Harun Raaj & AssociatesHarun Raaj & Associates
Business Compliance & Labour Law

DPDPA Compliance

DPDPA Compliance

Start — upload documents, pay when ready →Talk to a CAWhatsApp us
SCOPEConfirmed in writing

Overview

DPDPA compliance is the implementation of the Digital Personal Data Protection Act 2023 — India's comprehensive data protection law. The Act applies to the processing of digital personal data in India, whether by Indian entities or by foreign entities processing the data of Indian data principals. Its core obligations: notice and consent before processing (the consent-based framework of the Act), purpose limitation, the data principal's rights — access, correction, erasure — and the duties of the data fiduciary: security safeguards, breach notification, and the appointment of a Data Protection Officer where the fiduciary falls within the notified classes (VERIFY: the relevant sections of the DPDP Act 2023 — Sections 6, 8, 11 and 12 cover notice, duties, security safeguards and breach notification).

For a business, compliance is a system, not a policy. Every place personal data is collected — websites, apps, forms, CRM, HR records, customer support — must carry the notice, obtain the consent, and honour the purpose. Every data flow — to vendors, to the cloud, to group companies — must be mapped and justified. Breaches must be reportable to the Data Protection Board within the prescribed timelines. The Act also has special protections for children's data, requiring verifiable parental consent (VERIFY: the child-data consent provisions).

The cost of non-compliance is designed to be felt: the Act empowers the Data Protection Board to impose monetary penalties up to a substantial maximum for significant breaches (VERIFY: the penalty schedule of the DPDP Act 2023), and a data breach that was handled badly becomes a regulatory event on top of the reputational one. Regulators, customers and investors increasingly ask whether the business is DPDPA-ready.

This service is for businesses processing personal data — technology companies, e-commerce, fintechs, hospitals, HR-heavy employers and any data-driven enterprise. We map your data flows against the Act, draft the privacy notices and consent mechanisms, implement the data principal rights processes, set up breach notification and the DPO role, and audit the implementation so the compliance is real rather than decorative.

How It Works

  1. 1

    Data Flow Mapping

    We map where personal data is collected, processed, shared and stored across the business.

    Harun Raaj & Associates does this1-2 weeks
  2. 2

    Gap Analysis

    We assess the current state against the DPDP Act 2023 obligations — notice, consent, purpose and safeguards.

    Harun Raaj & Associates does this1 week
  3. 3

    Policies & Consent Build

    We draft the privacy notices, consent mechanisms and the data principal rights processes.

    Harun Raaj & Associates does this1-2 weeks
  4. 4

    DPO & Breach Processes

    We set up the Data Protection Officer role, the breach notification process and the security safeguards.

    Harun Raaj & Associates does this1 week
  5. 5

    Implementation & Audit

    We roll out the framework, train the team, and audit the implementation annually.

    Harun Raaj & Associates does thisOngoing

Frequently Asked Questions

Which organisations are required to comply with the Digital Personal Data Protection Act 2023, and when does it apply?
The Digital Personal Data Protection Act 2023 (DPDPA) applies to every 'Data Fiduciary' — any person who alone or in conjunction with others determines the purpose and means of processing digital personal data — as defined under Section 2(i) of the Act. The Act applies to processing of digital personal data within India where data is collected online or is digitised after collection offline, and also applies to processing outside India if it is in connection with offering goods or services to individuals in India under Section 3(b). The Act does not apply to personal data processed for personal or domestic purposes, or to publicly available personal data as carved out under the proviso to Section 3(a). The Act is notified but specific sections and rules are to be brought into force on dates notified by the Central Government — organisations should track the Ministry of Electronics and Information Technology (MeitY) notifications under Section 1(2) to determine applicable dates for each obligation, as some provisions may be phased.
What are the notice and consent requirements under the DPDPA 2023 before processing personal data?
Under Section 5 of the DPDPA 2023, a Data Fiduciary must give a notice to the Data Principal (the individual) before or at the time of collecting personal data, informing them of the personal data being processed, the purpose of processing, and the manner in which the Data Principal can exercise their rights. Section 6 requires that consent obtained must be free, specific, informed, unconditional, and unambiguous — given through a clear affirmative action — and must be limited to the specific purpose disclosed in the notice. Consent can be withdrawn at any time under Section 6(4) and the Data Fiduciary must provide a facility to withdraw consent as easily as it was given, ceasing processing upon withdrawal without affecting the lawfulness of prior processing. Section 7 provides legitimate uses (deemed consent) where consent is not required — such as processing for performance of a State function, compliance with law, or medical emergencies — but the Data Fiduciary bears the burden of establishing that its processing falls within a legitimate use category rather than relying on overly broad interpretations.
What obligations do Significant Data Fiduciaries have under the DPDPA 2023 that other companies do not?
Section 10 of the DPDPA 2023 empowers the Central Government to designate certain Data Fiduciaries as 'Significant Data Fiduciaries' (SDFs) based on factors including volume and sensitivity of data processed, risk to rights of Data Principals, national security implications, and potential impact on sovereignty. SDFs are subject to enhanced obligations under Section 10(2) including: appointment of a Data Protection Officer based in India who reports to the board, appointment of an independent data auditor to conduct periodic audits, and conducting Data Protection Impact Assessments (DPIAs) before undertaking new or high-risk processing activities. SDFs must also comply with any additional standards or restrictions notified by the Data Protection Board established under Section 18. Non-SDF companies must still comply with Sections 4–9 (notice, consent, data minimisation, accuracy, storage limitation, security) but are not subject to the enhanced SDF-specific obligations unless designated.
What data security obligations does the DPDPA 2023 impose, and what are the penalties for a data breach?
Section 8(5) of the DPDPA 2023 requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches, and the rules to be notified under the Act are expected to prescribe specific technical and organisational measures analogous to global standards. In the event of a personal data breach, Section 8(6) requires the Data Fiduciary to notify both the Data Protection Board and each affected Data Principal in the manner and within the timeframe prescribed by the forthcoming rules. The Schedule to the DPDPA 2023 sets out the penalty framework: failure to implement adequate security safeguards carries a penalty of up to ₹250 crore per breach, and failure to notify the Board of a breach carries a penalty of up to ₹200 crore. The Data Protection Board constituted under Section 18 has adjudicatory powers and may impose penalties after conducting an inquiry, and decisions of the Board are appealable to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29.
What rights do individuals (Data Principals) have under the DPDPA 2023, and how must companies handle these requests?
Sections 11 through 14 of the DPDPA 2023 confer four core rights on Data Principals: the right to access a summary of personal data being processed and the identities of all Data Fiduciaries with whom data has been shared (Section 11); the right to correction, completion, updating, and erasure of personal data that is no longer necessary for the specified purpose (Section 12); the right to grievance redressal with the Data Fiduciary before approaching the Board (Section 13); and the right to nominate another individual to exercise these rights in the event of death or incapacity (Section 14). Data Fiduciaries must provide a facility for Data Principals to exercise these rights under Section 8(7), and must respond within such period as prescribed by rules. Ignoring or denying rights requests without valid grounds exposes the Data Fiduciary to a penalty of up to ₹50 crore under the Schedule to the DPDPA 2023. Companies should establish a documented rights request management process, including identity verification of requestors and audit trails of responses, before the rules are notified to avoid remedial scrambling.

Ready to get DPDPA Compliance?

File a request in under 2 minutes. Our team contacts you within 24 hours.

Start — upload documents, pay when ready →