New Delhi: The Ministry of Electronics and Information Technology (MeiTY) has notified major rules under the Digital Personal Data Protection (DPDP) Act, 2023, which affirms the right to privacy and the need for a law to protect against data misuse. This act now requires companies, especially e-commerce, SaaS or government organizations, to seek your consent for using your data, with certain exemptions.
According to this law, all e-commerce, SaaS, social media or government organizations having more than 50 lakh users will have to follow certain rules and regulations when it comes to using the data you share with these platforms.
These platforms, or data fiduciaries, will have to undertake an annual audit and a Data Protection Impact Assessment to comply with the provisions of this Act. For users, this means greater protection from data misuse, especially for users under the age of 18. The Act requires companies to have a ‘Consent Manager’ responsible for compliance with the law.
Under the DPDP Act, 2023, a Consent Manager serves as a key enabler of trust and transparency in the digital ecosystem.#DataMeraNiyantranMera#DigitalIndia #DPDPAct #DPDP #PrivacyMatters pic.twitter.com/ab1Sw4eQrl
— Digital Personal Data Protection Act (@ind_dpdp) April 16, 2025
To ensure safety of underage users, the Act bars platforms from tracking them, especially for targeted advertisements. Additionally, the Act regulates the transfer of personal data of Indians overseas and outlines the conditions under which it is acceptable.
Industry leaders react
The first draft of the DPDP ACt, enacted in 2017, was furiously resisted by technology firms, as it imposed unacceptable conditions on data localisation. The new rules, however, have been relatively more welcomed by both Indian and global tech firms, as this Act was the need of the hour.
“The DPDP rules offer clarity of terms to companies, such as defining the timeline within which the privacy rules are to be implemented. It was also important to clarify exemptions to usage of underage personal data for enabling safety features for children—such as applications that parents use for tracking location, ensuring children see age-appropriate content and ads, etc. With these features now notified, a key industry demand has been clearly responded to by the Centre.” Aparajita Bharti, founding partner at policy consultancy firm The Quantum Hub, told Live Mint.
However, RTI activists have decried certain sections of the Act, which protect personal information that remains crucial for transparency in public records.
“Section 44.3 of the DPDP Act exempts all “personal information” from disclosure under RTI. For example, if someone asks for the name of a contractor involved in corruption, they can be told it is personal information. Similarly, the names of government employees, ministers, or their family members allegedly engaged in wrongdoing cannot be disclosed,” Anjali Bhardwaj, an RTI activist, explained in an interview.
Despite this, the Act is expected to address a growing challenge with privacy, especially as AI-enabled software has complicated the way data can be misused by vested interests.
Until now, most companies have managed data in good faith in India, and this law will help make data protection and privacy a responsibility that will be taken seriously.









