Corporate & Commercial Law

What the DPDP Act, 2023 Means for Indian Businesses

By Advocate Sharan Jain  · 

What the DPDP Act, 2023 Means for Indian Businesses

Every Indian business that collects a customer phone number, runs a payroll, stores CVs, or keeps a mailing list is now a handler of personal data with legal duties attached. The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first standalone law dedicated to personal data, and it changes how organisations of every size must collect, use, store, and delete information about people in India. This guide sets out what the DPDP Act means for a business in plain terms: the roles it creates, the consent and notice rules, individual rights, the security and breach duties it imposes, the regulator that enforces it, and a practical compliance checklist for an SME or startup. One caveat matters up front. The Act is on the statute book, but much of its day-to-day operation switches on only as the Central Government notifies commencement dates and finalises the accompanying Rules.

Key point: The DPDP Act received Presidential assent in 2023, yet its substantive obligations are set to come into force in stages, on dates the Central Government notifies, and the detailed compliance mechanics depend on the Digital Personal Data Protection Rules. Treat the run-up to full enforcement as the window to get ready, not as a reason to wait.

What the DPDP Act covers, and who it applies to

The Act governs the processing of digital personal data, meaning data about an identifiable individual that is either collected in digital form or collected on paper and then digitised. It applies to processing within India, and it also reaches processing carried out outside India where that processing is connected with offering goods or services to individuals in India, so an overseas company serving Indian customers is not beyond its scope. Purely personal or domestic handling, and certain data an individual has made public, sit outside the Act. The practical test is simple: if your business decides why and how personal data gets used, the Act speaks to you.

The Act builds everything on a few defined roles. Get these straight and the rest of the statute reads easily.

Role or termWhat it meansIn a typical business
Data PrincipalThe individual the personal data is about. For a child, the parent or lawful guardian stands in; for a person with a disability, the lawful guardian.Your customer, employee or job applicant
Data FiduciaryThe person, including a company or firm, that alone or with others determines the purpose and means of processing personal data.Your business
Data ProcessorA person who processes personal data on behalf of a Data Fiduciary, under a contract.Your cloud host, payroll or CRM vendor
Consent ManagerAn intermediary registered with the Data Protection Board through which an individual can give, manage, review and withdraw consent on a single accessible, interoperable platform.A registered third-party platform you may plug into
Significant Data FiduciaryA fiduciary, or class of them, that the Central Government may notify as significant based on the volume and sensitivity of data and the risks involved, carrying heavier duties.Large-scale or high-risk data handlers

These definitions live in the opening sections of the Act. The one to internalise is Data Fiduciary: that is almost certainly you, and it carries the obligations.

Under the Act, the ordinary basis for processing an individual's personal data is their consent, and that consent has to clear a real bar. It must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data actually needed for the stated purpose. Just as important, it must be as easy to withdraw as it was to give. Consent can be routed through a registered Consent Manager, which acts as a single point where a person manages and revokes permissions.

Consent does not stand alone. It has to be preceded or accompanied by a notice that tells the individual, in clear language, what personal data will be processed and for what purpose, how they can exercise their rights, and how they can complain to the Data Protection Board. The notice must be available in English or in any language listed in the Eighth Schedule to the Constitution. The Act also recognises certain legitimate uses where processing may proceed without fresh consent, for example where a person voluntarily provides data for a purpose, or for specified functions of the State, compliance with a legal obligation, a medical emergency, or defined employment purposes. These are narrower than they sound, so consent remains the safe default for most commercial processing.

Common mistake: the old habit of one pre-ticked box buried in the terms, giving blanket permission to use data for anything. That does not meet the standard. Consent must be specific to a purpose, and bundling unrelated purposes into a single take-it-or-leave-it tick is exactly what the Act is written to stop.

Purpose limitation and data minimisation

Two disciplines run through the whole Act. First, purpose limitation: you may use personal data only for the purpose you told the person about, not a fresh purpose you think of later. Second, data minimisation: collect only the data you genuinely need for that purpose. Tied to both is retention. Once the purpose is served, or the person withdraws consent, you are expected to erase the data unless a law requires you to keep it. Collecting everything, keeping it forever, and finding a use for it later is the opposite of what the Act asks.

Rights of individuals

The Act gives every Data Principal a set of enforceable rights against the businesses that hold their data:

  • Right to access: to obtain a summary of the personal data being processed, the processing activities, and the identities of others with whom it has been shared.
  • Right to correction and erasure: to have inaccurate or incomplete data corrected, updated or completed, and to have data erased where it is no longer needed.
  • Right of grievance redressal: to a readily available means of raising a grievance with the fiduciary or consent manager, before escalating to the Board.
  • Right to nominate: to nominate another individual to exercise these rights in the event of death or incapacity.

The Act also places duties on individuals, such as not registering false or frivolous grievances and not impersonating someone else when providing data. Those duties are a reminder that the rights are not a licence to harass a business with baseless complaints.

What a business must do: the Data Fiduciary obligations

The heart of compliance sits in the duties the Act places on you as a Data Fiduciary. The most important are these:

ObligationWhat it means in practice
Security safeguardsPut in place reasonable technical and organisational security measures to prevent a personal data breach.
Breach notificationOn a personal data breach, notify the Data Protection Board and each affected individual, in the manner to be prescribed.
AccuracyEnsure data is accurate and complete where it is used to make a decision affecting the person, or is disclosed to another fiduciary.
Erasure and retentionErase personal data once consent is withdrawn or the purpose is served, unless retention is required by law.
Point of contactPublish the contact details of a Data Protection Officer or another person able to answer questions about the processing.
Grievance mechanismProvide an effective mechanism to receive and respond to grievances from individuals.
Processor contractsEngage data processors only under a valid contract.

Worth remembering: a data breach is not only a security incident, it is a reportable legal event. Under the Act you are expected to notify both the Board and every affected individual, so an incident-response plan that ends at "fix the server" is only half a plan.

Children's data: a stricter regime

Where a business processes the personal data of a child, meaning anyone under 18, the rules tighten. Before processing, the fiduciary must obtain verifiable consent from a parent or lawful guardian. The Act prohibits processing that is likely to cause any detrimental effect on the wellbeing of a child, and it bars tracking, behavioural monitoring, and targeted advertising directed at children. The Central Government may exempt certain classes of fiduciaries, or permit processing for certain purposes, by notification, but the default is protective. If your product can be used by minors, this is not a corner to cut.

Significant Data Fiduciaries: extra duties

The government can designate a business, or a whole class of businesses, as a Significant Data Fiduciary where the scale and sensitivity of its data processing, and the risks it poses, justify closer control. If you fall into that category, you take on additional obligations: appointing a Data Protection Officer based in India who answers to your board or governing body, appointing an independent data auditor, and carrying out periodic Data Protection Impact Assessments and audits. Most SMEs will not be designated, but a fast-scaling platform handling large volumes of personal data should plan for it.

The Data Protection Board of India and penalties

Enforcement runs through the Data Protection Board of India, the body the Act establishes to police compliance. The Board inquires into complaints and breaches, can direct urgent remedial or mitigation measures when a breach occurs, and can impose monetary penalties after an inquiry. It is designed to function as a digital office, so proceedings are meant to be conducted largely online. An appeal from the Board's order lies to the Appellate Tribunal.

On penalties, the Act carries a Schedule that grades financial penalties by the nature of the failure. The steepest, for failing to take reasonable security safeguards to prevent a personal data breach, can run to a very large sum, reported at up to Rs 250 crore, with separate ceilings for breaches such as failing to notify a breach or failing on the children's-data duties. The Board fixes the actual amount after weighing statutory factors such as the nature, gravity and duration of the breach. Because these figures sit in the Schedule and can be revisited as the law is operationalised, treat the headline numbers as an indication of seriousness, not a fixed tariff.

Cross-border transfers and exemptions

The Act permits transfers of personal data outside India, but the Central Government may, by notification, restrict transfers to particular countries or territories, so cross-border flows are allowed by default subject to any restricted list the government issues. The Act also allows exemptions for certain classes of fiduciaries, including some startups, from specified obligations, and for processing needed for research, archiving or statistical purposes, again as notified. The detail here will come through the Rules and notifications.

A practical compliance checklist for an SME or startup

  1. Map your data. List what personal data you collect, where it lives, why you hold it, who you share it with, and how long you keep it. You cannot protect what you have not mapped.
  2. Fix your lawful basis. For each use, decide honestly whether you rely on consent or a recognised legitimate use.
  3. Rewrite notices and consent flows. Replace blanket, pre-ticked permissions with clear, purpose-specific notices and an affirmative opt-in, and make withdrawal genuinely easy.
  4. Put processor contracts in place. Every vendor that touches personal data on your behalf should be under a written contract with data protection terms; a well-drafted service agreement is the right vehicle.
  5. Harden security. Access controls, encryption where appropriate, logging and a written information-security policy are the baseline for the reasonable safeguards the Act expects.
  6. Write a breach-response plan. Decide in advance who assesses an incident, who notifies the Board and the affected individuals, and how fast.
  7. Build a rights-request process. Have a simple, documented way to handle access, correction, erasure and grievance requests within a sensible time.
  8. Handle children carefully. If minors can use your product, build verifiable parental consent and switch off behavioural tracking and targeted ads for them.
  9. Set retention and deletion rules. Define how long each category of data is kept, and delete on schedule or on withdrawal of consent.
  10. Name a point of contact and watch the Rules. Publish a contact for data questions, and track the notified commencement and the Digital Personal Data Protection Rules so your programme matches the final requirements.

Startups building this in from the beginning have a real advantage, and the groundwork overlaps with the other early-stage paperwork we cover in our guide to the legal documents every Indian startup needs. Where confidentiality of personal data is part of a commercial arrangement, a properly drafted non-disclosure agreement does part of the job, though it is not a substitute for a full compliance programme.

What I tell clients

The businesses that struggle with data protection are rarely the ones that set out to misuse data. They are the ones that never wrote down what data they hold and why. In practice, the single most useful thing an SME can do before the Act is fully enforced is the least glamorous one: a plain data map. Once you can see every place a customer or employee record sits, the consent, the security and the deletion rules almost design themselves. The clients who wait until an enforcement notice arrives find the same records scattered across spreadsheets, inboxes and three vendors, with nobody sure who owns them. Do the mapping first. For tailored help aligning contracts and policies, our corporate and commercial law team works with businesses on exactly this.

Frequently Asked Questions

Is the DPDP Act in force yet?

The Act is enacted, but its provisions come into force on dates the Central Government notifies, and different dates can be set for different provisions. Much of the operational detail depends on the Digital Personal Data Protection Rules, so businesses should prepare now and track the notified commencement rather than assume a single switch-on date.

Does the DPDP Act apply to small businesses and startups?

Yes. There is no general small-business exemption from the core duties, though the government can grant specified exemptions to certain classes, including some startups, by notification. If you determine why and how personal data is processed, you are a Data Fiduciary with obligations under the Act.

What is the difference between a Data Fiduciary and a Data Processor?

A Data Fiduciary decides the purpose and means of processing, while a Data Processor only processes data on the fiduciary's behalf under a contract. Your business is usually the fiduciary; your cloud or software vendors are usually processors.

Do I always need consent to process personal data?

Consent is the default basis, but the Act recognises certain legitimate uses where processing may proceed without fresh consent, such as data a person voluntarily provides for a purpose, some State functions, legal obligations, medical emergencies and defined employment purposes. For most ordinary commercial processing, consent remains the safe route.

What must I do if there is a data breach?

The Act requires a Data Fiduciary to notify the Data Protection Board and each affected individual of a personal data breach, in the manner to be prescribed by the Rules. That is why an incident-response plan should include who notifies whom, and how quickly.

How is children's data treated differently?

A child is anyone under 18. Before processing a child's data you must obtain verifiable consent from a parent or lawful guardian, you must not process data in a way likely to harm the child, and you must not run behavioural tracking or targeted advertising aimed at children, subject to any exemptions the government notifies.

What are the penalties for getting it wrong?

The Act sets out financial penalties in a Schedule, graded by the type of failure, with the largest reserved for a failure to take reasonable security safeguards to prevent a breach. The Data Protection Board decides the amount after an inquiry, weighing the nature and gravity of the breach, so the exact exposure depends on the facts.

Who enforces the DPDP Act?

The Data Protection Board of India inquires into breaches and non-compliance and can impose penalties, functioning largely as a digital office. An appeal from its orders lies to the Appellate Tribunal.

Related Legal Services

Dealing with a matter like this? Our Bangalore advocates can help. Explore the relevant practice areas:

SJ

About the Author

Advocate Sharan Jain

Advocate based in Bangalore, practising before the Karnataka High Court and District, Sessions, Consumer and Family courts. Writes on civil, criminal, corporate, family and constitutional law to make Indian law more accessible.

Related Articles

S Jain & Attorneys · Legal Consultation

Have a Legal Question? We're Here to Help.

Our experienced lawyers in Bangalore offer confidential consultations tailored to your specific legal needs.

All matters handled with complete confidentiality and legal discretion.