The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection statute, but a lot of the discussion around it — online and in boardrooms — conflates what the Act says with what the still-awaited Rules will actually operationalise. For businesses trying to plan compliance now, it helps to separate what's already settled from what's still pending.
What the Act itself establishes
The DPDP Act creates a framework built around a few core concepts: Data Principals (individuals whose personal data is processed), Data Fiduciaries (entities that determine the purpose and means of processing, roughly equivalent to a "controller" under other regimes), and Significant Data Fiduciaries — a category of entities the government can notify for additional obligations based on the volume and sensitivity of data they handle, likely to include large fintech and platform businesses.
The Act requires that personal data be processed only for a lawful purpose with the individual's consent, or under specified "legitimate uses" that don't require consent — such as for a purpose the individual voluntarily provided data for, compliance with law, or medical emergencies. It grants individuals rights to access, correct and erase their data, and to nominate someone to exercise these rights on their behalf in the event of death or incapacity. It also establishes the Data Protection Board of India as the enforcement authority.
What's still pending — and why it matters
The Act itself is largely a framework; the operational detail — exact breach notification timelines, the specific criteria for classification as a Significant Data Fiduciary, cross-border data transfer conditions, and consent manager requirements — is left to Rules that the government notifies separately. Several provisions of the Act, including its breach notification and enforcement mechanisms, only take effect once the corresponding Rules are in force.
This creates a genuine planning problem: businesses can't finalise exact breach-notification workflows or consent-architecture decisions until the Rules are notified, but waiting until then to start is not a sound compliance strategy either, given how much groundwork the Act's principles already require.
What businesses should be doing now, regardless of the Rules
Several obligations don't need the Rules to start acting on, because they follow directly from the Act's core principles:
- Data mapping — knowing what personal data you collect, why, where it's stored, and who has access, is a prerequisite for every other compliance step and takes real time to do properly
- Consent architecture — reviewing how consent is currently obtained (buried in terms of service vs. clear, specific, itemised consent) against what the Act's consent standard is likely to require
- Purpose limitation — auditing whether data collected for one stated purpose is being used for others, a common gap in fintech and lending apps that collect broad permissions at onboarding
- Vendor and processor agreements — ensuring contracts with vendors who process personal data on your behalf reflect the Data Fiduciary's ultimate responsibility for that processing
- Grievance redressal — the Act requires a mechanism for individuals to raise complaints, which needs a real process behind it, not just a stated email address
Where this intersects with existing obligations
The DPDP Act doesn't replace CERT-In's incident reporting requirements or RBI's sector-specific cyber security framework — it sits alongside them, and in some cases will add an additional notification obligation once its breach-notification provisions are in force. For regulated fintech entities already tracking CERT-In and RBI timelines, the practical approach is to build DPDP readiness into the same incident-response plan rather than as a separate compliance track. This is covered in the context of fintech breach response generally at cyber crime legal services for fintech companies and RBI data breach reporting for payment aggregators.
Penalties — what's actually at stake
The Act provides for significant financial penalties for non-compliance, including for failure to take reasonable security safeguards and for failure to notify a data breach where that obligation applies — with penalty amounts running into hundreds of crores for the more serious categories of default, imposed by the Data Protection Board following its own inquiry process. These are civil penalties under the Act itself, separate from any criminal liability that might arise under the IT Act or BNS if a breach also involves unauthorised access or data theft by a third party.
A practical starting point
Businesses that treat DPDP readiness as a one-time project tend to find it stalls once the initial data-mapping exercise is done. The more durable approach is to build data protection review into the same cadence as other compliance work — an annual (or more frequent, for higher-risk entities) review of what data is collected, how consent is structured, and whether the incident-response plan reflects current requirements, updated as the Rules are progressively notified.
Frequently asked questions
Is the DPDP Act already fully in force?
The Act has been enacted, but several of its operative provisions — particularly around breach notification and Significant Data Fiduciary obligations — depend on Rules that are notified separately and are not all yet in force. Businesses should track the notification status of the specific provisions relevant to them rather than assuming the whole Act is currently enforceable end to end.
Does the DPDP Act apply to a company outside India that processes Indian users' data?
The Act's territorial scope extends to processing of personal data of individuals in India even where the processing itself happens outside India, where that processing is connected to offering goods or services to those individuals. Foreign entities serving Indian users should not assume they fall outside its scope.
What counts as a "Significant Data Fiduciary" and does that apply to us?
This is a category the government notifies based on factors like volume and sensitivity of data processed, and the specific criteria are set out through notification rather than the Act itself. Larger fintech, e-commerce and platform businesses handling substantial volumes of personal or financial data should assume this classification is a realistic possibility and plan accordingly.
Do we need a Data Protection Officer?
This obligation is tied to Significant Data Fiduciary status under the Act, rather than applying universally. Entities uncertain about their classification should get this assessed rather than assume either way.
For an assessment of your DPDP readiness alongside your existing CERT-In and RBI obligations, call +91 82954 13475 at any hour, or send the details of your matter.
Facing this yourself?
Call +91 82954 13475 or send the details. The first consultation is free. This post is general information and is not advice on any particular case.
Read next
- Bank Account Frozen Because of Crypto Trading? Here's What to Do
- Cyber Crime and Fintech Companies in Gurugram: What Founders and Compliance Teams Need to Know
- What Payment Aggregators Must Report to RBI After a Data Breach
- Digital Lending App Harassment: When Recovery Practices Cross Into a Cyber Crime Complaint