DPDP Act India: Essential Guide for Indian Businesses

Chapter 1 of The DPDP Act Bible
⏱ 8 min read  ·  1,900 words

 
 

The Stakes

India processes 2.5 billion data transactions every single day. Is your business handling that data lawfully?

The DPDP Act India sets strict rules for how businesses collect, store, and use personal data — with penalties reaching ₹250 crore for non-compliance. This guide gives you complete clarity on what you must do, and when.

On August 11, 2023, India changed the rules for every business that touches personal data. The Digital Personal Data Protection Act 2023 — India’s landmark data privacy law — received Presidential assent, making it the most consequential piece of digital legislation this country has ever seen.

And yet, most Indian businesses are unprepared. Not because they’re reckless, but because the law is genuinely complex, the implementation rules are still being finalised, and nobody has explained it clearly in plain English — until now.

This guide is Chapter 1 of Xethium’s complete DPDP Act India series. By the time you finish reading, you’ll understand exactly what the law requires, whether it applies to your business, what the penalties look like, and what you need to do first. Deeper topics — consent management, data breach response, cross-border transfers — are covered in dedicated chapters later in this series.

Here’s what this guide covers:

  • What the DPDP Act is and why India needed it
  • Who must comply (hint: probably you)
  • What counts as “personal data” under the law
  • Your core obligations as a Data Fiduciary
  • The three-tier penalty structure
  • Your immediate next steps

DPDP Act India overview infographic showing key statistics and penalties
DPDP Act India overview infographic showing key statistics and penalties

What Is the DPDP Act India? A Brief History

The push for a proper data protection framework began in 2017, when the Supreme Court of India in Justice K.S. Puttaswamy v. Union of India unanimously declared privacy a fundamental right. That landmark judgment set the legal and moral foundation for what eventually became the Digital Personal Data Protection Act 2023.

Six years, three committee reports, two draft bills, and one withdrawal later — the Act finally passed in August 2023. It is built on a deceptively simple premise: individuals have the right to know how their personal data is used, and businesses have the obligation to use it responsibly.

In terms of scope, the law applies to digital personal data only — data that is either collected digitally, or collected offline and then digitised. Moreover, it covers processing that happens within India, and processing outside India when the data relates to Indian residents being profiled or offered goods and services. According to MeitY, the Act is designed to balance individual privacy rights with India’s need for a vibrant, data-driven economy.

Feature DPDP Act India GDPR (EU)
Scope Digital personal data only All personal data (digital + physical)
Legal Basis Consent OR legitimate use (narrow list) 6 legal bases including legitimate interest
Max Penalty ₹250 crore (~€28M) €20M or 4% of global turnover
DPO Requirement Only for Significant Data Fiduciaries Mandatory for high-risk processing orgs

TL;DR

The DPDP Act is India’s first comprehensive data privacy law. It covers digital personal data, applies within and outside India, and is modelled partly on GDPR — but with important differences, particularly around legal bases for processing.

Who Must Comply with the Digital Personal Data Protection Act?

Here’s the answer most businesses don’t want to hear: if your organisation collects or processes any personal data of Indian residents in digital form, the DPDP Act applies to you. There is no revenue threshold. No employee count cutoff. No “startup exemption.”

The Two Key Roles: Fiduciary and Processor

The Act uses two key roles to define compliance obligations:

  • Data Fiduciary: Any individual or organisation that determines the purpose and means of processing personal data. This is the primary compliance role — most businesses are Data Fiduciaries for their customer and employee data.
  • Data Processor: Any individual or organisation that processes personal data on behalf of a Data Fiduciary. SaaS companies, payroll vendors, and cloud providers often act as Processors — but may simultaneously be Fiduciaries for their own operational data.

Consequently, the distinction matters enormously — Fiduciaries bear the full weight of compliance obligations, while Processors have more limited duties, primarily around contractual requirements and security. We cover this in depth in Chapter 4: Data Fiduciary vs. Data Processor — Understanding Your Role.

🔍 Quick Check: Does DPDP Apply to Your Business?

Q1. Do you collect names, emails, phone numbers, or any other information from customers or employees? → Yes? You’re processing personal data. Continue.

Q2. Is that data collected or stored digitally (including spreadsheets, CRMs, email lists)? → Yes? The DPDP Act covers it. Continue.

Q3. Do any of those individuals reside in India? → Yes? The DPDP Act applies to your business.

If you answered Yes to all three — welcome to DPDP compliance. This guide is for you.

🚫 Myth Busting

“I’m too small to worry about DPDP compliance.”

False. The Act contains no small-business exemption for core obligations. A five-person startup with a customer email list is legally a Data Fiduciary. The Data Protection Board may exercise enforcement discretion initially, but the obligations — and the liability — exist from day one. Startups who build compliance into their foundation will also find it significantly cheaper than retrofitting it later.

TL;DR

The DPDP Act applies to virtually every business in India that handles digital data. If you have customers or employees, you are almost certainly a Data Fiduciary with full compliance obligations.

Understanding Personal Data Under the DPDP Act

The Act defines personal data as “any data about an individual who is identifiable by or in relation to such data.” In plain English: if a piece of information can be used to identify a specific person — directly or in combination with other data — it’s personal data. Crucially, this definition is broader than most business owners assume. Consider what you probably already hold:

✅ IS Personal Data

  • Full name, email, phone number
  • IP address, device ID, cookie ID
  • Location data, GPS coordinates
  • Purchase history linked to a person
  • Employee payroll records
  • Photo, biometric data, voice recording
  • Aadhaar number, PAN, passport number

❌ Is NOT Personal Data

  • Truly anonymised data (no re-identification risk)
  • Aggregate statistics (e.g., “60% of users prefer X”)
  • Publicly available government data
  • Fictional data used in testing

Special Category: Children’s Data

Beyond the standard definition, the Act also recognises a category of higher-risk data that demands extra caution: data of children (under 18). Processing this requires verifiable parental consent and is subject to the highest penalties — ₹250 crore — in the Act. Furthermore, we cover this in detail in Chapter 7: Children’s Data and Parental Consent Under the DPDP Act.

One crucial nuance: data that isn’t personal on its own can become personal when combined with other data. For example, an IP address alone may not identify someone. However, when combined with a timestamp and browsing history, that same IP address almost certainly does. In short, your compliance obligations follow the effective identifiability of the data — not just whether a name is attached.

TL;DR

Personal data is any information that can identify a person — directly or in combination with other data. When in doubt, treat it as personal data. Children’s data carries the strictest requirements and highest penalties.

Your Core Obligations as a Data Fiduciary

The DPDP Act doesn’t just set rules — it establishes a comprehensive framework of accountability. As a result, understanding each obligation individually is essential before you can build a compliance programme. Here are the eight core obligations every Data Fiduciary must meet, each covered in dedicated chapters of this series.

Obligations 1–4: Data Collection and Processing

1

Lawful Purpose & Data Minimisation

You may only collect personal data for a specific, clearly stated purpose — and collect only what you actually need. An e-commerce platform can collect a delivery address for shipping; it cannot collect that address to build unrelated behavioural profiles without separate consent. See Chapter 5: Data Minimisation and Purpose Limitation.

2

Transparency & Notice Requirements

Before or at the time of collecting data, you must provide a clear notice explaining what you’re collecting, why, and what rights the individual has. The notice must be in plain language — not buried in legal terms — and available in regional languages upon request. Your current privacy policy almost certainly needs a rewrite. See Chapter 10: Writing a DPDP-Compliant Privacy Policy.

3

Consent Management

When consent is your legal basis for processing, it must be freely given, specific, informed, unconditional, and unambiguous. Pre-ticked checkboxes, bundled consents, and consent buried in terms and conditions are all invalid under the Act. You also need systems to record, manage, and honour consent withdrawal. See Chapter 2: Consent Management Under the DPDP Act.

4

Security Safeguards

You must implement “reasonable security safeguards” to prevent personal data breaches. The standard is proportional to the sensitivity of the data you hold. For a fintech handling financial data, this means strong encryption, access controls, and regular security audits. For a SaaS startup with basic customer emails, baseline security hygiene is the starting floor. See Chapter 16: Security Safeguards Under the DPDP Act.

Obligations 5–8: Rights, Governance, and Accountability

5

Honour Data Principal Rights

Every individual whose data you process — called a “Data Principal” under the Act — has the right to access their data, correct inaccuracies, erase their data (in certain circumstances), and nominate a representative. You must have operational processes to respond to these requests promptly. A healthcare provider, for example, must be able to give a patient access to their records and correct them if wrong. See Chapter 21: Data Principal Rights and How to Operationalise Them.

6

Data Retention & Deletion

Personal data must not be retained beyond the period necessary for the purpose it was collected. Once that purpose is fulfilled, you must delete or anonymise the data. This requires a formal retention schedule — a document specifying how long each category of data you hold is kept, and what happens to it afterwards. See Chapter 22: Data Retention and Deletion Frameworks.

7

Appoint a Grievance Officer

Every Data Fiduciary must publish contact details for a Grievance Officer — an individual or team responsible for handling privacy complaints from Data Principals. For Significant Data Fiduciaries, a full Data Protection Officer (DPO) is also required. See Chapter 23: Appointing Your DPO and Grievance Officer.

8

Data Breach Notification

If a personal data breach occurs, you must notify both the Data Protection Board and each affected Data Principal. The notification must be prompt — implementing rules will specify timelines, but global norms suggest 72 hours to the Board. Your breach response plan needs to exist before you need it. See Chapter 24: Data Breach Response Planning.

“Compliance under the DPDP Act isn’t about perfect paperwork — it’s about building genuine accountability into how your business uses people’s data.”

TL;DR

As a Data Fiduciary, you have eight core obligations: lawful purpose, transparency, consent management, security, honouring individual rights, retention limits, appointing a grievance officer, and breach notification. Each has dedicated guidance in later chapters of this series.

DPDP Act Penalties: What’s at Stake

The Data Protection Board of India has the authority to investigate complaints and impose financial penalties. The Act structures penalties in three tiers, each tied to specific categories of violation.

₹50 Cr

Tier 1 — Administrative & Procedural Failures

Failure to maintain reasonable security safeguards for children’s data, failure to appoint a grievance officer, or failure to comply with obligations relating to Data Processors.

₹200 Cr

Tier 2 — Security Failures & Breach Non-Notification

Failure to implement reasonable security safeguards leading to a personal data breach, or failure to notify the Data Protection Board or affected individuals of a breach.

₹250 Cr

Tier 3 — Children’s Data Violations (Maximum Penalty)

Processing personal data of children without verifiable parental consent, or engaging in behavioural monitoring or targeted advertising directed at minors. This is the highest penalty in the Act.

Beyond financial penalties, the Data Protection Board can also issue directions requiring you to take specific corrective actions — which may include suspending data processing activities altogether. In practice, therefore, an enforcement action is as much a reputational event as a financial one. The first few high-profile cases decided by the Board will set the tone for enforcement across India.

For a complete breakdown of the penalty framework and how the Board calculates fines, see Chapter 25: DPDP Act Penalties and Enforcement — What the Data Protection Board Can Do.

TL;DR

Penalties range from ₹50 crore to ₹250 crore depending on severity. Security failures and breach non-notification attract ₹200 crore. Children’s data violations attract the maximum ₹250 crore. Reputational damage is an equal — if not greater — risk than the fine itself.

Your Next Steps: From Reading to Compliance

Understanding the DPDP Act is step one. Acting on it is what protects your business. Here’s how to move from awareness to action — this week and over the next 30 days.

🔥 This Week

  • List every place your business collects personal data
  • Identify which data belongs to children (under 18)
  • Check whether your privacy policy is readable and current
  • Designate someone as your initial DPDP point of contact

📅 30-Day Priorities

  • Complete a full data mapping exercise (Step 1 of our checklist)
  • Classify your role — Fiduciary, Processor, or both
  • Assess your consent mechanisms against DPDP standards
  • Review all third-party vendor agreements
  • Begin drafting your breach response plan

To take it further, the complete step-by-step implementation plan — with cost estimates and timelines for each action — is in Chapter 3: The DPDP Compliance Checklist: 15 Steps Every Company Must Take Before the Deadline. It’s the most actionable piece in this series.

DPDP Act India Compliance: Achievable, Not Optional

The DPDP Act India is not a threat to business — it’s a framework for building the kind of trust that modern customers demand and sophisticated investors expect. The businesses that treat compliance as a competitive differentiator, rather than a regulatory burden, will be better positioned in every way: legally, operationally, and reputationally.

The law is clear. The penalties are real. And the compliance path — while not trivial — is entirely achievable for businesses of every size. The Digital Personal Data Protection Act gives you a structured set of obligations. This series gives you a structured way to meet them.

Start with your data map. Everything else follows from knowing what data you hold, why you have it, and what you’ve promised about how you’ll use it.

✅ Key Takeaways from Chapter 1

  • The DPDP Act 2023 is India’s first comprehensive digital data privacy law — covering any business that processes personal data of Indian residents.
  • There is no exemption based on company size. Every Data Fiduciary has compliance obligations from day one.
  • Personal data is broader than most businesses assume — it includes IP addresses, device IDs, and any combination of data that identifies an individual.
  • Your eight core obligations cover consent, transparency, security, individual rights, data deletion, grievance mechanisms, and breach notification.
  • Penalties reach ₹250 crore for the most serious violations — children’s data breaches carry the maximum fine.
  • The best first step: map your personal data flows. You can’t protect what you don’t know you have.

Free Resource

Download the Free DPDP Compliance Toolkit

Includes: Data mapping template, privacy notice checklist, consent audit worksheet, breach response plan template, and the complete 15-step compliance checklist — all in one downloadable PDF.

⬇ Download Free Compliance Toolkit
📞 Schedule Free Assessment

No spam. No sales pressure. Just clarity on your DPDP obligations.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. The DPDP Act’s implementing rules are yet to be fully notified by the Government of India. Businesses should consult qualified legal counsel for advice specific to their situation. Information accurate as of March 2025.

Scroll to Top