Compliance
India’s Digital Personal Data Protection Act explained without legal jargon — who it applies to, the core rules, and what your business must change.
Check your DPDP readiness — free More on the blogFor years, Indian data privacy lived in Section 43A of the Information Technology Act, 2000 — a vague rule requiring "reasonable security practices" that resulted in almost zero public enforcement. That era ended with the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act). The DPDP Act is not merely a formality. It is an active compliance framework enforced by the Data Protection Board of India, equipped with statutory penalties reaching ₹250 crore per incident.
Regardless of whether you run a seed-stage SaaS product or an offline distributor with an online billing desk, five statutory duties apply immediately: Compliance is an engineering and operational inventory before it is a legal document. You cannot protect or delete data whose location you do not know.
Start by mapping every entry point where personal data enters your systems: signup forms, checkout pages, employee onboarding packets, customer support inboxes, and CCTV systems. You can take our free DPDP readiness check to diagnose your statutory exposure across 21 risk factors in under 5 minutes. Then deploy our audited DPDP privacy policy template and sign a compliant vendor DPA with every external processor handling your customer records. For deep dives into the underlying statutory provisions, review our statute analyses for Section 5 consent notices, Section 6 consent validity, Section 8 fiduciary duties, Section 11 data principal rights, and Section 33 penalties.
Passed in August 2023, the Digital Personal Data Protection Act (DPDP Act) is India's comprehensive data privacy legislation. It establishes rules for how organisations (Data Fiduciaries) collect, store, share, and delete digital personal data belonging to individuals (Data Principals), with statutory penalties up to ₹250 crore for non-compliance.
Yes. The Act contains no turnover or employee threshold. Any business collecting digital personal data in India — including names, phone numbers, delivery addresses, or IP logs — is classified as a Data Fiduciary and must comply with consent notices, security safeguards, and breach reporting.
Core duties include: (1) giving a clear consent notice before data collection under Section 5; (2) obtaining unambiguous consent under Section 6; (3) taking reasonable security safeguards to prevent data breaches under Section 8(5); (4) mandatory breach reporting under Section 8(6); (5) erasing data when the purpose is served under Section 8(7); (6) publishing a grievance officer contact under Section 8(10) and Section 16; and (7) respecting Data Principal rights under Section 11.
Section 33 read with the Schedule prescribes monetary penalties up to ₹250 crore for failing to prevent a personal data breach, up to ₹200 crore for failing to report a breach to the Board and affected individuals, and up to ₹50 crore for other statutory lapses.
Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this