A A P T & ASSOCIATES

AAPT & ASSOCIATES
AAPT Corp Advisors LLP unlock money
  • Home
  • Industry

    • Consumer
    • Automotive
    • Consumer Products
    • Retail, Wholesale & Distribution
    • Transportation, Hospitality & Services

    • Energy, Resources & Industrials
    • Industrial Products & Construction
    • Power, Utilities & Renewables
    • Energy & Chemicals
    • Mining & Metals

    • Financial Services
    • Banking & Capital Markets
    • Investment Management
    • Real Estate
    • Insurance

    • Government & Public Services
    • Defense, Security & Justice
    • Federal health
    • Civil
    • State & Local
    • Higher Education

    • Life Sciences & Health Care
    • Health Care
    • Life Sciences

    • Technology, Media & Telecommunications
    • Technology
    • Telecommunications
    • Media & Entertainment
  • Services

    • Business Advisory
    • Market Assessment
    • India Entry Strategies
    • Corporate Legal & Secretarial Advisory
    • Manufacturing set-up in India
    • Executive Search
    • Employer of Record (EOR) Services
    • Company Registration in India
    • PE Risk Advisory
    • Employee Stock Benefit Advisory
    • Family Office Services
    • Transition Support Services
    • Outbound Expansion Support
    • HR Consulting & Staff Outsourcing Services
    • Wealth Management Advisory

    • Corporate Support Services
    • Accounting & Book Keeping Services
    • Payroll
    • Company Secretarial Services
    • Dematerialization of Securities
    • SOFTEX Compliance Services
    • Labour Law Compliance and POSH Act
    • Virtual CFO Services
    • Ind AS/IFRS/IGAAP Financial Statements
    • Appointment of Independent Directors
    • Registrar and Transfer Agent Services

    • Transaction Advisory Services
    • Business Valuation
    • Due Diligence
    • Mergers & Acquisitions
    • Joint Venture
    • Vendor due Diligence Services
    • Internal Audit
    • Internal Financial Control
    • Statutory Audit Services
    • Forensic Accounting Services
    • audit outsourcing firm India
    • Audit Staffing Services

    • Taxation
    • Direct Tax
    • Indirect Tax
    • Expatriate Services
    • OIDAR Services
    • Goods and Services Tax
    • International Tax Planning
    • Transfer pricing services
    • Income Tax & GST Litigation Services

    US Tax & Accounting Services

    • payroll outsourcing services USA
    • accounting and bookkeeping services USA
    • Outsourced Sales Tax Compliance
    • Sales Tax Nexus Consultant
    • Federal Tax ID Registration & EIN Services USA
    • Form 1041 tax preparation
    • Form 1120-S S-Corp Tax Preparation
    • Form 1120 tax preparation
    • Form 1065 Partnership Tax Preparation
    • Outsourced Bookkeeping & Accounting Services
    • Individual Tax Returns
    • DPDP Act 2023 Compliance Services
  • About Us
    • Our Team
  • Blogs
  • Request Consultation
  • Home
  • Blog
  • Blog
  • DPDP Act 2023 Explained: What Every Indian Business Must Do to Stay Compliant
Laptop with a data protection shield icon and a compliance checklist, illustrating DPDP Act 2023 compliance
15
Sep
Blog

DPDP Act 2023 Explained: What Every Indian Business Must Do to Stay Compliant

If your business collects names, phone numbers, email IDs, employee records or customer purchase histories, the Digital Personal Data Protection Act, 2023 applies to you. The DPDP Act is India’s first comprehensive law on digital personal data. With the DPDP Rules, 2025 now notified, DPDP Act 2023 compliance has moved from a future concern to an active project with fixed deadlines.

This guide explains what the law requires, who it covers, what non-compliance can cost, and the practical steps businesses should take now.

Quick Answer

The DPDP Act 2023 governs how organisations collect, use, store and delete digital personal data of individuals in India. To comply, a business must process personal data only with valid consent or for a recognised legitimate use. It must give clear privacy notices, protect data with reasonable security safeguards, report data breaches, honour individuals’ rights, and erase data once its purpose is served. Most substantive obligations become enforceable in May 2027 under the phased DPDP Rules, 2025. Penalties go up to ₹250 crore per instance.

What Is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. The Ministry of Electronics and Information Technology (MeitY) notified the DPDP Rules, 2025 in November 2025, which operationalise the Act in phases. Once fully in force, the Act replaces the earlier data protection framework under Section 43A of the Information Technology Act, 2000.

The law uses its own vocabulary. It helps to understand these terms before looking at obligations:

Term Meaning
Data Principal The individual whose personal data is processed (a customer, employee or website visitor)
Data Fiduciary The business that decides why and how personal data is processed
Data Processor A vendor that processes data on the fiduciary’s behalf (payroll provider, CRM, cloud host)
Significant Data Fiduciary (SDF) A fiduciary notified by the government based on data volume, sensitivity and risk, with extra obligations
Consent Manager A registered entity that helps individuals give, manage and withdraw consent
Data Protection Board of India The body that inquires into breaches and imposes penalties

Does the DPDP Act Apply to Your Business?

The Act applies to the processing of digital personal data within India. This includes data collected online, and data collected offline that is later digitised. It also applies to businesses outside India if they process personal data in connection with offering goods or services to people in India.

There is no general turnover threshold. A 20-person manufacturing company in Noida that keeps employee records in a spreadsheet and customer leads in a CRM is a Data Fiduciary. So is a D2C brand, a hospital, a coaching institute and a fintech startup. The government can exempt certain classes of fiduciaries, including startups, from specific provisions. Businesses should check official notifications rather than assume they are exempt.

The main exclusions are data processed by an individual for personal or domestic purposes, and data that the individual has made publicly available themselves.

DPDP Act Compliance: The Core Obligations

1. Process data only on a lawful basis

Personal data can be processed with the individual’s consent, or for specific “legitimate uses” defined in the Act, such as certain employment purposes or complying with a legal obligation. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. Withdrawing consent must be as easy as giving it. Pre-ticked boxes and bundled “accept all” consents will not hold up.

2. Give a clear privacy notice

Before or at the time of seeking consent, you must tell individuals what data you collect and why. The notice must also explain how they can exercise their rights and how they can complain to the Data Protection Board. It must be available in English or any of the 22 languages in the Eighth Schedule of the Constitution.

3. Collect only what you need

Collect only the data needed for the stated purpose, and use it only for that purpose. A lead form that asks for date of birth and home address to send a brochure is a common example of over-collection.

4. Implement reasonable security safeguards

Businesses must protect personal data against breaches. This applies whether the data sits with them or with their processors. The Rules point to measures such as encryption or masking, access controls, monitoring, backups and maintaining logs. Failing to take reasonable safeguards carries the highest penalty under the Act.

5. Report personal data breaches

If a breach occurs, you must inform affected individuals and the Data Protection Board. The Rules require a detailed report to the Board within 72 hours of becoming aware of the breach. That timeline is only achievable if a breach response plan exists before an incident happens.

6. Honour Data Principal rights

Individuals can request information about how their data is processed. They can also seek correction, completion, updating or erasure, access grievance redressal, and nominate someone to exercise their rights. Businesses need a working process to receive, verify and respond to these requests. They must also publish contact details of a person who can answer data-related questions.

7. Erase data when the purpose is served

Personal data must be deleted once consent is withdrawn or the purpose is no longer served, unless another law requires you to retain it. Processors must delete it too, which means vendor contracts need clear deletion clauses.

8. Take extra care with children’s data

For anyone under 18, businesses need verifiable parental consent. They must not carry out tracking, behavioural monitoring or targeted advertising directed at children.

Significant Data Fiduciaries carry additional duties. They must appoint a Data Protection Officer based in India and an independent data auditor, and conduct periodic Data Protection Impact Assessments.

What Are the Penalties Under the DPDP Act?

Penalties are imposed by the Data Protection Board after an inquiry. They can apply per instance of breach:

Breach Maximum penalty
Failure to take reasonable security safeguards ₹250 crore
Failure to notify a personal data breach ₹200 crore
Breach of obligations related to children’s data ₹200 crore
Breach of additional obligations of an SDF ₹150 crore
Breach of any other provision ₹50 crore

DPDP Compliance Timeline

The DPDP Rules, 2025 roll out in three phases. Provisions establishing the Data Protection Board took effect on notification in November 2025. Consent Manager registration follows at 12 months, around November 2026. The substantive obligations, including notice and consent, security safeguards, breach reporting, children’s data and Data Principal rights, apply at 18 months, around May 2027.

Eighteen months sounds generous. In practice, data mapping, rebuilding consent flows and renegotiating vendor contracts can take most of that window, especially for businesses with several systems and legacy databases.

A Practical DPDP Compliance Checklist

  1. Map your data. List every point where personal data enters the business: website forms, WhatsApp, CRM, HR, payroll, billing, CCTV.
  2. Run a gap assessment against the Act and Rules.
  3. Rewrite privacy notices and redesign consent capture and withdrawal.
  4. Review processor contracts for security, breach-reporting and deletion clauses.
  5. Strengthen security controls and set up log retention.
  6. Prepare a breach response plan that can meet the 72-hour reporting requirement.
  7. Build a process for rights requests and grievances.
  8. Define retention periods for each category of data.
  9. Train employees who handle personal data.
  10. Document everything so you can demonstrate compliance to the Board.

Where Businesses Commonly Get Stuck

The hardest part is rarely the website privacy policy. The difficult areas are usually the less visible ones. Employee data is often scattered across HR, payroll and email. Old customer databases were collected without clear consent. Leads arrive through WhatsApp and personal phones. Marketing lists come from third parties. These gaps need to be found through a structured assessment rather than a template policy.

Getting DPDP Compliance Right

DPDP Act 2023 compliance is not a one-time document exercise. It affects how your business collects data, which vendors you use, how your teams work and how quickly you can respond to incidents. Businesses that start now have time to fix gaps properly instead of rushing before May 2027.

AAPT & Associates helps organisations assess their current data practices, close compliance gaps and build processes that stand up to scrutiny.

Explore DPDP Act Compliance Services

Frequently Asked Questions

Does the DPDP Act apply to small businesses?

Yes. There is no general size or turnover exemption. Any business processing digital personal data of individuals in India is covered, although the government may exempt certain classes, including startups, from specific provisions.

What is the deadline for DPDP compliance?

Most substantive obligations apply 18 months after the DPDP Rules, 2025 were notified, which is around May 2027.

Is consent always required under the DPDP Act?

No. Personal data can also be processed for legitimate uses defined in the Act, such as certain employment purposes or compliance with a legal obligation.

Who enforces the DPDP Act?

The Data Protection Board of India inquires into breaches and can impose penalties of up to ₹250 crore per instance.

  • DPDP Act
  • DPDP Act 2023 compliance
Share
Previous Post Next Post

Search

Categories

  • No categories

Recent Posts

Scale of justice balancing data security documents and coins, representing DPDP Act penalties for companies
DPDP Act Penalties: How Much Non-Compliance Can Cost Your Company
Sep 21, 2026
US small business owner in their shop with a tablet showing reconciled books from outsourced bookkeeping
Outsourced Bookkeeping for US Small Businesses: Cost, Process & What to Expect
Sep 19, 2026
Split image of a virtual CFO on a video call and a full-time CFO presenting financial charts in a boardroom
Virtual CFO vs Full-Time CFO: Which Is Right for Your Growing Business?
Sep 17, 2026

Tags

  • #AccountingServices
  • #bestcafirm
  • #bestcafirminnoida
  • #Bookkeeping
  • #BusinessCompliance
  • #BusinessFinance
  • #BusinessGrowth
  • #BusinessTax
  • #cafirm
  • #cafirminnoida
  • #CapitalGainsTax
  • #CashFlowManagement
  • #CorporateFinance
  • #corporategovernance
  • #CorporateTax
  • #directtax
  • #DueDiligence
  • #FinancialAdvisory
  • #FinancialClarity
  • #FinancialCompliance
  • #FinancialPlanning
  • #FinancialReporting
  • #FinancialStrategy
  • #gstcompliance
  • #GSTIndia
  • #IncomeTax
  • #IndustrialGrowth
  • #InputTaxCredit
  • #InvestmentPlanning
  • #LegalCompliance
  • #mergersandacquisitions
  • #PayrollManagement
  • #poshact
  • #RenewableEnergy
  • #RiskManagement
  • #StartupIndia
  • #StatutoryCompliance
  • #TaxAdvisory
  • #TaxCompliance
  • #TaxPlanning
  • #TaxStrategy
  • #topcafirm
  • #topcafirminnoida
  • #VirtualCFO
  • #WealthManagement

About

  • About Us
  • Our Team
  • Careers
  • Contact Us

Services

  • Business Advisory
  • Taxation
  • Corporate Support Services
  • Transaction Advisory Services

Industries

  • Consumer
  • Energy, Resources & Industrials
  • Financial Services
  • Government & Public Services
  • Life Sciences & Health Care
  • Technology, Media & Telecommunications
Quick Contact
info@aaptcorp.com 0120-4345715, +91-9582537757, +91-9319922127
Location
Office No-613 & 614, 6th Floor, Vishal Chambers, P Block, Pocket I, Sector 18, Noida, Uttar Pradesh 201301
Mon-Sat:
9:30 AM - 6:30 PM
*Excludes Holidays
Get in Touch

    2026 AAPT & ASSOCIATES, All Rights Reserved. Designed by- G Optimizers