DPDP Act 2023: A Readiness Checklist for Indian Businesses
What the Digital Personal Data Protection Act 2023 requires, who it applies to, the penalties for non-compliance, and a step-by-step checklist to get ready.
The Digital Personal Data Protection (DPDP) Act 2023 is India's first comprehensive data-protection law. If your business collects personal data of individuals in India — customers, employees, or users — it applies to you. This guide explains the essentials and gives you a practical readiness checklist.
Who does the DPDP Act apply to?
It applies to any organisation (a "Data Fiduciary") that processes the personal data of individuals ("Data Principals") in India — whether the processing happens inside India or abroad, if it relates to offering goods or services in India.
Key obligations
- Lawful purpose and consent — collect personal data only for a clear, lawful purpose, with free, informed, specific consent.
- Notice — tell people what data you collect and why, in clear language.
- Data minimisation — collect only what you need.
- Security safeguards — protect data with reasonable technical and organisational measures.
- Breach notification — report personal data breaches to the Data Protection Board and affected individuals.
- Rights of individuals — enable access, correction, and erasure of personal data, and a grievance mechanism.
- Children's data — obtain verifiable parental consent for users under 18, with restrictions on tracking and targeted ads.
Larger organisations may be notified as Significant Data Fiduciaries, with extra duties such as appointing a Data Protection Officer and conducting Data Protection Impact Assessments.
Penalties
Penalties for non-compliance can reach up to Rs. 250 crore per instance for failure to take reasonable security safeguards to prevent a data breach. The scale of these penalties is why early readiness matters.
Readiness checklist
- Map your data — what personal data you hold, where it lives, and who can access it.
- Document a lawful purpose for each processing activity.
- Rebuild consent flows — clear notices, granular consent, easy withdrawal.
- Update your privacy notice in plain language.
- Stand up data-subject rights — access, correction, erasure, and grievance handling.
- Tighten security — encryption, access controls, logging, vendor due diligence.
- Create a breach-response plan with notification timelines.
- Check children's data handling and parental-consent mechanisms.
- Assess Significant Data Fiduciary status and the extra obligations it triggers.
When does it come into force?
The Act is being operationalised through rules, with enforcement expected to phase in around 2027. Given the breadth of the changes — consent, security, and data-subject rights — most organisations need a head start.
This guide is general information, not legal advice. Your specific obligations depend on the nature and scale of your data processing.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.