Data Protection & Cybersecurity Compliance in India: A Practical DPDP Act Guide for Businesses
Published · 14 September 2026
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive law governing how businesses collect, use and protect the personal data of individuals. If your business has a website with a contact form, an app with user accounts, an e-commerce store, or any system that stores customer information, this law applies to you in some form - regardless of your company’s size.
This guide explains what the DPDP Act actually covers, in plain language, and gives growing businesses a practical starting point for understanding their obligations. It is not a substitute for legal advice - data protection law, and the rules implementing it, continue to evolve, and your specific obligations depend on facts about your business that only a qualified lawyer reviewing your situation can properly assess.
What the DPDP Act Is
The DPDP Act, 2023 sets out rules for how “digital personal data” - personal data processed in digital form - can be collected, used, stored and shared in India. It introduces a small set of core roles and concepts that most of the Act’s obligations are built around:
- Data Principal - the individual the personal data is about (your customer, user, or employee).
- Data Fiduciary - the entity that determines the purpose and means of processing personal data. If your business collects and uses customer data, you are almost certainly a Data Fiduciary.
- Data Processor - an entity that processes personal data on behalf of a Data Fiduciary (for example, a vendor you use to send emails or host data).
- Consent Manager - a registered entity through which individuals can manage their consent across different services.
Who the DPDP Act Applies To
The Act applies broadly to the processing of digital personal data within India, and in some circumstances to processing outside India where it relates to offering goods or services to individuals in India. In practice, this means most businesses with an online presence, a customer database, or a user-facing product that collects any personal information - names, emails, phone numbers, addresses, or more sensitive data - need to understand and act on their obligations, not just large enterprises or companies in specific regulated sectors.
Core Obligations for Businesses (Data Fiduciaries)
At a high level, the Act’s obligations for businesses collecting and using personal data include:
- Clear, informed consent - individuals must be given a clear notice about what data is being collected and why, in language they can understand, before their data is processed - and consent must generally be freely given, specific, and capable of being withdrawn.
- Purpose limitation - personal data should generally only be used for the purpose it was collected for, not repurposed without appropriate basis.
- Data accuracy and correction - individuals have rights to access and correct their personal data.
- Reasonable security safeguards - businesses are expected to implement reasonable technical and organizational measures to protect personal data against breaches.
- Breach notification - personal data breaches need to be reported, both to the relevant authority and, in many cases, to the affected individuals.
- Data retention limits - personal data shouldn't be retained indefinitely once it's no longer needed for the purpose it was collected for.
Significant Data Fiduciaries: Extra Obligations at Scale
The Act creates a category of Significant Data Fiduciary for organizations that meet certain thresholds (based on factors like the volume and sensitivity of personal data processed, and other criteria set out in the framework). Organizations in this category face additional obligations, which can include appointing a Data Protection Officer based in India, conducting periodic data protection impact assessments, and independent audits of their data protection practices. Most early-stage and growing businesses won’t meet these thresholds initially, but it’s worth understanding that obligations scale with the volume and sensitivity of data you handle - not a fixed requirement regardless of size.
The Data Protection Board of India
The Act establishes a Data Protection Board of India as the body responsible for enforcement - handling complaints, investigating breaches, and imposing penalties for non-compliance. Financial penalties for serious violations under the Act can be substantial, though the exact amounts and how they’re applied depend on the specific violation and the rules in force at the time - this is exactly the kind of detail that changes as rules are finalized and updated, which is why this guide intentionally doesn’t state a specific figure as a confirmed fact.
How This Relates to CERT-In Guidelines
Separately from the DPDP Act, the Indian Computer Emergency Response Team (CERT-In) issues cybersecurity directions and guidelines that apply to a range of organizations - covering areas like incident reporting timelines, log retention, and specific technical security practices. CERT-In’s mandate is focused on cybersecurity incident response and infrastructure, while the DPDP Act is focused on personal data protection rights - the two frameworks overlap in practice (a data breach is both a security incident and, often, a personal data breach) but come from different regulatory bases. A business handling personal data in India should be aware of both, not just one.
Practical Steps to Start Preparing
A reasonable, incremental starting point rather than an attempt to “become compliant” in one step:
- Map what personal data you actually collect - Across your website, app, CRM, marketing tools and any other system. You can't protect or manage what you haven't identified.
- Review your consent mechanisms - Are you clearly telling users what you collect and why, in plain language, before you collect it?
- Review your data retention practices - Are you keeping personal data indefinitely, or do you have a reasonable basis and timeline for how long you keep it?
- Review vendor and processor relationships - Any third party that processes personal data on your behalf (email tools, analytics, hosting) is part of your data protection posture, not separate from it.
- Put a breach response plan in place - Know, in advance, what you'd do and who you'd notify if a breach happened, rather than figuring it out during an actual incident.
- Review technical security measures - See Vulnerability Assessment & Penetration Testing and Secure SDLC Implementation for how to assess and build in the security safeguards the Act expects.
- Get qualified legal advice specific to your business - This guide explains the framework in general terms; your specific obligations depend on facts about your business, your data, and your sector that only a lawyer reviewing your situation can properly assess.
A Practical Data Protection Checklist
- Inventory of what personal data is collected, where, and why
- Clear, plain-language consent notices in place before data collection
- Data retention policy defined, not indefinite by default
- Vendor/processor relationships reviewed for how they handle data on your behalf
- Breach response plan documented before an incident happens, not during one
- Technical security safeguards assessed
- Legal review completed by a qualified professional familiar with current DPDP Act rules
Common Mistakes Businesses Make
- Assuming this only applies to large companies - the Act’s core consent and security obligations apply broadly, not just above a size threshold (the extra Significant Data Fiduciary obligations are what scale with size).
- Treating a privacy policy as sufficient on its own - a written policy that isn’t reflected in actual data handling practices doesn’t meet the Act’s expectations.
- Not knowing what data vendors and third-party tools actually collect on your behalf, and assuming it’s someone else’s responsibility.
- Waiting for “final” rules before doing anything - many of the practical steps above (data mapping, honest consent notices, reasonable security) are good practice regardless of exactly how implementation rules are finalized, and are far cheaper to do proactively than to retrofit after an incident.
Conclusion
The DPDP Act reflects a real shift in how personal data needs to be handled by businesses in India - not a one-time compliance project, but an ongoing practice of collecting only what you need, being honest with users about it, and protecting it properly. Growing businesses that treat this as part of how they build products and handle data from the start will have a much easier time than those that treat it as a last-minute checklist.
If you want a review of your current security safeguards alongside your data protection preparation, Cyber Security Consulting at Sarveonix can help assess where your real gaps are - though for the specific legal obligations that apply to your business, you should also consult a qualified lawyer. See Vulnerability Assessment & Penetration Testing for how to test your technical safeguards, and Secure SDLC Implementation for building security in from the start.
