VITI Security
We do the security engineering, not the audit or the legal work. VITI Security implements and tests the technical security controls these frameworks require - access control, encryption, logging and monitoring, vulnerability management, and penetration testing. The certification or attestation is issued by an independent, accredited auditor or CPA firm that you retain; formal policy authoring, legal review, and Data Protection Officer duties sit with your auditor and privacy counsel, not with us. We have no partnership, referral fee, or kickback with any certifying body - you pick them, and we make the technical controls pass.

Compliance · DPDP Act 2023

India's DPDP Act - compliance for anyone who handles Indian residents' data.

India's Digital Personal Data Protection Act (DPDP) 2023 applies to any business that processes the personal data of Indian residents - even from outside India. This page covers what the law requires and how we help you comply. If you need GDPR, CCPA, SOC 2, or ISO 27001 readiness instead, see our cybersecurity and compliance services.

The penalty side of the DPDP Act

INR 250 cr
Max penalty for missing reasonable security safeguards
INR 200 cr
Max penalty for not notifying a breach
"ASAP"
Breach notification timeline to Data Protection Board

What is the DPDP Act?

The key concepts you need to know.

The Digital Personal Data Protection Act 2023 is India first comprehensive data protection law. It draws from GDPR but is purpose-built for the Indian context.

Data Fiduciary

Your company, if you decide why and how personal data is processed.

Data Processor

A vendor processing data on your behalf (you remain accountable).

Significant Data Fiduciary (SDF)

Large-volume or sensitive-data processors with stricter obligations: DPO mandatory, DPIA required, independent audits.

Data Principal

The individual whose data is being processed - your customer, your employee.

Personal Data

Any data about an identifiable individual. Email, phone, location, behavioural - all in scope.

Where the law applies

You process personal data within India OR you process Indian residents data from outside India in connection with offering them goods or services. No small-business exemption.

What compliance requires

The seven core requirements.

The Act sets out a clear obligation framework. Get these seven right and you have a defensible posture.

1. Lawful, purpose-limited processing

You can process personal data only for the purpose you stated to the Data Principal - and only with their consent or under a "legitimate use" exception listed in the Act. Repurposing data without re-consent is a violation.

2. Notice to the Data Principal

Before collecting personal data, you must give a clear, plain-language notice covering: what data, what purpose, the rights the Data Principal has, how to file a grievance, how to withdraw consent. Buried-in-T&Cs language does not pass.

3. Consent management

Consent must be free, specific, informed, unambiguous, and revocable. You must be able to demonstrate consent on demand (audit trail). One-click "I accept" buttons buried in terms of service typically fail this standard.

4. Security safeguards

You must implement reasonable security safeguards to prevent breach. The regulator will compare your controls to industry-typical security baselines. Encryption at rest and in transit, access controls, logging, vulnerability management are table stakes.

5. Breach reporting

You must notify the Data Protection Board AND the affected Data Principals "as soon as possible" after becoming aware of a breach. The notification rules require an internal runbook, defined escalation, and clean communication templates - not improvisation in a crisis.

6. Data Principal rights

Data Principals have the right to: access their data, correct or update it, erase it, nominate someone to exercise rights on their behalf, and file a grievance. You need a documented, fast-turnaround process to honor these requests.

7. Children data + SDF obligations

Processing data of children (under 18) requires verifiable parental consent. Behavioural monitoring and targeted advertising aimed at children are prohibited. SDFs face additional obligations: India-based DPO, DPIA, independent audits.

How VITI Security helps

We do the 'reasonable security safeguards' half.

The DPDP Act has a security half (technical safeguards, breach detection) and a legal half (consent, notices, data-principal rights, and the DPO role). We do the security half; the legal half needs privacy counsel, and for a Significant Data Fiduciary the DPO must be an appropriately qualified person - not us.

Security-safeguards assessment

Where your technical controls stand against the "reasonable security safeguards" the Act expects. Output: a written report with ranked gaps and what each takes to close.

Security safeguard implementation

Encryption at rest and in transit, access controls, MFA, logging and monitoring, vulnerability management - mapped to ISO 27001 Annex A / CIS Controls so you have a defensible baseline when the regulator asks.

Vulnerability management & VAPT

Penetration testing and continuous scanning (Vexta) - the ongoing testing a defensible security posture needs.

Data-location mapping (technical)

Where personal data physically lives across your systems, so it can be secured - and so you can react quickly if a cross-border restricted list is published. The legal Record of Processing sits with your privacy lead.

Breach-detection & technical response

Detection, containment, and evidence-preservation runbook, drilled in a tabletop. The legal notification to the Data Protection Board and Data Principals is drafted by your counsel or DPO - we make sure you detect the breach in time to send it.

Alongside your DPO / counsel

Consent management, notices, data-principal-rights processes, DPIAs, and - for SDFs - the mandated DPO sit with privacy counsel. We handle the engineering and work alongside them.

How we scope the security side

How do we scope the DPDP security work?

Sized to your systems and data after a short scoping call. The legal-obligations track runs in parallel with your privacy counsel.

01

Assess

Map your technical controls against the reasonable-security-safeguards expectation. Output: a ranked backlog with effort estimates.

02

Implement

Encryption, access control, MFA, logging/monitoring, and vulnerability management around personal-data stores. Highest-impact gaps first.

03

Test

Penetration testing and scanning to confirm the safeguards hold and to give you a defensible baseline.

04

Rehearse

A breach-response tabletop so detection, containment, and evidence handling are practiced before you need them.

DPDP Act compliance FAQ

Are we a Significant Data Fiduciary?
The SDF threshold will be set by the government based on volume of data, sensitivity, risk of harm, and other factors. Indicators that you will likely be classified SDF: processing data of 10 lakh+ Indian residents, processing financial/health/biometric data, ecommerce or social media at scale. If any of these apply, plan for SDF obligations.
We are GDPR-compliant. Are we DPDP-compliant?
Not automatically. GDPR overlaps significantly with DPDP (consent, notice, rights, breach reporting), but DPDP has India-specific provisions: the DPO must be India-based, the breach notification differs, and children-data rules are stricter. On the security side, the technical safeguards you built for GDPR largely carry over - our assessment confirms that. The legal deltas (DPO, notice wording, consent) are for your privacy counsel.
What if our customer data is hosted outside India (AWS US, etc.)?
The Act allows cross-border transfer of personal data EXCEPT to countries the government places on a restricted list. As of writing no restricted list has been published. You should document where your data lives (data flow map) so when the list is published, you can react quickly.
What exactly do you do vs. not do?
We do the security half: a reasonable-security-safeguards assessment, technical controls (encryption, access, logging, vulnerability management), penetration testing, and breach-detection readiness. We do not do the legal half: consent management, notices, data-principal-rights processes, DPIAs as legal assessments, or the Significant Data Fiduciary DPO role. Those need privacy counsel and, for an SDF, an appropriately qualified India-based DPO - we work alongside them, we do not replace them.
How much does the security work cost?
The security-safeguards work is scoped per engagement after a short call, based on your systems and data footprint. A focused security gap assessment is fixed-scope, fixed-price; implementation is quoted before we start. Consent, notices, and DPO work are separate and handled by your privacy counsel, not us - so those costs are not ours to quote.
How do data principals raise a grievance or exercise their rights?
The DPDP Act requires every Data Fiduciary to publish the contact of a Grievance Officer who handles access, correction, erasure, and consent-withdrawal requests. VITI Security publishes its own at [email protected], as our own obligation. Standing up the equivalent intake-to-response workflow for your company is a privacy/legal exercise your counsel or DPO owns; on the technical side we make sure the systems behind it can actually action a deletion or export request.

Start with a security-safeguards assessment.

Find out exactly where your technical controls stand against the DPDP Act's reasonable-security-safeguards expectation. You get a written report with each gap, your current status, and what it takes to close - fixed price. Bring your privacy counsel for the consent, notice, and DPO side.