The Digital Personal Data Protection Act, 2023 is India's first comprehensive personal data law, and as compliance timelines under its rules take effect, "we'll deal with it later" has quietly become a board-level risk. This explainer translates the Act's obligations into the questions your team actually has to answer. (It is an explainer, not legal advice — engage counsel for your specific situation.)
Who it touches
If your organisation processes digital personal data of individuals in India — customers, users, employees — you are a Data Fiduciary under the Act, whether you are a bank, a D2C brand, or a ten-person SaaS startup. The law also reaches processing outside India when it is connected to offering goods or services to people in India. Vendors processing data on your instructions are Data Processors — but the accountability stays with you.
The core duties
- A lawful basis, usually consent: specific, informed, and as easy to withdraw as it was to give — accompanied by a clear notice of what is collected and why. Certain "legitimate uses" (like data voluntarily provided for a specified purpose, or employment matters) are recognized, but they are narrower than most teams assume.
- Security safeguards: reasonable measures to prevent breaches — the obligation that carries the headline penalty exposure, up to ₹250 crore for failure to protect data.
- Breach intimation: personal data breaches must be reported to the Data Protection Board and to affected individuals. That presumes you can detect a breach, scope it, and describe it — a capability question long before it is a legal one.
- Erasure and correction: individuals can demand correction and deletion; data should go when its purpose is served, which means knowing where it lives.
Significant Data Fiduciaries carry more
Entities the government designates as Significant Data Fiduciaries — based on volume and sensitivity of data, risk to rights, and similar factors — take on additional duties: a Data Protection Officer based in India, independent data audits, and periodic Data Protection Impact Assessments. If you operate at scale in fintech, health, or consumer platforms, plan as if the designation is coming.
The working checklist
Four artefacts cover most of the distance: a data map (what personal data, where, why, for how long); consent and notice flows rebuilt to be specific and revocable; processor contracts that pass your obligations downstream; and a breach runbook with named owners, drafted notification templates, and a tested detection path. Teams that build these four stop treating the DPDP Act as a legal abstraction and start treating it as an operations project — which is what it is.