The obligations are phased in.
The work is in your systems.
Data protection counsel under the DPDP Act, 2023 and the Rules made under it: mapping, lawful basis, consent design, rights machinery, contracts and breach response.
Data Protection
The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India, and to processing outside India in connection with offering goods or services to data principals in India, subject to the exclusions in Section 3.
We map what an organisation holds, assign a lawful basis to each processing activity, redraft consent notices to the standard the Act sets, and paper the vendor arrangements that carry data outside your systems.
Marketing and analytics tooling is a common source of undocumented processing. Tags and scripts added by teams that never spoke to legal push personal data to third parties nobody holds a contract with.
The Digital Personal Data Protection Act, 2023 turned data compliance in India from a documentation exercise into an operating obligation. The Rules made under the Act have been notified, and their provisions commence in stages rather than together.
Everything starts with an inventory, and the inventory is usually worse than expected. We work through the systems that hold personal data, the elements in each, why they were collected, who inside the organisation can see them, which vendors receive them, and how long they are kept. Very little of this is written down in one place, and a good deal of it lives in the heads of people who built the systems years ago and have since moved on. The exercise produces a defensible statement of what processing actually exists, which is the only foundation that lawful basis, notice and the rights process can be built on. It is also the part most often skipped, because it is slow, unglamorous and produces no document anyone outside the project will ever read. Skipping it means writing a privacy notice about an organisation you are guessing at, and building a consent flow on top of the guess.
Retention is where the surprises are. Data is rarely deleted, because nobody in the organisation owns deletion.
The Act permits processing on consent or on certain legitimate uses, and the mapping exercise has to assign one of those to every activity. Consent under the Act is a demanding standard. Section 6(1) requires it to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. Bundling, pre-ticked boxes and consent buried in terms of service do not meet it. Withdrawal has to be as easy as giving, and the consequences of withdrawal flow through to processors. Notices have to be itemised and in plain language, and made available in English or in any language specified in the Eighth Schedule to the Constitution, at the data principal’s option. Consent design is then a product problem as much as a legal one, because a notice that satisfies the Act but lands at the wrong point in a signup flow will either be ignored or cost the organisation the user. We work with product teams on where consent is captured, how it is recorded so that it can be evidenced a year later, how granular the purposes ought to be, and what has to happen when purposes change.
The Act also provides for consent managers registered with the Data Protection Board. Whether that route is relevant depends on the model.
Data principals have rights to access information about their data, to correction and erasure, to grievance redressal, and to nominate someone to exercise rights in specified circumstances. A right is only real if there is a process behind it: a published channel somebody monitors, a verification step that confirms identity without collecting more data than it needs to, a way of finding a person’s data across systems, and a log of what was done and when. The Rules set the periods within which requests are to be answered, and the grievance timeline is separate from the timeline for a rights request. Organisations that run this as an inbox rather than a workflow tend to miss them.
A vendor may process only under a valid contract, and the fiduciary stays answerable for what the vendor does. The data processing agreement is therefore an operating document rather than boilerplate: scope and purpose limits, a prohibition on processing for the vendor’s own ends, security safeguards described in terms somebody could audit, sub-processor controls, help with data principal requests, deletion or return at the end, and breach notification on a timeline that lets the fiduciary meet its own. Contracts predating the Act commonly lack these provisions.
Every fiduciary must publish the contact details of a person able to answer questions about its processing. Entities notified as significant data fiduciaries carry more under Section 10: a data protection officer based in India who is answerable to the board or governing body, periodic impact assessment and audit, and due diligence in respect of algorithmic software.
A breach is a run of decisions taken under time pressure, and most of them should have been made months earlier. The Act requires intimation of a personal data breach to the Data Protection Board and to affected data principals, and the Rules made under it set what that intimation has to contain and when it has to be given. Running alongside it, the CERT-In directions require the cyber security incidents they specify to be reported to CERT-In by the entities they cover. We help set the triggers, name the people who can declare an incident, and prepare the notification drafts in advance.
Preservation of logs and system images before remediation is relevant to later evidence. Material goes missing in the rush to fix things, and it cannot be recovered afterwards.
Asked most often
Programmes are commonly sequenced with the inventory before the policy. Until the systems holding personal data are known, along with the elements they hold, why, who receives them and how long they are kept, a privacy notice is guesswork and a consent flow is guesswork applied to a product. Once the map exists the usual sequence is to assign a lawful basis to each activity, rebuild notice and consent, stand up the rights process, then repaper vendor contracts. Programmes run in the reverse order tend to produce documents describing an organisation nobody actually works in.
Transfer outside India is permitted, subject to Section 16 of the Act, which allows the Central Government to restrict transfer to notified territories, and subject to any conditions the Central Government specifies. Sectoral requirements can be stricter, including the Reserve Bank of India directions on storage of payment system data, and localisation obligations can apply to entities notified as significant data fiduciaries. Contracts with enterprise customers frequently carry localisation commitments of their own. Intra-group transfers to a parent or a shared services centre are still transfers and need a contractual footing, and the analysis is better documented for each flow than taken from the general position.
Not every organisation does. Every data fiduciary must publish the contact details of a person able to answer questions about its processing. Section 10 requires a data protection officer based in India, answerable to the board or governing body, of entities notified as significant data fiduciaries, which also carry impact assessment, audit and algorithmic due diligence obligations at the frequency the Rules prescribe. Where the classification is uncertain, a documented view of where the organisation is likely to sit allows the programme to be designed so that the additional obligations can be added without rebuilding it.
Preservation and authority, mostly. Preservation of logs and system images before remediation is relevant to later evidence, because material goes missing in the rush to fix things. The other early question is who can declare an incident, since the reporting obligations are triggered by awareness of one, and the CERT-In directions and the DPDP intimation obligation each apply on their own terms. External communications are usually held until the facts are stable enough to state.
The work this covers
- Data inventory & processing mapping
- Lawful basis assessment
- Privacy notices & consent flow design
- Data principal rights process build
- Data processing agreements & vendor repapering
- Cross-border transfer analysis
- Breach response & CERT-In reporting
- Employee data & HR privacy
The rules in play
- Digital Personal Data Protection Act, 2023
- Consent and legitimate uses, fiduciary obligations, data principal rights, the Board and penalties.
- DPDP Rules, 2025
- Notified 14 November 2025; notice, consent managers, security, breach intimation and procedure, with provisions commencing in stages.
- Information Technology Act, 2000
- Computer-related offences and the intermediary framework that sits alongside the DPDP regime.
- CERT-In Directions, 2022
- Reporting of the cyber security incidents specified in the directions, by the entities they cover, and requirements on retention of logs.
- Sector regulator directions
- Additional storage, localisation and incident reporting obligations in regulated sectors.
Facing something in
ip, tech & data?
Every enquiry is confidential. Tell us what you’re facing and our team will come back to you.
Get in Touch