{"id":6740,"date":"2025-07-17T05:54:00","date_gmt":"2025-07-17T10:54:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=6740"},"modified":"2025-12-09T13:11:50","modified_gmt":"2025-12-09T19:11:50","slug":"indias-digital-personal-data-protection-act-dpdpa","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/","title":{"rendered":"India\u2019s Digital Personal Data Protection Act (DPDPA)"},"content":{"rendered":"\t\t<section id=\"block_fb6d4d51148d69b553b4b73a8d1d2ad1\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">article<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>India\u2019s Digital Personal Data Protection Act (DPDPA)<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_9da49737839aa0ebfbcc73fea1df7e51\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<a href=\"https:\/\/trustarc.com\/people\/aakanksha-tewari\/\">\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/08\/Aakanksha-Tewari-people.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Aakanksha Tewari<\/strong>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"block position\">Privacy Knowledge Researcher, Ph.D., Cybersecurity<\/span>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/a>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>Key principles, consent rules, and organizational readiness<\/h2>\n<p>On November 13, 2025, the Ministry of Electronics and Information Technology notified the <a href=\"https:\/\/www.meity.gov.in\/documents\/act-and-policies\/digital-personal-data-protection-rules-2025-gDOxUjMtQWa?pageTitle=Digital-Personal-Data-Protection-Rules-2025\" target=\"_blank\" rel=\"noopener\">Digital Personal Data Protection Rules 2025 (Rules)<\/a>, clarifying key implementation aspects of the <a href=\"https:\/\/www.meity.gov.in\/static\/uploads\/2024\/06\/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf\" target=\"_blank\" rel=\"noopener\">Digital Personal Data Protection Act (DPDPA) 2023<\/a>, marking a significant milestone in the rollout of India&#8217;s first comprehensive data protection law.<\/p>\n<p>India\u2019s landmark DPDPA\u00a0was enacted on August 11, 2023, to regulate the processing of all digital personal data (data collected in digital form, or later digitized) of India\u2019s residents, the DPDPA applies to any entity (data fiduciary) that determines the purpose and means of processing such data.<\/p>\n<p>Its extraterritorial scope is broad, and covers processing within India and processing abroad connected with offering goods or services to individuals in India. The Act introduces consent-based processing, individual rights, and regulatory mechanisms, elements familiar in global privacy laws, tailored to India\u2019s context.<\/p>\n<p>The Rules will take effect in phases. Certain provisions, such as those creating the Data Protection Board (Board), became effective as soon as they were published in the Official Gazette. Rules governing the registration and operation of consent managers will apply after 12 months, while all remaining regulations will come into force after 18 months.<\/p>\n<p>Stakeholders are advised to start preparing now. The law promises robust penalties (up to INR500\u202fmillion- 2.5\u202fbillion, approx. US$6-30\u202fmillion) for noncompliance and represents an urgent mandate to integrate privacy into business operations.<\/p>\n<h2>Who\u2019s covered under India\u2019s DPDPA? Scope, key terms, and processing principles explained<\/h2>\n<p>While the DPDPA introduces foundational data protection principles, it lacks the concept of \u201cspecial categories of data\u201d like the GDPR\u2019s sensitive personal data (e.g., health, biometric, sexual orientation). All personal data is treated uniformly; notably, any data made publicly available by the individual or required to be made public by law is wholly outside the law\u2019s scope. <strong>This is broader than exemptions in many laws<\/strong> and means scraped social-media or directory data may escape the law if already \u201cpublic,\u201d though legal questions remain if such data ceases to be public after collection.<\/p>\n<p>A <em>data fiduciary,<\/em> analogous to a GDPR controller, \u201cdetermines the purposes and means\u201d of processing, and bears the burden of compliance. By contrast, data processors (acting under a fiduciary\u2019s instructions) have no direct obligations under the DPDPA; instead, fiduciaries must contractually bind processors to protect data.<\/p>\n<p>Thus, unlike GDPR or CCPA, which impose some duties on processors, DPDPA focuses enforcement on the fiduciaries, who must, in turn, hold their vendors accountable.<\/p>\n<p>The DPDPA codifies the standard fair-information principles. All processing must be lawful, fair, transparent, purpose-specific, and minimally invasive. Personal data must be collected only for clear purposes and not retained longer than needed. Data fiduciaries must implement strong security safeguards (technical and organizational) to prevent breaches and maintain records demonstrating compliance.<\/p>\n<h2>DPDPA consent requirements: Lawful basis for processing personal data in India<\/h2>\n<p>A consent-oriented regime is at the core of the DPDPA, as it demands \u201cfree, specific, informed, unconditional and unambiguous\u201d consent from individuals (data principals) before processing their personal data. Consent must be an affirmative act; pre-checked boxes or implied agreements are prohibited.<\/p>\n<p>The Rules require very specific consent, where each piece of personal data must be clearly linked to the exact purpose for which it is used. Businesses handling large, varied data must rethink how they present this information and whether related purposes can be grouped together. Companies will need to redesign consent flows and user interfaces so that purposes are clearly stated and opting out is simple. Uniquely, the Rules also mandate providing a website or app link for opt-outs, unlike most countries that only require a contact point.<\/p>\n<p>Additionally, consent is the primary lawful basis for processing. The DPDPA does not recognize many of the non-consent bases familiar to European law.<\/p>\n<p>Aside from consent, the Act allows only a narrow list of \u201clegitimate uses\u201d (specific statutory or emergency purposes) without consent. These include situations where data is voluntarily shared and not objected to by the individual, compliance with court orders or law, employment necessities, and responses to natural disasters or epidemics.<\/p>\n<p>No general legitimate interest or contract necessity grounds exist as in the GDPR. This consent-centric approach will challenge many organizations: in contexts like AI model training or large-scale analytics, it may be impractical to obtain individualized consent.<\/p>\n<h2>Data principle rights under India\u2019s DPDPA: Access, correction, deletion, and redress<\/h2>\n<p>The DPDPA grants <a href=\"https:\/\/trustarc.com\/resource\/understanding-individual-rights\/\" target=\"_blank\" rel=\"noopener\">individuals rights<\/a> largely similar to those in GDPR, but with some country-specific enhancements. Data principals can access, correct, or erase their data held by a fiduciary, and they may receive a copy of their information. The law also mandates notice; organizations must provide clear privacy policies and notices about how data is processed and protected.<\/p>\n<p>Importantly, <strong>the law adds some unique rights:<\/strong> every data fiduciary must maintain a grievance redressal officer so that individuals have \u201creadily available and effective means\u201d to complain. Individuals also gain the right to nominate a representative to exercise their rights after death or incapacity. These procedural rights reflect India\u2019s emphasis on accessible redress. Additionally, the Rules require that grievances are resolved within a reasonable time, not exceeding ninety (90) days, adding certainty to the duration of internal grievance resolution processes between businesses and customers.<\/p>\n<p>Notably, there is no private right of action under the DPDPA; only the Board can enforce penalties. However, data principals can register complaints with the Board or seek other prescribed remedies.<\/p>\n<h3>DPDPA exemptions and special cases<\/h3>\n<p>The DPDPA provides several exemptions and carve-outs balancing privacy with other interests. Personal data processed by natural persons for purely personal or household purposes is out of scope. Personal data already made public by the individual or under a legal obligation is exempt.<\/p>\n<p>Critically for innovation, Section 17(2)(b) explicitly exempts research, archiving, and statistical processing from the Act\u2019s obligations, provided such processing meets government-prescribed standards and is not used for decisions about a specific individual. If rulemaking clarifies the standards, this could permit AI\/ML research using large datasets, a boon for innovation.<\/p>\n<p><strong>But questions remain:<\/strong> who qualifies (academic institutions only or also private labs), and what technical\/ethical guidelines will apply? Clear guidelines here will determine how \u201cclean\u201d personally identifiable data can be repurposed for research.<\/p>\n<p><strong>Children\u2019s data<\/strong> is another focus. The Act contemplates special protections for minors: a parent&#8217;s consent is needed for processing a child\u2019s data, and the government may mandate a parental consent mechanism. The draft version of the Rules provided for certain purposes for which children\u2019s personal data could be subject to tracking or behavioral monitoring. This list has been expanded to include the determination of real-time location of a child, where such processing is restricted to tracking real-time location of a child in the interest of their safety, protection or security. Further, children\u2019s data may also be monitored or tracked to restrict certain types of services and advertisements which may pose a detrimental effect on their well-being.<\/p>\n<p>Importantly, the DPDPA grants broad government exemptions. The government can declare law enforcement, national security, and sovereign interests out of scope, as can certain classes of data fiduciaries (e.g., startups) based on factors like the volume of data processed and the impact on national security or public order (these open-ended powers have drawn criticism).<\/p>\n<h3>DPDPA security obligations explained: Data minimization, breach notifications, and governance standards<\/h3>\n<h4>Security<\/h4>\n<p>The DPDPA reiterates and extends traditional security obligations. Data fiduciaries must adopt \u201creasonable security practices\u201d at least as stringent as international standards, akin to India\u2019s IT Act 43A (now largely superseded).<\/p>\n<p>The Rules also mandate that every data fiduciary protect personal data under its control, requiring the implementation of technical protections like encryption, strong access controls, logging, continuous monitoring, and incident-response capabilities. Data fiduciaries must also maintain backups and business-continuity measures to ensure data availability and integrity. Logs and relevant personal data must be retained for at least one year to support breach investigations. Data Processors must be contractually bound to meet the same security standards. SMEs, in particular, may need significant upgrades to their security infrastructure, policies, and practices to meet these requirements.<\/p>\n<h4>New retention requirement<\/h4>\n<p>The final rules introduce a new requirement, mandating all personal data, traffic data and logs generated from data processing activities to be retained at least for 1 year, even after the fulfilment of the purpose, or deletion of the user account, for (i) processing of personal data by government agencies in the interest of national security and sovereignty and integrity of India; (ii) performance of any function under any law in force in India; and (iii) disclosure of any information, pursuant to any law in force in India.<\/p>\n<h4>Breach notification<\/h4>\n<p>On breaches, the Act requires mandatory notification to both the Board and affected individuals whenever a personal data breach occurs, irrespective of scale.<\/p>\n<p>The Rules creates a two-stage breach reporting process requiring immediate intimation to affected principals and the Board, followed by a detailed report to the Board within 72 hours. Notifications must include breach details, impacts, mitigation steps, and user guidance. Due to the lack of materiality threshold, it is unclear whether even minor incidents must be reported, resulting in administrative overload and user \u201cnotification fatigue\u201d. The 72-hour window also differs from other sectoral rules like CERT-In\u2019s 6-hour timeline, adding compliance complexity for organizations.<\/p>\n<p>Importantly, organizations should align DPDPA breach procedures with other obligations (e.g., telecom or financial sector breach rules and CERT-IN requirements) to avoid conflicting processes.<\/p>\n<h4>Accountability<\/h4>\n<p>Beyond breach reports, the DPDPA embeds accountability measures. All fiduciaries must maintain records of their processing activities and implement privacy governance measures. Those designated as \u201cSignificant Data Fiduciaries\u201d (SDFs), based on factors like volume of data, sensitivity, and impact on India\u2019s sovereignty, democracy, or public order, face extra duties.<\/p>\n<p>To see how these SDF obligations apply to AI and high-volume data platforms, read our breakdown of the <a href=\"https:\/\/trustarc.com\/resource\/dpdpas-global-reach-cross-border-data-ai\/\" target=\"_blank\" rel=\"noopener\">DPDPA\u2019s global and sector-specific implications<\/a>.<\/p>\n<p>The Central Government may classify certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on factors such as data volume and sensitivity, risks to Data Principals, and national or public-order considerations. SDFs face enhanced obligations, including appointing an India-based Data Protection Officer and undergoing independent data audits.<\/p>\n<p>Once designated, they must conduct annual DPIAs and audits, and report key findings to the Data Protection Board. They must also ensure technical and algorithmic systems are tested and verified to prevent risks to data principals. SDFs must comply with any Government-mandated cross-border data transfer restrictions. Likely candidates include major tech platforms and organizations in regulated sectors such as finance, banking, and healthcare. The Government retains broad discretion to include additional categories when determining SDF status.<\/p>\n<p>These measures are aimed at high-volume tech firms, social platforms, and critical infrastructure providers, forcing them into a formal data governance posture.<\/p>\n<p>The government can also ease or tighten obligations (even exempt whole classes like startups), so companies should watch for objective criteria in the rules.<\/p>\n<h2>When will DPDPA be enforced? Understanding the Board\u2019s powers and what comes next<\/h2>\n<p>Along with the notification of the Rules, the Government has notified a phased timeline for implementing the DPDPA as follows:<\/p>\n<ul>\n<li>Effective immediately (November 13, 2025):\n<ul>\n<li>(a) definitions under the DPDPA (e.g., that of personal data, data fiduciary, etc.);<\/li>\n<li>(b) provisions establishing the Board along with its administrative machinery;<\/li>\n<li>(c) the rule-making and transitional powers of the Government of India; and<\/li>\n<li>(d) the ability to make amendments to the DPDPA.<\/li>\n<\/ul>\n<\/li>\n<li>After 1 year (November 13, 2026): the conditions for registration and operation of consent managers as well as the Board\u2019s corresponding jurisdiction over being intimated of any breach of such conditions.<\/li>\n<li>After 18 months (May 13, 2027): the core operational provisions of the DPDPA, relating to:\n<ul>\n<li>(a) consent and corresponding aspects;<\/li>\n<li>(b) obligations applicable to data fiduciaries;<\/li>\n<li>(c) obligations applicable to significant data fiduciaries ; and<\/li>\n<li>(d) the remaining powers of the Board.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The Board will be the DPDPA\u2019s enforcement authority. It is empowered to investigate complaints, conduct inquiries, and impose fines (up to INR\u202f2.5\u202fbillion) or corrective orders, including blocking data processing or demanding deletion. The Board can also mandate urgent remedial measures in case of a serious breach.<\/p>\n<p>The Board will function entirely online to handle complaints, investigate data breaches, and impose penalties, completing inquiries within six months (extendable by three-month blocks with written reasons), and its decisions must be issued in writing. Appeals first go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), with civil courts barred from intervening where the Board has jurisdiction. A further and final appeal may be made to the Supreme Court, creating a three-tier appeal structure.<\/p>\n<p>Regulators have signaled a progressive but firm stance. Indian policymakers aim to align the DPDPA with global best practices while accommodating local needs. For example, a Finance Ministry advisory sees robust data protection as central to economic and national security interests.<\/p>\n<p>At the same time, concerns about transparency (<a href=\"https:\/\/www.indiacode.nic.in\/bitstream\/123456789\/2065\/5\/a2005-22.pdf\" target=\"_blank\" rel=\"noopener\">Right to Information Act<\/a>) and law enforcement privacy (<a href=\"https:\/\/cag.gov.in\/uploads\/media\/IT-ACT-20210330163049.pdf\" target=\"_blank\" rel=\"noopener\">IT Act<\/a>) must be balanced. The DPDPA amends RTI rules to protect officials\u2019 personal data, a change that has sparked debate.<\/p>\n<h2>DPDPA implementation: Compliance challenges and business readiness<\/h2>\n<p>The new Rules mark the final step in putting India\u2019s first data protection law into action. The Government will clarify issues like cross-border data transfer limits and which organizations will be tagged as significant data fiduciaries. The Rules aim to balance clear regulation with enough flexibility for businesses to innovate. As the law becomes fully operational, companies must update their systems, processes, and documentation to ensure strong and resilient compliance.<\/p>\n<p>Companies should <strong>start by <a href=\"https:\/\/trustarc.com\/resource\/building-data-inventory-mapping-ropa\/\" target=\"_blank\" rel=\"noopener\">mapping all personal data flows<\/a><\/strong> to identify what data is collected, why, where it is stored, and to whom it is disclosed. Only with a complete inventory can firms apply the DPDPA\u2019s rules to each data set (e.g., requiring new consents or erasing old data).<\/p>\n<p><strong>Existing policies and practices will need revision<\/strong>. Privacy notices will have to explicitly track India\u2019s consent and data subject rights requirements. Global companies must check \u201cpolicy deltas\u201d: while the GDPR allows processing on legitimate interest or contracts, India\u2019s law will often demand fresh consent instead, which means consent mechanisms may need redesign in India-specific ways. Firms should also implement or upgrade systems to record and log consent transactions, evidence that valid consent was obtained for every processing activity.<\/p>\n<p><strong>Contractual agreements will also require review<\/strong>. Data processing agreements must be amended so that fiduciaries can enforce DPDPA obligations on their vendors, even though the law only directly binds fiduciaries. For example, cloud or analytics providers may need new clauses on security standards, audit rights, breach notification, and data return or deletion. Aligning such contracts across the supply chain is crucial since fiduciaries remain liable for breaches by their processors.<\/p>\n<p>Finally, organizations should <strong>invest in training and culture change<\/strong>. Given the DPDPA\u2019s novel features (consent managers, no default legal interests, nomination rights, etc.), employees will need education to handle data correctly. Companies may run simulation exercises for data breaches or rights requests, and ensure that even non-technical staff understand basic privacy tenets. Building privacy into day-to-day operations is not just legal risk mitigation; it is becoming a strategic imperative in India\u2019s digital economy.<\/p>\n<h3>Turning privacy principles into business practice<\/h3>\n<p>The Digital Personal Data Protection Act signals India\u2019s intent to build a modern privacy regime rooted in consent, transparency, and accountability. From redefining lawful data processing to mandating strong governance and breach preparedness, the DPDPA requires organizations to move beyond checkbox compliance and embrace a privacy-by-design mindset.<\/p>\n<p>But foundational understanding is only the first step. Implementation will require organizations to rework contracts, overhaul consent flows, inventory their data, and instill a culture of privacy across teams and tools. With enforcement timelines still unfolding, now is the time to build the infrastructure\u2014technical, procedural, and cultural\u2014that ensures long-term compliance.<\/p>\n<p>Next, <a href=\"https:\/\/trustarc.com\/resource\/dpdpas-global-reach-cross-border-data-ai\/\" target=\"_blank\" rel=\"noopener\">explore the global dimensions of the DPDPA from its approach to cross-border data transfers and international applicability, to how it compares with GDPR and CCPA, and the critical role it plays in shaping India\u2019s AI and cybersecurity future<\/a>.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/consent-management\/\" class=\"badge\">Consent Management<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/data-privacy\/\" class=\"badge\">Data Privacy<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_d1be13f2825668003c6da80b2cc725f4\" class=\"resource-section\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related resources<\/h2>\n\t\t\t\t<a href=\"\/resources\/\" class=\"cta block\">View all resources<\/a>\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/india-dpdpa-compliance-checklist\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-rect-blue-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Infographics, Research<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>India\u2019s Digital Personal Data Protection Act (DPDPA) Compliance Checklist<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/india-dpdpa-how-to-operationalize\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Whitepapers<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>India DPDPA: How to Operationalize Compliance at Scale<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-2026-global-privacy-benchmarks-report-trends-and-perspectives\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-rect-gray-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>May 5, 2026 &#8211; 2026 Global Privacy Benchmarks Report: Trends and Perspectives<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Navigate India\u2019s DPDPA: Learn the key rules on consent, scope, rights, and compliance to stay ahead of evolving privacy obligations.<\/p>\n","protected":false},"featured_media":1252,"template":"","topic-resource":[67,55],"type-resource":[6],"class_list":["post-6740","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-consent-management","topic-resource-data-privacy","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>India\u2019s Digital Personal Data Protection Act (DPDPA) | TrustArc<\/title>\n<meta name=\"description\" content=\"Navigate India\u2019s DPDPA: Learn the key rules on consent, scope, rights, and compliance to stay ahead of evolving privacy obligations.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/indias-digital-personal-data-protection-act-dpdpa\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/indias-digital-personal-data-protection-act-dpdpa\\\/\",\"name\":\"India\u2019s Digital Personal Data Protection Act (DPDPA) | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/indias-digital-personal-data-protection-act-dpdpa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/indias-digital-personal-data-protection-act-dpdpa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-plus-blue-test.png\",\"datePublished\":\"2025-07-17T10:54:00+00:00\",\"dateModified\":\"2025-12-09T19:11:50+00:00\",\"description\":\"Navigate India\u2019s DPDPA: Learn the key rules on consent, scope, rights, and compliance to stay ahead of evolving privacy obligations.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/indias-digital-personal-data-protection-act-dpdpa\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/indias-digital-personal-data-protection-act-dpdpa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-plus-blue-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-plus-blue-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"India\u2019s Digital Personal Data Protection Act (DPDPA) | TrustArc","description":"Navigate India\u2019s DPDPA: Learn the key rules on consent, scope, rights, and compliance to stay ahead of evolving privacy obligations.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/","url":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/","name":"India\u2019s Digital Personal Data Protection Act (DPDPA) | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test.png","datePublished":"2025-07-17T10:54:00+00:00","dateModified":"2025-12-09T19:11:50+00:00","description":"Navigate India\u2019s DPDPA: Learn the key rules on consent, scope, rights, and compliance to stay ahead of evolving privacy obligations.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/indias-digital-personal-data-protection-act-dpdpa\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/6740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1252"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=6740"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=6740"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=6740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}