DPDP Act 2023 Compliance Checklist: What Indian Businesses Must Do Now
The Digital Personal Data Protection (DPDP) Act 2023 is India's first comprehensive data protection law. Assented to on August 11, 2023, the Act establishes a consent-based framework for processing digital personal data by Data Fiduciaries — organisations that process personal data. Penalties for non-compliance reach ₹250 crore per breach for inadequate data security safeguards, with separate penalties of ₹200 crore for failure to notify data breaches, and ₹150 crore for non-compliance with Data Protection Board orders. For Indian businesses — particularly those in IT, BFSI, healthcare, and e-commerce — building DPDP compliance programmes now, rather than waiting for enforcement to begin, is both a legal obligation and a competitive necessity.
This guide covers the core DPDP Act obligations for Data Fiduciaries, consent management requirements, data breach notification timelines, and sector-specific obligations — with a practical compliance checklist for IT, BFSI, and healthcare organisations.
Who Does the DPDP Act Apply To?
The DPDP Act applies to any person (entity) that processes digital personal data:
- Within India, whether collected online or in physical form and subsequently digitised
- Outside India, if the processing relates to offering goods or services to data principals within India
This broad extraterritorial scope means foreign companies with Indian customers — including SaaS providers, e-commerce platforms, and overseas educational institutions accepting Indian students — must also comply with the Act when they process personal data of Indian residents. The applicability is based on where the data principal (the individual whose data is being processed) is located, not where the organisation is incorporated.
Exemptions: Personal data processed for national security, law enforcement, research and statistical purposes (with appropriate safeguards), personal or domestic purposes, and data of employees in certain employment-related contexts may be partially or fully exempt. The exemptions are narrower than similar carve-outs in GDPR, meaning a careful assessment is needed before assuming exemption applies.
Data Fiduciary Obligations Under DPDP Act 2023
1. Purpose Limitation and Lawful Processing
The DPDP Act requires that personal data be processed only for a lawful purpose — either with the data principal's voluntary consent, or for a "legitimate use" as specified in the Act (employment-related processing, processing necessary for the state or its instrumentalities providing services or benefits, and certain emergency situations). The fundamental principles of data processing under the Act are:
- Purpose limitation: Personal data may only be collected for a specific, clearly stated purpose. Processing for other purposes requires fresh consent.
- Data minimisation: Only the personal data actually necessary for the stated purpose may be collected. Collecting data "just in case it might be useful" is not lawful under DPDP.
- Storage limitation: Personal data must be erased once the purpose for which it was collected has been fulfilled and when the individual withdraws consent, unless there is a legal obligation to retain the data.
- Data accuracy: The data fiduciary must take reasonable steps to ensure that personal data processed is accurate and, where necessary, up to date.
2. Consent Management — The Core Mechanism
Consent under the DPDP Act is the primary lawful basis for processing most personal data. The Act specifies that valid consent must be:
- Free: Not coerced by bundling data collection with service access in a way that leaves the individual with no practical alternative
- Specific: For a clearly defined purpose — not an omnibus consent for "any and all purposes we might want to use your data for in the future"
- Informed: The data principal must be able to understand what data is being collected, for what purpose, and who will receive it
- Unambiguous: A positive, affirmative action by the individual — pre-checked boxes, continued use of a website, or inaction do not constitute consent under DPDP
- Withdrawable: The data principal must be able to withdraw consent at any time, and the process for withdrawal must be as easy as the process for giving consent
On withdrawal of consent, the data fiduciary must cease processing the personal data for that purpose and must erase the data, unless another lawful basis for continued processing or retention exists.
The Act introduces the concept of a Consent Manager — a registered intermediary that enables data principals to manage consent across multiple data fiduciaries through a single interface. Consent Managers must be registered with the Data Protection Board and must maintain standardised consent records that are auditable.
3. Data Principal Rights
Data principals (individuals whose data is processed) have four enforceable rights under the DPDP Act:
- Right to access information: The right to know what personal data is being processed about them, and to a summary of that data in a clear and understandable form
- Right to correction and erasure: The right to have inaccurate or incomplete personal data corrected; the right to have data erased when the purpose has been fulfilled or consent has been withdrawn
- Right to grievance redressal: The right to have their complaints addressed by the data fiduciary through an accessible grievance mechanism, with timely response
- Right to nominate: The right to nominate another person to exercise data rights on their behalf in the event of the data principal's death or incapacity — a practical right given India's demographic context
Data fiduciaries must have mechanisms in place to receive and respond to data principal requests within the timeframes to be specified by the Data Protection Board. Failure to respond is itself a violation of the Act.
4. Data Security Safeguards
The DPDP Act requires data fiduciaries to implement "reasonable security safeguards" to prevent personal data breaches. The Act does not prescribe specific technical standards in the legislation itself — rules are expected to specify requirements in more detail. However, the Data Protection Board is expected to consider alignment with internationally recognised standards. In practice, Indian organisations should align their security programmes with:
- ISO/IEC 27001 Information Security Management System — provides a comprehensive framework for technical and organisational security controls
- CERT-In Guidelines — mandatory for certain categories of organisations and for specific incident types
- RBI Cybersecurity Framework — applicable to banks, NBFCs, payment aggregators, and other regulated financial entities
- SEBI Cybersecurity and Cyber Resilience Framework — applicable to stock brokers, depositories, mutual funds, and other SEBI-regulated entities
- IRDA Information and Cyber Security Guidelines — applicable to insurance companies
5. Personal Data Breach Notification
On discovering a personal data breach, a Data Fiduciary must notify:
- The Data Protection Board of India: As soon as practicable; rules are expected to specify 72 hours as the notification timeframe (aligning with GDPR breach notification practice)
- Each affected data principal: Notified in the prescribed manner with sufficient information to allow them to take protective steps
The breach notification to the Board must include the nature of the personal data breached, the approximate number of affected individuals, the likely consequences of the breach, and the measures the data fiduciary has taken or plans to take.
Separately and critically, CERT-In Directions 2022 (issued under the Information Technology Act 2000) require mandatory incident reporting to CERT-In within 6 hours of detecting a significant cybersecurity incident. Incidents that trigger CERT-In reporting include: data breaches, ransomware attacks, malware deployment, unauthorised access to IT systems, website defacements, attacks on critical information infrastructure, and social media account compromise. The CERT-In obligation operates independently of the DPDP Act — both must be complied with for applicable incidents.
Significant Data Fiduciaries
The Central Government may designate certain Data Fiduciaries as "Significant Data Fiduciaries" (SDFs) based on volume of personal data processed, sensitivity of data, national security implications, or other factors. SDFs face additional obligations not required of ordinary Data Fiduciaries:
- Appointment of a Data Protection Officer (DPO) who is a senior representative of the SDF and who is based in India or can exercise authority within India
- Appointment of an independent Data Auditor to review compliance
- Periodic Data Protection Impact Assessments (DPIAs) for high-risk processing activities
- Algorithmic transparency and accountability obligations where AI systems process personal data to make decisions affecting data principals
Major platforms, large e-commerce companies, significant financial services firms, and large healthcare data processors are likely candidates for SDF designation when the government notifies the criteria.
DPDP Act Compliance Checklist
Data Governance Foundation
- Personal data inventory: all categories of personal data processed, purposes, storage locations, and retention periods documented
- Legal basis for processing each category identified: consent or specific legitimate use under the Act
- Data flow mapping: how does personal data enter the organisation, where is it processed, where is it stored, and with whom is it shared?
- Privacy policy / notice published: clear, accessible, and in plain language; updated for DPDP Act requirements
- Grievance Officer appointed; contact information accessible to data principals through the organisation's website and communication channels
Consent Management
- All consent notices reviewed: purpose clearly stated; no bundled consent for unrelated purposes
- Consent records maintained: for each data collection point, evidence of consent captured and retained
- Consent withdrawal mechanism: functional, accessible, and as easy as giving consent
- Pre-checked consent boxes eliminated from all digital forms and applications
- Children's consent: additional parental consent mechanism implemented where data of minors (under 18 years) may be processed
Data Principal Rights Fulfilment
- Process documented for responding to access information requests within Board-specified timeframe
- Process documented for correction and erasure requests; data deletion capabilities verified across all systems where personal data is stored
- Grievance redressal mechanism functional; response time target set and tracked
- Nomination mechanism for deceased or incapacitated data principals implemented
Data Security and Breach Response
- Information security programme aligned with ISO 27001 or equivalent framework
- Personal data breach detection capabilities: SIEM, DLP, anomaly detection, endpoint monitoring
- Data breach response plan documented: clear escalation path, evidence preservation steps, notification template for Board and affected data principals
- CERT-In mandatory incident reporting procedure documented; 6-hour notification capability confirmed
- Data processing agreements with vendors and processors: contractual obligations for security and breach notification in place
- Regular security assessments: vulnerability assessment, penetration testing, security audits at defined intervals
Sector-Specific Obligations (BFSI / Healthcare / IT)
- RBI Cybersecurity Framework assessment completed and gaps addressed (banks, NBFCs, payment aggregators)
- SEBI Cybersecurity and Cyber Resilience Framework compliance verified (capital market intermediaries)
- IRDA Information and Cyber Security Guidelines compliance verified (insurance companies)
- Health data handling: additional care given to sensitive personal data (health, financial, biometric) which attracts higher penalties under the DPDP Act
How POPProbe Supports DPDP Act Compliance
POPProbe's DPDP Act compliance checklists help IT, BFSI, and healthcare organisations audit their data governance frameworks, consent management processes, data principal rights fulfilment capabilities, and breach response readiness against the Act's requirements. Digital checklists generate compliance reports with clear evidence of controls implemented — the kind of documentation that demonstrates a genuine compliance programme to the Data Protection Board and sector-specific regulators.
Access DPDP Act compliance checklists in our India regulatory compliance library, including the data fiduciary obligations assessment, consent management audit, data breach response readiness checklist, CERT-In incident reporting compliance checklist, and RBI cybersecurity framework audit in the checklist library.
Conclusion
The DPDP Act 2023 marks a fundamental shift in how Indian businesses must handle personal data — from a largely permissive environment to one with specific consent requirements, defined individual rights, and severe financial penalties for breaches. Organisations that treat DPDP compliance as purely a legal formality will face significant exposure when the Data Protection Board becomes operational and enforcement actions begin. The organisations that will navigate the DPDP era successfully are those that treat personal data protection as an operational discipline — building data inventories, consent management systems, and breach response plans into their core business processes rather than treating them as compliance add-ons.