Compliance

DPDPA Compliance Services

Assess, implement and sustain compliance with India's Digital Personal Data Protection Act 2023, from finding where personal data actually lives to answering a data principal request inside the statutory window.

Talk to us about DPDPA
On this page

What the Act requires

The obligations below sit on the data fiduciary, which is whoever decides the purpose and means of processing. They apply whether or not the processing happens in India, once goods or services are offered to individuals here.

  • Notice and consent

    Consent must be free, specific, informed and unambiguous, requested through a notice that states the purpose in plain language.

  • Data principal rights

    Individuals can ask what you hold, have it corrected or erased, nominate someone to act for them, and escalate a grievance.

  • Purpose limitation and erasure

    Personal data must be erased once the stated purpose is served and retention is no longer required by law.

  • Consent managers

    The Act creates a registered intermediary through which individuals can give, review and withdraw consent across fiduciaries.

  • Significant data fiduciaries

    Organisations designated significant carry extra duties, including a data protection officer, independent audit and impact assessment.

  • Breach notification

    Personal data breaches must be reported to the Data Protection Board and to every affected individual, without a materiality threshold.

  • Cross-border transfer

    Transfer outside India is permitted except to territories the Central Government restricts, and sectoral rules may be stricter.

  • Reasonable security safeguards

    Fiduciaries must take reasonable measures to prevent breaches, and this is the obligation carrying the highest penalty in the schedule.

How an engagement runs

Five phases. Scope, boundaries and the rules of engagement are agreed in writing before anything is touched.

Talk to us about DPDPA
  1. Data discovery and mapping

    We find where personal data actually lives, including the copies in spreadsheets and test environments that no register lists.

  2. Gap assessment

    Your current handling is measured against each obligation in the Act, and the result is a ranked list rather than a maturity score.

  3. Consent and rights workflows

    Notice, consent capture and the request-handling path are designed so a data principal request can be answered inside the statutory window.

  4. Safeguards and breach readiness

    Technical and organisational measures are implemented against the risks your mapping surfaced, and the notification path is tested before it is needed.

  5. Evidence and review

    Records, policies and audit trails are left in a state you can show a regulator, and reviewed as your processing changes.

What we deliver

Personal data inventory and mapping

A record of what personal data you hold, where it moves, who processes it and on what basis, built from systems rather than from questionnaires.

Notice and consent design

Consent notices and capture flows written to the Act's specificity requirement, including withdrawal being as easy as giving consent.

Data principal request handling

A workable process for access, correction, erasure and nomination requests, with the verification step that stops a request becoming a breach.

Grievance redressal

The internal escalation route the Act requires before an individual can approach the Data Protection Board, with published contact details.

Breach detection and notification

Detection tied to your existing monitoring, plus a rehearsed notification path covering both the Board and affected individuals.

Significant data fiduciary readiness

Where designation is likely, the additional duties are prepared in advance: DPO appointment, independent audit and impact assessment.

Cross-border transfer review

Assessment of where your processing sends data, against both the Act and any sectoral rule that binds your industry more tightly.

Retention and erasure controls

Retention schedules and the deletion mechanics behind them, because a policy that nothing enforces is not an erasure control.

Practices that deliver this

DPDPA work is not a separate team. It draws on the practices already running, and consulting is where most engagements start.

Sectors where this applies

All sectors

These sector pages already name the Act among the frameworks they are measured against.

Frequently asked questions

Who does the DPDP Act apply to?

It applies to personal data processed in digital form in India, and to processing outside India where goods or services are offered to individuals in India. It does not cover personal data made publicly available by the individual themselves, or processing for purely personal or domestic purposes.

What is the difference between a data fiduciary and a data processor?

A data fiduciary determines the purpose and means of processing. A processor acts on the fiduciary's behalf under contract. The Act places its obligations on the fiduciary, who remains answerable for processing carried out by a processor on its instruction.

What makes an organisation a significant data fiduciary?

The Central Government designates significant data fiduciaries based on factors including the volume and sensitivity of personal data processed, risk to data principals, and impact on the sovereignty and integrity of India. Designation brings additional duties: a data protection officer based in India, an independent data auditor, and periodic data protection impact assessments.

Do we have to report every personal data breach?

Yes. The Act requires notification to the Data Protection Board and to each affected data principal. Unlike some regimes, it sets no materiality or risk threshold below which a breach need not be reported.

Can we transfer personal data outside India?

The Act permits transfer except to territories the Central Government restricts by notification. Sectoral regulators may impose stricter localisation requirements that continue to apply, so the position depends on which regulators bind you as well as on the Act.

What are the penalties for non-compliance?

The Act sets a schedule of financial penalties determined by the Data Protection Board, with the highest tier attaching to a failure to take reasonable security safeguards to prevent a personal data breach. Penalties are assessed on the nature, gravity and duration of the breach among other factors.

Is consent always required to process personal data?

No. The Act also allows processing for certain legitimate uses, including where an individual voluntarily provides data for a specified purpose, and for functions of the State, employment purposes, and specified emergencies. Where consent is the basis, it must be free, specific, informed, unconditional and unambiguous.

How does the DPDP Act relate to GDPR compliance we already have?

There is meaningful overlap in principles, so existing GDPR work is a useful starting point rather than wasted effort. The regimes differ in important places, including breach reporting thresholds, the consent manager mechanism, the treatment of legitimate uses, and the absence of a general legitimate-interests basis.

General information about the Act, not legal advice. Which obligations bind you depends on your processing and on any sectoral regulator.

Data protection

Find out where your personal data actually lives

Most DPDPA work starts with a map. Tell us what you process and our engineers will scope the assessment.

Book an assessment