India · Data Protection Law

India's DPDP Act — What It Means for Your Organisation

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data-protection law. It imposes binding obligations on every organisation that processes the personal data of Indian residents — regardless of where the organisation is incorporated. dpflo is purpose-built to make DPDP compliance measurable and audit-ready.

Key Obligations under Digital Personal Data Protection Act, 2023

What the law requires of organisations that process personal data in India.

Lawful Purpose & Consent

Every act of processing must rest on a lawful basis. Consent — the primary basis under the DPDP Act — must be free, specific, informed and unambiguous, and must be obtained through a clear, plain-language notice before processing begins. Withdrawal must be as easy as giving consent. Organisations must issue a notice (in English and the 22 Eighth Schedule languages on request) that itemises the personal data collected, the purpose, and the Data Principal's rights.

Data Principal Rights

Data Principals (individuals) have the right to access a summary of their personal data and processing activities; the right to correction and erasure; the right to nominate a representative for post-mortem data decisions; and the right to grieve against a Data Fiduciary. Organisations must fulfil these requests within the timelines prescribed by the Data Protection Board and keep audit-ready evidence of each fulfilment.

Grievance Redressal

Every Data Fiduciary must publish a clear and effective grievance mechanism that allows Data Principals to raise complaints. The grievance officer (or designated contact) must acknowledge and resolve complaints within the period specified by the Rules. Unresolved grievances can be escalated to the Data Protection Board of India.

Personal Data Breach Reporting

In the event of a breach affecting personal data, the Data Fiduciary must notify the Data Protection Board and each affected Data Principal promptly, in the manner prescribed by the Rules. Organisations must maintain an incident register and be able to produce evidence of the breach timeline, impact assessment and remediation steps.

Significant Data Fiduciary (SDF) Obligations

Organisations designated by the Central Government as Significant Data Fiduciaries face heightened requirements: appointment of a Data Protection Officer (DPO) based in India; appointment of an independent Data Auditor; and periodic Data Protection Impact Assessments (DPIAs). SDFs must also comply with additional restrictions on cross-border data transfers if notified.

Children's Data & Verifiable Parental Consent

Processing personal data of a child (under 18 years of age, or the age notified by the Government) requires verifiable consent from a parent or lawful guardian before processing. Data Fiduciaries are prohibited from processing children's data in a manner that is likely to cause harm to the child, and must not track or behaviourally monitor children or target advertising at them.

Data Minimisation, Purpose Limitation & Retention

Only personal data that is necessary for the specified purpose may be collected (data minimisation). Data must not be used for any purpose other than the one for which consent was obtained (purpose limitation). Once the purpose has been fulfilled, or consent has been withdrawn without another lawful basis applying, the personal data must be erased — organisations must implement retention schedules and automated deletion workflows to meet this obligation.

How dpflo maps to Digital Personal Data Protection Act, 2023

Each obligation addressed by a purpose-built dpflo module.

  • Consent Records

    Captures structured consent records with purpose codes, timestamps, withdrawal events and receipts — satisfying the Act's requirement for granular, auditable consent.

  • Privacy Notices

    Generates and version-controls DPDP-compliant notices in plain language, including multilingual delivery (English + Eighth Schedule languages on request).

  • DSR

    Manages the full lifecycle of Data Principal requests — access summaries, corrections, erasure and nomination — with SLA tracking and audit-ready evidence packets.

  • Grievances

    Provides a published grievance portal with acknowledgement workflows, resolution tracking, and escalation-ready audit logs for Data Protection Board inquiries.

  • Breaches

    Runs the breach intake, DPDPB notification workflow, impacted-Principal communication queue and incident evidence register — including the CERT-In 6-hour parallel reporting flow.

  • RoPA

    Maintains a living Record of Processing Activities mapped to DPDP purpose categories, lawful bases, and processor/vendor relationships — the backbone of SDF readiness.

  • DPDP Readiness

    A guided readiness assessment that benchmarks your organisation against every DPDP obligation, surfaces gaps and generates a remediation roadmap for DPO or board review.

  • Classification

    Automatically discovers and classifies personal data (including children's data and sensitive categories) across databases, cloud stores and SaaS apps, establishing the data-minimisation baseline.

  • Retention

    Enforces purpose-linked retention schedules and triggers automated erasure workflows when personal data has served its purpose — directly addressing the storage-limitation obligation.

  • Transfers

    Tracks cross-border data flows, maps them against the Government-notified permitted-countries list and flags transfers to non-permitted jurisdictions for DPO review.

  • Vendor Risk

    Maintains a Data Processor / sub-processor register with DPA tracking, ensuring accountability is contractually extended down the processing chain as required by the Act.

Penalties & Enforcement

Non-compliance can attract penalties of up to ₹250 crore per instance of breach (specific penalty quantum depends on the nature of the violation as specified in the Schedule to the Act). Penalties are determined by the Data Protection Board of India following an inquiry, with due-process safeguards.

Frequently Asked Questions

Common questions about Digital Personal Data Protection Act, 2023.

Does the DPDP Act apply to my organisation if we are not incorporated in India?
Yes. The DPDP Act applies to any processing of personal data of individuals in India, irrespective of where the Data Fiduciary is incorporated or where the processing takes place. If you collect or process data from Indian residents — through a website, app, store or service — you are in scope.
When does the DPDP Act come into force?
The Act received Presidential assent on 11 August 2023. Substantive provisions come into force on dates notified by the Central Government. The Data Protection Board of India is being constituted, and the Rules are expected to be finalised before full enforcement begins. Organisations should treat the current window as a compliance preparation period — dpflo's DPDP Readiness module tracks the live notification status.
What is the difference between a Data Fiduciary and a Data Processor under the DPDP Act?
A Data Fiduciary is the entity that determines the purpose and means of processing personal data — it bears the primary compliance obligations. A Data Processor processes data on behalf of a Data Fiduciary under a contract, and is accountable to the Fiduciary (not directly to the Data Principal) for that processing. Both can be penalised for breach of their respective obligations.
How does the DPDP Act treat children's data?
The Act defines a child as anyone under 18 (or such other age as may be notified). Processing children's personal data requires verifiable parental or guardian consent before any data is collected. Behavioural tracking of children and targeted advertising directed at them are prohibited. Organisations must implement age-gating and a parental-consent flow — not just a checkbox on a registration form.
What qualifies as a Significant Data Fiduciary (SDF) and what extra duties apply?
The Central Government will notify SDF status based on factors such as the volume and sensitivity of personal data processed, potential impact on national security or public order, and risk to the rights of Data Principals. SDFs must appoint an India-based DPO, engage an independent Data Auditor and conduct periodic DPIAs. dpflo's DPO Dashboard and DPIA modules are designed to support these obligations.
How long does an organisation have to respond to a Data Principal's erasure request?
The precise timeline will be prescribed by the Rules. Organisations should build their DSR workflows to be configurable as soon as the Rules are notified. dpflo's DSR module includes configurable SLA timers that can be updated to match the Rules without engineering work.

Start your DPDP compliance journey

dpflo is purpose-built for Digital Personal Data Protection Act, 2023. Map your obligations, close the gaps, and stay audit-ready — all from one platform.