34. Indian Cyber Law and Cyber Crime Awareness
34.4 The Digital Personal Data Protection Act, 2023
The DPDP Act, 2023 is India's personal data protection law. Its rules (the DPDP Rules) are being brought into force in phases, so check the current status on meity.gov.in.
| Term | Meaning |
|---|---|
| Data Principal | The person the data is about (you, a customer, a student) |
| Data Fiduciary | The organisation that decides why and how data is processed (a company, an app) |
| Data Processor | A vendor that processes data for the fiduciary (for example a cloud or payroll provider) |
| Consent | Must be free, specific, informed and clear, with an easy way to withdraw |
| Data Protection Board of India | The body that inquires into breaches and imposes penalties |
What organisations must do, in short:
- Collect only what is needed, for a stated purpose, and delete it when no longer needed.
- Protect it with reasonable security safeguards (everything in Chapters 29–33).
- Notify the Board and affected people about a personal data breach.
- Take extra care with children's data (verifiable parental consent).
- Respect rights of individuals: access, correction, erasure and grievance redressal.
Penalties are large: the Act allows fines of up to ₹250 crore for failing to take reasonable security safeguards (check the Schedule of the Act for each category).
Ravindra Bagale's Tip
DPDP mule security ha fakt IT cha vishay rahila nahi, to business risk zala. Public S3 bucket madhun customer data leak = mothi penalty. Mhanun Chapter 30 madhla "Block Public Access" ha kayda palnacha bhag aahe he interview madhe sanga.
Practice task
For the reels app from Chapter 16, list what personal data it collects (name, email, phone, videos, IP address). For each, write the purpose, where it is stored, who can access it and when it should be deleted. Draft a two-line consent message for the sign-up page.