DPDP Learning Series · #02 · Module 1

DPDP Act 2023 Explained

Section 1 — Short Title & Commencement and Section 2 — Definitions.

Indian Parliament building illustration
Slide 2 · Section 1

Why Start with Section 1?

Every law begins with its identity. Before diving into obligations, rights, or penalties, a statute must first establish two foundational facts — its name and when it takes effect. Section 1 of the DPDP Act answers exactly these two questions.

What is the name of this law?

The official title by which the Act is recognized in all legal, regulatory, and business contexts.

When does it become operational?

The mechanism by which the Central Government brings different provisions into force — potentially on different dates.

Slide 3 · Section 1

Official Name of the Act

The law is officially known as the Digital Personal Data Protection Act, 2023.

This is the precise legal title that must be used consistently across all contexts — including internal policies, privacy notices, board presentations, vendor agreements, and regulatory filings. Using an incorrect or abbreviated name in formal documents can create ambiguity about which law is being referenced.

Always use the full title in legal documents, compliance policies, and formal correspondence to avoid misinterpretation.

Slide 4 · Section 1

Does the Entire Act Start at Once?

No.

The DPDP Act does not come into force all at once. The Central Government retains the authority to decide when specific provisions become operational, by issuing notifications in the Official Gazette.

This means different parts of the Act may — and likely will — commence on different dates, giving stakeholders time to prepare for each phase.

Enacted by Parliament

The Act received Presidential assent and was published — but this alone does not make every provision operative.

Notified by the Government

The Central Government issues official notifications specifying which provisions are now in force and from which date.

Slide 5 · Section 1

Why Is This Distinction Important?

Passing a law and implementing a law are two distinct legal stages. Understanding this difference is critical for compliance professionals — acting too early on a provision not yet notified, or too late on one already in force, both carry risk.

Enactment

Parliament passes the Bill. The President provides assent. The Act is published in the Official Gazette. It exists as law — but is not yet enforceable.

Commencement

The Central Government issues a notification specifying the effective date for a specific provision. Only from this point is compliance required and enforcement possible.

Phased Approach

Many major data protection laws globally have used phased commencement. The DPDP Act follows this model, allowing organizations time to build systems and processes incrementally.

Slide 6 · Section 1

A Practical Example

Consider a company that launches its DPDP compliance project shortly after the Act was passed. Two teams take very different approaches — and only one gets it right.

❌ Team A

Assumes every provision of the DPDP Act is immediately applicable from the date of enactment and begins implementing all requirements at once — including provisions not yet notified by the Government.

✅ Team B

First checks the Official Gazette for Government notifications. They identify exactly which provisions are currently in force, prioritize those, and build a phased roadmap for the rest.

Team B is legally correct. Compliance actions should always be anchored to provisions that have been officially notified as operative.
Slide 7 · Section 1

The Business Perspective

For organizations planning or executing DPDP compliance programs, understanding commencement is not just a legal technicality — it directly shapes project planning, resource allocation, and risk prioritization. Before mobilizing any compliance effort, answer these three questions first.

1. Which provisions are already operational?

Review the most recent Official Gazette notifications to identify provisions currently in force. These require immediate compliance action.

2. Which provisions are yet to be notified?

Identify provisions that have been enacted but not yet commenced. Plan and prepare for these, but do not treat them as currently enforceable obligations.

3. What actions are required today?

Build your compliance roadmap around notified provisions first. Track the Government’s official communications regularly to update your plan.

Slide 8 · Section 1

A Common Misconception — Corrected

One of the most frequent errors organizations make is treating the date of Parliamentary enactment as the date of full applicability. This misunderstanding can lead to compliance gaps or premature and misdirected effort.

❌ The Misconception

The DPDP Act became fully applicable to all organizations immediately after it was passed by Parliament and received Presidential assent in August 2023.

✅ The Correct Position

Different provisions of the DPDP Act become effective on different dates, as specified by the Central Government through official notifications published in the Official Gazette. Full applicability requires phased commencement.

Slide 9 · Section 1

Key Takeaways from Section 1

Follow NotificationsDon’t Assume OperabilityCheck CommencementUse Correct Name

Section 1 may be the shortest section of the DPDP Act, but it establishes the legal foundation for everything that follows.

Slide 10 · Section 2

DPDP Act 2023 Explained: Section 2 — Definitions

DPDP ACT SERIES · MODULE 1 · INTRODUCTION & FOUNDATION

Slide 11 · Section 2

Why Are Definitions Important?

Every law has its own language. Before understanding rights, obligations or penalties, we must understand what the law means by specific terms. Section 2 provides that foundation.

Legal Language

Laws use precise terms that may differ from everyday meaning.

Foundation First

Definitions must be understood before obligations can be interpreted correctly.

Section 2’s Role

Section 2 is the starting point for understanding the entire DPDP Act.

Slide 12 · Section 2

Section 2 Contains Key Definitions

The Act defines important terms that are used throughout every provision.

1 · Personal Data2 · Digital Personal Data3 · Data Principal4 · Data Fiduciary5 · Data Processor6 · Consent Manager7 · Child8 · Data Protection Officer9 · Board
Slide 13 · Section 2

Why Should Businesses Care?

Understanding these definitions helps organizations approach the DPDP Act with clarity and confidence.

Interpret the law correctlyIdentify their legal roleUnderstand responsibilitiesAvoid incorrect assumptionsBuild effective compliance programs
Slide 14 · Section 2

One Wrong Definition Can Change Everything

Your legal role under the DPDP Act depends entirely on how you are defined. Each role carries different responsibilities.

Data Fiduciary

Determines the purpose and means of processing personal data. Bears the primary compliance obligations.

Data Processor

Processes data on behalf of a Data Fiduciary. Obligations are narrower but still significant.

Data Principal

The individual whose personal data is being processed. Holds rights under the Act.

Slide 15 · Section 2

Section 2 Is the Dictionary of the DPDP Act

Come back to Section 2.

Whenever you are confused about any provision, most legal questions can be answered by first understanding the defined terms.

Confused by a provision?

Check how Section 2 defines the key terms used in that provision.

Drafting a policy?

Ensure every term you use aligns with the Act’s own definitions.

Slide 16 · Section 2

A Common Mistake — Corrected

❌ The Common Mistake

Many professionals start reading the Act from compliance obligations — jumping straight to duties, penalties, and consent requirements without first understanding the defined terms.

✅ The Better Approach

Learn the definitions first. Once you understand what the Act means by “Data Fiduciary”, “Personal Data”, or “Consent Manager”, every other provision becomes significantly easier to interpret and apply.

Slide 17 · Section 2

Key Takeaways from Section 2

Avoid Everyday MeaningIdentify Legal RoleProvisions Rely on TermsDefinitions as Foundation

Section 2 is not just a glossary — it is the interpretive lens through which every other provision of the DPDP Act must be read.

Slide 18 · Additional Concepts

Core Concepts at the Heart of DPDP

Professionals discussing digital data governance

Data Principal

The individual whose personal data is being processed.

Data Fiduciary

Decides the purpose and means of processing.

Data Processor

Processes data on a Fiduciary’s behalf.

Digital Personal Data

Personal data in digital or digitised form.

Consent Manager

Manages consent on behalf of Data Principals.

Slide 19 · Next

Coming Up Next in the DPDP Learning Series

When Does the DPDP Act Apply?

Understanding the Applicability of the Digital Personal Data Protection Act, 2023 — Section 3.

Slide 20 · Important Notice

Disclaimer

Legal scales and documents representing legal guidance

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.