DPDP Act 2023: A Complete Compliance Guide for Indian Organisations
India's Digital Personal Data Protection Act 2023 (DPDP Act) marks a landmark shift in how personal data of Indian citizens must be handled. Passed in August 2023 after years of deliberation, the Act establishes a comprehensive framework for the processing of digital personal data within India and, in certain cases, outside India when personal data of Indian data principals is involved. Understanding its obligations is essential for any organisation operating in India.
Core Framework and Key Definitions
The DPDP Act applies to Data Fiduciaries — entities that determine the purpose and means of processing personal data. A Data Processor is an entity that processes data on behalf of a Fiduciary. A Data Principal is the individual whose data is being processed. The Act covers only digital personal data (data that is digitised or that is non-digitised but subsequently digitised). It explicitly excludes personal data processed for personal or domestic purposes, and anonymised data.
The Act establishes a consent-forward model: Data Fiduciaries must obtain free, specific, informed, unconditional, and unambiguous consent from Data Principals before processing their personal data. The consent notice must be provided in clear and plain language and, importantly, must be available in all languages listed in the Eighth Schedule to the Constitution (22 scheduled languages) to ensure Indian users can understand it in their preferred language. This multilingual requirement is one of the most operationally demanding aspects of compliance.
Significant Data Fiduciaries: Enhanced Obligations
The DPDP Act creates a higher-accountability class called Significant Data Fiduciaries (SDFs). The Central Government will notify which organisations qualify based on volume of data processed, sensitivity, potential impact, and security risk. SDFs must appoint a Data Protection Officer (DPO) who reports to the board of directors, register with a Consent Manager, conduct periodic Data Protection Impact Assessments (DPIAs), and undergo algorithmic accountability audits. For organisations likely to qualify as SDFs — large e-commerce platforms, health-tech, fintech, and social media companies — building the DPO function and DPIA process should be a priority.
Data Principal Rights
The Act grants Data Principals four core rights: the right to access information about their personal data being processed, the right to correction and erasure of inaccurate or incomplete data, the right to grievance redressal (the fiduciary must acknowledge within 48 hours and resolve within the period prescribed by rules), and the novel right to nominate an individual to exercise data rights on their behalf in case of death or incapacity. Organisations must build user-facing mechanisms to handle these rights requests — a "data request portal" or similar function is now a compliance requirement.
Breach Notification and Security
Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches. In the event of a breach, they must notify both the Data Protection Board and affected Data Principals. The notification timelines will be specified in the Rules. Maintaining a breach log, having an incident response plan, and conducting regular security assessments are essential elements of compliance. The penalty for failing to notify a breach is up to ₹200 crore — the second-highest in the penalty schedule.
Comparison with GDPR and Implementation Roadmap
While inspired by GDPR, the DPDP Act is structurally simpler. It does not enumerate multiple lawful bases for processing (like legitimate interests), does not mandate Data Processing Agreements in GDPR's detailed form, and has a narrower set of rights. For organisations already GDPR-compliant, adapting to DPDP is manageable but requires specific attention to: Indian-language privacy notices, the right to nominate, the Consent Manager registration requirement for SDFs, and the specific children's data obligations. Organisations not previously subject to any privacy law face a more significant compliance lift.