The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. Three years in the making, after multiple failed attempts, India finally has a comprehensive data protection law. The implementing rules - which will specify the precise compliance requirements - are being finalised. Many organisations are waiting for those rules before acting. That is a mistake.
What the DPDP Act Establishes
The DPDP Act creates a framework for the processing of digital personal data - personal data that is collected in digital form, or collected in non-digital form and then digitised. The Act applies to Data Fiduciaries: entities that determine the purpose and means of processing personal data. This encompasses virtually every organisation that processes customer, employee, or vendor data in digital form - which in practice means almost every organised business in India.
The Act introduces several fundamental concepts that are new to India's data governance landscape, even if familiar to practitioners of GDPR or other international frameworks.
Lawful bases for processing. Personal data may only be processed for a lawful purpose - one for which the Data Principal (the individual) has given consent, or one that is permitted by the Act without consent (such as voluntary provision of data for a specific purpose, state functions, emergencies, and employment). This requirement fundamentally changes the basis on which many organisations collect and process data.
Notice and consent. Where consent is the lawful basis, the Data Fiduciary must provide clear notice - in clear and plain language - of the personal data being collected, the purpose of processing, and the manner in which the Data Principal can exercise their rights. Consent must be free, specific, informed, and unambiguous. Bundled consent - a single checkbox agreeing to an extensive privacy policy - is unlikely to be compliant.
Data Principal rights. The Act grants Data Principals specific rights: the right to information about processing, the right to correction and erasure, the right to grievance redressal, and the right to nominate a person to exercise rights on their behalf. These rights must be honoured within timeframes that will be specified in the rules.
Data Fiduciary obligations. Data Fiduciaries are required to implement appropriate technical and organisational measures to ensure compliance, implement a personal data breach notification framework, and - for Significant Data Fiduciaries designated by the Central Government - comply with additional obligations including data localisation, data protection impact assessments, and the appointment of a Data Protection Officer.
Cross-border data transfers. The Act permits transfer of personal data outside India to countries and territories that the Central Government will whitelist. This is materially different from the original draft, which proposed a data localisation default. Organisations with international data flows - including multinationals processing Indian employee and customer data on global systems - need to understand the implications for their current data architecture.
Why Waiting for the Rules Is Risky
The common reason given for inaction is uncertainty: the rules have not been published, so the detailed compliance requirements are not yet known. This logic is understandable but flawed for several reasons.
First, the core obligations in the Act itself are clear enough to begin work. The requirements for lawful processing, consent management, data principal rights, and breach notification are established by the Act, not the rules. The rules will specify timelines, thresholds, and procedures - but the substantive requirements are already law.
Second, compliance readiness takes time. A data inventory is not completed in a week. Consent management infrastructure cannot be built overnight. Privacy notice redesign, contractual updates with vendors and processors, employee training, and breach response procedures all require lead time measured in months. Organisations that begin this work now will be ready to comply from day one. Organisations that wait until the rules are published will face a compliance sprint with compressed timelines.
Third, the rules, when they come, may provide less time than expected for compliance. International precedent - GDPR gave organisations two years between passage and enforcement - does not guarantee that India will follow a similar approach. Assuming adequate transition time is itself a risk that needs to be managed.
A Practical Compliance Programme: Where to Start
For most organisations, DPDP compliance should be approached as a structured programme with four phases.
Phase 1: Understand what you have (Data Discovery and Mapping). Before any compliance work can be designed, an organisation needs to know what personal data it processes, where that data is, how it flows through the organisation and to third parties, and what legal basis (if any) currently supports that processing. This is the personal data inventory and data flow mapping exercise. For large organisations with complex data landscapes, this exercise commonly takes three to four months and consistently reveals data processing practices that are neither well-understood internally nor well-documented.
Phase 2: Assess the gap (Obligations Mapping and Gap Assessment). With the data inventory complete, the organisation can assess what the Act requires against what currently exists: where consent is required but not obtained in a compliant manner, where notices are inadequate, where rights management processes do not exist, where breach detection and notification capabilities are absent. The gap assessment produces the compliance roadmap.
Phase 3: Build what is needed (Compliance Infrastructure). The infrastructure required for DPDP compliance is primarily process and operational - consent management workflows, rights request handling procedures, vendor contractual frameworks, breach response playbooks, privacy notice templates - with some technology components (consent capture, rights request intake, data subject management) where the volume of interactions warrants it. For most organisations, this phase is the most intensive, and is where the sequencing of dependencies matters most.
Phase 4: Sustain (Governance and Operating Model). DPDP compliance is not a project with an end date - it is an ongoing operational requirement. Organisations need to establish who owns data protection, how privacy is embedded in new product and process development (privacy by design), how the personal data inventory is kept current, and how compliance is monitored and reported. The Act's requirement for a grievance officer (for all Data Fiduciaries) and a Data Protection Officer (for Significant Data Fiduciaries) needs to be operationalised.
Sector-Specific Considerations
Several sectors face heightened DPDP compliance complexity that deserves specific attention.
Financial services (banks, NBFCs, insurance companies). Financial services organisations process large volumes of sensitive personal data - financial information, health information in the case of life and health insurers - and already operate under RBI, SEBI, and IRDAI data governance requirements. The DPDP Act adds a layer above these existing frameworks rather than replacing them. Financial services organisations need to map the DPDP requirements against existing regulatory obligations and resolve conflicts or overlaps before the rules are finalised.
Healthcare and pharma. Healthcare providers process highly sensitive personal data (health data is not separately categorised in the DPDP Act as "special category" data in the GDPR sense, but the Act does provide for additional protections for children and Significant Data Fiduciaries). The intersection of health data processing with consent requirements, data sharing between providers, and research use of patient data creates particular complexity.
E-commerce and consumer internet. Digital businesses with large consumer user bases face substantial consent management challenges. Many currently rely on broad, bundled consent for data processing across multiple purposes. Redesigning the consent experience for DPDP compliance, without materially degrading conversion metrics, is a legitimate design challenge that requires investment in both legal and product design capabilities.
Employers (all sectors). The Act covers employee personal data. Most organisations' HR data practices were not designed with DPDP compliance in mind. Employee data inventory, notice and consent for processing beyond the direct employment relationship, and employee rights management all require attention across every employing organisation in India.
The Enforcement Question
The Data Protection Board of India will be responsible for enforcement of the DPDP Act. The Board has not yet been constituted. The rules, which will specify the Board's procedures, have not been published. This creates genuine uncertainty about when enforcement will begin in earnest and how it will be conducted.
However, the penalty provisions in the Act are significant: up to Rs 250 crore for a breach of obligations in relation to children, up to Rs 200 crore for failure to take reasonable security safeguards, and up to Rs 50 crore for other breaches. For larger organisations, the calculation of whether compliance investment is worth making in advance of active enforcement is not complicated.
Organisations that use the rules delay as cover for inaction are not saving compliance costs - they are deferring them, compressing the available time to address them, and potentially incurring enforcement risk in the interim.