Clear answers about global compliance frameworks (DPDPA, SOC 2, ISO 27001, GDPR, and HIPAA) for modern businesses.
The Basics
The Digital Personal Data Protection Act, 2023 (DPDPA) is India's primary law governing how personal data in digital form may be collected, stored, and processed. It received Presidential assent on August 11, 2023.
It was enacted following the Supreme Court's landmark ruling in Puttaswamy v. Union of India (2017), which established privacy as a fundamental right. The Act balances individual privacy with the needs of India's digital economy, while aligning with global standards like the EU's GDPR.
The Act applies to the processing of digital personal data in two scenarios:
Personal data is any data about an individual who is identifiable — directly or indirectly — from that data. This includes names, email addresses, phone numbers, location data, financial details, health records, biometric data, and more.
The DPDPA does not create a separate "sensitive personal data" category, though the government may notify higher obligations for particularly sensitive data types.
Processing is lawful only on two grounds:
Your Rights as a Data Principal
The DPDPA grants you these statutory rights:
Yes, you can withdraw consent at any time. The withdrawal mechanism must be as easy to use as the consent mechanism.
On withdrawal, the Data Fiduciary and its processors must stop processing your data within a reasonable time. Processing before withdrawal remains lawful.
Yes. A child is anyone under 18 years of age. Data Fiduciaries must obtain verifiable parental or guardian consent before processing a child's data.
Data Fiduciaries are also prohibited from:
Obligations on Organisations
All Data Fiduciaries must:
The Central Government may designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs). SDFs must additionally:
Before seeking consent, a Data Fiduciary must provide a clear, plain-language notice covering:
Notices must be available in English and all 22 scheduled languages. Consent must be a clear affirmative action — pre-ticked boxes and opt-out defaults are invalid.
No. The Data Fiduciary remains fully accountable for any violation or breach caused by its Data Processors. Outsourcing does not transfer or reduce liability.
Enforcement & Penalties
The Data Protection Board of India (DPBI) is the statutory regulator established under the Act to investigate violations, adjudicate complaints, and impose penalties. It functions as a digital-first body with all proceedings conducted online.
| Violation | Max Penalty |
|---|---|
| Failure to implement security safeguards leading to a breach | ₹250 Crore |
| Failure to notify the Board and individuals of a breach | ₹200 Crore |
| Violation of children's data obligations | ₹200 Crore |
| Non-fulfilment of Significant Data Fiduciary obligations | ₹150 Crore |
| Violation of Data Principal's rights | ₹10,000 |
Yes. Any person aggrieved by a Board order may appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days. Further appeals from TDSAT lie before the High Court.
Cross-Border Transfers & Exemptions
The DPDPA uses a permissive "blacklist" model — data may be transferred to any country except those specifically restricted by the Central Government via notification.
SOC 2 (System and Organization Controls)
SOC 2 (System and Organization Controls 2) is a voluntary compliance standard developed by the AICPA (American Institute of CPAs). It specifies how organizations should manage customer data based on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy.
It is primarily required for technology, SaaS, and cloud-based vendors operating in or selling to the US market to prove they have robust cybersecurity controls.
Typically, the end-to-end process takes 6 to 12 months:
No. SOC 2 is an audit report, not a permanent certification. A SOC 2 report is generally considered valid for 12 months from the report date. Organizations must undergo surveillance audits annually to maintain continuous SOC 2 status.
ISO/IEC 27001 (Information Security Management)
ISO/IEC 27001 is the leading international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
It certifies that an organization has a systematic, risk-based approach to protecting sensitive corporate and customer data across people, processes, and technology.
An ISMS is a structured framework of policies, procedures, risk assessments, and technical controls designed to manage and protect an organization's information assets. It ensures confidentiality, integrity, and availability of data by mitigating security risks.
The updated ISO 27001:2022 standard contains 93 security controls in Annex A (consolidated from 114 in the 2013 version). These are organized into 4 thematic themes:
An ISO 27001 certificate is valid for 3 years. To maintain validity, organizations must pass annual surveillance audits conducted by an external registrar, followed by a full recertification audit at the end of the 3rd year.
GDPR (General Data Protection Regulation)
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy regulation. Yes, it has extraterritorial reach. It applies to any business outside the EU if they process the personal data of individuals residing in the EU, or offer goods/services to them.
GDPR penalties are substantial and structured into two tiers:
A DSAR is a formal request made by an individual to an organization exercising their rights under GDPR. It requires the organization to confirm whether they process their data, provide a copy of the data, and explain how it is used, corrected, or erased, typically within 30 days.
HIPAA (Health Insurance Portability and Accountability Act)
HIPAA is a US federal law that protects sensitive patient health information (Protected Health Information, or PHI). Compliance applies to two main groups:
PHI is any individually identifiable health information (including medical histories, test results, prescription details, location info, and billing records) that is transmitted or maintained by a covered entity, whether electronically (ePHI), on paper, or orally.
A BAA (Business Associate Agreement) is a legally binding contract required by HIPAA. It is signed between a Covered Entity and a Business Associate. It mandates how the associate will safeguard PHI, limits its use, details breach reporting procedures, and holds the associate directly liable for violations.
HIPAA violations carry strict civil and criminal penalties structured in four tiers based on culpability: