India’s DPDP Act for developers: what engineers need to know
The Digital Personal Data Protection Act, 2023 and the 2025 Rules, translated into engineering work: consent flows, withdrawal, erasure, breach notices, children’s data and user rights.
India’s Digital Personal Data Protection Act, 2023 governs how apps collect and use personal data, and its Rules were notified on 14 November 2025 with an 18-month phased timeline. For developers it means building clear consent flows, easy withdrawal, purpose-limited collection, security safeguards, breach notices, erasure, parental consent for under-18s and user-rights requests.
Most articles on the DPDP Act are written for lawyers or compliance teams. This one is for the people who actually build the systems: what the law says, in plain language, and what it turns into in your code, database and product. It is not legal advice; the note at the end explains where to check the details.
What is the DPDP Act, and when does it apply?
Parliament enacted the DPDP Act on 11 August 2023, and the Government notified the DPDP Rules, 2025 on 14 November 2025, giving organisations an 18-month phased period to comply. The full text of the Act is on the Ministry of Electronics and IT website.
According to the Act, it applies to digital personal data processed in India, whether collected digitally or digitised later. It also applies to processing outside India if that processing is connected with offering goods or services to people in India. It does not apply to personal data used by an individual for personal or domestic purposes, or to data that the person has made publicly available themselves.
What are the key terms?
What does the Act say about consent?
Under section 6 of the Act, consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to the specified purpose. Users can withdraw consent at any time, and withdrawing must be as easy as giving it. The Rules require standalone, clear and simple consent notices explaining the specific purpose. The Act also requires that users can read the notice in English or any language in the Eighth Schedule of the Constitution.
What that means in your product:
How long can you keep personal data?
The Act requires a Data Fiduciary to erase personal data when the user withdraws consent, or as soon as it is reasonable to assume the purpose is no longer being served, whichever is earlier, unless another law requires it to be retained. It must also make its Data Processors erase that data.
What happens if there is a data breach?
The Act requires reasonable security safeguards to prevent breaches, and, if a breach happens, intimation to both the Data Protection Board and each affected user. Under the Rules, users must be told in plain language what happened, the likely consequences, the steps taken, and whom to contact.
Penalties are significant. According to the Government’s explainer, failing to maintain reasonable security safeguards can attract a penalty of up to ₹250 crore; failing to notify a breach, or violating obligations relating to children, up to ₹200 crore each; and other violations up to ₹50 crore.
Engineering work that follows directly: encryption in transit and at rest, least-privilege access, secrets management, audit logs you can actually search, and an incident runbook that includes who drafts the user notice and how it is sent.
What are the rules for children’s data?
Under the Act, a child is anyone who has not completed 18 years. Before processing a child’s personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. It must not process data in ways likely to harm a child’s well-being, and must not undertake tracking, behavioural monitoring or targeted advertising directed at children. The Rules provide limited exemptions for purposes such as healthcare, education and real-time safety.
If you build for students, games, edtech or social features, this is likely the section that affects you most. Treat age checks, parental consent flows and switching off ad targeting for minors as product requirements, not afterthoughts.
What rights do users have, and how fast must you respond?
Users have the right to a summary of their personal data and how it is processed, to correction, completion, updating and erasure, to grievance redressal, and to nominate someone to exercise their rights in the event of death or incapacity. The Government says Data Fiduciaries must respond to such requests within a maximum of 90 days.
What extra duties do Significant Data Fiduciaries have?
The Government can notify some Data Fiduciaries as Significant, based on factors such as the volume and sensitivity of data. They must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments. The Rules add stronger due diligence for deployed technologies and government-specified restrictions on certain data, including localisation where required.
What about AI and machine learning?
The Act does not have a separate chapter on AI, but its principles apply to any system that processes personal data, including training data and prompts. Sensible engineering practices follow from it:
Handling personal data responsibly is part of building AI properly, not an afterthought. Program Zero, Careers Ninza’s 18-month live programme in AI, LLMs and full-stack development, teaches data handling and privacy alongside training and deploying the models themselves.
If you are building AI in Indian languages, the Act’s requirement for notices in scheduled languages connects with the work described in our guide to building AI for Indian languages.
A developer checklist
For the wider security skills behind this checklist, see our overview of what a modern software development course should cover. Program Zero’s Phase 11 covers application, data and AI security, including OWASP Top 10, encryption, secrets management, data minimisation and privacy principles, before a hands-on security audit of your own capstone.
This article summarises the DPDP Act and official Government releases for developers and is not legal advice. The Rules phase in over 18 months from November 2025, so check the current Act and Rules on the Ministry of Electronics and IT website, and involve a qualified lawyer for decisions about your product.
Want to learn this live, with mentors?
Program Zero covers full-stack development, AI and security, including a hands-on security audit of your own capstone, over 18 months of live, mentor-led classes. ₹5,999 for all 18 months; the batch starts 9 January 2027.
Frequently asked questions
Related reading
We teach this, live
Every article here comes from something we teach. Sit in on a free masterclass and judge the mentors yourself.