VITI Security

India · Compliance · Updated July 2026

India's DPDP Act 2023, explained without the lawyer-speak.

The Digital Personal Data Protection Act is India's first real privacy law. If your business handles any personal data of Indian residents - customers, employees, leads, anyone - this affects you. Here's what it actually says, what to fix first, and what happens if you ignore it.

TL;DR

  • · Every business that processes personal data of Indian residents is a "Data Fiduciary" and must comply.
  • · Penalties go up to ₹250 crore per instance for serious breaches.
  • · You need explicit, granular consent - not buried checkboxes. Plus the right to withdraw it.
  • · You must notify the Data Protection Board AND affected users within hours of a breach.
  • · Rules are being notified in phases. Most are now in force; cross-border data transfer rules are pending.
  • · The expensive thing isn't compliance. It's the after-breach defense if you skipped compliance.

1. What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 is India's first comprehensive privacy law. It was enacted in August 2023 and is being brought into force in phases through 2025-2026 as the Data Protection Board (DPB) and detailed rules get notified.

Conceptually it's closest to the EU's GDPR but with India-specific tweaks: looser cross-border transfer rules (mostly), stricter requirements on consent withdrawal, higher penalties as a percentage of revenue for SMBs, and a specific category of "Significant Data Fiduciaries" with additional duties.

2. Who it applies to

Any business - Indian or foreign - that processes the personal data of Indian residents in the context of offering goods or services in India. That includes:

  • Indian companies of any size (no SMB exemption)
  • Foreign companies selling to Indian customers (extraterritorial reach)
  • Non-profits, partnerships, sole proprietorships
  • SaaS products with Indian users (even free tiers)
  • Government bodies (with carve-outs for security/sovereignty)

If your customer list, employee records, lead database, or even your website analytics include Indian residents, the Act applies to you.

3. Key terms in plain English

  • Data Principal = the person whose data you have. (User, customer, employee, lead.)
  • Data Fiduciary = you, the business that decides what to do with the data.
  • Data Processor = a third party who handles data on your instructions (your CRM provider, your payroll service).
  • Significant Data Fiduciary (SDF) = the government can designate large-scale or sensitive Fiduciaries as SDFs, who get extra duties: DPO appointment, DPIA, audits.
  • Consent Manager = a registered intermediary that helps Data Principals manage consents across many Fiduciaries. (Think: a privacy dashboard like Indian DigiLocker for consents.)

4. What you must do

Minimum obligations every Data Fiduciary has:

  1. Lawful basis. Process personal data only with consent OR for "certain legitimate uses" (employment, public-interest functions, etc.). Most commercial uses require consent.
  2. Notice. At or before collecting data, give the Data Principal a clear notice (in any of India's 22 scheduled languages they request) of: what data you're collecting, what for, how to withdraw consent, how to file a complaint.
  3. Purpose limitation. Use the data only for the purpose you stated. New purpose = new consent.
  4. Data minimization. Collect only what you actually need.
  5. Accuracy. Keep data accurate; correct mistakes promptly.
  6. Retention. Delete data once the purpose is satisfied (unless law requires retention).
  7. Security safeguards. "Reasonable security safeguards" to prevent breach. Vague on purpose - the Board will define specifics by sector.
  8. Breach notification. Notify the Board and affected Data Principals (more on this below).
  9. DPIA + audits if you're a Significant Data Fiduciary.
  10. Children's data. Verifiable parental consent for under-18s. No tracking/profiling of children.
  11. DPO required if you're an SDF; recommended otherwise. Contact details must be public.

The biggest practical change from how most Indian companies operate today.

  • Specific. Each purpose needs its own consent. No "by signing up you agree to everything."
  • Informed. User must know exactly what they're consenting to, in clear language.
  • Free. No pre-ticked boxes. No "you must consent to use this site."
  • Granular. Marketing emails, third-party sharing, and product use all need separate consents.
  • Withdrawable. User must be able to withdraw any consent as easily as they gave it. "Email us to unsubscribe" is not enough.
  • Auditable. You must be able to prove, per user, what they consented to and when.

Most "Accept cookies" banners do not pass this test. Most marketing-list signup flows do not pass either. Fix this first.

6. Breach notification

On detecting a personal data breach, you must notify:

  • The Data Protection Board, in the prescribed format, within a tight timeline (the draft rules suggest 72 hours but expect this to tighten).
  • Every affected Data Principal directly - with what happened, what data was involved, what they should do, and what you're doing to mitigate.

The notification itself is mandatory regardless of severity. Hiding breaches is a separately punishable offense.

7. Penalties

Penalties are tiered. Maximum amounts (from Schedule of the Act):

  • ₹250 crore for failure to implement reasonable security safeguards (the headline penalty)
  • ₹200 crore for failure to notify a breach
  • ₹150 crore for child-related violations
  • ₹150 crore for SDF-specific failures
  • ₹50 crore for general non-compliance

The Board considers severity, recurrence, mitigation efforts, and the Fiduciary's ability to pay - so the headline maximum rarely hits SMBs in practice. But ₹5-25 crore range orders are realistic for sloppy mid-market companies.

8. DPDP vs GDPR - quick comparison

  • Both: need lawful basis, consent rules, breach notification, data subject rights, DPO requirement for large players.
  • DPDP-only: Consent Manager intermediaries, mandatory Indian-language notice, 22 official languages.
  • GDPR-only: Strict cross-border transfer regime (DPDP is permissive by default), legitimate interest as a standalone basis, fines up to 4% of global turnover.
  • Easier in DPDP: no profiling/automated-decision restrictions, looser cross-border rules (today).
  • Harder in DPDP: tighter consent withdrawal mechanics, language-localization requirement, faster expected breach notification.

If you're already GDPR-compliant, you're 80% of the way to DPDP. The remaining 20% is: India-specific language notice, Indian Consent Manager integration when those launch, and tightening up your consent UI.

9. 14-point compliance checklist

  1. Map every personal data flow (where you collect, where you store, where you share).
  2. Identify your Data Fiduciary role + any sub-processors you use.
  3. Inventory consent: what you have, when given, for which purpose.
  4. Rewrite privacy policy in plain language. Translate to top user languages.
  5. Rebuild signup/checkout flows with granular consent (marketing / third-party / product).
  6. Add an in-product consent dashboard (or use a Consent Manager once available).
  7. Implement "withdraw consent" + "delete my data" workflows. Test that they actually work.
  8. Implement data minimization (audit forms - remove fields you don't actually need).
  9. Set retention policies + auto-delete jobs.
  10. Encrypt personal data at rest and in transit. MFA on all admin access.
  11. Run a security assessment (VAPT) and remediate critical findings.
  12. Document a breach-response runbook. Tabletop exercise it.
  13. Appoint a DPO (mandatory for SDF, recommended otherwise) and publish contact.
  14. Train staff who handle personal data. Annual refresh.

10. How VITI Security helps

DPDP compliance work is what we do for SMBs every day. Typical engagement:

  1. Discovery (week 1): Data flow mapping, gap analysis against the 14-point checklist.
  2. Remediation (weeks 2-8): Rebuild consent flows, write new privacy policy, fix security gaps surfaced by VAPT, implement retention jobs, train staff.
  3. Audit prep (weeks 9-10): Document everything for the auditor (if you need one) or internal review.
  4. Ongoing: Monthly posture check, breach-response retainer, annual refresh.

Fixed-price proposal in two business days after a 30-minute scoping call. No hourly billing surprises.

Get DPDP-ready before the Board takes interest in you.

30-minute scoping call. Fixed-price proposal. We do this every day.