Data & technology

What is DPDP Act compliance?

DPDP compliance means meeting the obligations of the Digital Personal Data Protection Act, 2023, which governs the processing of digital personal data in India and processing outside India connected with offering goods or services to data principals in India. A data fiduciary must give a clear notice, obtain valid consent or rely on a permitted legitimate use, limit processing to the stated purpose, implement reasonable security safeguards, notify breaches and honour data principal rights.

Key takeaways

  • The Act applies extraterritorially where services are offered to data principals in India.
  • The data fiduciary determines the purpose and means, and carries the accountability.
  • Consent must be free, specific, informed, unconditional and unambiguous, and withdrawable.
  • Processors must be engaged under a valid contract; the fiduciary remains answerable.

Relevant law and authority

Digital Personal Data Protection Act, 2023
Primary legislation governing digital personal data in India.
Information Technology Act, 2000
Continues to apply to electronic records, offences and intermediary obligations.
CERT-In directions on cyber incident reporting
Impose short-timeline reporting obligations for specified cyber incidents.
Sector regulations (RBI, SEBI, IRDAI)
May impose additional data localisation and security requirements.

Who the obligations fall on

A data fiduciary is the person who alone or with others determines the purpose and means of processing personal data. That is the accountable entity. A data processor processes on behalf of a fiduciary, under a contract, and the fiduciary remains responsible for compliance notwithstanding the engagement.

A data principal is the individual to whom the personal data relates. The Act confers rights on data principals including access to information about processing, correction and erasure, grievance redressal, and nomination.

What a fiduciary has to do

Give a notice that is clear and itemised, stating the personal data to be processed, the purpose, how rights may be exercised and how a complaint may be made. Obtain consent that is free, specific, informed, unconditional and unambiguous, with a clear affirmative action, or establish a permitted legitimate use.

Limit processing to the purpose for which consent was given, maintain accuracy and completeness where the data is used for decisions affecting the principal, implement reasonable security safeguards, erase data when the purpose is no longer served, and notify the Board and affected principals of a personal data breach.

Where a processor is engaged, do so only under a valid contract, and flow down the relevant obligations including security, sub-processing controls, assistance with rights requests and deletion on termination.

Getting ready in practice

Readiness work usually starts with a data map: what personal data is collected, from whom, through which systems, for what purpose, where it is stored, who can access it, who it is shared with, and how long it is kept. Almost every subsequent obligation depends on that map.

The map then drives the notice and consent design, the retention schedule, the access control model, the processor contract programme, the rights-request process and the breach-response runbook. Trying to draft a policy before the map exists tends to produce a document that does not describe what the organisation actually does.

Practical implications

  • Build the data map before drafting any policy.
  • Make consent withdrawal as easy as giving consent.
  • Put processor contracts in place with every vendor that touches personal data.
  • Define retention periods per data category rather than a blanket rule.
  • Prepare the breach-response runbook before you need it, including CERT-In timelines.

Common questions

Does the DPDP Act apply to a company outside India?
Yes, where the processing of digital personal data takes place outside India but is in connection with any activity related to offering goods or services to data principals within India. This extraterritorial reach means an overseas SaaS provider with Indian users is generally in scope, and needs the same notice, consent and security posture as a domestic fiduciary.
What counts as valid consent under the DPDP Act?
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. It must be accompanied by a compliant notice, and it must be as easy to withdraw as it was to give. Bundled consent covering unrelated purposes, or consent inferred from continued use, does not meet the standard.
What are the penalties for non-compliance?
The Act provides for monetary penalties determined by the Data Protection Board following an inquiry, with the Schedule specifying significantly higher ceilings for failure to take reasonable security safeguards to prevent a breach and for failure to notify a breach. Penalties are levied on the entity, and the Board takes into account the nature, gravity and duration of the breach and any mitigating action.

Sources & editorial information

Jurisdiction
India
Last reviewed
Legal status
Current

This page is general legal information about Indian law, prepared against identified legal sources. It is not legal advice and does not create a lawyer–client relationship. Apply it to your own facts only after a consultation with a qualified legal professional.

Working out what DPDP means for your business?

Map the data, check your notice and consent position, and get the processor contracts in order.