Digital Personal Data Protection Act, 2023
The DPDP Act 2023 stands for the Digital Personal
Data Protection Act, 2023 — India’s first comprehensive law to protect
personal data and privacy in the digital world.
Here’s a simple and practical explanation:
What is DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 is a
law that regulates how personal data of individuals is collected,
stored, processed, and used by businesses, government, and organizations.
👉 Objective:
- Protect
privacy of individuals
- Ensure
lawful use of data
- Create
accountability for companies handling data
👤 Key Concepts (Very
Important)
1. Data Principal
- The person
whose data is being used
- Example:
Your client, employee, customer
2. Data Fiduciary
- The entity
handling the data
- Example:
Your CA firm, company, apps, websites
🔑 Key Features of DPDP
Act
✅ 1. Consent-based system
- Data
can be collected only with proper consent
- Must
be clear, specific, and informed
✅ 2. Rights of Individuals
People (data principals) have rights to:
- Access
their data
- Correct
data
- Delete
data
- File
complaints
✅ 3. Duties of Businesses
Companies must:
- Use
data only for specific purpose
- Keep
data secure
- Delete
data when not needed
- Inform
in case of data breach
✅ 4. Heavy Penalties 💰
- Up to
₹250 crore penalty for violations
✅ 5. Data Protection Board of
India
- Authority
to handle complaints & penalties
✅ 6. Applicability
- Applies
to:
- Indian
companies
- Foreign
companies handling Indian data
📅 Implementation Timeline
- Act
passed: 11 August 2023
- Rules
notified: 2025
- Full
compliance expected by: 2027
Practical Impact
This Act is very important for professionals:
You must ensure:
- Client
data is stored securely
- Consent
taken before collecting data
- No
unnecessary data retention
- Proper
privacy policy for your firm
👉 Even:
- GST
clients
- ITR
data
- PAN /
Aadhaar copies
All are covered under DPDP.
⚠️ Example (Simple)
If your office:
- Stores
client PAN data
- Shares
it without consent
👉 You may be liable
under DPDP Act
One-Line Summary
DPDP Act = “Data privacy law of India” ensuring consent,
security, and accountability in digital data handling.
.jpg)
Comments
Post a Comment