DPDP Act Explained: What India's Data Privacy Law Means for You
India's DPDP Act gives you rights over your personal data. Here is what data fiduciaries and consent managers actually mean for you.
Every time you tap "I agree" on an app's terms and conditions, you're handing over a small slice of yourself — your phone number, your location, sometimes your spending habits. For years, Indian law barely governed what companies could do with that data once they had it. That changed with the Digital Personal Data Protection Act, or DPDP Act, and most people using the internet in India still don't really know what it does for them.
What the DPDP Act actually covers
The DPDP Act is India's first dedicated data privacy law, passed by Parliament in 2023, with the detailed rules that make it enforceable notified through 2025 and 2026. At its core, it sets rules for anyone who collects or processes "personal data" — anything that can identify you, like your name, phone number, email, or biometric details — when that processing happens digitally, or starts on paper and gets digitised later.
The law splits the internet into a few roles. You, the person whose data is being collected, are the data principal. The company or app collecting it — a bank, an e-commerce site, a food delivery app — is the data fiduciary, because it's legally treated as holding your data in trust, not owning it outright. There's also a new type of intermediary called a consent manager, essentially a registered platform that lets you view, give, and withdraw consent for multiple apps from one dashboard, instead of digging through separate settings pages everywhere.
What rights you actually get
This is the part that matters day to day. Under the Act, you can ask a company what personal data it holds on you, get it corrected if it's wrong, and ask for it to be erased once it's no longer needed for the purpose you gave it for. Companies also have to tell you, in clear language rather than legal jargon, exactly what they're collecting and why, before you consent — not buried in a 40-page policy you'll never open.
- Right to access: ask what personal data a company holds about you and how it's being used.
- Right to correction and erasure: fix inaccurate data or request deletion once its purpose is served.
- Right to grievance redressal: file a complaint with the company first, and escalate to the Data Protection Board of India if it's not resolved.
- Right to nominate: name someone who can exercise these rights on your behalf if you die or become incapacitated.
Children's data gets extra protection — platforms need verifiable parental consent before processing data belonging to anyone under 18, and they're barred from behavioural tracking or targeted ads aimed at kids.
The Act doesn't ask companies to stop collecting data. It asks them to justify why they're holding it, and to let go of it when the reason runs out.
Why this matters more in India than it sounds
India has more internet users than any country except China, and a huge share of them came online through a low-cost smartphone and cheap mobile data rather than a desktop with a firewall and antivirus habit built over decades. That means the DPDP Act isn't just catching up to Europe's GDPR — it's arguably more consequential here, because it's the first real legal backstop for hundreds of millions of first-time digital users who've never had one. For Indian startups and app developers, it also changes the compliance calculus: significant data fiduciaries (bigger platforms handling large volumes of sensitive data) now need a data protection officer and regular audits, while penalties for serious breaches can run into hundreds of crores, enforced by the Data Protection Board rather than a civil court.
If you've ever wondered how apps decide what to ask permission for the moment you install them, that consent flow is where DPDP is meant to bite hardest — worth reading alongside our explainer on how passkeys are replacing passwords, since both are really about who controls access to your identity online.
What you should actually do about it
None of this works unless people use it. A few habits make the law useful in practice rather than theoretical:
- Read what permissions an app asks for at install time — location and contacts access for a calculator app is a red flag, not a formality.
- Use a consent manager or an app's own privacy dashboard, once available, to see which services actually hold your data.
- If a company won't tell you why it needs a piece of information, that's grounds to ask for correction or deletion once your business with them is done.
The DPDP Act won't stop every data breach or dodgy telemarketer overnight — enforcement takes years to mature, and awareness takes even longer. But for the first time, there's a legal answer to "who's responsible for my data once I hand it over," and that's worth knowing whether you're a first-time smartphone user or someone who's been online for twenty years.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0