India’s Digital Personal Data Protection Act 2023 represents the most significant development in Indian data regulation in a generation. It creates legally enforceable obligations for every organisation that processes the personal data of Indian citizens, whether inside or outside India, and establishes a framework of individual rights and organisational accountability that brings Indian law broadly in line with global standards.

Most compliance programmes we have reviewed are focusing on the wrong things. They are building consent banners, updating privacy policies, and conducting paper reviews of existing data processing activities. These are necessary but not sufficient. The six obligations that will determine whether an organisation is genuinely compliant are more fundamental.

The six obligations that matter most

1. Lawful basis identification for every processing activity

The DPDP Act requires a lawful basis for processing personal data. Unlike GDPR, which offers six lawful bases, the DPDP Act primarily works through consent and legitimate uses defined in the Act. Organisations need to have identified a clear lawful basis for every category of personal data processing they undertake, not just consumer-facing activities but HR data, vendor data, and operational data as well.

2. Consent architecture redesign

Where processing relies on consent, the Act’s requirements are specific and demanding. Consent must be free, specific, informed, unconditional, and unambiguous. It must be granular enough to allow individuals to consent to specific purposes, and it must be as easy to withdraw as to give. Most existing consent mechanisms will not meet these requirements without redesign.

3. Data Fiduciary obligations

The Act creates the concept of a Data Fiduciary, equivalent to a Data Controller under GDPR. Data Fiduciaries have specific obligations around purpose limitation, data minimisation, accuracy, storage limitation, and security. Significant Data Fiduciaries, those processing data at scale, face additional obligations including appointment of a Data Protection Officer and regular data protection impact assessments.

4. Data Principal rights fulfilment

Individuals have the right to access information about their data, to correct inaccurate data, to erase data where there is no longer a legitimate purpose for processing, and to nominate a representative for data rights. Organisations need operational processes for handling these requests within prescribed timelines. Most organisations currently have no systematic capability to respond to individual rights requests at scale.

5. Cross-border data transfer compliance

The Act restricts the transfer of personal data to countries not notified by the central government as having adequate protection. Organisations that currently transfer data internationally need to map these transfers and ensure they will have a compliant mechanism in place once the transfer restrictions take effect.

6. Breach notification and incident response

The Act requires notification to the Data Protection Board and to affected Data Principals in the event of a personal data breach. Organisations need incident response procedures that include personal data breach identification, assessment, and notification as a specific workflow, not as an afterthought to general incident response.

The organisations that will find DPDP Act compliance most manageable are those that treat it as a data governance programme rather than a legal compliance exercise. Data governance changes how data is managed. Legal compliance changes only what the organisation is prepared to say about how data is managed.

About the Author

Daipayan Das

Founder and CEO of Strategy TheFuture and Cechoes Technology. 26 years of Big 4 consulting across PwC, KPMG, and Protiviti. IIM Calcutta. B.E. Electronics and Communications, Nagpur University.

Full profile