If your business collects even a phone number or an email address from customers in India, the Digital Personal Data Protection Act, 2023 already applies to you. Most business owners still think of the DPDP Act as something for big tech companies to worry about. That's a costly assumption. The law covers virtually every organisation that handles personal data β€” from a five-person startup running an online store to a hospital chain managing patient records.

What Is the DPDP Act, in Simple Terms?

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data privacy law. It replaces the patchwork of rules that used to sit under the Information Technology Act, 2000, and gives India a dedicated framework for how personal data should be collected, stored, used, and protected.

The law applies to any processing of digital personal data within India β€” and even to processing outside India if it relates to offering goods or services to people in India. An e-commerce company based abroad but selling to Indian customers still falls within its reach.

Under the Act:

  • Data fiduciaries β€” businesses that collect and decide how personal data is used
  • Data principals β€” individuals whose data is being collected

Every obligation in the law flows from this relationship.

Consent Is the Foundation, Not a Formality

Consent sits at the centre of the DPDP Act. Businesses can no longer bury permissions inside a wall of legal text that nobody reads. Consent must be free, specific, informed, and given through a clear affirmative action β€” not assumed through a pre-ticked box.

Every consent request must tell the person what data is being collected and why, in language they can actually understand. And critically, withdrawing consent must be just as easy as giving it. If a customer can sign up with one click, they should be able to opt out with one click too.

Many businesses will end up relying on consent managers β€” a new category of registered intermediaries the Act introduces to help individuals manage, review, and withdraw consent across different platforms from a single dashboard.

Data Minimisation and Purpose Limitation

One of the more significant shifts under this law is a move away from collecting data "just in case." The Act expects businesses to gather only the personal data that's genuinely necessary for the specific purpose stated at the time of collection.

If you're running a delivery app, you don't need a customer's date of birth unless it's actually relevant to the service. Collecting more than you need isn't just bad practice anymore β€” it's a compliance risk. Businesses should also avoid retaining data indefinitely: once the purpose for which data was collected is fulfilled and there's no legal reason to keep it, it should be deleted.

Rights That Businesses Must Be Ready to Honour

The DPDP Act hands individuals a set of clear rights β€” to access their data, correct inaccuracies, withdraw consent, and seek grievance redressal. Businesses need actual internal processes in place to respond to these requests without excessive delay β€” not just a policy document sitting unused on a server. Someone in the organisation has to own these requests and respond within a reasonable timeframe.

Data Breach Notification Is Non-Negotiable

If a data breach occurs, the DPDP Act requires businesses to notify both the Data Protection Board of India and the affected individuals. There is no minimum threshold for severity β€” even a smaller breach has to be reported.

This makes having a breach response plan essential rather than optional. Businesses should know in advance:

  • Who investigates a suspected breach
  • How quickly notifications go out
  • What information gets shared with affected customers

Scrambling to figure this out after a breach has already happened almost always makes things worse.

Significant Data Fiduciaries Face Extra Obligations

The government can classify certain businesses as Significant Data Fiduciaries based on the volume of data they process, the sensitivity of that data, and potential risk to individuals or national security. These businesses face additional requirements:

  • Appointing a Data Protection Officer based in India
  • Conducting periodic data protection impact assessments
  • Getting independent data audits done

If your business processes large volumes of sensitive personal data β€” financial information, health records, or biometric data β€” it's worth preparing for this classification even before it's formally confirmed.

Penalties Are Steep

Penalties for non-compliance can go up to β‚Ή250 crore for a single instance, depending on the nature and severity of the violation. Failing to implement reasonable security safeguards or failing to notify a breach are treated as serious lapses.

For most businesses, these numbers alone should be reason enough to treat compliance as a priority rather than an afterthought.

What Businesses Should Actually Do Right Now

  • Start with a data audit. Most businesses don't actually know how much personal data they're sitting on, where it came from, or why they still have it. Mapping this out is the first real step toward compliance.
  • Revisit your consent flows. Pre-ticked boxes and buried permissions need to go.
  • Update privacy notices so they're written in plain language that customers can actually understand.
  • Set up a process for handling data principal requests β€” access, correction, withdrawal, grievance β€” before someone submits one.
  • Put together a breach response plan before you need one.
  • Review third-party vendor contracts. Liability doesn't disappear just because you outsourced the processing β€” make sure your contracts reflect DPDP obligations too.

Final Thoughts

The DPDP Act signals a genuine shift in how India expects businesses to treat personal data. It's no longer enough to have a privacy policy tucked away on a website that nobody reads. Compliance now means building real processes around consent, transparency, and accountability.

Businesses that get ahead of this β€” rather than waiting for enforcement to catch up β€” will find it easier to earn customer trust and avoid the very real financial risk that comes with getting it wrong.