3 mins
DPDP Act 2023: Mapping the Digital Privacy Framework
An analysis of India's Digital Personal Data Protection Act, 2023. The law details the statutory framework for digital personal data processing, establishes data principal rights, and sets territorial scope under Section 3.
Last updated:
What happened
A social media update summarized India's Digital Personal Data Protection Act, 2023. The Instagram post identified the legislation as the new digital privacy law of the country. It creates a formal framework for handling digital personal data. The text stated that the law gives individuals specific rights over their information. The update focused strictly on statutory intent. Parliament passed the Act to define clear rules for data processing. Granting specific rights to the data principal remains a core component of the legislation.
Does the DPDP Act apply here?
Section 3 of the DPDP Act dictates legal application. The statute covers the processing of digital personal data within India. Applicability requires the data fiduciary to collect the information in digital form initially or digitize it subsequently. The Act excludes personal data processed by an individual for a domestic purpose. It also exempts data made publicly available by the data principal or by a person under a legal obligation. The social media update stressed the word digital. Companies processing purely offline paper records fall outside the legal framework.
Legal implications under DPDP
The legislation formalizes individual rights over personal data. The Act classifies the individual as the data principal. Giving this person control over their digital information fulfills a main statutory goal. The social media post called this grant of rights a defining characteristic of the framework. However, operationalizing these individual rights requires the upcoming DPDP Rules, 2025. Section 1 allows the Central Government to enact different provisions at different times. Section 3 extends the territorial scope beyond India. Offshore processing triggers the Act if the activity connects to offering goods or services to Data Principals within the territory.
Could this happen to you
Misunderstanding the scope of the Act exposes organizations to legal risk. A company might assume offshore data centers isolate them from the legislation. Section 3 explicitly rejects this assumption. An entity processing data abroad to offer goods to Data Principals within India triggers full application of the Act. Section 16 governs cross-border transfers. The Central Government holds the power to restrict transfers by notifying specific countries. The Act permits transfers by default until the government publishes a negative list. Another local law providing a higher degree of restriction on data transfers will override the Section 16 allowance.
What companies should do in the next 30 days
1. Map personal data collection processes to identify all digital records subject to the DPDP Rules, 2025. Owner: Chief Information Officer. Artifact: Information inventory.
2. Segregate records digitized subsequently from those maintained strictly in physical paper format. Owner: Data Privacy Officer. Artifact: Applicability assessment report.
3. Review offshore data processing activities connected to offering goods or services within India. Owner: Legal Counsel. Artifact: Cross-border flow map.
What to watch
The Central Government will publish the DPDP Rules, 2025 to operationalize the statute. Act-only compliance models are outdated. The detailed mechanisms rely entirely on these forthcoming rules. Section 1 allows regulators to stagger the rollout of different provisions. Entities must track the Gazette notifications to know when specific rights take legal effect. Regulators will also issue lists of restricted countries under Section 16. The procedures for exercising the rights mentioned in the post depend on the DPDP Rules, 2025. Organizations should prepare internal systems to handle individual requests before the subordinate legislation activates.
Sources
Frequently asked questions
Does the DPDP Act cover physical paper records?
Section 3 excludes non-digital personal data unless a company digitizes it subsequently. The Act strictly applies to digital processing.
Can individuals demand rights over their personal data?
Yes. The legislation gives individuals specific rights relating to their personal information. The DPDP Rules, 2025 will define the exact mechanisms for exercising these rights.
Does the law apply outside the territory of India?
Section 3 extends applicability to offshore processing if the activity relates to offering goods or services to Data Principals within India. An overseas entity targeting the domestic market falls under the rules.
Are personal domestic activities regulated?
No. The Act specifically excludes personal data processed by an individual for any personal or domestic purpose. It also excludes data made publicly available by the data principal.
Can a company transfer digital personal data to another country?
Section 16 permits cross-border transfers by default. The Central Government holds the power to restrict transfers to specific countries by notification, subject to stricter restrictions in other local laws.
ComplyDP