The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection law. If your business collects personal data from people in India — customers, website visitors, job applicants, employees — it applies to you. Here is what it actually asks for, in the order most organisations need to tackle it.

Who the Act Applies To

The Act covers digital personal data processed within India. It also reaches processing that happens outside India where that processing relates to offering goods or services to people in India. Paper records that never get digitised sit outside it; almost everything else a modern business touches does not.

Three roles matter, and it is worth being precise about which one you occupy:

  • Data Principal — the individual the data is about.
  • Data Fiduciary — whoever determines the purpose and means of processing. If you decide why the data is collected, this is you.
  • Data Processor — whoever processes data on a Fiduciary's behalf, under contract.

Most businesses are Data Fiduciaries for their own customer and employee data, and Data Processors when they handle a client's data. IT services firms are routinely both at once, on different engagements. The obligations differ, so map this before anything else.

Notice and Consent

The default basis for processing is consent, and the Act sets a high bar for it. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. Pre-ticked boxes and bundled "agree to everything" flows do not meet it.

Every request for consent has to be accompanied by a notice that tells the person what personal data you want, the purpose you want it for, how to withdraw consent, how to exercise their rights, and how to complain to the Data Protection Board. The notice must be available in English or any language listed in the Eighth Schedule to the Constitution.

Withdrawal has to be as easy as giving consent in the first place. In practice this is the requirement that catches teams out, because it means consent has to be recorded in a way you can actually reverse — not buried in a form submission nobody kept.

Not everything needs consent. The Act sets out certain legitimate uses, including data a person voluntarily provides for a purpose they clearly intended, processing for employment purposes, and responding to medical emergencies. Employment is a useful one for most businesses: you do not need an employee's consent to run payroll.

What You Must Do With the Data

Once you hold personal data, the obligations are ongoing rather than one-off:

  • Purpose limitation — use it only for the purpose you gave notice of.
  • Data minimisation — collect only what that purpose actually requires.
  • Accuracy — keep it correct and complete, particularly where it will be used to make a decision affecting the person.
  • Storage limitation — erase it once the purpose is served or consent is withdrawn, unless the law requires you to retain it.
  • Reasonable security safeguards — protect it, and this obligation does not transfer away when you hand data to a processor.

That last point deserves emphasis. Engaging a vendor does not discharge your duty as a Fiduciary. If your processor leaks the data, you remain answerable for whether you had reasonable safeguards and a proper contract in place.

Rights You Have to Be Ready to Honour

Data Principals can ask you for a summary of the personal data you hold about them and what you are doing with it, ask you to correct or complete or erase it, and nominate someone to exercise their rights if they die or become incapacitated. They can also complain, and you must publish a way for them to do so.

Concretely: you need a named contact — a Data Protection Officer, or a person who can answer questions about your processing — published where people can find it, and a grievance redressal process behind it that actually responds. A privacy policy with no reachable human at the end of it does not satisfy this.

Children's Data

India sets the threshold at 18, not 13. Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and you may not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

If your product was designed against the US COPPA standard, its age gate is set eleven years too low for India. This is one of the most common gaps we see in policies that were written for a Western market and then reused here.

Breaches

A personal data breach must be notified to the Data Protection Board and to each affected Data Principal. There is no materiality threshold written into the Act the way there is in some other regimes, so the safe assumption is that anything qualifying as a breach is reportable.

The practical implication is operational, not legal: you cannot report what you cannot detect. Logging, alerting and a rehearsed incident process are what turn this obligation from a liability into a manageable procedure.

Significant Data Fiduciaries

Organisations designated as Significant Data Fiduciaries — based on factors such as the volume and sensitivity of data they handle and the risk to data principals — carry extra obligations: a Data Protection Officer based in India, an independent data auditor, and periodic data protection impact assessments and audits.

Most small and mid-sized businesses will not be designated. It is still worth knowing where the line sits before you scale into it.

Penalties

The Act carries financial penalties rather than criminal sanctions, and they are substantial. Failure to take reasonable security safeguards attracts a penalty of up to ₹250 crore. Failure to notify a breach, and breaches of the children's-data provisions, each attract up to ₹200 crore. The Data Protection Board determines penalties having regard to the nature and gravity of the breach and any mitigating action taken.

The mitigation point is the practical one. Demonstrable effort — documented safeguards, a real incident response, prompt remediation — is explicitly relevant to what you end up paying.

Where to Start

If you are beginning from nothing, the order that wastes the least effort is:

01

Map what you hold

List every system holding personal data, what is in it, why you collected it, who can reach it, and how long you keep it. Nothing else can be decided before this exists.

02

Decide your basis for each purpose

For every processing purpose, determine whether you are relying on consent or on a legitimate use. Where it is consent, check you can evidence it and reverse it.

03

Rewrite the notice

Bring your privacy notice in line with what the Act requires it to say, and make sure it reflects what your systems actually do rather than what you intended them to do.

04

Fix retention and erasure

Storage limitation is where most organisations are quietly non-compliant. Decide retention periods per data category and build the deletion path before anyone asks you to use it.

05

Put the safeguards in writing

Access control, encryption, logging, backups, and processor contracts that pass the obligation down. Document them — undocumented controls are hard to rely on later.

06

Stand up grievance redressal

Publish a contact, define response timelines internally, and rehearse an access request and an erasure request end to end before a real one arrives.

A Note on Timing

The Act was passed in 2023, and the operational rules and enforcement machinery have been phased in since. Because the detail of implementation continues to develop, treat this article as an orientation to the obligations rather than a compliance opinion, and confirm current requirements and timelines with your legal counsel before relying on them.

Need Help Getting DPDP-Ready?

We help organisations map their data, close the gaps between policy and system behaviour, and put the security safeguards and processes the Act expects into place.

Talk to Our Team Security & Infrastructure Services