India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) is the country’s first comprehensive, standalone data-protection law. If your business collects the personal data of people in India — and almost every business does — this law applies to you. This guide breaks down what the Act actually requires and gives you a checklist you can act on today.
What the DPDP Act covers
The Act governs the processing of digital personal data — any data about an identifiable individual, collected digitally or digitised after collection. It applies to organisations both inside India and outside India where they offer goods or services to people in India.
Two roles sit at the centre of the law:
- Data Fiduciary — the entity that decides why and how personal data is processed. That’s you.
- Data Principal — the individual the data is about.
- Data Processor — anyone who processes data on a Fiduciary’s behalf (your vendors and sub-processors).
Some organisations may be notified as Significant Data Fiduciaries based on volume and sensitivity of data, risk to rights, and other factors. They carry extra duties such as appointing a Data Protection Officer based in India, an independent data auditor, and conducting periodic Data Protection Impact Assessments.
The core obligations
At a high level, a Data Fiduciary must:
- Have a lawful basis to process. Under DPDP that is either valid consent or one of the defined “legitimate uses” (such as a voluntary provision of data for a specified purpose, or certain state functions).
- Give clear notice. Before or at the time of seeking consent, you must tell people what personal data you collect, the purpose, how they can exercise their rights, and how to complain to the Data Protection Board.
- Collect consent that is free, specific, informed, unconditional and unambiguous, with a clear affirmative action. It must be as easy to withdraw consent as it was to give it.
- Limit purpose and retention. Use data only for the stated purpose and erase it once the purpose is served (unless retention is legally required).
- Keep data accurate and secure. Implement reasonable security safeguards to prevent personal data breaches.
- Honour Data Principal rights — access, correction, completion, updating, erasure, grievance redressal, and nomination.
- Report personal data breaches to the Data Protection Board of India and to affected Data Principals.
- Protect children’s data. Processing children’s data (under 18) generally requires verifiable parental consent, and behavioural tracking or targeted advertising directed at children is restricted.
Penalties for non-compliance are significant — financial penalties can reach up to ₹250 crore per instance depending on the nature and gravity of the breach, as determined by the Data Protection Board.
A practical compliance checklist
Use this as your starting baseline. Each item maps to a concrete deliverable.
- Map your data. Build a Record of Processing: what personal data you hold, where it lives, why you have it, and who you share it with. You cannot protect what you cannot see.
- Identify your lawful basis for every processing purpose, and document it.
- Rewrite your privacy notice in clear, accessible language (the Act allows notices to be made available in English and the languages in the Eighth Schedule of the Constitution).
- Build a consent mechanism that captures, versions, and lets people withdraw consent easily. Track the consent artefact for each purpose.
- Stand up a Data Principal request workflow for access, correction, and erasure — with identity verification and a tracked turnaround time.
- Set retention and deletion rules per data category, and automate erasure where you can.
- Tighten security safeguards — access control, encryption, logging, and vendor controls.
- Review every Data Processor contract to ensure processing is under a valid contract and obligations flow down.
- Create a breach-response runbook with the notification timeline to the Board and to affected individuals.
- Handle children’s data — add age assurance and parental-consent flows where relevant.
- Appoint a contact — a DPO or a designated person — and publish how to reach them.
- Assess Significant Data Fiduciary status and, if applicable, plan for DPIAs and independent audits.
How DPDP fits with your other frameworks
If you already run SOC 2 or ISO 27001, you have a head start. Your access controls, encryption, logging, and vendor-management practices already satisfy much of the “reasonable security safeguards” expectation. The genuinely new work is privacy-specific: consent, notices, Data Principal rights, and the breach clock. Treating DPDP as an extension of your existing control set — rather than a separate programme — keeps the cost and effort down.
You can read more about how DPDP maps to other regimes in our DPDP framework guide, and how it compares structurally to Europe’s law in our breakdown of DPDP vs GDPR.
Start small, then operationalise
Most teams can reach a defensible baseline in a few weeks: map the data, fix the notice and consent, and put a request workflow and breach runbook in place. The harder part is keeping it current as your systems, vendors, and processing purposes change. That is where a purpose-built tool earns its keep.
Comply ships DPDP as a first-class, native module — data mapping, consent and notice management, Data Principal request workflows, and the breach clock — mapped to your existing controls so one piece of evidence satisfies many obligations. See how it works on our privacy platform page, or check our transparent pricing to plan your rollout.