The Digital Personal Data Protection (DPDPA) Act, 2023 is India’s first comprehensive law governing the protection of personal digital data. Its primary objective is to balance an individual’s right to privacy with the need for lawful data processing. The Act applies to digital personal data collected online or offline and later digitized. It introduces the concept of Data Principals (individuals) and Data Fiduciaries (entities processing data), emphasizing consent-based data processing. Consent must be free, informed, specific, and revocable.
The Act grants individuals key rights such as access to information, correction and erasure of personal data, and grievance redressal. It also outlines duties for individuals to prevent misuse of their rights. Organizations are required to implement reasonable security safeguards and report data breaches. A Data Protection Board of India is established to oversee compliance and impose penalties for violations. Overall, the DPDPA Act, 2023 strengthens India’s data governance framework and promotes responsible digital practices.
