ZF/blog/india-dpdpa-compliance
AI Governance8 min readMay 8, 2025

India DPDPA 2023 Compliance Guide

India's DPDPA 2023 is the country's first comprehensive personal data protection law. Here is what data fiduciaries must do to comply, including consent, notice, and breach handling.


DPDPA Overview

The Digital Personal Data Protection Act 2023 (DPDPA) is India's comprehensive personal data protection law, enacted in August 2023. It establishes obligations for processing personal data and rights for individuals (called "data principals") regarding their data.

Key entities under DPDPA:

  • Data Fiduciary: Any person who determines the purpose and means of processing personal data (similar to GDPR data controller)
  • Data Processor: Any person who processes personal data on behalf of a data fiduciary
  • Significant Data Fiduciary (SDF): Data fiduciaries notified by the government based on factors like volume of data, sensitivity, and risk to data principals
  • Data Principal: The individual to whom the personal data relates

DPDPA applies to digital personal data processed within India and to processing outside India that is in connection with offering goods or services to data principals within India.

Cross-reference the DPDPA framework reference for the full statutory structure.

Data Principal Rights

Data principals have the following rights under DPDPA:

  1. Right to access information about personal data: Description of processing, summary of personal data being processed
  2. Right to correction and erasure: Correct, complete, update, or erase personal data
  3. Right of grievance redressal: First with the data fiduciary, then escalation to Data Protection Board
  4. Right to nominate: Designate another individual to exercise rights in case of death or incapacity

Operational requirements for handling rights requests:

  • Provide a clear mechanism for data principals to exercise rights
  • Verify identity of requester before processing
  • Respond within time periods specified in rules (likely 30-90 days)
  • Maintain records of rights requests and responses
  • Train customer-facing staff on handling requests

Build the rights handling process before launch, not after the first request comes in. The first request will reveal whatever gaps exist in your data inventory.

Data Fiduciary Obligations

Beyond consent and rights, DPDPA imposes operational obligations:

  • Reasonable security safeguards: Protect personal data from breach. Specific technical and organizational measures expected.
  • Personal data breach notification: Notify the Data Protection Board and affected data principals about breaches. Specific timing in rules (likely 72 hours for the Board).
  • Children's data: Verifiable parental consent required for processing children's (under 18) personal data. Behavioral monitoring and targeted advertising are restricted.
  • Persons with disabilities: Special handling for data principals with disabilities.
  • Data retention and deletion: Personal data must be deleted when purpose is fulfilled and consent is withdrawn (with exceptions for legal obligations).
  • Cross-border transfers: Permitted to countries not specifically restricted by the government. The list of restricted countries has not yet been published.

Significant Data Fiduciaries have additional obligations: appointing a Data Protection Officer (DPO) based in India, conducting Data Protection Impact Assessments, and maintaining additional records.

Implementation Roadmap

DPDPA compliance roadmap:

  1. Personal data inventory: Document every collection, storage, processing, and sharing of personal data. Map data flows including third-party transfers.
  2. Consent and notice redesign: Update privacy notices, consent flows, and customer-facing language. Multilingual support per scheduled Indian languages.
  3. Rights handling process: Build the operational process for receiving, verifying, and responding to data principal requests.
  4. Vendor management: Update contracts with data processors. Ensure processor agreements meet DPDPA requirements.
  5. Breach response: Update incident response procedures to include DPDPA notification requirements.
  6. Children and protected categories: Build verifiable parental consent if applicable. Special handling for children's data.
  7. Cross-border transfer assessment: Review international data flows. Track government notifications for restricted countries.
  8. DPO appointment (if SDF): Identify if you are likely to be designated SDF. Appoint DPO and DPIA process.

Implementation timing depends on rule publication and enforcement dates. Build the program now to be ready when enforcement begins.

Frequently Asked Questions

DPDPAIndiaData ProtectionPrivacy

Related Articles