Skip to content

Guide

Data protection for NGOs: the DPDP Act and Rules

India’s data protection law applies to charities as much as to companies, and its main duties start on 13 May 2027. Here is what counts as personal data, what you will have to do, and how to get ready now.

SocioStory Knowledge desk

Reviewed 10 min read

At a glance10 min read

  • The Digital Personal Data Protection Act, 2023 covers personal data in digital form, including paper records that are later digitised, and applies to NGOs as it does to companies.
  • The DPDP Rules, 2025 were notified on 13 November 2025, and most duties on organisations apply from 13 May 2027.
  • Consent must be free, specific, informed and unambiguous, given after a clear notice, and as easy to withdraw as it was to give.
  • A child is anyone under 18: you need a parent’s or guardian’s verifiable consent before processing a child’s data, and you mustn’t track children or target advertising at them.
  • After a data breach, tell the people affected without delay and inform the Data Protection Board, with a detailed report within 72 hours.
  • Penalties reach ₹250 crore for failing to keep reasonable security safeguards.
On this page
  1. When the Act and the Rules apply
  2. What counts as personal data, and who is responsible
  3. Consent and notices
  4. Children’s data and people with disabilities
  5. Security, breaches and deleting data
  6. People’s rights
  7. Sharing data with funders and partners
  8. Penalties
  9. A checklist to get ready by May 2027
  10. Questions people ask
  11. Sources

The Digital Personal Data Protection Act, 2023 (the DPDP Act) is India’s law on how organisations collect and use people’s personal data, and it applies to NGOs just as it does to companies. Its Rules were notified in November 2025, and most of the duties they place on organisations begin on 13 May 2027, so now is the time to prepare.

NGOs hold some of the most sensitive data there is: beneficiaries’ health and income, children’s school records, survivors’ case notes, donors’ PAN numbers and volunteers’ phone numbers. This guide explains what the law covers, what consent and notices must look like, the extra rules for children, security and breaches, people’s rights and sharing data with funders, and ends with a checklist. It summarises the law; for questions about your own systems, take advice.

When the Act and the Rules apply

DateWhat happens
11 August 2023Parliament enacts the DPDP Act
13 November 2025The DPDP Rules, 2025 are notified. The definitions and the provisions setting up the Data Protection Board of India take effect, but no compliance duties for organisations yet
13 November 2026Rule 4 takes effect: the registration and duties of consent managers, which must be Indian companies
13 May 2027The main duties take effect: notices, security safeguards, breach reporting, retention and erasure, children’s data and people’s rights

What counts as personal data, and who is responsible

Personal data is any data about an individual who can be identified by it or with it: a name, a phone number, a photo, an Aadhaar or PAN number, an attendance register, a case file or a WhatsApp message. The Act covers personal data collected in digital form, and data collected on paper that is later digitised. It doesn’t cover data a person uses only for personal or domestic purposes, or data a person has made public themselves.

The Act uses three roles:

  • the Data Fiduciary decides why and how personal data is processed: your NGO, for the data it collects;
  • the Data Principal is the person the data is about, and for a child, their parent or lawful guardian too;
  • a Data Processor processes data on a fiduciary’s behalf, such as a donor database provider, a survey agency or a cloud service. You may use one only under a valid contract, and you stay responsible for what it does with your data.

The same rules apply to all personal data, but some of what NGOs hold, such as health information, caste, a survivor’s story or a child’s address, can do grave harm if it leaks. Protect it accordingly.

You may process personal data only for a lawful purpose, and either with the person’s consent or for one of the legitimate uses the Act lists. The legitimate uses that matter most to NGOs are:

  • data a person gives you voluntarily for a specific purpose, when they haven’t said they object, such as a phone number given so that you can send a donation receipt;
  • meeting a legal duty to give information to the government, such as reporting donations to the Income Tax Department;
  • responding to a medical emergency, or helping people during a disaster or an epidemic;
  • employment purposes, for your own staff.

For most other things, such as programme records, photos, newsletters and appeals, you will need consent.

The Rules add that the notice must stand on its own, separate from other information, list the personal data item by item and describe each purpose. If your consent is ever questioned, it is for you to prove that you gave notice and got consent, so keep records. For data you collected with consent before the Act took effect, give people a notice as soon as reasonably practicable.

Children’s data and people with disabilities

Under the Act a child is anyone under 18. Before you process any personal data of a child, you need the verifiable consent of a parent or lawful guardian. You must check that the person who says they are the parent is an adult who can be identified, using reliable identity and age details you already hold, or details they give you, including through a token from a service such as DigiLocker.

Two more rules apply to everyone: you mustn’t process a child’s data in a way likely to harm their well-being, and you mustn’t track or monitor children’s behaviour or target advertising at them. The Rules exempt a few kinds of organisations and purposes from the consent and tracking rules, such as health services and an educational institution’s monitoring for its teaching or for children’s safety, but the exemptions are narrow, so take advice before relying on one.

For a person with a disability who can’t take legal decisions even with support, their lawful guardian consents, and you must check the guardianship under the relevant law. Our guide to child protection and safeguarding covers the wider duty to keep children safe.

Security, breaches and deleting data

The Rules set a minimum for reasonable security safeguards: encryption or masking of personal data, control over who can access it, logs that let you spot and investigate unauthorised access, backups, contracts that require your processors to keep data safe, and the organisational measures to make all this work. Logs and the related data must be kept for at least a year.

For a small NGO, that means practical steps: no shared passwords; two-step login for email and databases; access to beneficiary files only for those who need it; no case notes on personal phones or in WhatsApp groups; encrypted laptops; and locked cupboards for paper files.

If there is a personal data breach, such as a lost laptop, a hacked email account or a spreadsheet sent to the wrong group:

  1. tell each person affected without delay, in plain language: what happened, what it may mean for them, what you are doing and what they can do;
  2. tell the Data Protection Board without delay, and send it a detailed report within 72 hours of becoming aware of the breach;
  3. fix the cause, and record what happened.

Deleting data. Erase personal data when consent is withdrawn or its purpose is no longer served, unless another law requires you to keep it, as tax law does for donation records. Publish the contact details of someone who can answer questions about your use of personal data, and set up a way to handle complaints, with replies within a period you publish of no more than 90 days.

People’s rights

People can ask you for a summary of their personal data and how you use it; ask you to correct, complete, update or erase it; complain to you; and nominate someone to use these rights if they die or become unable to. If they aren’t satisfied, they can complain to the Data Protection Board of India, which works online. Appeals against the Board’s decisions go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

Sharing data with funders and partners

CSR funders and other donors often ask for beneficiary lists, photos and case studies. Share aggregated or anonymised figures wherever you can, share personal data only with consent or another lawful ground, and set out in your CSR agreement what will be shared, why and how it will be protected. Never share anything that identifies a child at risk or a survivor.

If you are on a CSR team, ask only for what your compliance and reporting really need: usually numbers, not names. Once a company holds beneficiaries’ personal data for its own purposes, it has duties under the Act too. The same goes for volunteers’ details: use them only for the activity they signed up for, and don’t pass them on.

Penalties

The Data Protection Board can impose penalties of up to ₹250 crore for failing to keep reasonable security safeguards; up to ₹200 crore each for failing to report a breach and for breaking the rules on children’s data; and up to ₹50 crore for other breaches of the Act or the Rules. The maximums are high, and the duties apply whatever an organisation’s size.

A checklist to get ready by May 2027

  1. Map your data: what you collect, from whom, why, where it is kept, who can see it and for how long.
  2. Stop collecting what you don’t need.
  3. Write clear notices in the languages your communities use.
  4. Redo your consent forms, with a separate choice for each purpose, and verifiable consent from parents for children.
  5. Keep consent records you can find again.
  6. Name a person to answer questions about personal data, publish their contact details, and set up a complaints process.
  7. Secure your systems: access control, two-step login, encryption, backups and logs.
  8. Agree data protection terms with every processor.
  9. Write a breach plan that can meet the 72-hour deadline.
  10. Set retention periods, keeping what tax and other laws require.
  11. Train staff and volunteers, and add data protection to your policies.

For donors’ data in particular, see our guide to individual giving and crowdfunding.

Questions people ask

Does the DPDP Act apply to NGOs?

Yes. The Digital Personal Data Protection Act, 2023 applies to any organisation that processes digital personal data, charities included, and has no general exemption for NGOs. Most of its duties on organisations, such as notices, security, breach reporting and the rules on children’s data, apply from 13 May 2027.

When do the DPDP Rules come into force?

In phases. The DPDP Rules, 2025 were notified on 13 November 2025, when the definitions and the Data Protection Board provisions took effect. The rules on consent managers start on 13 November 2026, and the main duties on organisations start on 13 May 2027.

Does an NGO need consent to keep donors’ details?

Not always. The Act allows you to use data a donor gave you voluntarily for a specific purpose, such as issuing a receipt, and to meet legal duties such as reporting donations to the Income Tax Department. For other uses, such as newsletters and appeals, get consent, make it easy to withdraw, and keep only what you need.

Can an NGO collect children’s data under the DPDP Act?

Yes, but you need the verifiable consent of a parent or lawful guardian first, and you must check that the person consenting is an adult who can be identified. You mustn’t process a child’s data in a way likely to harm their well-being, or track children or target advertising at them. The exemptions in the Rules are narrow.

What should an NGO do after a data breach?

Tell each person affected without delay, in plain language, what happened, what it may mean for them and what they can do. Tell the Data Protection Board without delay too, and send it a detailed report within 72 hours of becoming aware of the breach. Then fix the cause and keep a record.

Sources

  1. Digital Personal Data Protection Act, 2023 · Ministry of Electronics and Information Technology
  2. Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) · Ministry of Electronics and Information Technology
  3. DPDP Rules, 2025 notified: backgrounder (17 November 2025) · Press Information Bureau
  4. MeitY reply in Parliament on the DPDP Rules (5 August 2026) · Press Information Bureau

Go deeper in the Academy

Your work deserves a story.

Tell us what you’ve done. Our editors will help you shape it, free.

Share your story
  • Starting an NGO

    Policies every NGO should have: a checklist

    Policies turn good intentions into habits that funders can check. Here are the ones every NGO needs, what each should say, which the law requires, which funders ask for, and how to adopt and review them.

    Checklist · 10 min read

  • People and safeguarding

    Consent, photos and dignity in storytelling

    A photo or a story can win support for good work, or strip someone of their dignity and put them at risk. Here is how to ask for consent properly, protect children and survivors, and keep records that show you did.

    Guide · 10 min read

  • Funding for NGOs

    Individual giving and crowdfunding

    Money from individuals is the most flexible funding an NGO can have, and the slowest to build. Here is how to start, what the law requires for receipts, tax and donors’ data, and what to check before you crowdfund.

    Guide · 10 min read

  • People and safeguarding

    Child protection and safeguarding for NGOs

    Any organisation that works with children must keep them safe, and act fast when something is wrong. Here is what the law requires, what a good policy contains and exactly what to do if you are worried about a child.

    Guide · 11 min read