legalanswers.in logolegalanswers.in
Step-by-step guide

DPDPA Compliance Guide for Indian Businesses: Data Protection, Breach Notification and Consent

Updated · 27 July 2026 · 8 steps

India's Digital Personal Data Protection Act, 2023 (DPDPA) received Presidential assent on 11 August 2023 and represents the country's first standalone data protection law. While the subordinate rules under the Act are still being finalised, the statute itself is in force — and the obligations it imposes on organisations that collect or process personal data of individuals in India are clear enough to act on now.

DPDPA applies to any organisation — Indian or foreign — that processes 'digital personal data' about individuals in India, whether the processing happens in India or abroad. The penalties are significant: up to ₹250 crore for inadequate security, ₹200 crore for breach notification failure, and ₹200 crore for children's data violations, per instance. This guide walks through the key compliance obligations in practical terms — what you need to do, in what order, and what the consequences of non-compliance look like.

DPDPA applies to the processing of digital personal data about individuals (data principals) in India. The geographic scope is broad by design:

  • Data collected in India: any organisation — Indian or foreign — that collects digital personal data from individuals in India is covered. This includes apps, websites, e-commerce platforms, fintech services, healthtech, edtech, and any other digital touchpoint used by Indian consumers.
  • Data collected outside India for Indian individuals: if an overseas organisation processes personal data of Indian individuals in connection with an activity targeted at Indian residents, it is covered — similar to GDPR's territorial reach.

What counts as 'digital personal data'? Any data about an individual that is collected digitally, or that is in non-digital form but subsequently digitised. This covers: names, phone numbers, email addresses, Aadhaar numbers, PAN, financial data, health records, location data, biometrics, and any combination of data that can identify an individual.

What is excluded? Data processed by individuals for personal or domestic purposes; data that is made publicly available by the individual or by law; anonymised data (where re-identification is not possible).

Two key actors: data fiduciary (the entity that determines the purpose and means of processing — this is most organisations collecting data) and data processor (a third party that processes on the fiduciary's instructions — your cloud vendor, your CRM provider, your analytics platform). Most of the Act's obligations fall on the fiduciary.

Before you can comply, you need to know what personal data you hold, where it comes from, where it flows, and for what purpose it is used. This is called a data mapping exercise — it is foundational to every other compliance step.

What to map: data categories collected (name, phone, email, financial data, health data, children's data); source (user registration, third-party APIs, social login, CRM import); storage location (on-premise, cloud vendor, third-party SaaS); retention period; who has access; and who it is shared with (partners, analytics tools, advertising networks, government authorities).

Lawful bases under DPDPA: unlike GDPR's six lawful bases, DPDPA primarily recognises two: (1) consent of the data principal; and (2) legitimate uses specified in Section 7 (which cover government and state functions, compliance with law, medical emergencies, employment-related processing, and public interest). For most commercial organisations, consent is the primary — and often the only — available lawful basis.

What valid consent requires under DPDPA: it must be free, specific, informed, unconditional, and unambiguous; given through a clear affirmative action; not bundled with terms and conditions; and revocable at any time. Pre-ticked boxes, implied consent, and consent buried in T&Cs are non-compliant. The request for consent must be presented in simple English (and local language if the principal prefers) before the data is collected.

Every data collection point must be accompanied by a notice that tells the data principal: (a) what personal data is being collected; (b) the purpose for which it will be processed; (c) how to withdraw consent; and (d) how to exercise rights (access, correction, erasure, grievance). The notice must be presented before or at the time of collection — not buried in a privacy policy that nobody reads.

Practical consent implementation:
For websites and apps: a layered notice — a brief plain-language statement at the point of data collection linking to a detailed privacy notice. Separate consents for separate purposes (e.g., 'I agree to receive marketing emails' must be a separate checkbox from 'I agree to create an account'). For minors (under 18): verifiable parental consent is mandatory before any processing. DPDPA prohibits tracking, behavioural monitoring, and targeted advertising directed at children — implement age verification before data collection.

Consent withdrawal: users must be able to withdraw consent as easily as they gave it. A withdrawal mechanism — in-app toggle, email request, account deletion — must be available and must actually stop the processing. On withdrawal, data must be deleted unless retention is required by law.

Privacy notice must disclose: the name and contact details of the data fiduciary; categories of data collected; purposes; retention period; rights of the data principal; grievance redressal mechanism; and the data protection officer's contact (mandatory for Significant Data Fiduciaries).

Section 8(5) of DPDPA requires data fiduciaries to implement reasonable security safeguards to prevent personal data breaches. The maximum penalty for inadequate security is ₹250 crore per breach — the highest penalty in the Act.

DPDPA does not prescribe a specific technical standard (unlike, say, PCI-DSS for payment card data). 'Reasonable' will be assessed against the nature and volume of data held, the sensitivity of the data, the state of the art in security, and the scale of the fiduciary's operations. In practice, compliance with ISO/IEC 27001 (Information Security Management System) or the equivalent provides a strong defence — it demonstrates that a systematic approach to security was in place.

Minimum practical measures:
Encryption of personal data at rest and in transit; access controls (need-to-know basis, multi-factor authentication for privileged access); regular vulnerability assessments and penetration testing; patch management; audit logs for access to personal data; vendor due diligence for data processors (contractual data processing agreements mandating equivalent security); and a documented incident response plan.

Data processor obligations: data fiduciaries are responsible for breaches caused by their data processors. Section 8(1) requires processors to process data only as per the fiduciary's instructions and to implement equivalent security. Include data processing agreements (DPAs) in all contracts with cloud vendors, SaaS tools, analytics platforms, and outsourced service providers — these must specify the processor's security obligations, breach notification timelines, and data deletion on contract termination.

Section 8(6) of DPDPA requires data fiduciaries to notify both the Data Protection Board and each affected data principal of any personal data breach. This obligation exists regardless of the cause — ransomware, insider threat, misconfiguration, or accidental disclosure all trigger the notification requirement.

What is a notifiable breach? DPDPA's definition is broad: any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access that compromises the confidentiality, integrity, or availability of personal data. Unlike GDPR, there is no materiality or risk threshold in the statute — any breach must be notified. (The Rules, when finalised, may introduce a threshold.)

What to include in the notification (following international best practice pending the Rules): nature of the breach; categories of data affected; approximate number of individuals affected; contact point for questions; likely consequences; measures taken or proposed to address the breach and mitigate its effects.

Timeline: the Rules will specify a reporting window — benchmark against GDPR's 72 hours. Start the internal breach response process immediately on discovery: contain the breach, preserve evidence, assess scope, notify the DPB and individuals, and document everything.

Penalty for failure to notify: up to ₹200 crore per instance (Schedule 1, Item 2 of DPDPA). Repeated notification failures, or systematic failure to maintain the required security posture, will attract the Board's attention even before the Rules are fully operational.

DPDPA gives individuals (data principals) four core rights that organisations must be able to respond to. Building the operational capability to honour these rights takes time — start now, before enforcement begins.

Right to access (Section 11): a data principal can request confirmation of whether their personal data is being processed and a summary of the data held. The fiduciary must respond within the time prescribed in the Rules.

Right to correction and erasure (Section 12): the data principal can request correction of inaccurate data, completion of incomplete data, or erasure of data that is no longer necessary for the purpose for which it was collected. Erasure must also be carried out when the data principal withdraws consent and there is no other lawful basis to retain.

Right to nominate (Section 14): a data principal can nominate another person to exercise their rights in the event of their death or incapacity — a novel right specific to DPDPA.

Right to grievance redressal (Section 13): the data principal must be able to raise a grievance with the data fiduciary. The fiduciary must respond. Unresolved grievances can be escalated to the Data Protection Board.

Operationalising these rights: build a data subject request (DSR) intake mechanism — an email address, an in-app form, or an online portal. Log all requests with timestamps. Verify the requestor's identity before responding (to prevent data disclosure to the wrong person). Aim to respond within 30 days as a working standard pending the Rules' timeline.

The Central Government will designate certain entities as Significant Data Fiduciaries (SDFs) based on volume of data processed, sensitivity of data, national security implications, or risk to electoral democracy. Once designated, SDFs face additional obligations:

  • Data Protection Officer (DPO): mandatory appointment of a DPO based in India, responsible for ensuring compliance and serving as the contact point for the Data Protection Board.
  • Data Protection Impact Assessment (DPIA): mandatory for high-risk processing activities — profiling, large-scale processing of sensitive data, automated decision-making with significant consequences.
  • Periodic audits: compliance audits by an independent auditor on a schedule specified by the government.
  • Algorithmic accountability: assessment of risks from processing using algorithms that can significantly affect data principals.

Who is likely to be designated as SDF? Major social media platforms, large e-commerce companies, healthcare and insurance data processors, fintech companies processing large volumes of financial data, and organisations processing sensitive data (health, children's data, financial data) at scale. The SDF designation list has not been published as of mid-2026 — monitor the Ministry of Electronics and Information Technology (MeitY) and Data Protection Board notifications.

Cross-border data transfers: DPDPA enables the Central Government to restrict transfer of personal data to certain countries by notification. Until such restrictions are notified, cross-border data transfers are generally permitted. Standard contractual clauses (similar to GDPR's SCCs) are expected in the Rules — implement contractual data transfer safeguards with international processors in anticipation.

The Data Protection Board of India will be the enforcement authority — an adjudicatory body with powers to receive complaints, investigate, issue notices, hold hearings, and impose monetary penalties. The Board is appointed by the Central Government and its decisions are appealable to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) and then to the High Court.

Penalty structure (Schedule 1 of DPDPA):
Item 1: Failure to implement reasonable security safeguards → up to ₹250 crore.
Item 2: Failure to notify breach to Board and data principals → up to ₹200 crore.
Item 3: Non-compliance by Significant Data Fiduciaries → up to ₹150 crore.
Item 4: Violation of children's data obligations → up to ₹200 crore.
Item 5: Breach of other obligations → up to ₹50 crore.

These are per-instance caps — multiple violations result in cumulative liability. There is no 4%-of-global-turnover alternative as under GDPR; the amounts are fixed.

Preparing for Board proceedings: document your compliance program — consent architecture, privacy notices, data mapping, security measures, breach response procedures, DSR handling. In enforcement proceedings, demonstrating that a systematic compliance effort was made (even if imperfect) will mitigate penalties. The Board can also issue binding directions requiring remediation — not just monetary penalties.

Compliance timeline: DPDPA is in force; the Rules will specify timelines for compliance with specific obligations once published. Use the current period — before the Rules are finalised and before the Board is constituted — to build your compliance infrastructure. It takes months to implement proper consent mechanisms, security controls, and DSR processes. Start now.

Disclaimer: Content provided here is for general legal knowledge only and does not constitute formal legal advice. If you have an urgent or specific matter, please consult a registered advocate.