Chapter IX · Miscellaneous
Section 38: Consistency with Other Laws
Section 38 sets how the DPDP Act sits alongside everything else: it adds to other laws rather than replacing them, but where it genuinely conflicts with another law, the DPDP Act wins to the extent of that conflict.
- Chapter
- Chapter IX · Miscellaneous
- Status
- In force
- Effective
- 13 November 2025
- Applies to
- All regulated entities
- Official citation
- DPDP Act, 2023, s.38
- Reading time
- 4 min
- Updated
- August 2026
At a glance
Section 38 governs how the DPDP Act interacts with other Indian laws. It provides that the Act is in addition to, and not in derogation of, any other law in force [38(1)], so it generally stacks on top of existing obligations rather than displacing them. Where a provision of the DPDP Act conflicts with a provision of any other law in force, the DPDP Act prevails to the extent of that conflict [38(2)]. The practical effect is that a Data Fiduciary must comply with the DPDP Act and its sector or other obligations together, and only where two duties genuinely cannot both be met does the DPDP Act override. Unlike much of the Act, Section 38 is already in force, having commenced on 13 November 2025.
Key takeaways
- Section 38 makes the DPDP Act additional to other laws, not a replacement for them [38(1)].
- You generally have to comply with both the DPDP Act and your other legal obligations at the same time.
- Only where there is a genuine conflict does the DPDP Act prevail, and only to the extent of that conflict [38(2)].
- It is not a blanket override: sector rules, contract law and other statutes keep applying wherever they can coexist.
- Unlike most of the Act, Section 38 is already in force (since 13 November 2025).
Who should read this
Read this if your data obligations already come from other laws (sectoral regulators, IT rules, contracts): it explains how the DPDP Act layers on top, and what happens in the rare case of a true clash.
In plain language
Section 38 answers a question every compliance team asks: does the DPDP Act replace our existing obligations, or add to them? The answer is: it adds to them. The Act is in addition to and not in derogation of other laws in force.
The tie-breaker is narrow. Only where a DPDP provision and another law genuinely conflict does the DPDP Act win, and only to the extent of the conflict. Everywhere the two can both be satisfied, you still have to satisfy both.
The text of the law
Section 38: Consistency with Other Laws
38(1) The provisions of the Act are in addition to, and not in derogation of, any other law for the time being in force.
38(2) Where a provision of the Act conflicts with a provision of any other law in force, the Act prevails to the extent of the conflict.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Map your overlapping obligations: identify where sectoral rules, IT rules, or contracts already govern the same data, and treat the DPDP Act as an added layer, not a substitute.
- Reserve the override for genuine clashes: do not use Section 38(2) to ignore another law simply because the DPDP Act also speaks to the topic; both apply wherever they can coexist.
- Document any true conflict and how you resolved it: if you rely on the DPDP Act prevailing, record the specific provisions and why they could not both be met, and take legal advice on close calls. Want help mapping overlaps? Take the readiness assessment or find a specialist.
Frequently asked questions
Does the DPDP Act replace our other data obligations?
What happens if the DPDP Act conflicts with another law?
Can we ignore a sector rule because the DPDP Act covers the topic?
Is Section 38 in force yet?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.