Compliance · DPDP Act 2023
India's DPDP Act - compliance for anyone who handles Indian residents' data.
India's Digital Personal Data Protection Act (DPDP) 2023 applies to any business that processes the personal data of Indian residents - even from outside India. This page covers what the law requires and how we help you comply. If you need GDPR, CCPA, SOC 2, or ISO 27001 readiness instead, see our cybersecurity and compliance services.
The penalty side of the DPDP Act
What is the DPDP Act?
The key concepts you need to know.
The Digital Personal Data Protection Act 2023 is India first comprehensive data protection law. It draws from GDPR but is purpose-built for the Indian context.
Data Fiduciary
Your company, if you decide why and how personal data is processed.
Data Processor
A vendor processing data on your behalf (you remain accountable).
Significant Data Fiduciary (SDF)
Large-volume or sensitive-data processors with stricter obligations: DPO mandatory, DPIA required, independent audits.
Data Principal
The individual whose data is being processed - your customer, your employee.
Personal Data
Any data about an identifiable individual. Email, phone, location, behavioural - all in scope.
Where the law applies
You process personal data within India OR you process Indian residents data from outside India in connection with offering them goods or services. No small-business exemption.
What compliance requires
The seven core requirements.
The Act sets out a clear obligation framework. Get these seven right and you have a defensible posture.
1. Lawful, purpose-limited processing
You can process personal data only for the purpose you stated to the Data Principal - and only with their consent or under a "legitimate use" exception listed in the Act. Repurposing data without re-consent is a violation.
2. Notice to the Data Principal
Before collecting personal data, you must give a clear, plain-language notice covering: what data, what purpose, the rights the Data Principal has, how to file a grievance, how to withdraw consent. Buried-in-T&Cs language does not pass.
3. Consent management
Consent must be free, specific, informed, unambiguous, and revocable. You must be able to demonstrate consent on demand (audit trail). One-click "I accept" buttons buried in terms of service typically fail this standard.
4. Security safeguards
You must implement reasonable security safeguards to prevent breach. The regulator will compare your controls to industry-typical security baselines. Encryption at rest and in transit, access controls, logging, vulnerability management are table stakes.
5. Breach reporting
You must notify the Data Protection Board AND the affected Data Principals "as soon as possible" after becoming aware of a breach. The notification rules require an internal runbook, defined escalation, and clean communication templates - not improvisation in a crisis.
6. Data Principal rights
Data Principals have the right to: access their data, correct or update it, erase it, nominate someone to exercise rights on their behalf, and file a grievance. You need a documented, fast-turnaround process to honor these requests.
7. Children data + SDF obligations
Processing data of children (under 18) requires verifiable parental consent. Behavioural monitoring and targeted advertising aimed at children are prohibited. SDFs face additional obligations: India-based DPO, DPIA, independent audits.
How VITI Security helps
We do the 'reasonable security safeguards' half.
The DPDP Act has a security half (technical safeguards, breach detection) and a legal half (consent, notices, data-principal rights, and the DPO role). We do the security half; the legal half needs privacy counsel, and for a Significant Data Fiduciary the DPO must be an appropriately qualified person - not us.
Security-safeguards assessment
Where your technical controls stand against the "reasonable security safeguards" the Act expects. Output: a written report with ranked gaps and what each takes to close.
Security safeguard implementation
Encryption at rest and in transit, access controls, MFA, logging and monitoring, vulnerability management - mapped to ISO 27001 Annex A / CIS Controls so you have a defensible baseline when the regulator asks.
Vulnerability management & VAPT
Penetration testing and continuous scanning (Vexta) - the ongoing testing a defensible security posture needs.
Data-location mapping (technical)
Where personal data physically lives across your systems, so it can be secured - and so you can react quickly if a cross-border restricted list is published. The legal Record of Processing sits with your privacy lead.
Breach-detection & technical response
Detection, containment, and evidence-preservation runbook, drilled in a tabletop. The legal notification to the Data Protection Board and Data Principals is drafted by your counsel or DPO - we make sure you detect the breach in time to send it.
Alongside your DPO / counsel
Consent management, notices, data-principal-rights processes, DPIAs, and - for SDFs - the mandated DPO sit with privacy counsel. We handle the engineering and work alongside them.
How we scope the security side
How do we scope the DPDP security work?
Sized to your systems and data after a short scoping call. The legal-obligations track runs in parallel with your privacy counsel.
Assess
Map your technical controls against the reasonable-security-safeguards expectation. Output: a ranked backlog with effort estimates.
Implement
Encryption, access control, MFA, logging/monitoring, and vulnerability management around personal-data stores. Highest-impact gaps first.
Test
Penetration testing and scanning to confirm the safeguards hold and to give you a defensible baseline.
Rehearse
A breach-response tabletop so detection, containment, and evidence handling are practiced before you need them.
DPDP Act compliance FAQ
Are we a Significant Data Fiduciary?
We are GDPR-compliant. Are we DPDP-compliant?
What if our customer data is hosted outside India (AWS US, etc.)?
What exactly do you do vs. not do?
How much does the security work cost?
How do data principals raise a grievance or exercise their rights?
Start with a security-safeguards assessment.
Find out exactly where your technical controls stand against the DPDP Act's reasonable-security-safeguards expectation. You get a written report with each gap, your current status, and what it takes to close - fixed price. Bring your privacy counsel for the consent, notice, and DPO side.

