Back to blog
Home/Blog/Navigating the DPDPA 2023: Key Obligations & Rights
RegulationsJuly 23, 20266 min read

Navigating the DPDPA 2023: Key Obligations & Rights

A comprehensive guide to India's Digital Personal Data Protection Act (DPDPA) 2023, outlining fundamental definitions, compliance obligations, and citizen rights.

MetaSight Compliance Team
Compliance Specialist

Introduction to DPDPA

The Digital Personal Data Protection Act, 2023 (DPDPA) is a landmark legislation designed to regulate the processing of digital personal data in India. It balances the right of individuals to protect their personal data with the need to process such data for lawful purposes.

Real-World Example

When an individual registers for an online streaming service, the DPDPA ensures that their personal information (such as name, email address, and viewing preferences) is collected, stored, and processed responsibly, securely, and transparently.

Regulatory Q&A

Q: What is a Data Fiduciary and a Data Principal?

Under the DPDPA, a Data Fiduciary is any entity (like a company, healthcare provider, or government body) that determines the purpose and means of processing personal data. A Data Principal is the individual to whom the personal data belongs (e.g., a customer, employee, or user).

Fundamental Rights of Data Principals

The DPDPA empowers individuals (Data Principals) with extensive rights to control their personal data. Organizations must provide simple mechanisms for individuals to exercise these rights:

  • Right to Access: Individuals can request a summary of the personal data being processed and a list of third parties it has been shared with.
  • Right to Correction & Erasure: Individuals can request corrections to incomplete or inaccurate data, or erasure of data once the purpose is served.
  • Right to Grievance Redressal: Fiduciaries must provide a clear channel to resolve complaints before they are escalated to the Data Protection Board.
Regulatory Q&A

Q: Does the DPDPA apply to foreign websites accessed by Indians?

Yes. The DPDPA applies to any entity—Indian or foreign—that processes personal data of individuals located in India, provided they are offering goods or services to individuals in India, or profiling their behavior. Even without physical presence, serving Indian users triggers compliance.

Compliance Warning

Non-compliance with Data Principal rights can lead to significant disputes and escalation to the Data Protection Board of India, which has the power to issue binding remedies and levy monetary penalties.