DPDP Act 2023 Readiness: What Data Fiduciaries Must Do Now
All Insights Compliance

DPDP Act 2023 Readiness: What Data Fiduciaries Must Do Now

CoSol Team 11 March 2026 8 min read

India’s Digital Personal Data Protection Act reshapes how organisations collect and process personal data. Here is a practical checklist for Data Fiduciaries preparing for enforcement.

The Digital Personal Data Protection Act, 2023 is India’s first standalone law for digital personal data. It applies to any organisation — a Data Fiduciary — that decides why and how personal data of people in India is processed.

It also reaches processing done abroad when goods or services are offered to people in India. If you handle customer, employee, or partner data digitally, it almost certainly applies to you.

You do not need every rule notified to start — the core governance building blocks are principle-based and rarely change in substance.

Under 18
child needs parental consent
72 hrs
target erasure turnaround
4 rights
access, correct, erase, redress

Consent and notice: the foundation

Processing generally requires free, specific, informed, and unambiguous consent, given by clear affirmative action. Each purpose must be agreed separately — one checkbox for bundled purposes does not comply.

A plain-language notice must sit alongside consent, describing what you collect, why, and how to exercise rights or complain to the Data Protection Board.

  • Separate each purpose in consent flows — describe and agree to each one.
  • Offer notices in English and the Eighth Schedule languages.
  • Make withdrawal as easy as giving consent, and stop processing on withdrawal.
  • Keep an auditable record of every consent captured.
DPDP data lifecycle
1
Collect
Lawful, minimal
2
Consent
Explicit, logged
3
Store
Encrypted · RoPA
4
Use
Purpose-limited
5
Erase
On request / expiry
The DPDP data lifecycle: consent and notice feed a data map, which drives rights, retention, and erasure.

Map your data: build a Record of Processing

You cannot protect data you have not mapped. A Record of Processing Activities documents what you hold, where it lives, why you process it, who you share it with, and how long you keep it.

This inventory feeds nearly every other obligation — rights fulfilment, breach assessment, retention, and erasure all depend on it.

  • Inventory data across apps, databases, SaaS, backups, and spreadsheets.
  • Record the lawful basis for each processing activity.
  • List every Data Processor and confirm a written contract exists.
  • Capture retention periods so data is not kept past its purpose.
Networked data flows across a connected globe
Cross-border transfers and processor relationships all trace back to a single data map.

Honour Data Principal rights

Individuals can access a summary of their data, correct it, request erasure, seek grievance redressal, and nominate someone to act for them. You need a time-bound process to receive, verify, locate, and respond.

Ad-hoc handling breaks down at scale, so wire these workflows into your systems early.

Grievance officer and the DPO threshold

Every Data Fiduciary must publish contact details for someone who can answer Data Principal questions. Significant Data Fiduciaries carry heavier duties — an India-based DPO reporting to the board, an independent auditor, and periodic impact assessments.

“Design your programme so it can scale to Significant Data Fiduciary duties, even if you are not classified as one yet.”
— CoSol compliance practice

Security, breaches, and children’s data

You must apply reasonable safeguards and notify both the Board and affected individuals of a breach. Processing children’s data needs verifiable parental consent, and targeted advertising to children is restricted.

Takeaway: start with a data map, fix consent and notice, and stand up a rights-request process. Those three moves cover most day-one exposure. Treat readiness as ongoing governance, not a one-time project.

Run your operations with CoSol

Compliance, networking and security — managed 24×7, delivered in India.