Compliance with the DPDP Act, 2023 & DPDP Rules 2025
A comprehensive guide to India's Digital Personal Data Protection Act — scope, consent, data principal rights, penalties, and compliance strategy
The Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) marks a significant step towards regulating the processing and handling of personal data in India. By focusing on the management of digital personal data without distinguishing between tiers of data sensitivity, the Act aims to provide a comprehensive framework that safeguards individuals' data privacy while accommodating the needs of businesses and organisations.
For organisations operating in India — or offering goods and services to Indian data principals — adapting to these changes demands a rigorous approach to data protection, requiring a blend of legal, technical, and operational strategies.
Overview of the DPDP Act, 2023
The DPDP Act, 2023 redefines how personal data is handled in India, mandating stringent compliance measures for organisations. It is an evolution in the realm of personal data regulation, replacing the patchwork of data protection provisions previously scattered across the Information Technology Act, 2000 and its rules.
Scope of the Act
- ▸Applies to the processing of personal data in digital form.
- ▸Covers processing activities within India and extraterritorial processing related to offering goods or services to Indian data principals.
- ▸Excludes personal data made publicly available under legal obligation.
Key Definitions
Data about an identifiable individual.
Entity determining the purpose and means of personal data processing.
The individual to whom the personal data belongs.
Entity processing personal data on behalf of a Data Fiduciary.
Individual appointed for compliance oversight.
Consent and Notification Obligations
- ▸Strict consent standards: free, specific, informed, unconditional, and unambiguous.
- ▸Notice required with each consent request.
- ▸Continued processing permissible until withdrawal of consent.
Responsibilities of Data Fiduciaries
Compliance Assurance
Responsibility for any processing activity carried out by or on behalf of the Data Fiduciary.
Specific Erasure Requirements
Obligation to erase personal data once the purpose of processing is fulfilled or consent is withdrawn.
Personal Data Breach Reporting
Mandatory reporting of data breaches to the Data Protection Board and affected Data Principals.
Children's Data
Verifiable parental or guardian consent required. Prohibitions on behaviour tracking and targeted advertising towards children.
Significant Data Fiduciaries (SDFs)
Periodic audits, impact assessments, and appointment of a DPO domiciled in India, responsible for grievance resolution.
Rights of a Data Principal
- 1Right to access personal data held by a Data Fiduciary
- 2Right to correction and erasure of personal data
- 3Right to grievance redressal through the Data Fiduciary
- 4Right to nominate another individual to exercise rights in case of death or incapacity
Data Protection Board & Penalties
Data Protection Board
The Act establishes a Data Protection Board of India as the investigatory and enforcement authority for personal data violations. Appeals lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Consent Managers
Platforms for managing data principal consent must be registered with the Data Protection Board and must operate as independent, interoperable systems.
Penalties
The Act introduces a civil liability regime with penalties up to INR 250 crore for violations. Organisations may also opt for voluntary rectification undertakings before the Board. The Central Government retains authority to issue blocking orders and regulatory notifications.
International Data Transfers
The Central Government may restrict data transfer to certain territories by notification. Existing laws with stricter data transfer regulations continue to prevail. Organisations must define clear protocols for cross-border transfers and ensure recipient countries provide adequate data protection.
Compliance Strategies
- ▸Appointment of a Data Protection Officer (DPO)
- ▸Regular risk assessments and data handling audits
- ▸Transparent data policies communicated to all stakeholders
- ▸Regular employee training on data protection obligations
Advisory Services
We offer a suite of services to assist businesses in navigating the complex requirements of the DPDP Act, 2023, ensuring compliance and safeguarding the privacy of data principals:
DPDP Readiness Assessment
Assess current data handling and processing practices against the requirements of the DPDP Act, 2023 to identify compliance gaps and areas needing improvement.
DPDP Training and Awareness
Conduct detailed training sessions for all employees to deepen their understanding of the DPDP Act, 2023, emphasising the critical nature of compliance in everyday operations.
Contract Review and Revision
Ensure existing contracts with stakeholders are revised to incorporate necessary clauses for compliance with the DPDP Act, aligning all agreements with the latest personal data standards.
DPDP Policies and Procedures
Develop and implement robust policies and procedures covering data processing, security, retention, and breach response.
Data Principal Rights Procedures
Create efficient processes allowing data principals to exercise their rights under the DPDP Act effectively, including rights to access, correct, and delete personal data.
Privacy by Default
Integrate privacy at the design stage of all systems and processes handling personal data, ensuring data protection is an inherent aspect of all operations.
Data Protection Impact Assessment (DPIA)
Implement DPIAs for new and ongoing projects that handle personal data to identify potential risks and implement measures to mitigate them.
Cross-Border Transfer Procedures
Define clear protocols for the international transfer of personal data in compliance with the DPDP Act, ensuring recipient countries provide adequate data protection.
Incident Response Plan
Develop a thorough incident response plan to address data breaches or security incidents swiftly, minimising impact and complying with reporting obligations under the DPDP Act.
DPDP Audit
Perform regular audits to verify the effectiveness of data protection measures and ongoing compliance with the DPDP Act, pinpointing areas for ongoing improvement.
The Digital Personal Data Protection Act, 2023 introduces comprehensive measures for personal data protection, emphasising consent, data principal rights, and the responsibilities of data fiduciaries and processors. For organisations, adapting to these changes demands a rigorous approach to data protection — requiring a blend of legal, technical, and operational strategies.
AEQUITAS LEGIS ASSOCIATES | Advocates & Solicitors | Pune | Mumbai | Delhi
This article is prepared for general informational purposes only and does not constitute legal advice or a legal opinion on any specific matter. Readers should seek independent advice from qualified counsel before acting on any of the matters discussed.
