Regulation

DPDP — Digital Personal Data Protection Act, 2023

India’s first comprehensive data protection law. The DPDP Act governs the processing of digital personal data and is built on a consent-first model: a Data Fiduciary must give clear notice and obtain free, specific, informed and unambiguous consent — through a clear affirmative action — before processing personal data, which includes data collected via non-essential cookies. It is enforced by the Data Protection Board of India.

What DPDP actually requires

India's first comprehensive data protection law. The DPDP Act governs the processing of digital personal data and is built on a consent-first model: a Data Fiduciary must give clear notice and obtain free, specific, informed and unambiguous consent — through a clear affirmative action — before processing personal data, which includes data collected via non-essential cookies. It is enforced by the Data Protection Board of India.

Key requirements

  • Give a clear, itemised notice describing what personal data is collected and the purpose
  • Obtain free, specific, informed and unambiguous consent through a clear affirmative action
  • Offer the notice and consent request in English or any language in the Eighth Schedule of the Indian Constitution
  • Let Data Principals withdraw consent as easily as they gave it
  • Honour rights to access, correction, completion, erasure and grievance redressal
  • Support consent withdrawal and requests via a registered Consent Manager where used
  • Report personal data breaches to the Data Protection Board and affected Data Principals

At a glance

Full name

Digital Personal Data Protection Act, 2023

Region

India

Status

Enacted 2023; rules being operationalised

Who it affects

Any organisation (a 'Data Fiduciary') that processes digital personal data of individuals (Data Principals) in India — including businesses based outside India that offer goods or services to people in India.

Penalties

Financial penalties up to ₹250 crore (~USD 30M) per instance for failure to take reasonable security safeguards to prevent a data breach, with significant penalties across other categories of non-compliance.

How GrantCookie covers it

Compliant defaults

Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.

Provable records

Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.

Easy withdrawal

A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.

This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.

More regulations

Get compliant in an afternoon, not a quarter

Start on the free plan, scan your site, and publish a banner your visitors understand. No card, no sales call, no implementation project.

14-day trial on paid plans · Cancel any time · No card required to start