DPDP Act 2023
Definition
Digital Personal Data Protection Act 2023. India's general data protection statute, in force in phases from 2024. Applies to IoT-collected personal data with consent, purpose limitation, storage limitation and breach-notification obligations on the data fiduciary (the device vendor and any aggregator).
- Governed sector
- Private data fiduciaries (device vendors, aggregators, service providers)
- Key obligations
- Consent, purpose limitation, storage limitation, breach notification
- Related law
- IT Act 2000, Aadhaar Act 2016
Common questions
What is the DPDP Act 2023 and when did it come into force?+
The Digital Personal Data Protection Act 2023 is India's general data protection statute. It was rolled out in phases starting in 2024. The law applies to personal data collected by IoT devices, smartphones, and digital systems, placing obligations on data fiduciaries (vendors and aggregators) to get consent, limit storage, and notify users of data breaches.
How does the DPDP Act handle biometric data?+
The DPDP Act requires private companies to obtain consent and follow strict purpose-limitation rules before processing biometric data. However, central government agencies can process biometric data for national security without these restrictions. The law also preserves the separate Aadhaar Act 2016 framework, which has its own biometric rules.
Why do forensic investigators and cyber crime analysts need to know about the DPDP Act?+
In privacy-related cyber crime cases in India, the DPDP Act must be read alongside the IT Act 2000. Investigators need to understand data principal rights and data fiduciary obligations when examining devices, cloud storage, and breach evidence. The law also defines the Data Protection Board of India, which oversees violations.
Related terms
- Binwalk
- An open-source firmware analysis tool that scans a binary blob for known file signatures (squashfs, JFFS2, gzip, LZMA, certificates) and extracts the...
- BIPA
- Illinois Biometric Information Privacy Act (740 ILCS 14, 2008). Requires informed written consent before collecting biometric identifiers and prohibits their sale. The...
- CERT-in
- Indian Computer Emergency Response Team. Statutory body under Section 70B IT Act; mandatory reporting of qualifying incidents within 6 hours under the...
- Clearview AI
- New York company that built a face-recognition database of approximately 30 billion images scraped from public websites without consent; subject to BIPA...
- CoAP
- Constrained Application Protocol (RFC 7252). A RESTful protocol over UDP on port 5683 (or 5684 with DTLS), designed for constrained devices that...
- Conformity Assessment
- The process by which a provider of a high-risk AI system (such as a face recognition database for law enforcement) demonstrates compliance...
- eMMC Dump
- Embedded Multi-Media Card flash chip extraction. The chip is desoldered (chip-off) or read in-circuit with an ISP adapter; the raw NAND or...
- EU AI Act 2024
- Regulation (EU) 2024/1689, the first comprehensive AI regulatory framework, which prohibits real-time biometric identification in publicly accessible spaces with three narrow exceptions,...
- High-Risk AI System
- An AI system classified under Annex III of the EU AI Act as requiring mandatory technical documentation, risk management, human oversight, transparency,...
- I4C
- Indian Cybercrime Coordination Centre, the central node under the Ministry of Home Affairs running the National Cybercrime Reporting Portal (cybercrime.gov.in), state cyber...
- Intermediary Safe Harbour
- The conditional immunity under Section 79 IT Act read with the IT Rules 2021. Lost when due diligence and grievance officer obligations...
- IT Act 2000
- The Information Technology Act 2000, the parent Indian statute on computer offences, electronic records and digital signatures. Came into force on 17...
Explained in these topics
- Biometric Evidence in Court: EU AI Act, DPDP and US StatutesIndia's Digital Personal Data Protection Act 2023, which requires consent and purpose-limitation for biometric data processing by private entities, while exemp...
- Cyber Crime Taxonomy and the IT Act 2000Digital Personal Data Protection Act 2023. Defines data principal rights, data fiduciary obligations, and the Data Protection Board of India. Read alongside IT...
- IoT Forensics: Smart Home, Wearables, MQTT/CoAP and Firmware AnalysisDigital Personal Data Protection Act 2023. India's general data protection statute, in force in phases from 2024. Applies to IoT-collected personal data with c...