Ravindra BagaleCourses & study guides

34. Indian Cyber Law and Cyber Crime Awareness

34.4 The Digital Personal Data Protection Act, 2023

The DPDP Act, 2023 is India's personal data protection law. Its rules (the DPDP Rules) are being brought into force in phases, so check the current status on meity.gov.in.

Term Meaning
Data Principal The person the data is about (you, a customer, a student)
Data Fiduciary The organisation that decides why and how data is processed (a company, an app)
Data Processor A vendor that processes data for the fiduciary (for example a cloud or payroll provider)
Consent Must be free, specific, informed and clear, with an easy way to withdraw
Data Protection Board of India The body that inquires into breaches and imposes penalties

What organisations must do, in short:

  • Collect only what is needed, for a stated purpose, and delete it when no longer needed.
  • Protect it with reasonable security safeguards (everything in Chapters 29–33).
  • Notify the Board and affected people about a personal data breach.
  • Take extra care with children's data (verifiable parental consent).
  • Respect rights of individuals: access, correction, erasure and grievance redressal.

Penalties are large: the Act allows fines of up to ₹250 crore for failing to take reasonable security safeguards (check the Schedule of the Act for each category).

Ravindra Bagale's Tip

Because of DPDP, security is no longer just an IT topic – it has become a business risk. Customer data leaking from a public S3 bucket = a big penalty. So in interviews, say that "Block Public Access" from Chapter 30 is part of legal compliance.

Practice task

For the reels app from Chapter 16, list what personal data it collects (name, email, phone, videos, IP address). For each, write the purpose, where it is stored, who can access it and when it should be deleted. Draft a two-line consent message for the sign-up page.