The Digital Personal Data Protection Act, 2023 is India's first comprehensive personal data law, and as compliance timelines under its rules take effect, "we'll deal with it later" has quietly become a board-level risk. This explainer translates the Act's obligations into the questions your team actually has to answer. (It is an explainer, not legal advice — engage counsel for your specific situation.)

Who it touches

If your organisation processes digital personal data of individuals in India — customers, users, employees — you are a Data Fiduciary under the Act, whether you are a bank, a D2C brand, or a ten-person SaaS startup. The law also reaches processing outside India when it is connected to offering goods or services to people in India. Vendors processing data on your instructions are Data Processors — but the accountability stays with you.

The core duties

Significant Data Fiduciaries carry more

Entities the government designates as Significant Data Fiduciaries — based on volume and sensitivity of data, risk to rights, and similar factors — take on additional duties: a Data Protection Officer based in India, independent data audits, and periodic Data Protection Impact Assessments. If you operate at scale in fintech, health, or consumer platforms, plan as if the designation is coming.

The working checklist

Four artefacts cover most of the distance: a data map (what personal data, where, why, for how long); consent and notice flows rebuilt to be specific and revocable; processor contracts that pass your obligations downstream; and a breach runbook with named owners, drafted notification templates, and a tested detection path. Teams that build these four stop treating the DPDP Act as a legal abstraction and start treating it as an operations project — which is what it is.

Penalty exposure concentrates where security is weakest, and the clock on breach intimation starts whether or not you are ready. The data map is the cheapest insurance in the whole programme.