Data Privacy Compliance in India: The DPDP Act Framework
For two years, the Digital Personal Data Protection Act, 2023 was a law that existed without teeth. Passed in August 2023, it sat dormant while businesses filed it mentally under "future problems."
That ended on November 13, 2025. The Ministry of Electronics and Information Technology notified the DPDP Rules, 2025, constituted the Data Protection Board of India, and started a three-phase enforcement clock. The final phase begins on May 13, 2027, when every substantive obligation under the Act becomes enforceable, with penalties running up to Rs. 250 crore per violation.
The businesses that will navigate this well are not the ones scrambling in April 2027. They are the ones using the current window to rebuild consent flows, vendor contracts, retention schedules, and breach response while the regulator is still in setup mode. This guide explains the complete DPDP framework: who it catches, what it demands, what it costs to ignore, and the order in which to fix things.
How India Got Here: From Puttaswamy to the DPDP Act
India's privacy regime rests on a constitutional foundation that businesses should understand, because it explains the law's direction of travel. In 2017, a nine-judge bench of the Supreme Court in Justice K.S. Puttaswamy v. Union of India held unanimously that privacy is a fundamental right, intrinsic to life and personal liberty under Article 21. Informational privacy, the right to control how one's personal information is used, was expressly part of that holding.
The legislative path from that judgment to the present statute took six years and several withdrawn drafts. What finally emerged as the DPDP Act, 2023 (Act No. 22 of 2023) is a deliberately lean law: it covers digital personal data only, rejects the GDPR's elaborate category system, and builds on two pillars, consent backed by itemized notice, and accountability enforced by a dedicated regulator. Until the Act's substantive provisions activate in May 2027, the older framework of the IT Act, 2000 and the SPDI Rules, 2011 continues to govern, which means Indian businesses are currently living under both regimes at once.
Does the DPDP Act Apply to You?
The threshold question has a deliberately wide answer. Under Section 3, the Act applies to:
- All digital personal data processed within India, whether collected digitally from the start or collected offline and digitized afterwards
- Processing outside India, if it is connected to offering goods or services to Data Principals within India
Two features of this scope catch businesses off guard. First, there is no size, revenue, or startup exemption. A two-person SaaS team collecting customer emails carries the same core obligations as a listed company. Second, "personal data" is defined simply as any data about an individual who is identifiable by or in relation to that data. Names, phone numbers, emails, device identifiers, employee records, customer support logs: if a person can be identified from it, it is in scope. Our companion article on what Indian websites get wrong about DPDP compliance covers how even a basic contact form triggers the Act.
The Four Roles That Determine Your Obligations
Every DPDP compliance analysis starts by assigning roles correctly:
| Role | Who It Is | Core Consequence |
|---|---|---|
| Data Principal | The individual whose data it is | Holds the rights: access, correction, erasure, grievance, nomination |
| Data Fiduciary | The entity that decides why and how data is processed, meaning almost every business collecting customer or employee data | Carries all statutory obligations and penalties; cannot contract out of them |
| Data Processor | Any entity processing data on a Fiduciary's behalf: CRMs, cloud hosts, payroll tools, analytics platforms | Governed through contract; the Fiduciary answers for its failures |
| Consent Manager | A registered, India-based intermediary that lets Data Principals manage consents across platforms | Registration with the Data Protection Board opens November 13, 2026 |
The single most important structural rule: under Section 8(1), the Data Fiduciary remains responsible for compliance including for processing carried out by its Data Processors, irrespective of any agreement to the contrary. Your vendor's failure is your penalty. We covered the contract mechanics of this exposure in depth in our article on SaaS vendor liability under the DPDP Act.
The Lawful Basis: Consent and Legitimate Uses
Section 4 permits processing only for a lawful purpose, and only on one of two bases: consent, or a defined set of legitimate uses.
What Valid Consent Requires
DPDP consent is not a checkbox buried in terms of service. It must be free, specific, informed, unconditional, and unambiguous, given by clear affirmative action, and limited to the data necessary for the specified purpose. Before seeking consent, the Fiduciary must deliver a notice that itemizes the personal data sought, the specific purpose, how the individual can exercise their rights and withdraw consent, and how to complain to the Data Protection Board. The Rules demand plain language, with the notice available in English or any of the 22 languages of the Eighth Schedule at the individual's option.
Two disciplines follow. Withdrawal must be as easy as giving, and withdrawal obliges the Fiduciary and its processors to stop processing within a reasonable time. And bundled consent is dead: conditioning a service on consent to data use that the service does not need fails the "unconditional" test.
The Legitimate Uses: Narrower Than You Think
Section 7 permits processing without consent for specified "legitimate uses," and businesses consistently overestimate this list. It covers voluntary provision of data by the individual for a purpose they sought (a customer handing you their number for a delivery), state functions and subsidies, legal obligations, medical emergencies, employment-related purposes, and a few similar categories. It does not contain a GDPR-style open-ended "legitimate interests" ground. If your processing does not fit a listed category, consent is the only door, and marketing, analytics, and profiling almost never fit a listed category.
Core Obligations of Every Data Fiduciary
Whether you employ five people or five thousand, Section 8 and the Rules impose a common floor:
- Security safeguards. Reasonable technical and organizational measures to prevent breaches: encryption, access controls, logging, and backups. Failure here carries the Act's highest penalty tier, up to Rs. 250 crore.
- Breach notification. On any personal data breach, intimate every affected Data Principal without delay and file with the Data Protection Board, including a detailed report within 72 hours. There is no harm threshold; fifty records trigger the same duty as five million.
- Accuracy and erasure. Keep data accurate where it feeds decisions about the individual, and erase personal data once the purpose is served and retention is no longer legally required. The Rules add active triggers: for specified classes of large platforms, accounts inactive for defined periods must have their data erased after notice.
- A named, published contact. Every Fiduciary must publish the contact details of a person able to answer data-related questions. Note carefully: a formal Data Protection Officer is mandatory only for Significant Data Fiduciaries, not for everyone, contrary to much of the commentary you will read.
- Grievance redressal. An effective mechanism to resolve Data Principal complaints, with the Rules setting defined response timelines.
- Processor contracts. Engage processors only under a valid contract that imposes the obligations the Act expects.
- Children's data. Before processing data of anyone under 18, obtain verifiable parental or guardian consent, and do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
Significant Data Fiduciaries: The Enhanced Tier
The Central Government can notify classes of Fiduciaries as Significant Data Fiduciaries (SDFs) based on factors including data volume and sensitivity, risk to Data Principals' rights, and impact on sovereignty, security, and public order. SDF status adds a second layer of obligations:
- A Data Protection Officer based in India, answerable to the board of directors, as the point of accountability
- An independent data auditor conducting periodic audits of compliance
- Periodic Data Protection Impact Assessments, covering risks to Data Principals' rights
- Algorithmic due diligence: verifying that algorithmic processing does not pose risks to Data Principals' rights
If your business processes high volumes of personal data in sectors like e-commerce, fintech, health, or social media, plan on the working assumption that SDF notification is a matter of when, not if, and build the audit and assessment machinery early rather than retrofitting it under a notification deadline.
Data Principal Rights and the Grievance Machine
The Act hands individuals four operational rights and one structural one:
- Access: a summary of their personal data, what is being done with it, and who it has been shared with
- Correction, completion, updating, and erasure
- Grievance redressal for any act or omission regarding their data
- Nomination: appointing someone to exercise rights in the event of death or incapacity
The operational consequence businesses underestimate is the plumbing. Each right requires the ability to locate one individual's data across production systems, backups, and every processor in the chain, then act on it within defined timelines. A rights request that cannot be fulfilled because your CRM vendor cannot delete across backups is a compliance failure with your name on it, which is why rights-assistance clauses belong in every vendor contract.
Data Principals also carry duties under the Act, including not filing false or frivolous complaints and not impersonating others, with penalties up to Rs. 10,000, a small but real counterweight against complaint abuse.
Breach Notification, the Data Protection Board, and Enforcement
Enforcement runs through the Data Protection Board of India, a digital-first adjudicator already constituted and operational, with complaints filed and tracked online and appeals lying to TDSAT. The Board can inquire into breaches on complaint, on reference, or on its own motion, direct remedial measures, and impose the Act's monetary penalties.
The breach mechanics under Rule 7 are the provision most likely to be tested first. On any personal data breach, the Fiduciary must tell every affected individual, without delay, in plain language, what happened, what it might mean for them, and what is being done; send an initial intimation to the Board without delay; and file a detailed report within 72 hours of becoming aware. The clock starts at awareness, not at the end of the investigation. Two regulators may hold parallel clocks for the same incident: CERT-In's 2022 directions independently require reporting of specified cyber incidents within 6 hours.
The penalty Schedule is structured by violation type:
| Violation | Maximum Penalty |
|---|---|
| Failure to maintain reasonable security safeguards | Rs. 250 crore |
| Failure to notify the Board and affected individuals of a breach | Rs. 200 crore |
| Breach of obligations relating to children's data | Rs. 200 crore |
| Breach of additional obligations of Significant Data Fiduciaries | Rs. 150 crore |
| Breach of Data Principal duties | Rs. 10,000 |
| Breach of any other provision of the Act or Rules | Rs. 50 crore |
Penalties are per violation and stack across violations. In setting amounts, the Board weighs the nature and gravity of the breach, its repetitiveness, and whether the Fiduciary took mitigation steps, which makes a documented, rehearsed breach response plan a direct financial mitigation, not just good hygiene.
Cross-Border Transfers: The Negative List Model
Section 16 permits transfer of personal data outside India to any country except those the Central Government restricts by notification. This is a negative list model, sharply different from the GDPR's adequacy-and-safeguards architecture: no adequacy assessments, no standard contractual clauses, no binding corporate rules are required by the Act itself.
The flexibility cuts both ways. Restrictions can be notified at any time, can target specific countries, classes of Fiduciaries, or sectors, and sit on top of sectoral localization mandates that already exist in payments, insurance, and other regulated fields. The practical posture for businesses is contractual: record where your data lives across every processor, and preserve exit or relocation rights if a jurisdiction lands on the restricted list.
The Phased Timeline and the Compliance Roadmap
The enforcement calendar, set by the November 13, 2025 notifications:
| Phase | Date | What Activates |
|---|---|---|
| Phase 1 | November 13, 2025 (done) | Definitions, Data Protection Board constitution and procedure; the regulator is live |
| Phase 2 | November 13, 2026 | Consent Manager registration framework |
| Phase 3 | May 13, 2027 | The substantive core: consent and notice, legitimate uses, Fiduciary obligations, Data Principal rights, SDF obligations, breach notification, cross-border rules, penalties |
Between now and May 2027, the work sequences itself into six blocks:
| Step | What It Involves | Why It Comes First or Later |
|---|---|---|
| 1. Data mapping | Inventory every personal data flow: what you collect, why, where it lives, who touches it, which processors hold it | Everything else depends on knowing the data |
| 2. Consent and notice rebuild | Itemized notices in plain language, granular consent capture, withdrawal parity | User-facing changes take longest to ship and test |
| 3. Vendor contract remediation | DPAs with notification timelines, security terms, erasure assistance, audit rights across the processor stack | Renegotiation across dozens of vendors takes months |
| 4. Retention and erasure engineering | Retention schedules, deletion workflows that actually reach backups and processors | Rights requests are unfulfillable without it |
| 5. Breach response build | Detection-to-notification runbook meeting the 72-hour and 6-hour clocks, with tabletop drills | The deadline starts at awareness; rehearsal buys hours |
| 6. Governance and training | Published contact, grievance mechanism, staff protocols, and SDF-readiness if applicable | Sustains the other five blocks over time |
A useful division of labour: your internal team owns data mapping and process change, while counsel owns consent architecture, vendor contract remediation, and the regulatory interfaces. Businesses running a corporate legal retainership are already executing this as a standing workstream rather than a one-time project; our Corporate Advisory team structures DPDP programs the same way, and growth-stage companies can find the packaged version at our Startup Hub.
The Bottom Line
The DPDP framework asks Indian businesses to make one transition: from treating personal data as an asset they hold by default, to treating it as a responsibility they hold on conditions. Consent that is actually itemized. Retention that actually ends. Vendors that are actually bound. Breaches that are actually reported inside 72 hours. And documentation that proves all of it to a regulator that is already constituted and already accepting complaints.
May 13, 2027 is the enforcement date, but the working deadline is earlier, because consent flows, vendor renegotiations, and erasure engineering each take months, and they take longer when forty of your vendors are being renegotiated by every customer at once. Speak to our Corporate Advisory team about sequencing your DPDP program while the window is still a window.
Strategic Legal Counsel
Discuss the implications of this briefing for your specific corporate or cross-border operations.