Understanding India's landmark data privacy legislation — obligations for businesses, rights of data principals, and how Dravincon helps you comply in 2025–26.
The Digital Personal Data Protection Act 2023 (DPDPA) is India's comprehensive data protection legislation, enacted in August 2023. It governs the processing of digital personal data of individuals (Data Principals) in India.
The Act applies to any entity (Data Fiduciary) that collects, stores, or processes personal data of Indian residents — whether the processing occurs within or outside India.
Non-compliance can attract penalties up to ₹250 crore (approx. USD 30 million). Rules and enforcement mechanisms are being progressively notified through 2025–26.
What your organisation must do to comply with DPDPA.
Obtain free, specific, informed, and unconditional consent before processing personal data. Provide clear notice of purposes.
Process personal data only for the specific purpose for which consent was obtained. No secondary use without fresh consent.
Implement reasonable technical and organisational security safeguards to prevent personal data breaches.
Notify the Data Protection Board and affected Data Principals in the event of a personal data breach — promptly.
Erase personal data once the purpose is fulfilled or upon withdrawal of consent by the Data Principal.
Obtain verifiable parental consent before processing personal data of children under 18. Prohibit profiling and targeted advertising to children.
Rights granted to individuals whose data you process.
Right to know what personal data is being processed and for what purpose.
Right to correct inaccurate data and request erasure when processing purpose is fulfilled.
Right to withdraw consent at any time, with the same ease as it was given.
Right to seek redressal of grievances from the Data Fiduciary and Data Protection Board.
Our structured DPDPA compliance programme takes you from awareness to full readiness, covering all obligations under the Act and its Rules.
Identify all personal data processed, its flow, storage, and sharing across your organisation.
Benchmark current practices against DPDPA obligations and identify compliance gaps.
Design and implement compliant consent flows, privacy notices, and purpose registries.
Implement security measures, breach detection, and incident response for personal data.
Develop DPDPA-aligned policies and train staff on data protection obligations.
* Penalties are per instance. Significant Fiduciaries face enhanced obligations.
Achieving ISO 27001 certification provides a strong foundation for DPDPA compliance — the security controls in Annex A map directly to DPDPA's security obligations. Dravincon can help you pursue both simultaneously for maximum efficiency.
Book a free DPDPA readiness assessment with our compliance experts today.