What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's primary law governing how organisations collect, store, use, and share personal data of Indian citizens. It received Presidential assent on 11 August 2023 and applies to any entity — company, platform, or individual — that processes digital personal data of people in India.
Before the DPDP Act, India had no dedicated data protection legislation. Personal data collection happened informally — landlords received Aadhaar cards on WhatsApp with no consent record, no stated purpose, and no right of deletion for the person whose data was shared. The DPDP Act changes this structurally.
Key Terms — Plain Language
| Term | What it means in practice |
|---|---|
| Data Principal | The person whose data is being collected — in the rental context, this is the tenant. They have rights over their own data. |
| Data Fiduciary | The entity collecting and processing the data — in the rental context, this is Tenanting (and through it, the landlord). They have obligations. |
| Personal Data | Any data that can identify a person — name, Aadhaar number, PAN, mobile number, address, employment details, income, photographs. |
| Consent | The tenant's explicit, informed agreement to share specific data for a specific purpose. Must be given freely, not as a condition of something unrelated. |
| Purpose Limitation | Data collected for rental verification cannot be used for advertising, profiling, or any other purpose. The stated purpose is the only permitted use. |
| Data Processor | A third party that processes data on behalf of the Fiduciary — e.g. AWS S3 for storage, MSG91 for notifications. Bound by the same rules. |
Your Rights as a Tenant (Data Principal)
Under the DPDP Act, every tenant whose data is collected has the following rights:
- Right to Information — You must be told what data is being collected, why it is being collected, and who it will be shared with — before you share anything.
- Right to Consent — Your consent must be free, specific, informed, and unambiguous. A single checkbox buried in terms is not valid DPDP consent.
- Right to Withdraw Consent — You can withdraw consent at any time. Withdrawal does not affect the legality of processing done before withdrawal, but the Fiduciary must stop processing after withdrawal.
- Right to Correction — You can request correction or updating of inaccurate personal data.
- Right to Erasure — You can request deletion of your personal data. The Fiduciary may retain what is required by law (e.g. financial records for 7 years under the Income Tax Act) but must delete the rest.
- Right to Grievance Redressal — You have the right to have grievances about data handling addressed by the Fiduciary within a defined timeframe.
- Right to Nominate — In the event of death or incapacity, you can nominate someone to exercise your data rights on your behalf.
What Landlords Must Do
If you use a digital platform to collect tenant data, you are a Data Fiduciary under the DPDP Act. Your obligations:
- Collect only what you need — You cannot collect data "just in case." Every field collected must have a stated purpose. Aadhaar is for identity verification. PAN is for tax documentation. Salary slip is for income verification. That is the limit.
- Get valid consent before collection — You must inform the tenant of what is collected and why before they submit anything. Consent must be per-category, not a blanket "I agree to everything."
- Protect the data — You are responsible for implementing reasonable security safeguards. Storing Aadhaar in a WhatsApp chat is not a safeguard.
- Respond to data requests — If a tenant requests access, correction, or deletion of their data, you must respond within the prescribed period.
- Retain only as long as necessary — Once the tenancy ends and the statutory retention period passes, personal data must be deleted.
- Not sell or share data — Tenant data collected for verification cannot be shared with third parties for commercial purposes.
How Tenanting Implements DPDP Compliance
Tenanting is built to comply with the DPDP Act from the ground up — not retrofitted. Here is what we implement for every tenant KYC flow:
A Note on Aadhaar
The Aadhaar Act, 2016 and associated UIDAI regulations impose additional restrictions on Aadhaar data specifically. Key rules for landlords:
- You cannot demand Aadhaar as the sole identity proof — tenants can offer alternative identity documents
- You cannot store Aadhaar numbers in plain text — masking is required
- You cannot share Aadhaar data with third parties without explicit consent
- Aadhaar-based authentication (OTP to UIDAI) requires authorisation from UIDAI — it is not something any platform can implement without approval
Tenanting collects Aadhaar as a document upload (front and back) for identity verification purposes, stores the number masked, and does not connect to UIDAI's authentication API. This is the legally compliant approach for rental verification under current UIDAI rules for non-authorised entities.
Penalties for Non-Compliance
The DPDP Act establishes the Data Protection Board of India as the enforcement authority. Penalties for violations:
- Failure to implement reasonable security safeguards leading to a data breach — up to ₹250 crore
- Failure to notify the Board of a data breach — up to ₹200 crore
- Breach of obligations with respect to children's data — up to ₹200 crore
- Non-fulfilment of additional obligations by Significant Data Fiduciaries — up to ₹150 crore
- Breach of any other provision — up to ₹50 crore
Related Guides & Resources
- Model Tenancy Act, 2021 — What landlords and tenants need to know
- Tenanting Legal & Compliance overview
- Tenanting Privacy Policy
- Grievance Redressal — submit a data request
- FAQ — DPDP Act questions answered
Disclaimer: This guide is for informational purposes only and does not constitute legal advice. Consult a qualified legal practitioner for advice specific to your situation.