Skip to main content
ComplianceCorporate Legal

DPDP Compliance Guide for Indian Enterprises

A board-ready walkthrough of DPDP compliance for Indian enterprises, from consent and breach rules to SDF duties and the 13 May 2027 deadline.

13 min read2412 words

Introduction

For most Indian enterprises, DPDP compliance has moved from a policy discussion to a hard deadline. The Digital Personal Data Protection Act, 2023 became law in August 2023, but it was written to be operationalised through subordinate rules, and those rules arrived when the government notified the DPDP Rules, 2025 in November 2025. That notification started the clock. Substantive obligations on every Data Fiduciary become enforceable in a phased manner, with the core duties around notice, consent, security and breach handling due to bite around the middle of 2027. For a compliance head, company secretary or general counsel reading this in mid-2026, the honest position is that you have months, not years, and that most of the real work sits inside the business rather than in the legal department.

This guide is written specifically for Indian enterprises, not as a rebadged global-privacy explainer. The DPDP Act borrows familiar vocabulary from international regimes but it is its own statute, with its own regulator in the Data Protection Board of India, its own consent architecture, its own penalty schedule reaching up to Rs 250 crore per instance, and its own awkward interfaces with the sectoral rules Indian companies already live under, from the CERT-In incident-reporting directions to RBI data-localisation mandates and SEBI disclosure obligations. Treating DPDP as if it were the GDPR with a rupee sign is one of the more common and expensive mistakes being made right now.

What follows is a practical walkthrough: what the Act actually asks of you, who the key players are, how consent and notice must work, what rights your customers and employees can now assert, the heavier duties that fall on Significant Data Fiduciaries, how breaches and penalties are handled, and finally how to build a compliance programme that survives an audit and a board review. The aim is to give you enough to scope the work accurately and to know where the difficult judgment calls lie.

What the DPDP Act 2023 Actually Requires

At its core the DPDP Act governs the processing of digital personal data, meaning any data about an identifiable individual that is collected in digital form or later digitised. It applies to processing within India, and it reaches outside India where the processing is connected with offering goods or services to individuals in India, so a foreign group entity handling Indian customer data is not outside its scope. It does not apply to personal data an individual has themselves made publicly available, nor to purely personal or domestic processing, and the Act carves out room for the state to exempt certain agencies, which remains one of its more debated features.

The Act is built around a small number of duties that every enterprise must be able to demonstrate. You may process personal data only for a lawful purpose, either with the individual's consent or under one of the specified legitimate uses. You must give clear notice of what you collect and why. You must limit processing to the stated purpose, keep the data accurate, protect it with reasonable security safeguards, delete it once the purpose is served or consent is withdrawn, and report breaches. Crucially, the obligation is not merely to comply but to be able to prove compliance to the Board on demand, which turns record-keeping and documentation into a first-order concern rather than an afterthought.

A point worth internalising early is that the DPDP Act replaces the older section 43A regime and the sensitive-personal-data rules made under the Information Technology Act, 2000, which many Indian companies had treated as the whole of their privacy obligation. The Act does not grade data into sensitive and non-sensitive categories the way the earlier rules did; almost all personal data attracts the same baseline duties, with heightened treatment reserved for children and for large-scale processors designated as Significant Data Fiduciaries.

  • Applies to digital personal data processed in India, and to processing abroad tied to offering goods or services in India
  • Processing requires either valid consent or a specified legitimate use, always for a lawful purpose
  • Core duties: purpose limitation, accuracy, security safeguards, deletion when purpose ends, and breach reporting
  • The burden is to prove compliance to the Board, making documentation and record-keeping mandatory
  • Supersedes the older IT Act section 43A and sensitive-personal-data rules that many firms relied on

The Roles That Define Your Obligations

The Act allocates duties by role, and mapping your organisation to these roles is the first practical step in any readiness exercise. Get the mapping wrong and you will either over-engineer controls you do not need or, more dangerously, miss obligations that clearly attach to you. Most enterprises will find they are a Data Fiduciary for their customer and employee data and simultaneously a Data Processor for data they handle on behalf of clients, and the same dataset can carry different duties depending on which hat you are wearing.

  • You are usually a Data Fiduciary for your own customer and staff data and a Processor for clients' data
  • The Fiduciary stays accountable even for processing carried out by its vendors
  • Processor relationships must sit under a valid written contract, not an informal arrangement
  • Significant Data Fiduciary status is a government designation that triggers heavier duties

Data Principal and Data Fiduciary

The Data Principal is the individual to whom the personal data relates, including, notably, a child and the parent or guardian acting for them. The Data Fiduciary is the person or entity that alone or with others determines the purpose and means of processing. If your organisation decides why and how personal data is used, whether for marketing, payroll, KYC or analytics, you are a Data Fiduciary for that data and you carry the primary compliance burden, including notice, consent, security, deletion and breach reporting.

Data Processor and Significant Data Fiduciary

A Data Processor processes personal data on behalf of a Fiduciary, and the Act requires that this relationship be governed by a valid contract. The Fiduciary remains accountable for what its processors do, which makes vendor contracting and oversight a genuine compliance control rather than paperwork. A Significant Data Fiduciary is a class the government may designate based on the volume and sensitivity of data processed, risk to electoral democracy, security of the state and similar factors, and it attracts additional obligations covered later in this guide.

Consent and Notice: Getting the Foundation Right

Consent is the centre of gravity of the DPDP Act, and it is where the most re-engineering effort is going. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the stated purpose. Bundling consent for unrelated purposes, or making access to a service conditional on consent that is not needed to deliver that service, will not survive scrutiny. Every request for consent must be accompanied by a notice, and the Rules envisage that this notice be available in plain language and in the languages set out in the Eighth Schedule to the Constitution, which for a pan-India consumer business is a real design constraint rather than a formality.

The notice must tell the individual what personal data is being collected and for what purpose, how they can exercise their rights, and how they can complain to the Board. The Data Principal must also be able to withdraw consent as easily as it was given, and withdrawal must trigger the cessation of processing and, ordinarily, deletion. This means consent cannot be a checkbox captured once and forgotten; it must be a state your systems track, honour and can reconstruct on request. For enterprises that have accumulated personal data over years under older or vaguer notices, the hard question is what to do with that legacy data, and the practical answer usually involves fresh notice, re-consent where required, and disciplined deletion of what can no longer be justified.

The Act also permits processing without consent for certain legitimate uses, such as where an individual has voluntarily provided data for a purpose and not objected, for employment-related purposes, for compliance with law or a court order, or in specified emergencies. These are narrower than they first appear, and reading employment or legal-obligation grounds too generously is a recognisable failure mode. The safer posture is to document, for every processing activity, precisely which lawful basis you are relying on rather than assuming consent covers everything.

  • Consent must be free, specific, informed, unambiguous and limited to what the purpose requires
  • Notice must be plain-language and available in the constitutionally recognised languages for consumer-facing services
  • Withdrawal must be as easy as giving consent and must stop processing and trigger deletion
  • Legitimate-use grounds exist but are narrow; do not stretch employment or legal-obligation bases
  • Record the specific lawful basis for every processing activity rather than defaulting to consent

The Rights Your Customers and Employees Can Now Assert

The DPDP Act creates a set of enforceable rights for Data Principals, and enterprises need an operational process to receive, verify and answer these requests within reasonable timelines, not merely a policy that says they will. The right of access lets an individual obtain a summary of the personal data being processed and the identities of others with whom it has been shared. The right to correction and erasure lets them have inaccurate data fixed and unnecessary data deleted. There is a right to grievance redressal, and a right of nomination that allows an individual to nominate another person to exercise their rights in the event of death or incapacity, a provision that has no clean equivalent in most foreign regimes and that Indian enterprises must specifically build for.

Importantly, the Act obliges every Fiduciary to publish the contact details of a person able to answer questions about processing, and Significant Data Fiduciaries must appoint a Data Protection Officer based in India. A Data Principal must exhaust the Fiduciary's own grievance mechanism before approaching the Board, which makes your internal grievance process the first line of defence and a genuine risk control. If it is slow, opaque or unstaffed, you convert routine requests into complaints to the regulator. The Act also, unusually, places duties on Data Principals themselves, including not to raise false or frivolous complaints, which gives Fiduciaries some protection against abuse but does not dilute the obligation to answer legitimate requests promptly.

  • Individuals can demand access to their data and the list of parties it has been shared with
  • Correction and erasure rights require a workflow to locate and act on data across systems
  • The right of nomination is India-specific and must be built into your request-handling design
  • A Data Principal must use your grievance mechanism before escalating to the Board
  • A staffed, responsive grievance process is itself a control that keeps disputes out of the regulator's inbox

Heavier Duties for Significant Data Fiduciaries

If your organisation is designated a Significant Data Fiduciary, a category aimed at large-scale and higher-risk processors such as major consumer platforms, large financial institutions and data-heavy enterprises, a set of additional obligations applies on top of the baseline. These are the duties most likely to require external specialists and the longest lead time, so identifying early whether you are likely to be designated is a planning decision, not a wait-and-see one.

  • Appoint an India-based Data Protection Officer with real authority and board access
  • Engage a genuinely independent data auditor to assess compliance periodically
  • Conduct periodic Data Protection Impact Assessments, refreshed when systems materially change
  • Apply heightened diligence before deploying new or higher-risk technologies on personal data

Governance Appointments

A Significant Data Fiduciary must appoint a Data Protection Officer who is based in India and reports to the board or its equivalent, and who serves as the point of contact for grievance redressal. It must also engage an independent data auditor to evaluate its compliance. These are not titles to be added to an existing role casually; the DPO is expected to have genuine standing and the auditor genuine independence, and a designation that exists only on paper is a visible weakness in any regulatory review.

Assessment and Audit

A Significant Data Fiduciary must undertake periodic Data Protection Impact Assessments and periodic audits, and exercise additional diligence when adopting new or higher-risk technologies. A DPIA is a structured examination of the rights of Data Principals and the risks a processing activity creates, and it should be treated as a living document revisited when systems change. For enterprises deploying AI or large-scale analytics on personal data, this assessment obligation is where privacy and emerging technology governance meet, and it deserves board-level visibility.

Breaches, Penalties and the Data Protection Board

The DPDP Act treats a personal data breach broadly, covering any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises the confidentiality, integrity or availability of personal data. On becoming aware of a breach, a Data Fiduciary must notify both the Data Protection Board and each affected Data Principal, and the Rules set expectations for prompt intimation followed by a fuller account within a defined window. The notice to individuals must describe the breach in plain language, the data involved, the measures the individual can take to protect themselves, and how to reach the Fiduciary. This is a standalone obligation and does not displace the separate CERT-In directions, which require reporting of specified cyber incidents within six hours, so a serious incident can trigger multiple, differently-timed reporting duties at once, and your incident-response runbook must reflect that reality.

Enforcement sits with the Data Protection Board of India, a body empowered to inquire into breaches and non-compliance and to impose monetary penalties. The penalty schedule is the part that concentrates board attention, because the figures are large and are assessed per instance rather than capped across an organisation. Directors and company secretaries should note that while the penalties fall on the entity, the expectation of demonstrable, documented compliance means the quality of your governance record is what stands between a defensible position and an indefensible one when the Board comes asking.

  • A breach must be reported to both the Data Protection Board and every affected Data Principal
  • DPDP breach duties are separate from, and additional to, the six-hour CERT-In incident reporting rule
  • Penalties reach up to Rs 250 crore and are assessed per instance, not capped across the organisation
  • The Board can inquire into non-compliance, making a documented governance record your primary defence
Up to Rs 250 cr
Maximum Penalty
The ceiling for failing to implement reasonable security safeguards, assessed per instance under the Act's schedule
Up to Rs 200 cr
Breach Reporting Failure
Indicative maximum for failing to notify the Board or affected individuals of a personal data breach
6 hours
CERT-In Window
The separate cyber-incident reporting timeline that can run in parallel with DPDP breach duties
By mid-2027
Core Deadline
The phased horizon by which substantive Fiduciary obligations are expected to be enforceable following the 2025 Rules

Building a DPDP Compliance Programme That Holds Up

Because DPDP compliance is proven through evidence rather than intention, the programme that survives scrutiny is one built around a defensible record of what data you hold, why, on what basis, and how you protect and dispose of it. The single most valuable early investment is a data-mapping and Record of Processing Activities exercise, because almost every downstream obligation, notice, consent, deletion, breach scoping, grievance handling, depends on knowing what personal data lives where and why. Enterprises that skip this and jump to drafting policies find those policies describe a system they cannot actually locate.

From the map, the work sequences naturally: rationalise your lawful bases and rewrite notices; rebuild consent capture and withdrawal so it is granular, multilingual where required, and auditable; renegotiate processor contracts so vendor obligations flow through; stand up the grievance and rights-request workflow; implement retention and deletion schedules; and, if you are a Significant Data Fiduciary, appoint your DPO and auditor and run your first DPIA. Ownership should be cross-functional, because personal data flows through marketing, HR, product, IT and procurement, and a programme owned by legal alone will stall at the point where it needs the business to change how it collects and stores data.

With the Rules notified and the compliance horizon set, the practical judgment for a general counsel is sequencing under a fixed deadline. The activities with the longest lead time, data mapping, consent re-engineering, vendor recontracting and, for Significant Data Fiduciaries, appointments and audits, should start first, because they depend on system changes and third-party cooperation you do not fully control. Leaving them late is the most common way an enterprise finds itself technically committed to a deadline it cannot operationally meet.

  • Start with data mapping and a Record of Processing Activities; nearly every other duty depends on it
  • Rationalise lawful bases, then rewrite notices and rebuild granular, auditable consent capture
  • Flow DPDP obligations into processor contracts and stand up rights-request and grievance workflows
  • Make ownership cross-functional across marketing, HR, product, IT and procurement, not legal alone
  • Sequence the longest-lead-time items first, because they depend on system change and third parties

How DPDP Sits Within India's Wider Regulatory Web

The DPDP Act does not operate in isolation, and one of the recurring errors in Indian enterprises is treating it as a self-contained project rather than a layer over existing sectoral obligations. Financial-services firms already handle personal data under RBI frameworks, including the requirement that payment system data be stored within India, and those localisation and sectoral duties continue alongside DPDP rather than being replaced by it. Where two regimes both apply, the safe reading is that the stricter obligation governs, and a bank or fintech cannot use DPDP compliance to relax an existing RBI mandate.

For listed entities, a significant personal data breach can also be a material event requiring disclosure under the SEBI listing and disclosure obligations, meaning the same incident may need to be reported to affected individuals, the Data Protection Board, CERT-In and the stock exchanges, each on its own timeline and in its own form. The board's own accountability under the Companies Act, 2013 for risk management and internal controls now clearly extends to personal data risk, which is why DPDP readiness increasingly appears on audit committee and risk management committee agendas rather than sitting solely with the legal function.

The workable mental model is to treat DPDP as the horizontal privacy baseline that runs underneath your vertical, sector-specific regulation. Your KYC, your employee records under labour and POSH-related processes, your GST and tax records, and your customer contracts all involve personal data that DPDP now governs, but they remain subject to their own retention and handling rules. Mapping where DPDP overlaps, reinforces or must yield to those sectoral requirements is precisely the kind of analysis that repays doing carefully once, at the design stage, rather than discovering the conflicts during an incident.

  • DPDP layers over, and does not replace, RBI, SEBI and other sectoral obligations; the stricter duty governs
  • A serious breach at a listed entity may trigger parallel disclosure to the Board, CERT-In and the exchanges
  • Board accountability for risk under the Companies Act now clearly extends to personal data risk
  • Treat DPDP as the horizontal privacy baseline beneath your vertical sectoral regulation

Conclusion

DPDP compliance is no longer a horizon item for Indian enterprises; with the DPDP Rules, 2025 notified and a phased enforcement timeline running into 2027, it is a scoped programme with a fixed deadline and a penalty schedule serious enough to warrant board attention. The organisations that will meet it comfortably are those that started with an honest data map, sequenced the long-lead work first, and treated consent, rights handling and breach response as operational systems the business runs every day rather than policies the legal team files away. The ones that struggle will be those that mistook DPDP for a document-drafting exercise or for a rebadged foreign privacy law, and discovered too late that the real work lived inside their systems and their vendor contracts.

Vidhaana helps compliance heads, company secretaries and general counsel turn that scope into a manageable programme, mapping personal data flows, tracking lawful bases and consent state, surfacing the obligations and deadlines that apply to your specific footprint, and giving your board a defensible, evidence-backed view of where you stand against the Act. If you would like to see how a compliance dashboard built for the DPDP regime handles data mapping, rights requests and breach readiness against your own processes, book a demonstration and we will walk through it with your real obligations in view, without the hype, so you can judge fit before your deadline rather than after an incident.

Tags

#Compliance#DPDPAct#DataPrivacy#DataProtection#RegulatoryCompliance

Frequently Asked Questions

When does the DPDP Act 2023 actually become enforceable for enterprises?

The Act was passed in 2023 but was operationalised only when the DPDP Rules, 2025 were notified in November 2025. Enforcement is phased: the Data Protection Board became functional first, consent-manager registration follows, and the substantive obligations on ordinary Data Fiduciaries are expected to bite by around the middle of 2027, giving most enterprises months rather than years to prepare.

How is DPDP different from the GDPR that our global teams already follow?

DPDP shares GDPR vocabulary but differs in substance. It has no separate sensitive-data category, applies a consent-plus-legitimate-use model rather than GDPR's six bases, introduces an India-specific right of nomination, requires multilingual notices, and is enforced by the Data Protection Board with per-instance penalties up to Rs 250 crore. Reusing a GDPR programme unchanged will leave real gaps in Indian compliance.

What makes an enterprise a Significant Data Fiduciary?

The government may designate an organisation as a Significant Data Fiduciary based on factors such as the volume and sensitivity of personal data processed, risk to individuals, security of the state and risk to electoral democracy. Designation adds duties: an India-based Data Protection Officer, an independent data auditor, periodic Data Protection Impact Assessments and audits, and extra diligence with new technologies.

How quickly must we report a personal data breach under DPDP?

On becoming aware of a breach you must notify both the Data Protection Board and every affected Data Principal, with prompt initial intimation followed by fuller detail within the defined window under the Rules. This is separate from the CERT-In direction requiring certain cyber incidents to be reported within six hours, so one incident can trigger several parallel reporting duties.

Does DPDP replace our existing RBI and SEBI data obligations?

No. DPDP is a horizontal privacy baseline that sits over your sector-specific rules rather than replacing them. RBI localisation mandates, SEBI disclosure duties and your retention obligations under tax, labour and company law all continue. Where both a sectoral rule and DPDP apply to the same data, the safer reading is that the stricter obligation governs your handling of it.

Transform Your Legal Operations with AI

Ready to experience the power of AI-driven legal solutions? Vidhaana's platform delivers measurable results across compliance, helping organizations reduce costs, improve accuracy, and scale operations efficiently.

15+
Industries Served
AI-Powered
Document Analysis
Pan-India
Coverage
SOC 2
Aligned Security