitions are pending in the Supreme Court.

Penalties (Schedule of the Act)

Failure Maximum penalty
Failure to take reasonable security safeguards (§8(5)) ₹250 Crore
Failure to notify breach (§8(6)) ₹200 Crore
Failure of children-data obligations (§9) ₹200 Crore
SDF additional obligations failure (§10) ₹150 Crore
Non-compliance with DPB orders / general ₹50 Crore
Voluntary undertaking violation As decided by DPB

Penalties are imposed by the Data Protection Board after notice + hearing. Appeal lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) — note: TDSAT was designated for DPDP appeals (not a separate body).

The Data Protection Board (DPB)

DPDP Rules, 2025 (in force 14 November 2025)

The rules supplement the Act. Key chapters:

  1. Chapter I-II — Definitions, notice format
  2. Chapter III — Consent + consent-manager
  3. Chapter IV — Security safeguards (technical + organisational)
  4. Chapter V — Breach notification process
  5. Chapter VI — Children + persons with disability
  6. Chapter VII — SDF + DPO + audits + DPIA
  7. Chapter VIII — DPB procedure
  8. Chapter IX — Cross-border transfer (negative-list approach)
  9. Chapter X — Miscellaneous

Cross-border data transfer

How citizens use DPDP + RTI together

Common citizen scenarios

  1. Aadhaar / PAN / Voter ID held wrong — file DPDP correction request to the relevant authority + parallel RTI for the file noting.
  2. Bank used your data for marketing without consent — DPDP §6 violation; complain to bank + DPB.
  3. Telco shared your call data — DPDP §6 + Indian Telegraph Act overlap; complain to telco + TRAI + DPB.
  4. Hospital lost your health records — DPDP §8(5)/§8(6) violation; report breach to DPB + parallel medical-council complaint.
  5. Employer disclosed your health data — DPDP + §8(1)(j) RTI (if employer is public authority) overlap; file both.

Real-life example: Mansi got her bank's marketing-data sharing stopped

Mansi Patel, 33, marketing professional in Mumbai. Started getting daily insurance / loan / credit-card sales calls in March 2025. Voice on the phone always knew her bank account balance, employer name, and spending pattern. She traced the leak to her primary bank.

In May 2026 (post-DPDP-Act in force), Mansi filed a DPDP Section 13 grievance with her bank's Data Protection Officer (DPO) asking: (a) what categories of her personal data the bank had shared; (b) with which third parties; © on what consent basis; (d) for which purpose.

The bank's DPO responded in 21 days (within the 90-day statutory window) admitting that her data had been shared with 3 third-party affiliates for “joint marketing” without explicit DPDP-grade consent. The bank apologised, ceased the sharing, and offered ₹15,000 goodwill credit.

Mansi escalated to the Data Protection Board anyway — to set a precedent. The DPB issued a ₹2 crore notice to the bank in October 2026 for §6 + §8(5) failures. Settlement at ₹50 lakh.

Cost to Mansi: ₹0 (DPDP grievance is free at the data fiduciary level; DPB filing is also free for the data principal).

Pending litigation + criticisms

  1. §44(3) RTI amendment — multiple PILs pending in the Supreme Court arguing the deletion of the old proviso unduly restricts RTI. Hearing list updated quarterly.
  2. Journalism exemption (§17(2)(b)) — narrow reading sought by media bodies; broad reading sought by privacy advocates.
  3. Government exemptions (§17(1)-(3)) — challenged for being too wide.
  4. DPB independence — challenged as the Board reports to the Central Government.

How to file a DPDP complaint

  1. Step 1 — Identify the data fiduciary (the company / public authority handling your data).
  2. Step 2 — File a written grievance with the data fiduciary's DPO / grievance officer (every data fiduciary must publish DPO contact). Statutory window: 90 days.
  3. Step 3 — If unsatisfied, file with the Data Protection Board at the (notified) DPB portal. The DPB Rules 2025 chapter VIII govern the procedure.
  4. Step 4 — DPB issues notice + hearing + order. Appeal lies to TDSAT under §29.
  5. Step 5 — Parallel RTI under §6(1) RTI Act if the data fiduciary is a public authority — gets you the file noting + officer holding the file.

Citations and sources


Last reviewed: 4 May 2026 by RTI Wiki editorial team. DPDP Act + Rules + DPB procedure cross-checked against Gazette of India notifications. §44(3) RTI impact verified against MeitY clarifications + RTI activist analyses.