Compliance14 min read

India's DPDP Act 2026 — What Businesses Must Do to Protect Personal Data

India's DPDP Act 2026 — What Businesses Must Do to Protect Personal Data

India's Digital Personal Data Protection Act (DPDP Act) is no longer pending — it is the law. For the millions of Indian businesses that collect, store or process personal data of customers, employees, students or patients, compliance is not optional. This guide explains what the law requires, what technical measures you need to implement, and how organisations in India are getting DPDP-ready in 2026.


What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) was passed by India's Parliament in August 2023. It is India's first comprehensive personal data protection law and governs how organisations process the personal data of Indian citizens.

Key definitions:

  • Personal data: Any data that identifies or can identify a natural person — name, email, phone number, PAN, Aadhaar, location data, biometrics, financial data
  • Data fiduciary: An organisation that determines the purpose and means of processing personal data (i.e., businesses that collect customer or employee data)
  • Data principal: The individual whose personal data is being processed
  • Data processor: An entity that processes personal data on behalf of a data fiduciary (e.g., a cloud provider, payroll service)

Who Does the DPDP Act Apply To?

The Act applies to any organisation that:

  1. Processes personal data of Indian citizens within India, OR
  2. Processes personal data of Indian citizens outside India if it involves offering goods or services to Indian data principals

In practical terms: if you are an Indian company that stores customer records, employee data, student data, patient records, or any personal information of Indian individuals — the Act applies to you.

Notably, the Act does not have a size threshold. A startup with 50 employees and 1,000 customers is as subject to the Act as a large bank with millions of customers.


Key Obligations for Data Fiduciaries

1. Purpose Limitation

You can only collect personal data for a specific, lawful purpose and must inform data principals of this purpose before collection. The purpose must be clearly stated in your privacy notice.

2. Consent Requirement

Before collecting personal data, you must obtain free, specific, informed, and unambiguous consent from the data principal. The consent must be:

  • Granular (separate consent for separate purposes)
  • Revocable at any time
  • Verifiable

Important: Pre-ticked checkboxes and bundled consent do not satisfy this requirement.

3. Data Minimisation

Collect only the personal data that is necessary for the stated purpose. Collecting additional personal data "just in case" violates this principle.

4. Accuracy and Storage Limitation

Personal data must be accurate and up-to-date. You must delete personal data when the purpose for which it was collected has been fulfilled and there is no legal basis for continued retention.

5. Security Safeguards

This is where DLP and technical security measures directly apply. The Act requires data fiduciaries to implement appropriate technical and organisational measures to prevent personal data breaches. These measures must be:

  • Reasonable given the nature of the data and the risk of harm
  • Adequate to prevent unauthorised access, use, modification, disclosure, or destruction

Specific technical safeguards expected (based on best practice interpretation):

  • Encryption of personal data at rest and in transit
  • Access controls limiting who can access personal data
  • Data Loss Prevention tools preventing unauthorised exfiltration
  • Audit logging of all access to personal data

6. Breach Notification

In the event of a personal data breach, you must notify the Data Protection Board of India and affected data principals "in the prescribed manner." Current drafts suggest a 72-hour notification window for serious breaches.

7. Consent Manager Integration

For significant data fiduciaries, you may need to register consent transactions with an accredited Consent Manager — a third-party entity that manages consents on behalf of data principals.


Penalties Under the DPDP Act

The Act prescribes substantial financial penalties for violations. These are not theoretical — the Data Protection Board has powers equivalent to civil courts:

ViolationMaximum Penalty
Failure to implement security safeguards leading to a breach₹250 crore
Failure to notify a data breach₹200 crore
Non-fulfilment of obligations regarding children's data₹200 crore
Failure to comply with Data Protection Board orders₹150 crore
Breach of any other provision₹50 crore

The ₹250 crore penalty for failure to implement security safeguards is the one most relevant to businesses evaluating DLP solutions. It applies when a breach occurs and adequate safeguards were not in place.


What "Appropriate Technical Safeguards" Means in Practice

The Act does not define a specific technology list — it requires "appropriate" measures based on the nature and volume of personal data processed. Regulators typically look at:

Access Controls

  • Role-based access to personal data systems
  • Multi-factor authentication for systems holding personal data
  • Privileged access management for database and server administrators

Encryption

  • Personal data encrypted at rest (database-level or field-level encryption)
  • TLS 1.2+ for all data in transit
  • End-to-end encryption for communications containing personal data

Data Loss Prevention

  • Technical controls preventing personal data from leaving the organisation without authorisation
  • Monitoring and alerting on anomalous access to personal data repositories
  • USB/device control to prevent physical data exfiltration

Audit Logging

  • Complete audit trail of who accessed personal data, when, and from where
  • Immutable logs retained for a minimum period (1–3 years recommended)
  • Automated alerting on suspicious access patterns

Incident Response

  • Documented breach detection and response procedure
  • Ability to determine within 72 hours whether a breach involving personal data has occurred and its scope
  • Breach notification templates and Data Protection Board contact process

DPDP Act Compliance Checklist for Indian Businesses

Governance and Policy

  • Appoint a Data Protection Officer (for significant data fiduciaries)
  • Create and publish a DPDP-compliant Privacy Notice
  • Document all personal data processing activities (Record of Processing Activities / ROPA)
  • Review and update all data collection forms for DPDP-compliant consent language
  • Create a Data Retention Policy and deletion schedule

Technical Controls

  • Implement access controls with least-privilege principles
  • Enable encryption for all databases and file stores containing personal data
  • Deploy DLP solution to monitor and prevent unauthorised data exfiltration
  • Enable comprehensive audit logging for all personal data systems
  • Implement email security that can scan and prevent personal data in outbound email
  • Configure USB/device control policies

Vendor and Processor Management

  • Review all third-party data processors (CRM, payroll, cloud storage)
  • Ensure Data Processing Agreements (DPAs) exist with all processors
  • Verify processor security standards and certifications

Incident Response

  • Document breach detection and response procedure
  • Test breach simulation at least annually
  • Set up Data Protection Board notification process
  • Create breach notification templates for data principals

How DLP Solutions Help with DPDP Compliance

Data Loss Prevention software directly addresses the "appropriate technical safeguards" requirement and the breach notification readiness requirement:

How DLP helps:

  1. Classification: DLP identifies and tags personal data across your endpoints, email, and cloud storage — creating the data inventory required for ROPA documentation

  2. Prevention: DLP blocks or restricts personal data from leaving through unauthorised channels (email to personal accounts, USB drives, public cloud uploads) — demonstrating the "reasonable safeguards" standard

  3. Audit trail: Every DLP policy match and enforcement event is logged with user, timestamp, content type, and action taken — this is the audit evidence regulators want to see

  4. Breach detection: DLP anomaly alerts can trigger breach response procedures — reducing the time between a breach event and the 72-hour notification window

Specific DPDP report outputs from Safetica ONE:

  • Personal data access log by user and date
  • Policy violation incidents with severity classification
  • USB transfer audit with file names
  • Email exfiltration attempts by recipient domain
  • Anomalous user activity report (UBA)

Industry-Specific DPDP Obligations

Financial Services (BFSI)

Banks, NBFCs, insurance companies, and stockbrokers process very large volumes of personal financial data. The DPDP Act adds to existing RBI and IRDAI data protection requirements. Key additional obligation: stronger consent mechanisms for automated credit decisioning and profiling.

Healthcare

Hospitals, diagnostic labs, and telehealth platforms process sensitive health data, which is classified as "sensitive personal data" under the Act. Higher security standard required. Consider encryption of all patient records at rest and DLP to prevent health data leaving the organisation.

Education

Schools, universities, and EdTech companies process student and parent personal data. For schools using platforms like Google Workspace for Education, ensure DLP policies cover student data specifically.

IT / ITES and BPO

Companies processing personal data on behalf of foreign clients (as data processors) are subject to the Act for the Indian data principals within the data they process. Review all client contracts for conflicting data protection obligations.


Getting DPDP-Ready: A Practical Timeline

Month 1: Discovery and Gap Assessment

  • Map all personal data: where it is, who has access, how it flows
  • Identify gaps against the DPDP compliance checklist above
  • Prioritise remediation by risk level

Month 2–3: Technical Implementation

  • Deploy DLP solution (Safetica, Purview, or ManageEngine DLP Plus)
  • Implement access controls and encryption for highest-risk data
  • Enable audit logging across all personal data systems

Month 3–4: Policy and Governance

  • Update Privacy Notice, consent forms, and data collection practices
  • Draft ROPA, Data Retention Policy, and Incident Response Procedure
  • Negotiate DPAs with key data processors

Month 4–6: Testing and Operationalisation

  • Run breach simulation exercise
  • Test DLP policy effectiveness with simulated exfiltration scenarios
  • Train staff on DPDP obligations and data handling procedures

Frequently Asked Questions

Is there a deadline for DPDP Act compliance?

The Act is in force, but the Data Protection Board has not yet specified a grace period deadline for existing organisations. However, organisations are already liable for breaches that occur without adequate safeguards. Do not wait for a formal deadline — start your gap assessment now.

Does the DPDP Act apply to employee data?

Yes. Employee data — including payroll information, Aadhaar collected for tax purposes, health records, and personal contact information — is personal data under the Act. Your HR and payroll systems need to meet the same safeguard standards as customer data systems.

What is a "significant data fiduciary"?

The government will notify certain data fiduciaries as "significant" based on factors like the volume and sensitivity of data processed. Significant data fiduciaries face additional obligations: appointment of DPO, data audit requirement, and Data Protection Impact Assessments (DPIAs). Most SMEs will not be classified as significant, but larger B2C companies, health platforms, and fintech firms likely will be.

Does using Google Cloud or Microsoft Azure help with DPDP compliance?

Major cloud providers are typically DPDP compliant as data processors — they maintain the infrastructure security on their side. However, compliance for your organisation as a data fiduciary depends on what you do with the data on that infrastructure, not just where it's hosted.


Next Steps

Cloudfy Systems helps Indian organisations achieve DPDP Act compliance through DLP deployment, technical safeguard implementation, and ongoing compliance monitoring.

Free Consultation

Talk to a Cloud Expert

Tell us about your team and stack — we'll recommend the right cloud and SaaS setup with transparent pricing in INR.

Google Cloud PartnerMicrosoft PartnerZoho Authorised
Already decided? Submit your details to start provisioning

Request a Callback

Fill the form — we'll get back within one business day.

We respond within one business day · No spam, ever.