Introduction
The Digital Personal Data Protection (DPDP) Act, 2023 has introduced new rules for businesses that collect, store, or use personal data in India. The Act also sets penalties for non-compliance and provides exemptions in certain situations. Gaining first hand knowledge on these rules helps businesses protect personal data, avoid legal problems, and meet their compliance responsibilities.
What Happens If A Business Fails To Protect Personal Data?
Businesses that handle personal data are expected to keep it safe by using reasonable security measures. Under the Information Technology (IT) Act, 2000, if a business fails to protect personal information because of negligence and this causes loss or harm to someone, it may have to pay compensation. The Act also provides penalties for breaching confidentiality, privacy, or sharing personal information without permission.
What Are The Penalties Under The DPDP Act?
The DPDP Act, 2023 allows the government to impose financial penalties on businesses that fail to comply with the law. Depending on the type of violation, penalties can range from ₹5 crore to ₹250 crore. The Act also places certain responsibilities on individuals, known as Data Principals. If they fail to follow their duties under the Act, they may face a penalty of up to ₹10,000. The Government of India may revise these penalties in the future, but they cannot be increased beyond twice the current limit set under the Act.
How Does The Data Protection Board Decide A Penalty?
The Data Protection Board of India (DPBI) is responsible for investigating complaints and deciding penalties under the DPDP Act. Before imposing a penalty, the Board considers several factors. These include how serious the breach was, how long it continued, the type of personal data involved, whether the business had committed similar breaches before, whether it gained any benefit from the violation, and whether it took quick steps to reduce the impact of the breach.
What Happens If A Business Does Not Follow CERT-In Directions?
Businesses must also follow the Cyber Security Directions issued by CERT-In. If an organisation fails to provide information requested by CERT-In or does not comply with these directions, it may face imprisonment of up to one year, a fine of up to ₹1 crore, or both.
Are Some Businesses Exempt From Certain DPDP Rules?
The DPDP Act allows the Government to exempt certain Data Fiduciaries, including some startups, from specific obligations. These exemptions depend on the type and amount of personal data they process. For example, exempt businesses may not have to issue consent notices, erase personal data after the purpose is completed, obtain parental consent for children’s data, or follow some of the additional rules that apply to Significant Data Fiduciaries (SDFs).
Are There Exemptions For Certain Types Of Data Processing?
The DPDP Act also provides exemptions when personal data is processed for specific purposes. These include enforcing legal rights, court or regulatory proceedings, investigating offences, processing data for foreign companies under a contract, court-approved mergers or acquisitions, and debt recovery activities.
Is Research Covered By The DPDP Act?
The Act provides exemptions for personal data used for research, archiving, or statistical purposes, as long as the data is not used to make decisions about a particular individual. Even in these cases, organisations must process only the data they need, keep it secure, maintain reasonable accuracy, and retain it only for as long as necessary.
Are Government Bodies Exempt?
The DPDP Act allows the Government of India to exempt certain government agencies when personal data is processed for reasons such as national security, public order, or the sovereignty and integrity of India. The Government may also notify additional exemptions for certain businesses or categories of businesses during the first five years after the Act comes into force.
Why Is It Important To Understand These Rules?
Knowing the penalties and exemptions under the DPDP Act helps businesses understand their legal responsibilities. It also helps them improve their data protection practices, reduce compliance risks, and prepare for future regulatory requirements.
Conclusion
The DPDP Act, 2023 introduces clear rules for protecting personal data in India. It also sets penalties for businesses that fail to comply while providing exemptions in certain situations. By understanding these provisions and following good data protection practices, businesses can stay compliant, reduce legal risks, and build trust with customers.


