Glossary

DPDP Act 2023

The DPDP Act 2023 is India’s law on digital personal data: it sets how businesses may collect, use and protect it, and the rights of the people it describes.

Also called Digital Personal Data Protection Act, 2023; DPDP Act; DPDPA.

It also sets the penalties for getting data handling wrong. The Act (No. 22 of 2023) (PDF), opens in a new tab is dated 11 August 2023.

How it works

The Act uses its own vocabulary:

  • Data Principal: the person the data is about, such as a home buyer who enquired.
  • Data Fiduciary: whoever decides why and how the data is processed, such as the developer running the campaign.
  • Data Processor: anyone processing data on the fiduciary’s behalf, such as a calling or CRM vendor.

Consent, under section 6(1), must be “free, specific, informed, unconditional and unambiguous with a clear affirmative action”, and limited to the data needed for the stated purpose. Under section 6(4), withdrawing consent must be as easy as giving it. Under section 8, the fiduciary stays responsible for processing done on its behalf, may use a processor only under a valid contract, and must take reasonable security safeguards. The penalty for failing to take those safeguards can reach ₹250 crore.

When it applies

The Act comes into force in stages. The DPDP Rules, 2025 were notified in November 2025 with an 18-month phased timeline, and the Rules on notice, security safeguards, breach reporting and retention periods take effect 18 months after publication, around May 2027. The Data Protection Board of India has been established, and MeitY invited applications for its chairperson and members in May 2026 (PDF), opens in a new tab. As of September 2026, most of the duties on businesses are therefore still in their transition period.

Why it matters for sales teams

A lead list is personal data. So are call recordings, transcripts and the notes a salesperson or an AI voice agent writes after a call. Under the Act, a developer should be able to say why it holds each lead, for what purpose it will call, how long it keeps recordings, and how a buyer can ask for their data to be corrected or erased. A calling vendor should be working under a contract that says what it may do with the data, and nothing more.

Example

A buyer in Chennai enquired about a 2 BHK, spoke to the developer’s team twice and then bought elsewhere. She writes asking the developer to delete her details. Once the Act’s obligations apply, the developer has to be able to find her across its CRM, its recordings and its vendors’ systems, act on the request, and keep only what another law requires it to keep.

Common confusions

  • DPDP consent vs TCCCPR consent. They are different permissions. Consent under TCCCPR 2018 is about receiving commercial calls and SMS; consent under the DPDP Act is about processing personal data. TRAI’s Third Amendment of September 2026 (PDF), opens in a new tab says so directly: nothing in TCCCPR exempts a sender from its DPDP obligations.
  • DPDP vs DND. A DND preference in the NCPR is a telecom rule about calls. A DPDP erasure request is a data rule about records. A buyer can make either, or both.
  • “DPDP compliant” software. Compliance belongs to the data fiduciary. A vendor can make it easier, for example by keeping each client’s data separate and recordings private, but it cannot be compliant on the client’s behalf.

This entry summarises the Act as of September 2026 and is not legal advice.

Your phone, answered.In their language.

Tell us how your leads arrive today. We will show you the agent that answers and calls them.