Digital Personal Data Protection Act 2023: What Businesses Must Do

A practical guide for Indian businesses on the Digital Personal Data Protection Act, 2023, covering key obligations, consent requirements, and penalties.
Digital Personal Data Protection Act 2023: What Businesses Must Do
Short answer: To comply with the DPDP Act 2023, your business must collect personal data only after giving clear notice and obtaining explicit, specific consent for a lawful purpose. You must protect this data, honour user rights to access and delete it, and appoint a contact person for data-related queries. Non-compliance can lead to penalties of up to ₹250 crores, making immediate action crucial for all businesses handling digital personal data.
What is the Digital Personal Data Protection Act, 2023?
The DPDP Act, 2023 is India's first comprehensive law focused on the protection of digital personal data. It replaces existing data privacy rules under the Information Technology Act, 2000, and establishes a principles-based framework for how businesses (Data Fiduciaries) must handle the personal data of individuals (Data Principals). The Act aims to balance the right of individuals to protect their data with the need for businesses to process data for legitimate purposes.
Who must comply with the DPDP Act?
The Act applies to any entity that processes digital personal data within India. If your business collects, stores, uses, or shares personal information in a digital format—such as customer names, email addresses, phone numbers, or employee records—you are considered a 'Data Fiduciary' and must comply. This includes private limited companies, startups, proprietorships, LLPs, and even freelancers. The Act also has extraterritorial reach, applying to foreign businesses that offer goods or services to individuals in India.
What are the key obligations for my business?
As a Data Fiduciary, your business has several core obligations under Section 8 of the DPDP Act. You must:
- Purpose Limitation: Process personal data only for the specific, lawful purpose for which you obtained consent. You cannot use data collected for order processing to send marketing emails unless you have separate consent for it.
- Data Minimisation: Collect only as much personal data as is necessary for the stated purpose.
- Data Accuracy and Retention: Make reasonable efforts to ensure the data is accurate and complete. You must delete the personal data once the purpose is served and it is no longer required for legal or business reasons.
- Security Safeguards: Implement reasonable security measures to prevent data breaches. The scale of your security should be proportionate to the amount and sensitivity of the data you handle.
- Breach Notification: Report any personal data breach to the Data Protection Board of India and affected individuals.
- Grievance Redressal: Provide an easily accessible way for Data Principals to raise grievances and respond to them in a timely manner.
How do I obtain valid user consent under the Act?
Valid consent is the cornerstone of the DPDP Act (Section 6). Consent must be free, specific, informed, and unambiguous. This means you can no longer rely on pre-ticked boxes or bundle consent for multiple purposes into a single statement.
To obtain valid consent, your request must be accompanied by a clear notice (Section 5) that explains:
- What personal data is being collected.
- The specific purpose for which it will be processed.
- How the individual can exercise their rights (e.g., withdraw consent, access data).
- The contact details for a Data Protection Officer or a designated person who can answer queries.
Consent must be as easy to withdraw as it is to give. If a user withdraws consent, you must cease processing their data for that purpose.
DPDP Act Compliance Checklist
This checklist provides a starting point for businesses to align their practices with the Act's requirements.
| Compliance Area | Action Required | Relevant Section (DPDP Act) |
|---|---|---|
| Notice | Draft and display a clear, simple privacy notice before or at the time of data collection. | Section 5 |
| Consent | Implement consent mechanisms that are explicit and separate for each purpose. Remove pre-ticked boxes. | Section 6 |
| Data Audit | Map all personal data your business holds. Identify its purpose, location, and retention period. | Section 8(3), 8(7) |
| Security | Implement technical and organisational security measures like encryption and access controls. | Section 8(5) |
| User Rights | Establish a clear process for users to request access, correction, or erasure of their data. | Sections 12, 13 |
| Data Breach Plan | Create an internal protocol for identifying, assessing, and reporting data breaches. | Section 8(6) |
| Vendor Contracts | Review agreements with third-party processors (e.g., cloud providers, marketing tools) to ensure they are DPDP compliant. | Section 8(1) |
| Grievance Redressal | Appoint and publish the contact details of a person responsible for handling data protection queries. | Section 17(1) |
Worked example
'Bengaluru Handlooms', a sole proprietorship, sells sarees online. They collect customer names, shipping addresses, phone numbers, and email IDs.
Before DPDP Act: Their checkout form had a single, pre-ticked box: "I agree to the terms and conditions and privacy policy."
To comply with DPDP Act:
- Notice: They redraft their privacy policy into simple language. At checkout, just before the payment button, they display a clear summary: "We will use your name, address, and phone number to deliver your order. We need your email to send order updates."
- Consent: They replace the single pre-ticked box with two optional, unticked checkboxes:
[ ]I consent to my data being used to process and deliver this order.[ ]I would like to receive updates on new collections and offers via email and WhatsApp. A customer must tick the first box to place an order. The second box is optional.
- User Rights: They add a 'My Data' section to the customer's account page, allowing them to view the data held and request its deletion. They also provide an email ID (e.g.,
privacy@bengaluruhandlooms.com) for data-related requests. - Data Retention: Their new policy states that order data will be retained for 7 years for accounting purposes and then anonymised or deleted. Marketing consent is valid until withdrawn.
By taking these steps, Bengaluru Handlooms moves towards compliance by being transparent and respecting user choice.
Common mistakes
- Using Bundled Consent: Asking for a single consent for multiple, unrelated purposes (e.g., transaction, marketing, data sharing) is invalid.
- Ignoring Employee Data: The Act applies to all personal data, including that of your employees, not just customers.
- Making Consent Withdrawal Difficult: Hiding the 'unsubscribe' or 'withdraw consent' option violates the Act's requirement that withdrawal be as easy as giving consent.
- No Data Breach Plan: Failing to have a process to notify the Data Protection Board and affected users after a breach can lead to severe penalties.
- Assuming the Act is Not Yet in Force: While the government will notify the implementation dates for various sections in phases, the Act is law. Proactive compliance is essential to avoid business disruption and penalties when enforcement begins.
How SP & SC helps
Navigating the DPDP Act, 2023 requires a clear understanding of its legal and technical implications. SP & SC Legal helps businesses of all sizes achieve compliance by reviewing existing data handling practices, drafting compliant privacy policies and consent notices, and reviewing vendor agreements. We provide a clear roadmap to ensure your operations respect data privacy laws from the ground up. For a complete review of your business processes and documentation, see our Business Contract Drafting & Review services.
Frequently asked questions
H3: Does the DPDP Act apply to physical records?
The Act primarily applies to personal data collected in digital form. It also applies to non-digital data if it is subsequently digitised. Historical, non-digitised records are outside its direct purview.
H3: Do I need to appoint a Data Protection Officer (DPO)?
The Act requires every Data Fiduciary to appoint a person to respond to grievances. The government may later classify certain businesses as 'Significant Data Fiduciaries' based on the volume and sensitivity of data they process, who will have additional obligations, including appointing a DPO based in India.
H3: What is a 'Data Principal'?
A Data Principal is the individual to whom the personal data relates. Under the Act, this includes your customers, employees, and website visitors. For children under 18, their parents or lawful guardians are the Data Principals.
H3: What are the penalties for non-compliance?
Penalties are significant and can be levied by the Data Protection Board of India. For instance, failing to take reasonable security safeguards to prevent a data breach can attract a penalty of up to ₹250 crore. Breach of obligations related to children's data can lead to a penalty of up to ₹200 crore.
H3: When is the deadline for compliance?
The DPDP Act, 2023 is already law. However, the Central Government will notify the effective dates for different provisions of the Act. It is expected to be implemented in a phased manner. Businesses should not wait for the final notification and must begin their compliance journey immediately.
Get a fixed-fee quote
Ensuring your business is compliant with the DPDP Act is a critical legal requirement. Share your existing privacy policy, website terms, and a summary of your business operations with us for a review. We provide a written fixed-fee quote to make your business fully compliant. Contact SP & SC or message us on WhatsApp at +91 90356 74566. We handle all documentation and process changes end-to-end.
Written by
SP & SC Editorial
Editorial team at SP & SC Legal and Taxation Services — practising advocates, chartered accountants, and company secretaries publishing hands-on guidance from live client files.
Next steps
What to do next
Guides help you decide. If you need an advocate, CA, or CS on your side, the SP & SC team files, drafts, and represents.

