Skip to content

DPDP Act 2023

Definition

Digital Personal Data Protection Act 2023. India's general data protection statute, in force in phases from 2024. Applies to IoT-collected personal data with consent, purpose limitation, storage limitation and breach-notification obligations on the data fiduciary (the device vendor and any aggregator).

Governed sector
Private data fiduciaries (device vendors, aggregators, service providers)
Key obligations
Consent, purpose limitation, storage limitation, breach notification
Related law
IT Act 2000, Aadhaar Act 2016

Common questions

What is the DPDP Act 2023 and when did it come into force?+

The Digital Personal Data Protection Act 2023 is India's general data protection statute. It was rolled out in phases starting in 2024. The law applies to personal data collected by IoT devices, smartphones, and digital systems, placing obligations on data fiduciaries (vendors and aggregators) to get consent, limit storage, and notify users of data breaches.

How does the DPDP Act handle biometric data?+

The DPDP Act requires private companies to obtain consent and follow strict purpose-limitation rules before processing biometric data. However, central government agencies can process biometric data for national security without these restrictions. The law also preserves the separate Aadhaar Act 2016 framework, which has its own biometric rules.

Why do forensic investigators and cyber crime analysts need to know about the DPDP Act?+

In privacy-related cyber crime cases in India, the DPDP Act must be read alongside the IT Act 2000. Investigators need to understand data principal rights and data fiduciary obligations when examining devices, cloud storage, and breach evidence. The law also defines the Data Protection Board of India, which oversees violations.

Related terms

Binwalk
An open-source firmware analysis tool that scans a binary blob for known file signatures (squashfs, JFFS2, gzip, LZMA, certificates) and extracts the...
BIPA
Illinois Biometric Information Privacy Act (740 ILCS 14, 2008). Requires informed written consent before collecting biometric identifiers and prohibits their sale. The...
CERT-in
Indian Computer Emergency Response Team. Statutory body under Section 70B IT Act; mandatory reporting of qualifying incidents within 6 hours under the...
Clearview AI
New York company that built a face-recognition database of approximately 30 billion images scraped from public websites without consent; subject to BIPA...
CoAP
Constrained Application Protocol (RFC 7252). A RESTful protocol over UDP on port 5683 (or 5684 with DTLS), designed for constrained devices that...
Conformity Assessment
The process by which a provider of a high-risk AI system (such as a face recognition database for law enforcement) demonstrates compliance...
eMMC Dump
Embedded Multi-Media Card flash chip extraction. The chip is desoldered (chip-off) or read in-circuit with an ISP adapter; the raw NAND or...
EU AI Act 2024
Regulation (EU) 2024/1689, the first comprehensive AI regulatory framework, which prohibits real-time biometric identification in publicly accessible spaces with three narrow exceptions,...
High-Risk AI System
An AI system classified under Annex III of the EU AI Act as requiring mandatory technical documentation, risk management, human oversight, transparency,...
I4C
Indian Cybercrime Coordination Centre, the central node under the Ministry of Home Affairs running the National Cybercrime Reporting Portal (cybercrime.gov.in), state cyber...
Intermediary Safe Harbour
The conditional immunity under Section 79 IT Act read with the IT Rules 2021. Lost when due diligence and grievance officer obligations...
IT Act 2000
The Information Technology Act 2000, the parent Indian statute on computer offences, electronic records and digital signatures. Came into force on 17...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.