The Digital Personal Data Protection Act 2023 is India's first comprehensive personal data protection law. It was enacted in August 2023, the Draft Rules were published for consultation in early 2025, and enforcement is being rolled out in phases. If you process personal data of anyone in India in connection with offering goods or services, this applies to you. Penalties reach Rs 250 crore per breach category. This guide walks through obligations in plain English, what to prioritise, what most startups get wrong, and a 90-day action plan you can actually execute against. Always verify the current status of the Rules and any specific obligation with qualified counsel before acting; this guide is practitioner reference material, not legal advice.
The Digital Personal Data Protection Act 2023 (Act 22 of 2023) is India's dedicated law governing the processing of digital personal data. It replaces the patchwork of privacy protections that previously lived across the Information Technology Act 2000 and the SPDI Rules 2011. It creates a rights-based framework: individuals (Data Principals) have specific rights over their personal data, entities that process that data (Data Fiduciaries) have specific duties, and a regulator (the Data Protection Board of India) enforces the framework with penalties up to Rs 250 crore per breach category. It applies to processing of digital personal data within India, and to processing outside India when connected with offering goods or services to individuals in India (extraterritorial reach similar to GDPR).
The Act was enacted in August 2023. The Draft Digital Personal Data Protection Rules 2025 were published for consultation and are in the process of being finalised and notified. Different provisions are being notified in phases. Some provisions are already in force; others follow specific commencement dates. Treat the Act as "already in force with phased enforcement" and prepare accordingly. Verify the current status of specific provisions with counsel before relying on any particular timeline.
Four categories of actors, defined by the Act. Understanding which one you are is the first compliance question.
Data Principal. The individual whose personal data is being processed. In the case of a child, includes parent or lawful guardian. In the case of a person with disability, includes lawful guardian. These are the rights-holders.
Data Fiduciary. Any person who alone or in conjunction with others determines the purpose and means of processing personal data. This is you if you decide why customer data gets collected and how it gets used. A D2C brand collecting customer names and phone numbers is a Data Fiduciary. A SaaS company managing its own customer accounts is a Data Fiduciary for those accounts. Primary accountability sits here.
Data Processor. Any person who processes personal data on behalf of a Data Fiduciary. Your cloud provider, your email marketing tool, your payroll processor, your third-party analytics service are Data Processors. Processors are bound by contract to the Fiduciary and have specific obligations under the Fiduciary's instructions.
Significant Data Fiduciary (SDF). A Data Fiduciary designated as such by the Central Government based on volume and sensitivity of personal data processed, risk to Data Principals, and other factors. SDFs have extra obligations: appoint a Data Protection Officer based in India, appoint an Independent Data Auditor, undertake periodic Data Protection Impact Assessments, and comply with any additional measures the government prescribes.
Extraterritorial reach. A foreign entity processing personal data of individuals in India in connection with offering goods or services to those individuals is covered by the Act. If you are a US SaaS with Indian customers, you are within scope.
Eleven obligations that apply to nearly every Data Fiduciary. The details are calibrated based on scale and risk, but the fundamentals apply from day one.
Process personal data only for a lawful purpose. The lawful bases under the Act are consent, and certain enumerated legitimate uses (voluntary provision of data for specified purpose, employment, compliance with law, medical emergency, public interest situations). Marketing and most commercial processing require consent.
Give the Data Principal a plain-language notice at or before collection covering the personal data being collected, the purpose of processing, the manner of exercising rights, and the manner of complaining to the Data Protection Board. Notice must be available in English and any of the Eighth Schedule languages the individual can access. Layered notices (short summary plus detailed policy) are the practical approach.
Where processing rests on consent, that consent must be free, specific, informed, unconditional, unambiguous, and given by clear affirmative action. It must be limited to the personal data necessary for the specified purpose. It must be as easy to withdraw as to give. Pre-ticked boxes, bundled consent for unrelated purposes, and consent hidden in terms of service do not qualify.
Use personal data only for the purpose for which it was collected. Do not silently expand the use. If purposes change materially, obtain fresh consent. Collect only what you need, not everything you could.
Make reasonable efforts to ensure personal data is accurate and complete, especially where used for decisions affecting the Data Principal or where the data may be shared with another Data Fiduciary.
Implement reasonable technical and organisational security safeguards to protect personal data from breach. Encryption at rest and in transit, access controls, audit logs, secure disposal, vendor security review, and incident response planning are the baseline expectations. Failure to take reasonable safeguards leading to a breach carries the highest penalty tier (up to Rs 250 crore).
Notify the Data Protection Board and each affected Data Principal upon a personal data breach. The Draft Rules specify concrete timelines. Plan for an initial notification within 72 hours of becoming aware of the breach with follow-up detailed reporting as the investigation progresses. This is one of the most operationally demanding obligations because it requires incident detection, incident response, communication templates, and a designated response team, all rehearsed before an incident happens.
Retain personal data only as long as necessary for the specified purpose, unless retention is required by law. Once the retention period ends, delete or anonymise. Have documented retention schedules per category of data. Silent forever-retention is not defensible under the Act.
Respond to Data Principal requests to access, correct, complete, update, and erase personal data, and to nominate another individual to exercise rights on their behalf in the event of death or incapacity. Provide a mechanism for grievance redressal. Set up an internal workflow to intake, verify identity, respond, and document each request within timelines the Rules prescribe.
Publish a mechanism for Data Principals to raise grievances. Designate a person as the contact point. Respond within the timelines specified in the Rules. Grievances not resolved satisfactorily can escalate to the Data Protection Board.
Enter into a valid contract with every Data Processor engaged. The Fiduciary is accountable for compliance by its Processors. This means vendor due diligence, contractually binding Processors to security and confidentiality obligations, restricting sub-processing, and maintaining an updated Data Processing Agreement (DPA) with each Processor.
The rights granted to individuals under the Act, which you must be able to fulfil.
| Right | What the individual can ask for | What you must do |
|---|---|---|
| Right to information | Summary of personal data being processed and processing activities | Provide clear, accessible summary within prescribed timeline |
| Right to correction and erasure | Correct inaccurate data, complete incomplete data, erase data no longer needed | Verify, act, communicate outcome |
| Right to grievance redressal | Raise a grievance and get response | Provide mechanism, designated contact, response within timeline |
| Right of nomination | Nominate another person to exercise rights in event of death or incapacity | Provide mechanism to record and honour nomination |
| Right to withdraw consent | Withdraw consent as easily as it was given | Provide mechanism, stop consent-based processing, communicate impact |
If you are notified as an SDF, extra obligations apply on top of the standard Fiduciary duties.
Data Protection Officer (DPO). Appoint a DPO based in India who reports to the Board of Directors or equivalent governing body. The DPO is the primary contact point for grievance redressal and coordinates with the Data Protection Board. Publish the DPO's contact details.
Independent Data Auditor. Appoint an independent auditor to evaluate compliance with the Act on a periodic basis. The auditor's findings inform your remediation.
Data Protection Impact Assessment (DPIA). Conduct a DPIA in accordance with the process specified in the Rules. DPIAs are structured evaluations of processing activities that carry higher risk to Data Principals.
Periodic audit. Undertake a periodic audit as specified. This is beyond the independent auditor's engagement and is a structured self-audit of policies, processes, and technical measures.
Other measures. The government may prescribe additional measures for SDFs. Track notifications.
Most startups are not SDFs. Large platforms, financial institutions, e-commerce marketplaces, and health data processors are the likely designees. Being notified as an SDF is a real operational shift; plan a 3 to 6 month runway to stand up the extra machinery if notification appears likely.
15-minute call. We will run through your data inventory, current consent practice, breach readiness, and vendor DPAs. You come out with a prioritised checklist of what to fix first and rough effort estimates for each item.
Book Free 15-min CallThe DPDP Act adopts a blacklist approach rather than the whitelist approach in GDPR. Transfers of personal data outside India are generally permitted, except to countries specifically notified by the Central Government as restricted. As of July 2026, no notified blacklist is public, and the practical position is that ordinary cross-border transfers to standard cloud providers (AWS, Azure, GCP in their global regions) are permissible under the Act.
Sectoral rules still apply. RBI mandates payment data localisation. Health data has specific sectoral treatment. Financial data has additional obligations. Government data, telecom data, and certain other categories have separate regimes. The DPDP Act does not override these sectoral requirements. Check both the DPDP position and your applicable sectoral regulator's position.
Practical guidance. Continue to prefer India-region hosting where operationally feasible (AWS Mumbai, Azure Central India, GCP Delhi) especially for regulated data. Where you host abroad, document the basis, the countries involved, and the safeguards in place. Include cross-border clauses in your DPAs with Processors.
The Data Protection Board is empowered to impose financial penalties for specific categories of breach. Penalties are not aggregate-capped; multiple category breaches can compound.
| Breach category | Maximum penalty | Typical trigger |
|---|---|---|
| Failure to take reasonable security safeguards leading to personal data breach | Up to Rs 250 crore | Unencrypted database exposed, credentials leaked, no MFA, ransomware event |
| Failure to notify Board or affected Data Principals of a breach | Up to Rs 200 crore | Breach known but hidden, delayed notification, incomplete communication |
| Non-fulfilment of additional obligations relating to children | Up to Rs 200 crore | Processing child data without verifiable parental consent, targeted advertising to children |
| Non-fulfilment of additional obligations as SDF | Up to Rs 150 crore | No DPO appointed after notification, no DPIA, no independent audit |
| Non-compliance with any other provision | Up to Rs 50 crore | Missing notice, inadequate consent flow, poor grievance redressal, retention violations |
| Data Principal duties breach (false grievance, impersonation) | Up to Rs 10,000 | Symbolic; targeted at abuse of process |
The Rs 250 crore cap is per category, per breach. A poorly-secured database that leaks 200,000 records and is not disclosed on time compounds security-safeguards, notification, and additional-obligation categories. The financial exposure is business-ending for most startups. Insurance can help but does not substitute for compliance.
The Act introduces a novel Consent Manager concept: a registered intermediary that provides Data Principals with a single interface to give, manage, review, and withdraw consent across multiple Data Fiduciaries. Think of it as an Account Aggregator-like model but for consent.
What Consent Managers do. Registered with the Data Protection Board. Interoperable, provide an accountable dashboard for the Data Principal. Enable consent to be given and withdrawn once, with the effect propagating to all connected Data Fiduciaries. Subject to specific obligations around transparency, non-manipulation, and audit.
What this means for you. For most businesses, Consent Manager registration is not something you pursue yourself. You engage with Consent Managers as they emerge in the ecosystem and integrate their protocols into your consent capture flow. Watch this space; the operational maturity of Consent Managers is still developing in 2026.
A concrete, week-by-week programme that gets a mid-sized Indian company from "not started" to "meaningfully compliant with documented gaps and a remediation roadmap." This is not "fully compliant with every provision" (that is a longer journey) but it is defensible against a routine regulator query and dramatically reduces breach exposure.
Notice must be a separate, clear, plain-language document. Burying data-collection purposes inside 40-page Terms is not compliant. Split them out and link the notice prominently.
Not valid under DPDP. Every consent must be a clear affirmative action. Un-tick your default checkboxes and rebuild the flow so the user actively opts in.
Asking one consent to cover product functionality plus marketing plus data sharing with partners is not lawful. Separate the purposes and let the user consent to each independently.
Every Processor needs a signed DPA. Missing DPAs are the single most common finding in a first-time DPDP readiness review. Get templates in place and start signing.
Keeping customer data forever "just in case" is not defensible. Publish a retention schedule and enforce it. Include backups.
You cannot notify a breach within 72 hours if you cannot detect one. Basic logging, alerting on abnormal access patterns, and periodic log review are the minimum. If you have no way to know a breach happened, you have a bigger problem than DPDP.
The Act requires withdrawal to be as easy as giving consent. If a user has to email support to unsubscribe, that is not compliant. Build a self-serve preferences page.
There is no blanket small-business exemption in the Act. Some Significant Data Fiduciary obligations only apply once notified as SDF, but the core Data Fiduciary duties apply to everyone. Do not skip because you are small.
Directors and officers can face personal accountability for governance failures leading to major breaches. Compliance is not something to fully delegate; founders and boards should be personally briefed on posture and open risks.
Notice availability in Eighth Schedule languages the user can access is a real obligation. English-only privacy pages for a consumer-facing business in India are exposure. Add at least Hindi plus one regional language relevant to your user base.
Compliance work has two layers. Policy and posture (what you do, how you do it, how you evidence it) is legal and strategic work best done with counsel and internal leadership. The mechanical operations (consent capture, DPA management, request intake and workflow, breach notification templates, retention scheduling, audit trail) are software problems.
Dcomply is our compliance automation product built for Indian businesses under DPDP. It automates the mechanical layer: consent capture components you drop into your app, a self-serve preferences dashboard for your users, DPA templates and a signature workflow for your vendors, request intake with SLA tracking, breach notification templates aligned to Board format, retention scheduling with enforcement across your systems, and an audit-ready dashboard for your board or a regulator. It does not replace counsel for the policy layer. It does replace the spreadsheet, the shared inbox, and the ad-hoc workflows that most startups patch together for the mechanical layer.
Whether you use Dcomply or build the machinery yourself, the mechanical work is not optional. The Data Protection Board will not accept "we did not have time to set up the consent flow" as a defence. Get the mechanical layer in place in the first 90 days.
DPDP compliance is not a one-time project. It is an operating discipline. The 90-day plan gets you to meaningfully-compliant with documented gaps. Sustaining compliance means quarterly reviews, annual security work, keeping up with Rules notifications, and treating a breach exercise as as routine as a fire drill. Start now, iterate quarterly, and document everything.
Questions we hear on nearly every discovery call about India data protection compliance.
Tell us your business, your data footprint, and your current compliance state. We come back within 48 hours with a prioritised gap list, a 90-day remediation roadmap you can execute, and whether Dcomply is the right tool to automate the mechanical work.