Introduction

In today's digital world, individuals regularly share personal information while using websites, mobile apps, social media platforms, online banking, e-commerce services, and government portals. To protect personal data and ensure responsible data handling, India enacted the Digital Personal Data Protection Act, 2023 (DPDP Act).

The DPDP Act establishes a legal framework for the collection, processing, storage, and use of digital personal data. It also grants individuals certain rights over their personal information while imposing obligations on organizations that process such data.

This guide explains the key features of the DPDP Act, the rights available to individuals, the responsibilities of organizations, and how individuals can seek redress if their rights are violated.

What is the DPDP Act, 2023?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's primary legislation governing the processing of digital personal data.

The Act aims to:

  • Protect individuals' personal data.

  • Promote responsible data processing.

  • Ensure transparency and accountability.

  • Provide individuals with enforceable privacy rights.

  • Create a legal framework for handling digital personal information.

What is Personal Data?

Under the DPDP Act, personal data generally means any data about an individual who can be identified by or in relation to that data.

Examples include:

  • Name.

  • Mobile number.

  • Email address.

  • Aadhaar number (where applicable).

  • PAN details.

  • Date of birth.

  • Address.

  • Biometric information.

  • Financial information.

  • IP address and certain online identifiers.

  • Photographs and digital records.

Who Does the DPDP Act Apply To?

The Act generally applies to organizations and persons processing digital personal data, including:

  • Private companies.

  • Startups.

  • E-commerce platforms.

  • Banks and financial institutions.

  • Healthcare providers.

  • Educational institutions.

  • Government bodies (subject to the provisions of the Act).

  • Digital service providers.

Its applicability depends on the circumstances and the provisions of the Act.

Rights of Individuals Under the DPDP Act

The Act provides several important rights to individuals, including:

  • Right to access information about personal data being processed.

  • Right to correct inaccurate or incomplete personal data.

  • Right to update personal information.

  • Right to erase personal data in certain circumstances.

  • Right to withdraw consent where processing is based on consent.

  • Right to grievance redressal.

  • Right to nominate another person to exercise rights in specified situations, as provided under the Act.

These rights are subject to the conditions and limitations prescribed by law.

Responsibilities of Organizations

Organizations processing personal data are generally required to:

  • Process personal data lawfully.

  • Obtain valid consent where required.

  • Use personal data only for lawful purposes.

  • Protect personal data with appropriate security measures.

  • Maintain transparency regarding data processing.

  • Respond to data-related requests.

  • Report certain personal data breaches as required under the Act.

What is Consent Under the DPDP Act?

Consent is an important basis for processing personal data under the Act.

Consent should generally be:

  • Free.

  • Specific.

  • Informed.

  • Unambiguous.

  • Given through a clear affirmative action.

Individuals also have the right to withdraw consent in accordance with the provisions of the Act.

What is a Personal Data Breach?

A personal data breach refers to an unauthorized or accidental event that compromises the confidentiality, integrity, or availability of personal data.

Examples include:

  • Unauthorized access.

  • Data leaks.

  • Hacking incidents.

  • Identity theft.

  • Accidental disclosure.

  • Loss of digital records.

Organizations are required to take appropriate action in accordance with the DPDP Act when a data breach occurs.

What to Do if Your Privacy Rights Are Violated

Step 1: Contact the Organization

Request clarification regarding:

  • What personal data is being processed.

  • Why it is being processed.

  • Correction or deletion of incorrect information, where applicable.

Step 2: Submit a Grievance

Use the organization's grievance redressal mechanism and retain a copy of your complaint.

Step 3: Preserve Evidence

Keep copies of:

  • Emails.

  • Screenshots.

  • Privacy policy.

  • Data requests.

  • Responses received.

  • Any relevant communications.

Step 4: Escalate the Matter

If the grievance remains unresolved, individuals may seek further remedies in accordance with the DPDP Act and applicable legal procedures.

Documents That May Be Required

Depending on the issue, you may need:

  • Identity proof.

  • Contact details.

  • Copies of communications.

  • Screenshots.

  • Emails.

  • Account details.

  • Privacy policy references.

  • Complaint acknowledgments.

  • Any other supporting documents.

Common Mistakes to Avoid

  • Sharing personal information with unverified websites.

  • Ignoring privacy notices.

  • Reusing weak passwords.

  • Not enabling two-factor authentication.

  • Clicking suspicious links.

  • Failing to report suspected data breaches promptly.

Tips to Protect Your Personal Data

  • Use strong and unique passwords.

  • Enable multi-factor authentication.

  • Regularly update your devices and applications.

  • Review app permissions before granting access.

  • Avoid sharing sensitive information unnecessarily.

  • Monitor your online accounts for suspicious activity.

  • Read privacy policies before using digital services.

RightToLaw Team
Written by

RightToLaw Team

Legal Research Team

RightToLaw Legal Research Team is a dedicated group of legal researchers, advocates, and content specialists committed to making Indian law accessible and easy to understand. With extensive experience in legal research and statutory interpretation, the team creates accurate, well-researched, and…

View all articles by RightToLaw Team →

Frequently Asked Questions

The Digital Personal Data Protection Act, 2023 is India's law governing the processing and protection of digital personal data.

Personal data is information relating to an identifiable individual, such as a name, mobile number, email address, or financial details.

Individuals have rights relating to access, correction, updating, erasure of personal data in certain cases, withdrawal of consent, grievance redressal, and nomination, subject to the Act.

Yes. Individuals generally have the right to request correction or updating of inaccurate or incomplete personal data, subject to the Act.

Contact the organization, use its grievance mechanism, preserve evidence, and pursue available remedies under the DPDP Act if necessary.

Yes. Where processing is based on consent, individuals generally have the right to withdraw that consent in accordance with the Act.

A data breach is an unauthorized or accidental event that compromises the security, confidentiality, integrity, or availability of personal data.

Yes. The Act generally applies to organizations processing digital personal data, including many private entities, subject to its provisions.

Organizations should adopt appropriate security measures, process data lawfully, maintain transparency, and comply with the obligations prescribed by the DPDP Act.

Yes. If your privacy rights have been significantly affected or your grievance remains unresolved, consulting a qualified legal professional is advisable.