DPDP Act 2023 Explained
Section 1 — Short Title & Commencement and Section 2 — Definitions.

Why Start with Section 1?
Every law begins with its identity. Before diving into obligations, rights, or penalties, a statute must first establish two foundational facts — its name and when it takes effect. Section 1 of the DPDP Act answers exactly these two questions.
What is the name of this law?
The official title by which the Act is recognized in all legal, regulatory, and business contexts.
When does it become operational?
The mechanism by which the Central Government brings different provisions into force — potentially on different dates.
Official Name of the Act
This is the precise legal title that must be used consistently across all contexts — including internal policies, privacy notices, board presentations, vendor agreements, and regulatory filings. Using an incorrect or abbreviated name in formal documents can create ambiguity about which law is being referenced.
Always use the full title in legal documents, compliance policies, and formal correspondence to avoid misinterpretation.
Does the Entire Act Start at Once?
The DPDP Act does not come into force all at once. The Central Government retains the authority to decide when specific provisions become operational, by issuing notifications in the Official Gazette.
This means different parts of the Act may — and likely will — commence on different dates, giving stakeholders time to prepare for each phase.
Enacted by Parliament
The Act received Presidential assent and was published — but this alone does not make every provision operative.
Notified by the Government
The Central Government issues official notifications specifying which provisions are now in force and from which date.
Why Is This Distinction Important?
Passing a law and implementing a law are two distinct legal stages. Understanding this difference is critical for compliance professionals — acting too early on a provision not yet notified, or too late on one already in force, both carry risk.
Enactment
Parliament passes the Bill. The President provides assent. The Act is published in the Official Gazette. It exists as law — but is not yet enforceable.
Commencement
The Central Government issues a notification specifying the effective date for a specific provision. Only from this point is compliance required and enforcement possible.
Phased Approach
Many major data protection laws globally have used phased commencement. The DPDP Act follows this model, allowing organizations time to build systems and processes incrementally.
A Practical Example
Consider a company that launches its DPDP compliance project shortly after the Act was passed. Two teams take very different approaches — and only one gets it right.
❌ Team A
Assumes every provision of the DPDP Act is immediately applicable from the date of enactment and begins implementing all requirements at once — including provisions not yet notified by the Government.
✅ Team B
First checks the Official Gazette for Government notifications. They identify exactly which provisions are currently in force, prioritize those, and build a phased roadmap for the rest.
The Business Perspective
For organizations planning or executing DPDP compliance programs, understanding commencement is not just a legal technicality — it directly shapes project planning, resource allocation, and risk prioritization. Before mobilizing any compliance effort, answer these three questions first.
1. Which provisions are already operational?
Review the most recent Official Gazette notifications to identify provisions currently in force. These require immediate compliance action.
2. Which provisions are yet to be notified?
Identify provisions that have been enacted but not yet commenced. Plan and prepare for these, but do not treat them as currently enforceable obligations.
3. What actions are required today?
Build your compliance roadmap around notified provisions first. Track the Government’s official communications regularly to update your plan.
A Common Misconception — Corrected
One of the most frequent errors organizations make is treating the date of Parliamentary enactment as the date of full applicability. This misunderstanding can lead to compliance gaps or premature and misdirected effort.
❌ The Misconception
The DPDP Act became fully applicable to all organizations immediately after it was passed by Parliament and received Presidential assent in August 2023.
✅ The Correct Position
Different provisions of the DPDP Act become effective on different dates, as specified by the Central Government through official notifications published in the Official Gazette. Full applicability requires phased commencement.
Key Takeaways from Section 1
Section 1 may be the shortest section of the DPDP Act, but it establishes the legal foundation for everything that follows.
DPDP Act 2023 Explained: Section 2 — Definitions
DPDP ACT SERIES · MODULE 1 · INTRODUCTION & FOUNDATION
Why Are Definitions Important?
Every law has its own language. Before understanding rights, obligations or penalties, we must understand what the law means by specific terms. Section 2 provides that foundation.
Legal Language
Laws use precise terms that may differ from everyday meaning.
Foundation First
Definitions must be understood before obligations can be interpreted correctly.
Section 2’s Role
Section 2 is the starting point for understanding the entire DPDP Act.
Section 2 Contains Key Definitions
The Act defines important terms that are used throughout every provision.
Why Should Businesses Care?
Understanding these definitions helps organizations approach the DPDP Act with clarity and confidence.
One Wrong Definition Can Change Everything
Your legal role under the DPDP Act depends entirely on how you are defined. Each role carries different responsibilities.
Data Fiduciary
Determines the purpose and means of processing personal data. Bears the primary compliance obligations.
Data Processor
Processes data on behalf of a Data Fiduciary. Obligations are narrower but still significant.
Data Principal
The individual whose personal data is being processed. Holds rights under the Act.
Section 2 Is the Dictionary of the DPDP Act
Whenever you are confused about any provision, most legal questions can be answered by first understanding the defined terms.
Confused by a provision?
Check how Section 2 defines the key terms used in that provision.
Drafting a policy?
Ensure every term you use aligns with the Act’s own definitions.
A Common Mistake — Corrected
❌ The Common Mistake
Many professionals start reading the Act from compliance obligations — jumping straight to duties, penalties, and consent requirements without first understanding the defined terms.
✅ The Better Approach
Learn the definitions first. Once you understand what the Act means by “Data Fiduciary”, “Personal Data”, or “Consent Manager”, every other provision becomes significantly easier to interpret and apply.
Key Takeaways from Section 2
Section 2 is not just a glossary — it is the interpretive lens through which every other provision of the DPDP Act must be read.
Core Concepts at the Heart of DPDP

Data Principal
The individual whose personal data is being processed.
Data Fiduciary
Decides the purpose and means of processing.
Data Processor
Processes data on a Fiduciary’s behalf.
Digital Personal Data
Personal data in digital or digitised form.
Consent Manager
Manages consent on behalf of Data Principals.
Coming Up Next in the DPDP Learning Series
When Does the DPDP Act Apply?
Understanding the Applicability of the Digital Personal Data Protection Act, 2023 — Section 3.
Disclaimer

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.