DPDP Act

Trust, Privacy & ComplianceDPDPalso: Digital Personal Data Protection Act 2023also: India data protection lawalso: DPDP Act 2023

Not legal advice. This page describes legal and regulatory frameworks in general terms. Jurisdiction changes the answer, and the same voice deployment can be lawful in one market and unlawful in another. Take advice on your specific circumstances.

In one sentence

The DPDP Act is the Indian data protection law, built around consent as the principal basis for processing, which makes it narrower than GDPR in exactly the place most international deployments assume it will be looser.

13 May 2027 Digital Personal Data Protection Act 2023 and implementing Rules, 2025Last reviewed 30 July 2026

Not to be confused with GDPR.

Definition

The DPDP Act is the Indian data protection law. It governs how organizations handle personal data about people in India.

It runs on consent, and that is the one thing to carry away from it.

The Digital Personal Data Protection Act 2023 set up the framework. Implementing Rules landed in November 2025, and compliance phases in, with the full obligation due on 13 May 2027. It parts company with GDPR in ways that change designs, and treating a European position as portable is an error.

Five structural differences that change the design

  • Consent-primary. The Act leans on consent, with a narrow band of alternative grounds it calls legitimate uses. Nothing in it plays the part GDPR gives to legitimate interests, and that missing flexibility is one a lot of international deployments quietly rely on.
  • Fixed penalty ceilings. The Act names amounts, up to Rs 250 crore, in place of a share of global turnover. For a multinational that ceiling sits below the GDPR maximum. For an Indian SME it does not.
  • No separate biometric category. Nothing carves biometric or voice data out for special treatment the way GDPR Article 9 does. For voice that absence is real and it has consequences, because a voiceprint ends up under the general obligations instead of heightened ones.
  • Different vocabulary. The controller is a Data Fiduciary, the data subject is a Data Principal, and an entity over certain thresholds becomes a Significant Data Fiduciary with extra obligations attached.
  • Consent Manager. Registered intermediaries are contemplated, through which a person handles consents across several organizations at once. GDPR has no counterpart, and it is the most distinctive piece of the design.

What a voice deployment has to do

  • The notice has to be clear and itemized, naming the personal data and the purposes.
  • Consent has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and it has to be withdrawable.
  • Purpose limitation and data minimization both apply.
  • Erasure obligations bite when consent is withdrawn, or once the purpose has stopped being served.
  • Breach notification requirements apply.
  • Data about children gets specific protection, including limits on tracking and on behavioral advertising aimed at them.

Because consent is the principal basis, the practical consequence for an Indian voice deployment is that keeping transcripts, deriving sentiment and any later use for model improvement each have to sit inside the consent that was given, and each has to appear in the notice. Withdrawal has to erase, which lands the same architectural demand GDPR lands: being able to locate and remove every artifact that came from one person.

This page describes a statute and its Rules and is not legal advice. The compliance timeline is still running, interpretation is unsettled, and an Indian deployment needs advice checked against the Act and the Rules themselves rather than against a summary.

Common misconception

That the DPDP Act is a softer GDPR, cleared automatically by a GDPR position. Without a broad legitimate-interests basis, designs that pass in Europe can fail in India, because the ground they stand on is not there. People expect the gap to run the other way.

Why it matters commercially

Any voice deployment with Indian users, and any vendor based in India, answers to this framework. Consent sitting at the center changes the product rather than the paperwork, because a feature riding on legitimate interests in another market needs an explicit ask here.

In voice specifically

GDPR treats a voiceprint used to identify somebody as biometric data with heightened protection. The DPDP Act builds no equivalent category, so the same voiceprint answers to the general obligations. Read that as an open question rather than a permission: guidance on voice data has not been developed much, and the general obligations still apply in full.

Where AsqVox fits

This is the governing framework for any Indian deployment. The Orb holds transcripts, sentiment and lead data, and each one needs a consent whose scope reaches retention and use rather than collection alone, spelled out in the notice at the moment it is given. The missing biometric category is worth noting neutrally rather than reading as a license.

Visual

DPDP against GDPR, four differences that change designs

DPDP against GDPR, four differences that change designsDPDP ActGDPRWhat it changesLawful basisConsent-primary, plus narrow legitimateusesSix bases including broad legitimateinterestsDesigns relying on legitimate interestsmay not transfer to IndiaPenalty structureFixed amounts, up to Rs 250 croreUp to EUR 20m or 4 percent of globalturnoverA lower ceiling for a multinational, notfor an SMEBiometric and voice dataNo separate special categoryArticle 9 special category protectionVoiceprints governed by generalobligations in IndiaInfrastructureConsent Manager intermediariescontemplatedNo direct equivalentA registered layer for handling consentacross organizations

GDPR compliance does not automatically satisfy this. The gap runs the other way from what people expect.

The timeline behind the table: enactment in 2023, implementing Rules in November 2025, full compliance due 13 May 2027. Dates and thresholds in this area move, so verify against the Act and the Rules rather than restating them from a secondary source.

Statistics

Every figure carries its source and year. Vendor numbers are labelled as vendor numbers, and where no reliable figure exists this page says so rather than borrowing one.

Enactment came in 2023. The implementing Rules were notified in November 2025, and compliance phases in, with the full obligation due on 13 May 2027.

13 May 2027industry range

Digital Personal Data Protection Act 2023 and implementing Rules, 2025 - The phased timeline is why enforcement practice is nascent. Use the deadline as a planning anchor and verify it against the Rules before it goes in a contract.

Penalties take the form of fixed monetary ceilings, capped at Rs 250 crore, in place of a turnover percentage.

Up to Rs 250 croreindustry range

Digital Personal Data Protection Act 2023, 2023 - The structure matters more than the number. Quoting a turnover-linked penalty overstates the exposure for a small company and understates it for a large one.

Consent is the principal basis. A limited set of alternative legitimate uses sits beside it, and nothing in the Act plays the role GDPR Article 6(1)(f) plays.

Consent-primaryindustry range

Digital Personal Data Protection Act 2023, 2023 - This is the provision that invalidates transplanted European designs. Anything resting on legitimate interests in the EU needs an explicit consent path in India.

Biometric and voice data get no category of their own, so there is nothing here matching GDPR Article 9.

No special categoryindustry range

Digital Personal Data Protection Act 2023, 2023 - An absence rather than an exemption. General obligations still reach voiceprints, and guidance may develop in a direction that narrows this.

Estimates of the India conversational AI market for 2024 sit between roughly USD 455 million and USD 653 million, depending on which research firm you read.

USD 455m to 653manalyst forecast

Research firm estimates for the India conversational AI market, 2024 - The spread is the useful fact. Two reputable estimates of a single year differ by around 40 percent, which is what an early category looks like from outside.

Indian voice platform pricing runs from about Rs 7 per minute down to about Rs 3 per minute at volume, at Bolna, which raised a USD 6.3 million seed round led by General Catalyst in January 2026.

Rs 7 to Rs 3 per minutevendor claim

Bolna published pricing and funding announcement, 2026 - Published by the vendor. Useful as an Indian price point rather than as a comparison against dollar-denominated platform rates, which are set against a different cost base.

Enforcement under the Act is nascent, since the phased timeline has not finished running, and no meaningful body of precedent exists to cite.

-no reliable figure

Any claim about how a provision will be read is speculation at this point, including a confident one from a vendor.

Guidance dealing specifically with voice data has not been developed at any length.

-no reliable figure

Treat the missing biometric category as an open question rather than settled permission. It is the kind of gap that tends to close rather than widen.

Examples

In practice

An international company runs a voice agent in India and leans on legitimate interests for transcript retention and quality analysis, the way it does in Europe. That ground is not available in the same form here, so the retention needs a consent covering the purpose by name. The remedy is a rewrite of the notice and the consent flow, cheap when it is caught early and awkward once a year of data has piled up behind it.

The everyday version

The DPDP Act is the Indian data protection law, and what to remember is how much of it rests on asking first. Europe leaves room to justify some uses of data without explicit consent. India leaves less of it, so keeping recordings or reusing what somebody said generally means having asked.

Usage

Who says it

  • Indian privacy and legal practitioners, precisely.
  • Compliance teams anywhere that serves Indian users.
  • Indian enterprise procurement, increasingly, as a qualifying requirement rather than a preference.

Where it turns up

  • Alongside notice and consent mechanisms, how withdrawal is handled, erasure, breach notification, questions about data localization, and the obligations attaching to a Significant Data Fiduciary.
  • Indian public sector procurement, and regulated industries, apply it most stringently of all.

Common misuse

  • Assuming GDPR compliance carries over. The lawful basis structure is built differently.
  • Reading the missing biometric category as freedom to handle voiceprints as you like. The general obligations have not gone anywhere, and guidance may yet arrive.
  • Quoting a turnover-linked penalty. The ceilings are fixed sums, and getting that wrong misstates the risk in one direction for a small company and the other for a large one.

Questions people ask

Is the DPDP Act the same as GDPR?

No, and the differences change designs. The Act runs on consent, with a narrow band of alternative legitimate uses and nothing playing the part GDPR gives to legitimate interests. Penalties are fixed sums capped at Rs 250 crore rather than a percentage of turnover, and biometric or voice data gets no category of its own. A GDPR position does not clear a deployment here.

When does the DPDP Act take full effect?

Enactment was in 2023, the implementing Rules arrived in November 2025, and compliance phases in with the full obligation due on 13 May 2027. Enforcement practice is nascent while that timeline runs, so there is little precedent to reason from and any prediction about interpretation is speculation.

Does the DPDP Act treat voice as biometric data?

It builds no special category for biometric or voice data of the kind GDPR sets out in Article 9. A voiceprint therefore answers to the general obligations rather than heightened ones. Read that as an open question rather than settled permission, since guidance on voice data has not been developed at any length.

What are the penalties under the DPDP Act?

They are fixed monetary ceilings, capped at Rs 250 crore, in place of a share of global turnover. For a large multinational that sits below the GDPR maximum. For an Indian SME it does not, and quoting a turnover-linked figure misstates the exposure in one direction or the other.

Share this definition

Last reviewed 30 July 2026. Written and reviewed by Dhruv Dholakia, founder of AsqVox.