India DPDPA 2023 Compliance Guide
India's DPDPA 2023 is the country's first comprehensive personal data protection law. Here is what data fiduciaries must do to comply, including consent, notice, and breach handling.
DPDPA Overview
The Digital Personal Data Protection Act 2023 (DPDPA) is India's comprehensive personal data protection law, enacted in August 2023. It establishes obligations for processing personal data and rights for individuals (called "data principals") regarding their data.
Key entities under DPDPA:
- Data Fiduciary: Any person who determines the purpose and means of processing personal data (similar to GDPR data controller)
- Data Processor: Any person who processes personal data on behalf of a data fiduciary
- Significant Data Fiduciary (SDF): Data fiduciaries notified by the government based on factors like volume of data, sensitivity, and risk to data principals
- Data Principal: The individual to whom the personal data relates
DPDPA applies to digital personal data processed within India and to processing outside India that is in connection with offering goods or services to data principals within India.
Cross-reference the DPDPA framework reference for the full statutory structure.
Consent and Notice Requirements
DPDPA establishes consent as the primary lawful basis for processing personal data, with specific exceptions for legitimate uses (employment, legal obligations, medical emergencies, etc.).
Consent requirements:
- Free, specific, informed, unconditional, unambiguous: All elements required
- Clear affirmative action: Pre-checked boxes do not constitute consent
- Itemized purposes: Each processing purpose must be specified separately
- Withdrawable: Same ease as giving consent
- In English or 22 scheduled Indian languages: Per data principal preference
Notice must be provided alongside or before consent. The notice must contain:
- Description of personal data being collected
- Purpose of processing
- Manner of exercising data principal rights
- Manner of complaining to the Data Protection Board
For pre-existing personal data (collected before DPDPA enforcement), data fiduciaries must give notice to data principals as soon as reasonably practicable. Continued processing without renewed consent may not be permissible for many data flows.
Data Principal Rights
Data principals have the following rights under DPDPA:
- Right to access information about personal data: Description of processing, summary of personal data being processed
- Right to correction and erasure: Correct, complete, update, or erase personal data
- Right of grievance redressal: First with the data fiduciary, then escalation to Data Protection Board
- Right to nominate: Designate another individual to exercise rights in case of death or incapacity
Operational requirements for handling rights requests:
- Provide a clear mechanism for data principals to exercise rights
- Verify identity of requester before processing
- Respond within time periods specified in rules (likely 30-90 days)
- Maintain records of rights requests and responses
- Train customer-facing staff on handling requests
Build the rights handling process before launch, not after the first request comes in. The first request will reveal whatever gaps exist in your data inventory.
Data Fiduciary Obligations
Beyond consent and rights, DPDPA imposes operational obligations:
- Reasonable security safeguards: Protect personal data from breach. Specific technical and organizational measures expected.
- Personal data breach notification: Notify the Data Protection Board and affected data principals about breaches. Specific timing in rules (likely 72 hours for the Board).
- Children's data: Verifiable parental consent required for processing children's (under 18) personal data. Behavioral monitoring and targeted advertising are restricted.
- Persons with disabilities: Special handling for data principals with disabilities.
- Data retention and deletion: Personal data must be deleted when purpose is fulfilled and consent is withdrawn (with exceptions for legal obligations).
- Cross-border transfers: Permitted to countries not specifically restricted by the government. The list of restricted countries has not yet been published.
Significant Data Fiduciaries have additional obligations: appointing a Data Protection Officer (DPO) based in India, conducting Data Protection Impact Assessments, and maintaining additional records.
Implementation Roadmap
DPDPA compliance roadmap:
- Personal data inventory: Document every collection, storage, processing, and sharing of personal data. Map data flows including third-party transfers.
- Consent and notice redesign: Update privacy notices, consent flows, and customer-facing language. Multilingual support per scheduled Indian languages.
- Rights handling process: Build the operational process for receiving, verifying, and responding to data principal requests.
- Vendor management: Update contracts with data processors. Ensure processor agreements meet DPDPA requirements.
- Breach response: Update incident response procedures to include DPDPA notification requirements.
- Children and protected categories: Build verifiable parental consent if applicable. Special handling for children's data.
- Cross-border transfer assessment: Review international data flows. Track government notifications for restricted countries.
- DPO appointment (if SDF): Identify if you are likely to be designated SDF. Appoint DPO and DPIA process.
Implementation timing depends on rule publication and enforcement dates. Build the program now to be ready when enforcement begins.
Frequently Asked Questions
Related Articles
CERT-In 6-Hour Incident Reporting
CERT-In requires Indian organizations to report cyber incidents within 6 hours. Here is what counts as reportable, how to file, and how to operationalize the timeline.
AI Governance Policy Template
An AI governance policy is the foundational document for any AI program. Here is a template covering scope, principles, lifecycle controls, and accountability.
RBI Cybersecurity Framework
The RBI Cybersecurity Framework establishes mandatory cybersecurity requirements for banks and financial institutions in India. Here is what it covers and how to operationalize compliance.