The Basics

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's primary law governing how personal data in digital form may be collected, stored, and processed. It received Presidential assent on August 11, 2023.

It was enacted following the Supreme Court's landmark ruling in Puttaswamy v. Union of India (2017), which established privacy as a fundamental right. The Act balances individual privacy with the needs of India's digital economy, while aligning with global standards like the EU's GDPR.

The Act applies to the processing of digital personal data in two scenarios:

  • Processing carried out within India — whether data was collected online or digitised from offline sources.
  • Processing carried out outside India, if it involves offering goods or services to individuals in India.
Not covered: Personal/domestic use, data the individual made publicly available themselves, or data processed for law enforcement and national security.

Personal data is any data about an individual who is identifiable — directly or indirectly — from that data. This includes names, email addresses, phone numbers, location data, financial details, health records, biometric data, and more.

The DPDPA does not create a separate "sensitive personal data" category, though the government may notify higher obligations for particularly sensitive data types.

💡 Once data is fully anonymised such that no individual can be identified from it, it falls outside the scope of the Act.
  • Data Principal — the individual to whom personal data belongs (you, the user or customer). Children under 18 are Data Principals with additional protections.
  • Data Fiduciary — any entity that determines the purpose and means of processing personal data. Equivalent to a "data controller" under GDPR.
  • Data Processor — an entity that processes data on behalf of a Data Fiduciary under a contract (e.g. a cloud host or analytics vendor).

Processing is lawful only on two grounds:

  • Consent — free, specific, informed, unconditional, and unambiguous consent given through a clear affirmative action.
  • Legitimate uses — State services and subsidies, legal compliance obligations, medical emergencies, employment, and disaster response.
ℹ️ Unlike GDPR, there is no general "legitimate interests" ground. Consent is the primary mechanism for most private-sector processing.

Your Rights as a Data Principal

The DPDPA grants you these statutory rights:

  • Right to information — know what data is held about you, for what purpose, and with whom it has been shared.
  • Right to correction & erasure — request correction of inaccurate data and deletion once the purpose is complete or consent is withdrawn.
  • Right to grievance redressal — complain to the Data Fiduciary and escalate unresolved issues to the Data Protection Board of India.
  • Right to nominate — appoint someone to exercise your rights in case of death or incapacity.
ℹ️ The Act does not currently include a right to data portability or a right to object to automated decision-making, unlike GDPR.

Yes, you can withdraw consent at any time. The withdrawal mechanism must be as easy to use as the consent mechanism.

On withdrawal, the Data Fiduciary and its processors must stop processing your data within a reasonable time. Processing before withdrawal remains lawful.

⚠️ Withdrawal is not retroactive; it only applies to future processing.

Yes. A child is anyone under 18 years of age. Data Fiduciaries must obtain verifiable parental or guardian consent before processing a child's data.

Data Fiduciaries are also prohibited from:

  • Tracking or behaviourally monitoring children.
  • Serving targeted advertising to children.
  • Processing data in any manner harmful to a child's well-being.
ℹ️ Healthcare providers or educational institutions acting in a child's interest may be exempted from parental consent by government notification.

Obligations on Organisations

All Data Fiduciaries must:

  • Purpose limitation — collect only data necessary for the stated purpose.
  • Storage limitation — erase data once the purpose is fulfilled or consent withdrawn.
  • Data accuracy — keep data accurate and complete, especially for decisions affecting individuals.
  • Security safeguards — implement reasonable measures to prevent data breaches.
  • Breach notification — notify the Data Protection Board and affected individuals promptly upon discovering a breach.
  • Grievance mechanism — publish a contact for data complaints and respond in a timely manner.

The Central Government may designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs). SDFs must additionally:

  • Appoint a Data Protection Officer (DPO) — a senior employee based in India, accountable to the board.
  • Appoint an independent data auditor for periodic compliance audits.
  • Conduct regular Data Protection Impact Assessments (DPIAs).
  • Comply with any additional standards notified specifically for SDFs.

Before seeking consent, a Data Fiduciary must provide a clear, plain-language notice covering:

  • What personal data is being collected and the specific purpose.
  • How the individual can withdraw consent.
  • How to file a complaint with the Data Protection Board.

Notices must be available in English and all 22 scheduled languages. Consent must be a clear affirmative action — pre-ticked boxes and opt-out defaults are invalid.

No. The Data Fiduciary remains fully accountable for any violation or breach caused by its Data Processors. Outsourcing does not transfer or reduce liability.

⚠️ If your cloud vendor or third-party processor suffers a breach involving your users' data, you are responsible for breach notification and remediation.

Enforcement & Penalties

The Data Protection Board of India (DPBI) is the statutory regulator established under the Act to investigate violations, adjudicate complaints, and impose penalties. It functions as a digital-first body with all proceedings conducted online.

Violation Max Penalty
Failure to implement security safeguards leading to a breach ₹250 Crore
Failure to notify the Board and individuals of a breach ₹200 Crore
Violation of children's data obligations ₹200 Crore
Non-fulfilment of Significant Data Fiduciary obligations ₹150 Crore
Violation of Data Principal's rights ₹10,000
ℹ️ The Board considers gravity, repetitiveness, harm caused, and remedial steps taken before determining the actual penalty amount.

Yes. Any person aggrieved by a Board order may appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days. Further appeals from TDSAT lie before the High Court.

  • Step 1 — Data Protection Board of India
  • Step 2 — Telecom Disputes Settlement & Appellate Tribunal (TDSAT)
  • Step 3 — High Court

Cross-Border Transfers & Exemptions

The DPDPA uses a permissive "blacklist" model — data may be transferred to any country except those specifically restricted by the Central Government via notification.

📌 No restricted countries have been notified as of the Act's enactment. Sector-specific rules (e.g. RBI, IRDAI) may impose additional transfer restrictions.
  • Personal/domestic use — individuals processing data for purely household purposes are not covered.
  • Research & statistics — processing for research or public interest archiving, subject to safeguards.
  • Startups & small entities — the government may relax certain obligations for notified categories of smaller fiduciaries.
  • Law enforcement — processing by competent authorities for prevention or investigation of offences.
  • Similar: Lawful consent, rights to access and erasure, breach notification, fiduciary accountability for processors.
  • DPDPA is simpler: No sensitive data category, no right to portability or automated decision-making objection, no mandatory DPO for all fiduciaries.
  • Transfers: GDPR uses adequacy decisions (whitelist); DPDPA uses restricted countries (blacklist), which is permissive by default.
  • Penalties: GDPR allows up to 4% of global annual turnover; DPDPA has fixed rupee caps (max ₹250 Crore).

SOC 2 (System and Organization Controls)

SOC 2 (System and Organization Controls 2) is a voluntary compliance standard developed by the AICPA (American Institute of CPAs). It specifies how organizations should manage customer data based on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy.

It is primarily required for technology, SaaS, and cloud-based vendors operating in or selling to the US market to prove they have robust cybersecurity controls.

  • SOC 2 Type I: Audits the design of a company's security controls at a single point in time. It reports whether the controls are set up correctly.
  • SOC 2 Type II: Audits the operational effectiveness of those controls over a sustained testing period (typically 3 to 12 months). It proves that security is maintained continuously.

Typically, the end-to-end process takes 6 to 12 months:

  • Gap Assessment & Remediation: 2 to 3 months (fixing policy gaps and configuring security controls).
  • Observation Period (Type II): 3 to 6 months (collecting logs and evidence).
  • Audit & Report Generation: 1 to 2 months (the CPA firm reviewing evidence and writing the report).

No. SOC 2 is an audit report, not a permanent certification. A SOC 2 report is generally considered valid for 12 months from the report date. Organizations must undergo surveillance audits annually to maintain continuous SOC 2 status.

ISO/IEC 27001 (Information Security Management)

ISO/IEC 27001 is the leading international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

It certifies that an organization has a systematic, risk-based approach to protecting sensitive corporate and customer data across people, processes, and technology.

An ISMS is a structured framework of policies, procedures, risk assessments, and technical controls designed to manage and protect an organization's information assets. It ensures confidentiality, integrity, and availability of data by mitigating security risks.

The updated ISO 27001:2022 standard contains 93 security controls in Annex A (consolidated from 114 in the 2013 version). These are organized into 4 thematic themes:

  • Organizational Controls: 37 controls (e.g. policy frameworks, asset management).
  • People Controls: 8 controls (e.g. background checks, training).
  • Physical Controls: 14 controls (e.g. secure areas, visitor entries).
  • Technological Controls: 34 controls (e.g. encryption, network security, backups).

An ISO 27001 certificate is valid for 3 years. To maintain validity, organizations must pass annual surveillance audits conducted by an external registrar, followed by a full recertification audit at the end of the 3rd year.

GDPR (General Data Protection Regulation)

The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy regulation. Yes, it has extraterritorial reach. It applies to any business outside the EU if they process the personal data of individuals residing in the EU, or offer goods/services to them.

GDPR penalties are substantial and structured into two tiers:

  • Lower Tier: Up to €10 million or 2% of global annual turnover, whichever is higher (for administrative errors, record-keeping violations).
  • Higher Tier: Up to €20 million or 4% of global annual turnover, whichever is higher (for violating core principles of consent, data subjects' rights, and unauthorized transfers).
  • Data Controller: The organization that determines the purposes ("why") and means ("how") of processing personal data. They own the compliance obligation.
  • Data Processor: The third-party entity (like a SaaS platform or cloud host) that processes data only on behalf of and under the direct instructions of the Controller.

A DSAR is a formal request made by an individual to an organization exercising their rights under GDPR. It requires the organization to confirm whether they process their data, provide a copy of the data, and explain how it is used, corrected, or erased, typically within 30 days.

HIPAA (Health Insurance Portability and Accountability Act)

HIPAA is a US federal law that protects sensitive patient health information (Protected Health Information, or PHI). Compliance applies to two main groups:

  • Covered Entities: Healthcare providers, health plans, and healthcare clearinghouses.
  • Business Associates: Any vendor or service provider (IT, hosting, billing, legal) that handles, transmits, or stores PHI on behalf of a Covered Entity.

PHI is any individually identifiable health information (including medical histories, test results, prescription details, location info, and billing records) that is transmitted or maintained by a covered entity, whether electronically (ePHI), on paper, or orally.

A BAA (Business Associate Agreement) is a legally binding contract required by HIPAA. It is signed between a Covered Entity and a Business Associate. It mandates how the associate will safeguard PHI, limits its use, details breach reporting procedures, and holds the associate directly liable for violations.

HIPAA violations carry strict civil and criminal penalties structured in four tiers based on culpability:

  • Tier 1 (Unknowing): $137 to $68,928 per violation (max $2.06M/yr).
  • Tier 2 (Reasonable Cause): $1,379 to $68,928 per violation (max $2.06M/yr).
  • Tier 3 (Willful Neglect, Corrected): $13,785 to $68,928 per violation (max $2.06M/yr).
  • Tier 4 (Willful Neglect, Uncorrected): $68,928 per violation (max $2.06M/yr).