
The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive national law governing the collection, storage, processing and sharing of digital personal data, while protecting the privacy of individuals. It received Presidential assent on 11 August 2023, and its enabling DPDP Rules, 2025 were notified on 13–14 November 2025, finally operationalising the law.
These study notes cover the Act’s key concepts, rights, obligations, penalties, the new 2025 Rules and enforcement timeline, the DPDP vs GDPR comparison, and a full bank of practice MCQs — ideal for IBPS, SBI, RBI Grade B, NABARD, JAIIB, CAIIB and other banking/regulatory exams.
What Is the DPDP Act 2023?
The DPDP Act is India’s standalone data-protection statute. It applies to the processing of digital personal data within India and also has extra-territorial reach — it covers entities outside India that offer goods or services to people in India. The Act is built on a foundation of explicit consent and the principle that data should be collected only for a lawful, specified purpose.
- Passed / assent: 11 August 2023.
- Rules notified: 13–14 November 2025 (DPDP Rules, 2025) by MeitY.
- Administered by: Ministry of Electronics and Information Technology (MeitY).
- Applies to: All organisations handling digital personal data of individuals in India — banks, fintech, NBFCs, telecom, insurance, e-commerce and digital apps.
- Scope: Only digital personal data (not non-digital or non-personal data).
Objectives of the Act
- Protect the personal data and privacy of individuals.
- Prevent misuse of data by companies or fraudsters.
- Build trust in digital banking and the digital economy.
- Set clear legal rules for collection, use, storage and deletion of data.
- Enable safe digital innovation across UPI, the Digital Rupee, AI and fintech.
Important Terms (Definitions)
| Term | Meaning |
|---|---|
| Data Principal | The individual whose personal data is collected (the customer). For a child, it includes the parent/guardian. |
| Data Fiduciary | The entity that decides the purpose and means of processing data (e.g., a bank). |
| Significant Data Fiduciary (SDF) | A large/high-risk fiduciary notified by the government, with extra obligations. |
| Data Processor | An entity that processes data on behalf of a Data Fiduciary. |
| Consent Manager | A platform registered with the Board that lets individuals give, manage, review and withdraw consent. |
| Consent | Free, specific, informed and unambiguous permission to process data. |
| Data Breach | Any unauthorised processing, access, disclosure or loss of personal data. |
Rights of the Data Principal
- Right to Access – to know what personal data is being processed.
- Right to Correction and Update – to correct or complete data.
- Right to Erasure / Deletion – to have data deleted once the purpose ends.
- Right to Grievance Redressal – a readily available complaint mechanism.
- Right to Nominate – to nominate another person to exercise rights in case of death or incapacity.
- Right to Withdraw Consent – at any time, as easily as it was given.
Memory aid: A-C-D-N — Access, Correct, Delete, Nominate (plus withdraw consent and grievance redressal).
Obligations of the Data Fiduciary
- Collect only the data needed (data minimisation) for a specified, lawful purpose.
- Process data only with free, informed consent, after giving a clear notice.
- Maintain accuracy and protect data with reasonable security safeguards (encryption, access control).
- Delete data once the purpose is served (storage limitation).
- Report data breaches to the Data Protection Board and affected individuals.
- Establish an effective grievance redressal mechanism.
Significant Data Fiduciary (SDF) — Extra Obligations
The government can classify large or high-risk fiduciaries (based on data volume, sensitivity and risk to rights) as SDFs. They must additionally:
- Appoint a Data Protection Officer (DPO) based in India, reporting to the Board of Directors.
- Appoint an independent Data Auditor.
- Conduct periodic Data Protection Impact Assessments (DPIA) and audits.
Likely SDFs include large banks (SBI, HDFC, ICICI), NPCI, big fintech (Paytm, Razorpay), telecom and large tech firms.
Children’s Data — Special Protection
A child is anyone under 18 years of age. Data Fiduciaries must obtain verifiable parental/guardian consent before processing a child’s data, and the Act prohibits tracking, behavioural monitoring and targeted advertising directed at children.
Data Protection Board of India (DPB)
The DPB is established under Section 18 (Chapter 5) of the Act as an independent body that handles breaches, complaints and enforcement. Key features:
- Functions as a fully digital, paperless office — a first for an Indian regulator.
- It is being set up in the National Capital Region with four members.
- It can impose penalties and direct corrective measures, but must give entities a chance to be heard.
- Its decisions can be appealed to TDSAT (Telecom Disputes Settlement and Appellate Tribunal) within 60 days, and further to the Supreme Court.
Penalties Under the DPDP Act
Penalties are listed in the Schedule to the Act and are per-instance (per breach). There is no cure period, though the entity gets an opportunity to be heard.
| Violation | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards (leading to a breach) | Up to ₹250 crore |
| Failure to notify the Board / affected persons of a breach | Up to ₹200 crore |
| Breach of additional obligations regarding children’s data | Up to ₹200 crore |
| Breach of SDF’s additional obligations | Up to ₹150 crore |
| Breach of duties by a Data Principal | Up to ₹10,000 |
DPDP Rules, 2025 — The Big Update
The Act’s principles became enforceable only after the DPDP Rules, 2025 were notified on 13–14 November 2025. Key features:
- Breach notification: Notify the Board without delay; submit a detailed report within 72 hours (extendable). Affected individuals must also be informed.
- Consent Manager: Must register with the Board and maintain a minimum net worth of ₹2 crore; must keep consent audit trails for at least 7 years.
- Cross-border transfer: A “negative list” (blacklist) approach — data may be transferred abroad unless the government restricts a specific country. (This differs from GDPR’s whitelist/adequacy model.)
- Special protections for children and persons with disabilities, and rules for State processing of subsidies/benefits.
Phased Enforcement Timeline
| Phase | Effective Date | What Comes Into Force |
|---|---|---|
| Phase 1 | 14 November 2025 | Data Protection Board set up; definitions; complaint mechanism live. |
| Phase 2 | 14 November 2026 | Consent Manager registration and obligations. |
| Phase 3 | 14 May 2027 | All substantive provisions — full compliance required. |
Impact on Banking & Digital Finance
- Protects sensitive financial data — KYC, Aadhaar, PAN, biometrics, UPI IDs and account numbers.
- Strengthens secure digital banking across UPI, IMPS, RTGS, AEPS, QR and wallets.
- Reduces fraud such as phishing, vishing and SIM-swap by tightening data handling.
- Builds trust in NPCI systems and the CBDC (Digital Rupee).
- Requires explicit customer consent for data-based lending and credit decisions.
- Encourages tokenisation, anonymisation and encryption.
DPDP Act vs GDPR — Comparison
| Feature | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Region | India | European Union |
| Maximum penalty | Up to ₹250 crore per breach | Up to 4% of global turnover |
| Sensitive data category | Not separately defined | Distinct, strictly regulated category |
| Breach reporting time | Detailed report within 72 hours (Rules 2025) | Within 72 hours |
| Cross-border transfer | Negative list (blacklist) approach | Whitelist / adequacy decisions |
| DPO requirement | Only for Significant Data Fiduciaries | Mandatory in defined cases |
| Extra-territorial reach | Yes | Yes |
Advantages and Limitations
The Act delivers strong consumer protection and privacy, greater transparency and accountability, reduced cybercrime and financial fraud, easier global-business compliance, and support for Digital India and fintech innovation. However, critics note real concerns: wide government exemptions, no separate sensitive-data category (unlike GDPR), high compliance cost for small firms, and a complex implementation and audit burden.
2-Minute Quick Revision Sheet
- DPDP = Digital Personal Data Protection Act, 2023.
- Assent: 11 August 2023; Rules notified: 13–14 November 2025.
- Full compliance deadline: 14 May 2027 (phased: Nov 2025 / Nov 2026 / May 2027).
- Regulator: Data Protection Board of India (Section 18); appeals to TDSAT.
- Key roles: Data Principal, Data Fiduciary, Significant Data Fiduciary, Data Processor, Consent Manager.
- Rights: Access, Correct, Delete, Nominate, Withdraw consent, Grievance redressal.
- Child: under 18 → verifiable parental consent.
- Max penalty: ₹250 crore (per breach); no cure period.
- Breach report: within 72 hours to the Board.
- Cross-border: negative-list approach. Model: inspired by GDPR but not identical.
Most Important MCQs — DPDP Act 2023
Read each question with its options, attempt it, then click “Show Answer” to check. Useful for IBPS, SBI, RBI Grade B, NABARD, JAIIB and CAIIB.
How this topic is tested: Since RBI, IIBF and IBPS don’t release official papers, these are original practice questions modelled on common exam patterns. DPDP questions cluster around a few facts — the assent date (Aug 2023) and Rules date (Nov 2025), the key roles (Data Principal vs Data Fiduciary), the ₹250 crore penalty, the regulator and appeal body (DPB → TDSAT), the child age of 18, and the DPDP vs GDPR differences. Lock these in.
Chapter 1: Basics
Q1. The DPDP Act received Presidential assent in:
a) August 2023 b) January 2023 c) November 2025 d) August 2024
Show Answer
Answer: a) August 2023 (11 August 2023). The enabling Rules came later, in November 2025.
Q2. The DPDP Act applies to:
a) All forms of data b) Only digital personal data c) Only paper records d) Only government data
Show Answer
Answer: b) Only digital personal data — non-digital and non-personal data are outside its scope.
Q3. Which Ministry administers the DPDP Act and notified the 2025 Rules?
a) Ministry of Finance b) Ministry of Home Affairs c) MeitY (Electronics & IT) d) RBI
Show Answer
Answer: c) MeitY (Ministry of Electronics and Information Technology).
Q4. The DPDP Act has:
a) No effect outside India b) Extra-territorial application c) Effect only in metro cities d) Effect only on banks
Show Answer
Answer: b) Extra-territorial application — it covers foreign entities offering goods/services to people in India.
Chapter 2: Key Roles & Rights
Q5. The individual whose personal data is collected is called the:
a) Data Fiduciary b) Data Processor c) Data Principal d) Consent Manager
Show Answer
Answer: c) Data Principal
Q6. An entity that decides the purpose and means of processing data is the:
a) Data Principal b) Data Fiduciary c) Data Auditor d) Consent Manager
Show Answer
Answer: b) Data Fiduciary
Q7. Which of the following is NOT a right of the Data Principal under the Act?
a) Right to access b) Right to correction c) Right to erasure d) Right to unlimited compensation
Show Answer
Answer: d) Right to unlimited compensation — the Act grants access, correction, erasure, grievance redressal, nomination and consent withdrawal.
Q8. The “Right to Nominate” allows a Data Principal to:
a) Nominate a bank b) Nominate another person to exercise rights on death/incapacity c) Nominate a regulator d) Nominate a processor
Show Answer
Answer: b) Nominate another person to exercise their rights in case of death or incapacity.
Q9. A Consent Manager must maintain a minimum net worth of:
a) ₹50 lakh b) ₹1 crore c) ₹2 crore d) ₹10 crore
Show Answer
Answer: c) ₹2 crore — as per the DPDP Rules, 2025.
Chapter 3: Children, SDF & Penalties
Q10. Under the DPDP Act, a “child” is a person below the age of:
a) 12 years b) 14 years c) 16 years d) 18 years
Show Answer
Answer: d) 18 years — verifiable parental consent is required to process a child’s data.
Q11. A Significant Data Fiduciary (SDF) must mandatorily appoint a:
a) Branch Manager b) Data Protection Officer (DPO) c) Cashier d) Relationship Manager
Show Answer
Answer: b) Data Protection Officer (DPO) — based in India, plus an independent Data Auditor and DPIAs.
Q12. The maximum penalty for failing to take reasonable security safeguards is:
a) ₹50 crore b) ₹150 crore c) ₹200 crore d) ₹250 crore
Show Answer
Answer: d) ₹250 crore — the highest tier in the Schedule, per breach.
Q13. The penalty for failure to notify a data breach to the Board / affected persons can be up to:
a) ₹10,000 b) ₹50 crore c) ₹200 crore d) ₹500 crore
Show Answer
Answer: c) ₹200 crore
Q14. The DPDP Act provides for:
a) A 30-day cure period b) No cure period (but a right to be heard) c) A 90-day cure period d) Automatic waiver for first offence
Show Answer
Answer: b) No cure period, though the entity gets an opportunity to be heard before any penalty.
Chapter 4: Board, Rules & GDPR Comparison
Q15. The regulatory body established under the DPDP Act is the:
a) RBI b) Data Protection Board of India c) CERT-In d) TRAI
Show Answer
Answer: b) Data Protection Board of India (constituted under Section 18).
Q16. Appeals against the Data Protection Board’s decisions lie with:
a) High Court directly b) TDSAT c) NCLT d) SEBI
Show Answer
Answer: b) TDSAT (Telecom Disputes Settlement and Appellate Tribunal), within 60 days.
Q17. The DPDP Rules, 2025 were notified in:
a) August 2023 b) January 2025 c) November 2025 d) May 2027
Show Answer
Answer: c) November 2025 (13–14 November 2025).
Q18. The full compliance deadline for the DPDP framework is:
a) 14 November 2025 b) 14 November 2026 c) 14 May 2027 d) 11 August 2025
Show Answer
Answer: c) 14 May 2027 — the final phase of the staggered timeline.
Q19. Under the DPDP Rules, a detailed data-breach report must be submitted to the Board within:
a) 24 hours b) 48 hours c) 72 hours d) 7 days
Show Answer
Answer: c) 72 hours (extendable with approval).
Q20. For cross-border data transfer, the DPDP framework adopts a:
a) Whitelist (adequacy) approach like GDPR b) Negative-list (blacklist) approach c) Total ban d) No rules at all
Show Answer
Answer: b) Negative-list approach — transfer allowed unless the government restricts a specific country.
Q21. Compared to GDPR, the DPDP Act:
a) Has a separate sensitive-data category b) Does not separately define a sensitive-data category c) Has no penalties d) Applies only within the EU
Show Answer
Answer: b) The DPDP Act does not create a distinct “sensitive data” category, unlike GDPR.
Q22. The Data Protection Board of India operates as a:
a) Paper-based office b) Fully digital, paperless office c) Branch of the RBI d) State-level body
Show Answer
Answer: b) Fully digital, paperless office — a first for an Indian regulator.
Frequently Asked Questions (FAQs)
When did the DPDP Act 2023 come into force?
The Act received Presidential assent on 11 August 2023, but it became operational only after the DPDP Rules, 2025 were notified on 13–14 November 2025, with full compliance required by 14 May 2027.
Who is a Data Principal and a Data Fiduciary?
A Data Principal is the individual whose data is collected (the customer). A Data Fiduciary is the entity that decides how and why the data is processed (such as a bank).
What is the maximum penalty under the DPDP Act?
Up to ₹250 crore per breach for failing to take reasonable security safeguards. There is no cure period, but the entity gets a chance to be heard.
What is the age of a “child” under the DPDP Act?
Anyone under 18 years. Verifiable parental or guardian consent is required to process a child’s personal data.
Where can a Data Protection Board decision be appealed?
To the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), within 60 days, and further to the Supreme Court.
Conclusion
The DPDP Act, 2023, together with the DPDP Rules, 2025, gives India its first complete, enforceable data-protection regime. For exams, anchor your memory on the assent date (Aug 2023), the Rules date (Nov 2025), the phased deadline ending 14 May 2027, the key roles (Data Principal, Data Fiduciary, SDF, Consent Manager), the ₹250 crore maximum penalty, the regulator (Data Protection Board → TDSAT), the child age of 18, and the main differences from GDPR. These cover almost everything examiners ask on this topic.
