India's DPDP Act — What It Means for Your Organisation
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data-protection law. It imposes binding obligations on every organisation that processes the personal data of Indian residents — regardless of where the organisation is incorporated. dpflo is purpose-built to make DPDP compliance measurable and audit-ready.
Key Obligations under Digital Personal Data Protection Act, 2023
What the law requires of organisations that process personal data in India.
Lawful Purpose & Consent
Every act of processing must rest on a lawful basis. Consent — the primary basis under the DPDP Act — must be free, specific, informed and unambiguous, and must be obtained through a clear, plain-language notice before processing begins. Withdrawal must be as easy as giving consent. Organisations must issue a notice (in English and the 22 Eighth Schedule languages on request) that itemises the personal data collected, the purpose, and the Data Principal's rights.
Data Principal Rights
Data Principals (individuals) have the right to access a summary of their personal data and processing activities; the right to correction and erasure; the right to nominate a representative for post-mortem data decisions; and the right to grieve against a Data Fiduciary. Organisations must fulfil these requests within the timelines prescribed by the Data Protection Board and keep audit-ready evidence of each fulfilment.
Grievance Redressal
Every Data Fiduciary must publish a clear and effective grievance mechanism that allows Data Principals to raise complaints. The grievance officer (or designated contact) must acknowledge and resolve complaints within the period specified by the Rules. Unresolved grievances can be escalated to the Data Protection Board of India.
Personal Data Breach Reporting
In the event of a breach affecting personal data, the Data Fiduciary must notify the Data Protection Board and each affected Data Principal promptly, in the manner prescribed by the Rules. Organisations must maintain an incident register and be able to produce evidence of the breach timeline, impact assessment and remediation steps.
Significant Data Fiduciary (SDF) Obligations
Organisations designated by the Central Government as Significant Data Fiduciaries face heightened requirements: appointment of a Data Protection Officer (DPO) based in India; appointment of an independent Data Auditor; and periodic Data Protection Impact Assessments (DPIAs). SDFs must also comply with additional restrictions on cross-border data transfers if notified.
Children's Data & Verifiable Parental Consent
Processing personal data of a child (under 18 years of age, or the age notified by the Government) requires verifiable consent from a parent or lawful guardian before processing. Data Fiduciaries are prohibited from processing children's data in a manner that is likely to cause harm to the child, and must not track or behaviourally monitor children or target advertising at them.
Data Minimisation, Purpose Limitation & Retention
Only personal data that is necessary for the specified purpose may be collected (data minimisation). Data must not be used for any purpose other than the one for which consent was obtained (purpose limitation). Once the purpose has been fulfilled, or consent has been withdrawn without another lawful basis applying, the personal data must be erased — organisations must implement retention schedules and automated deletion workflows to meet this obligation.
How dpflo maps to Digital Personal Data Protection Act, 2023
Each obligation addressed by a purpose-built dpflo module.
- Consent Records
Captures structured consent records with purpose codes, timestamps, withdrawal events and receipts — satisfying the Act's requirement for granular, auditable consent.
- Privacy Notices
Generates and version-controls DPDP-compliant notices in plain language, including multilingual delivery (English + Eighth Schedule languages on request).
- DSR
Manages the full lifecycle of Data Principal requests — access summaries, corrections, erasure and nomination — with SLA tracking and audit-ready evidence packets.
- Grievances
Provides a published grievance portal with acknowledgement workflows, resolution tracking, and escalation-ready audit logs for Data Protection Board inquiries.
- Breaches
Runs the breach intake, DPDPB notification workflow, impacted-Principal communication queue and incident evidence register — including the CERT-In 6-hour parallel reporting flow.
- RoPA
Maintains a living Record of Processing Activities mapped to DPDP purpose categories, lawful bases, and processor/vendor relationships — the backbone of SDF readiness.
- DPDP Readiness
A guided readiness assessment that benchmarks your organisation against every DPDP obligation, surfaces gaps and generates a remediation roadmap for DPO or board review.
- Classification
Automatically discovers and classifies personal data (including children's data and sensitive categories) across databases, cloud stores and SaaS apps, establishing the data-minimisation baseline.
- Retention
Enforces purpose-linked retention schedules and triggers automated erasure workflows when personal data has served its purpose — directly addressing the storage-limitation obligation.
- Transfers
Tracks cross-border data flows, maps them against the Government-notified permitted-countries list and flags transfers to non-permitted jurisdictions for DPO review.
- Vendor Risk
Maintains a Data Processor / sub-processor register with DPA tracking, ensuring accountability is contractually extended down the processing chain as required by the Act.
Penalties & Enforcement
Non-compliance can attract penalties of up to ₹250 crore per instance of breach (specific penalty quantum depends on the nature of the violation as specified in the Schedule to the Act). Penalties are determined by the Data Protection Board of India following an inquiry, with due-process safeguards.
Frequently Asked Questions
Common questions about Digital Personal Data Protection Act, 2023.
Does the DPDP Act apply to my organisation if we are not incorporated in India?
When does the DPDP Act come into force?
What is the difference between a Data Fiduciary and a Data Processor under the DPDP Act?
How does the DPDP Act treat children's data?
What qualifies as a Significant Data Fiduciary (SDF) and what extra duties apply?
How long does an organisation have to respond to a Data Principal's erasure request?
Start your DPDP compliance journey
dpflo is purpose-built for Digital Personal Data Protection Act, 2023. Map your obligations, close the gaps, and stay audit-ready — all from one platform.