The Digital Personal Data Protection Act, 2023 creates a focused framework for processing digital personal data in India. Its central bargain is simple: use personal data for a lawful purpose, respect the individual and remain accountable for how the data is handled.
1. Begin with scope
The Act applies to digital personal data processed in India, including information first collected offline and digitised later. It can also reach processing outside India when that processing is connected with offering goods or services to people in India.
Two exclusions are especially useful at the outset: personal data used by an individual for a personal or domestic purpose, and data made publicly available by the individual or under a legal obligation. The governing starting point is section 3.
2. Identify the lawful ground
Processing must be for a lawful purpose and rest on either the Data Principal's consent or one of the “certain legitimate uses” in section 7. This choice should be made deliberately for each purpose; it shapes the notice, the operational workflow and what happens when an individual withdraws consent.
For every personal-data use, can your team name the purpose, the lawful ground, the data involved, the retention point and the person accountable for the decision?
3. Build around the core duties
The Data Fiduciary remains responsible for compliance, including processing carried out on its behalf by a Data Processor. Section 8 turns that accountability into concrete work: keep data accurate where decisions or disclosures depend on it, use reasonable security safeguards, notify breaches as prescribed, erase data when retention is no longer necessary, and provide an effective grievance mechanism.
Children's data and Significant Data Fiduciaries carry additional duties. These should be treated as separate workstreams rather than small additions to a general privacy notice.
4. Design for individual rights
The Act gives a Data Principal rights to information about processing, correction and erasure, grievance redressal, and nomination. A reliable request process needs more than an inbox: it needs identity checks, ownership, retrieval across systems, response tracking and a clear escalation route.
5. Start with a data-purpose map
A useful first deliverable is not a policy. It is a compact map of the organisation's important processing activities: what personal data is used, for which purpose, under which ground, by which systems and vendors, for how long, and with what safeguard. That map exposes the gaps a policy can otherwise hide.
From there, prioritise public-facing notices and consent journeys, processor contracts, breach readiness, retention and deletion, and the workflow for Data Principal requests. The result is a compliance programme tied to actual processing rather than a stack of documents.
This article is an educational summary of the DPDP Act, 2023 and does not constitute legal advice. Consult the statutory text and qualified counsel for decisions about a specific organisation.