The Digital Personal Data Protection Act, 2023 is India’s first standalone law for digital personal data. It applies to any organisation — a Data Fiduciary — that decides why and how personal data of people in India is processed.
It also reaches processing done abroad when goods or services are offered to people in India. If you handle customer, employee, or partner data digitally, it almost certainly applies to you.
You do not need every rule notified to start — the core governance building blocks are principle-based and rarely change in substance.
Consent and notice: the foundation
Processing generally requires free, specific, informed, and unambiguous consent, given by clear affirmative action. Each purpose must be agreed separately — one checkbox for bundled purposes does not comply.
A plain-language notice must sit alongside consent, describing what you collect, why, and how to exercise rights or complain to the Data Protection Board.
- Separate each purpose in consent flows — describe and agree to each one.
- Offer notices in English and the Eighth Schedule languages.
- Make withdrawal as easy as giving consent, and stop processing on withdrawal.
- Keep an auditable record of every consent captured.
Map your data: build a Record of Processing
You cannot protect data you have not mapped. A Record of Processing Activities documents what you hold, where it lives, why you process it, who you share it with, and how long you keep it.
This inventory feeds nearly every other obligation — rights fulfilment, breach assessment, retention, and erasure all depend on it.
- Inventory data across apps, databases, SaaS, backups, and spreadsheets.
- Record the lawful basis for each processing activity.
- List every Data Processor and confirm a written contract exists.
- Capture retention periods so data is not kept past its purpose.
Honour Data Principal rights
Individuals can access a summary of their data, correct it, request erasure, seek grievance redressal, and nominate someone to act for them. You need a time-bound process to receive, verify, locate, and respond.
Ad-hoc handling breaks down at scale, so wire these workflows into your systems early.
Grievance officer and the DPO threshold
Every Data Fiduciary must publish contact details for someone who can answer Data Principal questions. Significant Data Fiduciaries carry heavier duties — an India-based DPO reporting to the board, an independent auditor, and periodic impact assessments.
“Design your programme so it can scale to Significant Data Fiduciary duties, even if you are not classified as one yet.”
Security, breaches, and children’s data
You must apply reasonable safeguards and notify both the Board and affected individuals of a breach. Processing children’s data needs verifiable parental consent, and targeted advertising to children is restricted.
Takeaway: start with a data map, fix consent and notice, and stand up a rights-request process. Those three moves cover most day-one exposure. Treat readiness as ongoing governance, not a one-time project.