Back to Blog

DPDP Act 2023: The Complete Compliance Guide for Companies in India

19 July 202618 min read1 views
DPDP Act 2023: The Complete Compliance Guide for Companies in India

A comprehensive guide to India's Digital Personal Data Protection Act 2023 — covering key obligations, rights of data principals, penalties up to ₹250 crore, and a step-by-step compliance roadmap for Indian and global companies.

DPDP Act 2023 Compliance Guide India

What Is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's landmark data privacy legislation, passed by Parliament on August 9, 2023, and receiving Presidential assent on August 11, 2023. It replaces decades of fragmented data handling under the Information Technology Act, 2000 and establishes a comprehensive, consent-based framework for the processing of digital personal data.

With over 900 million internet users and a digital economy projected to cross $1 trillion by 2030, India's DPDP Act signals a clear shift: individuals now hold legal rights over their personal data, and organisations that collect or process it must comply or face severe penalties.

Key Definitions You Must Know

Understanding the DPDP Act starts with its terminology:

  • Personal Data: Any data about an individual who is identifiable by or in relation to such data — names, email addresses, phone numbers, IP addresses, biometric data, health records, location data, and more.
  • Data Principal: The individual to whom the personal data relates. Children under 18 are Data Principals whose consent must be given by a parent or guardian.
  • Data Fiduciary: Any person, company, or organisation that determines the purpose and means of processing personal data. If you collect customer data, you are a Data Fiduciary.
  • Data Processor: Any entity that processes personal data on behalf of a Data Fiduciary — cloud providers, analytics vendors, payment gateways.
  • Significant Data Fiduciary (SDF): A Data Fiduciary designated by the Central Government based on volume of data processed, sensitivity, risk to national security, or impact on rights of Data Principals. SDFs face additional obligations.
  • Consent Manager: A registered intermediary enabling Data Principals to give, manage, review, and withdraw consent through an interoperable platform.

Core Principles of the DPDP Act

The Act is built on seven foundational principles that govern how personal data must be handled:

  1. Lawful purpose: Data must be collected for a lawful purpose either with consent or under a legitimate use.
  2. Purpose limitation: Data may only be used for the specific purpose it was collected for.
  3. Data minimisation: Only collect what is strictly necessary.
  4. Data accuracy: Reasonable efforts must be made to keep data accurate and up to date.
  5. Storage limitation: Data must be deleted once the purpose is fulfilled.
  6. Reasonable security safeguards: Technical and organisational measures to prevent breaches.
  7. Accountability: The Data Fiduciary is responsible for compliance — this cannot be delegated away.

Legal Bases for Processing Personal Data

Unlike GDPR's six lawful bases, the DPDP Act recognises two primary grounds:

1. Consent

Consent must be free, specific, informed, unconditional, and unambiguous. A clear affirmative action (ticking a box, clicking agree) is required. Pre-ticked boxes are invalid. Consent requests must be in plain language and available in all 22 languages listed in the Eighth Schedule of the Constitution.

Users have the right to withdraw consent at any time, and the Data Fiduciary must make withdrawal as easy as giving consent. On withdrawal, the fiduciary must stop processing and notify all processors within a reasonable timeframe.

2. Legitimate Uses (without consent)

The Act permits processing without consent for specific legitimate uses:

  • Performing a function of the State (government services, subsidies, licences)
  • Compliance with a legal obligation or court order
  • Medical emergencies threatening life or public health
  • Disaster or public order situations
  • Employment-related processing (HR, payroll, background checks)
  • Processing in the public interest by entities such as research bodies, archiving organisations, or journalism (subject to standards set by the government)

Rights of Data Principals

Every individual whose data is collected has the following enforceable rights:

Right to Information

Data Principals can request a summary of what personal data is held about them, the purposes it is used for, and the identities of all Data Processors and Data Fiduciaries it has been shared with.

Right to Correction and Erasure

Individuals can demand correction of inaccurate or misleading data, completion of incomplete data, and erasure of data that is no longer necessary. The fiduciary must comply unless retention is required by law.

Right to Grievance Redressal

Every Data Fiduciary must establish a readily accessible grievance mechanism. Complaints must be addressed within a timeframe specified by the government. If unsatisfied, Data Principals can escalate to the Data Protection Board of India (DPBI).

Right to Nominate

A Data Principal can nominate another individual to exercise their rights in case of death or incapacity — a unique provision compared to GDPR.

Obligations on Data Fiduciaries

If your organisation processes personal data, these are your core obligations under the DPDP Act:

1. Privacy Notice

Before collecting data, provide a clear notice describing: what data is collected, the purpose, how to exercise rights, and how to approach the grievance officer. The notice must be available in English and any other language specified by the Data Principal.

2. Consent Management

Implement systems to record when consent was given, what was consented to, and how and when it was withdrawn. Consent logs must be maintained as evidence of compliance.

3. Data Breach Notification

Any personal data breach must be reported to the Data Protection Board and to each affected Data Principal in a prescribed manner. The Act does not yet define an exact breach notification timeframe, but subordinate rules (expected from the Ministry of Electronics and IT) are expected to specify a 72-hour window similar to GDPR.

4. Appointment of a Data Protection Officer (DPO)

Significant Data Fiduciaries must appoint a DPO based in India who reports to the Board of Directors. The DPO is the point of contact for the DPBI and Data Principals.

5. Data Impact Assessments

Significant Data Fiduciaries must conduct periodic Data Protection Impact Assessments (DPIAs) when introducing new processing activities that may carry high risk to Data Principals.

6. Algorithmic Audits

SDFs must also undergo periodic algorithmic audits and publish summaries to ensure automated decision-making processes do not discriminate or cause harm.

7. Data Localisation (Conditional)

The DPDP Act does not mandate blanket data localisation. However, the Central Government can restrict cross-border data transfer to specific countries or territories. Transfers are permitted to any country not on a government-notified negative list. This is a significant departure from the draft PDPB 2021, which had proposed a positive whitelist model.

8. Children's Data

Processing personal data of children (under 18) requires verifiable parental consent. Data Fiduciaries are prohibited from processing data likely to cause detrimental effect on children's wellbeing, tracking, behavioural monitoring, or targeted advertising directed at children. Entities providing services known to be primarily used by children must implement age-gating mechanisms.

Significant Data Fiduciaries (SDF) — Extra Obligations

The Central Government will designate organisations as SDFs based on:

  • Volume and sensitivity of personal data processed
  • Risk to rights and freedoms of Data Principals
  • Potential impact on sovereignty, integrity, and security of India
  • Risk to electoral democracy
  • Security of the State
  • Public order

SDFs are expected to include large tech platforms, social media companies, fintech firms, health-tech platforms, and potentially large e-commerce players. If designated as an SDF, obligations include appointing an India-based DPO, conducting DPIAs, algorithmic audits, and complying with additional rules under SDF-specific subordinate regulations.

The Data Protection Board of India (DPBI)

The DPBI is the quasi-judicial body established under the DPDP Act to adjudicate complaints, levy penalties, and issue directions. Key features:

  • Entirely digital proceedings — no physical hearings required
  • Can impose penalties up to ₹250 crore per instance and up to ₹10,000 crore for the most serious breaches
  • Appeals lie with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) and subsequently with the Supreme Court
  • The Board can call for information, conduct investigations, and issue compliance orders

Penalty Structure Under the DPDP Act

The penalty schedule under Schedule 1 of the Act is tiered by severity:

ViolationMaximum Penalty
Breach of child data obligations or significant data fiduciary obligations₹200 crore
Failure to implement adequate security safeguards leading to a breach₹250 crore
Non-compliance with the DPBI's directions or orders₹150 crore
Failure to notify breach to the Board and Data Principals₹200 crore
Other violations of the Act or its rules₹50 crore
Repeated or multiple violations (aggregate cap)₹500 crore

These are per-instance penalties. An organisation suffering multiple breaches across different obligations could face cumulative fines far exceeding any single cap.

How DPDP Compares to GDPR

For companies already GDPR-compliant, DPDP is broadly comparable but has important differences:

  • Scope: DPDP covers only digital personal data (collected online or digitised). GDPR covers all personal data regardless of medium.
  • Lawful bases: DPDP has two primary grounds (consent + legitimate use) vs GDPR's six. DPDP's legitimate use is more restrictive.
  • Data localisation: DPDP uses a negative-list model (permitted unless restricted). GDPR uses an adequacy-decision or safeguard model.
  • DPO requirement: DPDP limits it to SDFs. GDPR requires DPOs for all public authorities and high-risk private processors.
  • Right to portability: GDPR includes data portability. DPDP does not explicitly include it (may come via rules).
  • Penalties: GDPR caps at €20M or 4% of global turnover. DPDP caps at ₹250 crore per instance (~$30M).
  • Proceedings: DPDP's DPBI operates entirely digitally, which is a modern design choice.

DPDP Compliance Impact by Industry

E-Commerce and Retail

Platforms like Flipkart, Meesho, Nykaa, and thousands of D2C brands collect purchase history, browsing behaviour, payment data, delivery addresses, and preferences. Under DPDP:

  • Consent banners must be purpose-specific (marketing, analytics, and personalisation must be separate consent items)
  • Loyalty programme data must be erased when a user closes their account
  • Third-party tracking pixels and ad networks used for retargeting must be disclosed and consented to
  • Children's data — if a platform sells products to under-18s — requires parental consent

Fintech and Banking

Banks, NBFCs, lending apps, and payment aggregators handle the most sensitive personal data: Aadhaar, PAN, bank statements, credit scores, and transaction histories. DPDP compliance here means:

  • Separating regulatory processing (RBI-mandated KYC) from marketing use cases — the former falls under legitimate use, the latter requires explicit consent
  • Ensuring third-party credit bureau sharing has proper disclosures
  • Retention policies aligned with RBI data retention requirements while ensuring post-relationship erasure where permitted

Health Tech and Hospitals

Health data is not separately categorised as "sensitive" in DPDP the way GDPR does, but the sheer volume of personal data and the potential for harm means hospitals, diagnostics labs, and health apps must:

  • Obtain explicit consent for sharing records with insurers or pharmaceutical researchers
  • Enable patients to request erasure of diagnostic history not required for ongoing treatment
  • Implement breach notification processes — a breach of health records would attract the full ₹250 crore penalty

SaaS and Tech Startups

Indian SaaS companies serving global clients already navigate GDPR. DPDP adds domestic obligations:

  • If processing data of Indian users on behalf of a client (as a Data Processor), the processor must follow the Data Fiduciary's instructions and implement equivalent safeguards
  • Contracts with Data Fiduciaries must include DPDP-compliant Data Processing Agreements (DPAs)
  • Sub-processing (passing data to another vendor) must be disclosed and authorised

HR and Recruitment Platforms

Resume data, background check results, salary information, and interview recordings are all personal data. Employment-related processing can rely on the legitimate use ground, but only for the purpose of the employment relationship. Using employee data for marketing or research requires separate consent.

Step-by-Step DPDP Compliance Roadmap for Companies

Here is a practical roadmap to achieve DPDP readiness:

Phase 1: Data Discovery and Mapping (Months 1–2)

  • Conduct a data inventory — list every category of personal data collected, where it is stored, who has access, and how long it is retained
  • Map data flows: from collection through processing to deletion and any third-party sharing
  • Identify all Data Processors (vendors, SaaS tools, cloud providers) and review existing contracts
  • Determine whether your organisation is at risk of SDF designation

Phase 2: Consent and Notice Infrastructure (Months 2–3)

  • Audit all current consent mechanisms — remove pre-ticked boxes, bundled consent, and vague language
  • Implement a Consent Management Platform (CMP) capable of recording, storing, and proving consent
  • Draft and publish DPDP-compliant privacy notices in plain English (and other required languages)
  • Create easy consent withdrawal flows — a single button or form accessible from the user's account settings

Phase 3: Rights Fulfilment Processes (Month 3)

  • Build internal workflows for handling access, correction, and erasure requests within a legally compliant timeframe
  • Designate a Grievance Officer and publish their contact details prominently
  • Test the end-to-end data subject rights process before go-live

Phase 4: Security and Breach Response (Months 3–4)

  • Implement encryption at rest and in transit for all personal data
  • Conduct penetration testing and vulnerability assessments
  • Draft and test a Data Breach Response Plan: detection → containment → assessment → DPBI notification → Data Principal notification
  • Set up a security incident register

Phase 5: Vendor Management (Month 4)

  • Review and update contracts with all Data Processors to include DPDP-compliant clauses
  • Ensure sub-processors are disclosed and authorised
  • Conduct vendor due diligence — your processor's breach is your liability

Phase 6: Training and Culture (Ongoing)

  • Train all employees who handle personal data, not just the legal and tech teams
  • Run annual DPDP awareness sessions
  • Include DPDP compliance in the onboarding checklist for every new hire with data access

DPDP Compliance Checklist

Use this checklist to assess your current compliance posture:

  • ☐ Data inventory and data flow maps completed
  • ☐ All consent mechanisms reviewed and updated
  • ☐ Privacy notice published in plain language
  • ☐ Consent withdrawal mechanism is as easy as giving consent
  • ☐ Children's age-gating implemented where applicable
  • ☐ Data access, correction, and erasure workflows built and tested
  • ☐ Grievance Officer appointed and contact details published
  • ☐ Data Breach Response Plan documented and tested
  • ☐ Vendor contracts updated with DPDP-compliant DPAs
  • ☐ Retention schedules defined and automated deletion implemented
  • ☐ Employee training completed
  • ☐ DPO appointed (if SDF designation is expected)
  • ☐ Cross-border transfer restrictions reviewed against the government's negative list

Key Timelines and What to Watch

As of mid-2026, the DPDP Act has received Presidential assent but its rules (DPDP Rules, 2025) are being finalised by the Ministry of Electronics and Information Technology (MeitY). The rules will specify:

  • Exact breach notification timelines
  • Standards for consent managers and their registration process
  • The negative list of countries to which data transfer is restricted
  • The criteria for designating Significant Data Fiduciaries
  • Specific standards for children's data processing and age verification

Companies should not wait for the rules to be finalised before beginning their compliance journey. The underlying obligations — consent, minimisation, security, grievance redressal — are already enacted law. Starting now also gives organisations time to fix legacy systems that were never built with data privacy in mind.

Consequences of Non-Compliance

Beyond monetary penalties, DPDP non-compliance carries significant business risks:

  • Reputational damage: A published DPBI order against your company is a public record. In an era of social media scrutiny, this can cause severe brand damage.
  • Loss of customer trust: 73% of Indian consumers in a 2024 survey said they would switch brands after a data breach.
  • Regulatory cascade: A DPDP violation may trigger parallel investigations by SEBI (for listed companies), RBI (for regulated entities), or IRDAI (for insurance companies).
  • M&A due diligence impact: Investors and acquirers are increasingly conducting DPDP due diligence. Non-compliant companies face valuation discounts or deal blockers.
  • Global market access: Non-compliance with DPDP may affect your ability to enter data-sharing agreements with GDPR-regulated clients in Europe, who must ensure their Indian vendors meet equivalent standards.

DPDP and India's AI Ecosystem

The rise of AI systems trained on personal data creates direct intersections with DPDP:

  • Training large language models or recommendation engines on user data requires clear consent or a legitimate use basis
  • Automated decisions affecting individuals (credit scoring, hiring, insurance underwriting) could trigger algorithmic audit requirements for SDFs
  • Synthetic data generation from personal data may still require consent if it is possible to re-identify individuals
  • AI vendors acting as Data Processors must sign DPDP-compliant DPAs before receiving personal data for model training

Companies building AI products on Indian user data would be wise to incorporate privacy-by-design principles from the ground up rather than retrofitting compliance later.

Frequently Asked Questions

Does DPDP apply to companies outside India?

Yes. The Act applies to processing of digital personal data of Indian residents, regardless of where the processing takes place. A US company processing data of Indian customers is subject to DPDP — a provision similar to GDPR's extra-territorial reach.

Is anonymised data covered by DPDP?

No. The Act explicitly excludes anonymised data — data that has been irreversibly de-identified such that no individual can be identified from it. However, pseudonymised data (where re-identification is possible) remains personal data and is fully covered.

Does a small startup need to comply?

Yes, if it collects digital personal data of individuals in India. The Act does not have a size-based exemption. However, the government may notify certain classes of Data Fiduciaries as exempt from specific obligations — likely small businesses — through subordinate rules.

What is the difference between a Data Fiduciary and a Data Processor?

A Data Fiduciary decides why and how data is processed. A Data Processor carries out that processing on the fiduciary's instructions. A payment gateway processing transactions for your e-commerce platform is a Data Processor. Your e-commerce company is the Data Fiduciary. Both have obligations, but the fiduciary bears primary accountability.

Can personal data be used for marketing without consent?

Generally no. Marketing and profiling are commercial purposes and do not fall under the legitimate use exemptions. Explicit, purpose-specific consent is required for marketing communications.

Final Thoughts

The DPDP Act 2023 is not merely a compliance checkbox — it is a structural shift in how India's digital economy will operate. Companies that treat it as a legal burden to minimise will find themselves exposed to penalties, reputational damage, and erosion of customer trust. Those that treat it as an opportunity to build genuine data governance will find themselves with a competitive advantage: customers who trust you with their data stay longer, convert better, and refer more.

The compliance journey is not trivial, but it is entirely achievable with a structured approach, the right tooling, and genuine organisational commitment from leadership down. Start your data inventory now, audit your consent flows, appoint a grievance officer, and engage your legal counsel to track the evolving DPDP Rules from MeitY. The regulatory clock has started — and the companies that prepare now will be the ones best positioned when enforcement begins in earnest.

Was this article helpful?

C

Written by

CoderCrafter Team

Developer & Technical Writer

Building developer tools and writing practical engineering content at CoderCrafter. Covers JavaScript, React, Node.js, DevOps, and modern web development.

Comments

Leave a comment

0/2000

Comments are reviewed before appearing. Be kind and constructive.

Call UsWhatsApp