DataDefend top 6 compliance platform. Book a free demo

DataDefend Logo
Book Demo
Compliance Deadline: May 13, 2027

The Complete Guide to the
DPDP Act 2023 & Rules 2025

A comprehensive, chapter-by-chapter breakdown of India's Digital Personal Data Protection Act, mapped with implementation timelines and compliance obligations.

Get Compliance RoadmapOfficial PDFs

Structure of the DPDPA 2023

The Act is organized into 9 distinct chapters and one schedule detailing financial penalties. Here is what every organization must know.

Chapter 1

Preliminary (Sections 1-3)

Covers the short title, commencement, key definitions (like Data Fiduciary, Data Principal, Personal Data), and the territorial application of the Act.

Chapter 2

Obligations of Data Fiduciary (Sections 4-10)

Details the grounds for processing, providing notice, obtaining verifiable consent, processing children's data, and additional obligations for Significant Data Fiduciaries.

Chapter 3

Rights and Duties of Data Principal (Sections 11-15)

Outlines the user's right to access, correction, erasure, grievance redressal, right to nominate, and the statutory duties they must follow.

Chapter 4

Special Provisions (Sections 16-17)

Governs the processing of personal data outside India (cross-border transfers) and lists specific exemptions for state agencies, research, and legal compliance.

Chapter 5

Data Protection Board of India (Sections 18-26)

Mandates the establishment of the DPB, detailing the composition, qualifications, proceedings, and powers of the Chairperson and its members.

Chapter 6

Powers, Functions and Procedure (Sections 27-28)

Defines the powers and functions of the Board, including how it conducts inquiries and the procedures it must follow.

Chapter 7

Appeal and Alternate Dispute Resolution (Sections 29-32)

Establishes the process for appeals to the Appellate Tribunal (TDSAT) and mechanisms for voluntary undertakings and alternate dispute resolution.

Chapter 8

Penalties and Adjudication (Sections 33-34)

Specifies the penalties for non-compliance and directs that sums realized by way of penalties be credited to the Consolidated Fund of India.

Chapter 9

Miscellaneous (Sections 35-44)

Covers protection of action taken in good faith, consistency with other laws, power of the Central Government to make rules, and amendments to other Acts.

The Schedule

Penalties for Breaches

A detailed matrix of financial penalties ranging up to ₹250 crore for various breaches, including failure to take reasonable security safeguards.

Ready for DPDP Compliance?

DataDefend helps you automate consent, DSARs, data discovery, and breach response. Keep your focus on business while our AI agents handle the compliance.

Schedule DemoExplore Platform

Be in the know

Sign up to receive the latest information about our organization, platform capabilities, and events.

DataDefend

Built in India with ❤️

Kamla Palace, 2, 2nd Floor, Old Jail Road, Near Sohna Chowk, Gurugram, Haryana - 122001

support@datadefend.in+91 0124 3534997
  • Home
  • About
  • Platform
  • Blogs
  • Legal Glossary
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
  • Manage Consent

© 2026 Cybersecure Digital Intelligence Private Limited. All rights reserved.

Powered by cybersec.enterprises

CIN: U80200HR2023PTC113597

GSTIN: 06AALCC1978R1ZT