Abstract
India’s Digital Personal Data Protection Act, 2023(“DPDP Act” or “the Act”) marks the result of a long process of data protection laws. This began with the Supreme Court’s recognition of privacy as a fundamental right and the recommendation made by Justice B.N. Srikrishna Committee . The Act has now become fully operative with the notification of the Digital Personal Data Protection Rules, 2025 and the establishment of the Data Protection Board of India.
This article examines the compliance architecture the DPDP Act creates for businesses acting as Data Fiduciaries: the grounds for lawful processing and consent, core duties such as data minimization, security safeguards and breach notification, the retention and erasure of data, grievance redressal, and the enhanced obligations imposed on Significant Data Fiduciaries.
It further considers the rights conferred on Data Principals, the practical challenges of implementation for start-ups, mid-sized enterprises and multinational entities, and situates the Indian framework within a comparative perspective alongside the European Union's General Data Protection Regulation. The article concludes that while the DPDP Act adopts a deliberately simple and principle-based drafting style, its true compliance burden will be defined by subordinate rule-making and the enforcement practice of the Data Protection Board, making proactive, audit-ready compliance programs indispensable for Indian and foreign businesses alike.