DPDP Compliance

What is the DPDP Act 2023? Complete Guide for Indian Companies

Cor Advance Solutions
July 11, 2026
15 min read
What is the DPDP Act 2023? Complete Guide for Indian Companies

What is the DPDP Act 2023? Complete Guide for Indian Companies

The Digital Personal Data Protection (DPDP) Act 2023 is India's first comprehensive data privacy legislation. Effective from September 2024, it fundamentally changes how Indian companies collect, process, and store personal data. dpdp penalties explained

What is Personal Data?

Under DPDP, personal data is any information that identifies or can identify an individual. This includes:

Obvious Identifiers:

  • Names, email addresses, phone numbers
  • Postal addresses, financial account numbers
  • Identification document numbers (Aadhaar, PAN, passport)

Sensitive Identifiers (heightened protection):

  • Financial data (bank accounts, transaction history, credit scores)
  • Health records and medical history
  • Biometric data (fingerprints, face, iris, voice)
  • Genetic data
  • Caste, religion, political affiliation
  • Sexual orientation, gender identity

Behavioral Data:

  • Website browsing history
  • Purchase history
  • Location data
  • Device identifiers
  • Behavioral analytics

Key Requirements Under DPDP

1. Consent is Mandatory

You must collect explicit, informed, written consent before collecting personal data. Consent cannot be a condition for service unless the data is necessary for that service. dpdp vs gdpr

What This Means:

  • Generic checkbox consent is not enough
  • "Agree to our privacy policy" is not enough
  • You must explain WHAT data you're collecting, WHY, and HOW you'll use it
  • Consent must be given in a clear, granular manner
  • Users can withdraw consent anytime

2. Data Minimization

Collect and process only the data you actually need. If you're building a newsletter signup, you don't need:

  • Phone numbers (unless you'll SMS)
  • Location data (unless necessary for the service)
  • Employment history (unless relevant)

3. Purpose Limitation

Once you collect data for a specific purpose, you cannot use it for something else without new consent.

Example: If you collect email for marketing, you can't later use it for credit assessment without asking again.

4. Data Retention Limits

You cannot keep personal data indefinitely. Retention must be:

5. User Rights (Right to Data)

Users have a right to:

  • Access: Get a copy of their data within 30 days
  • Correction: Fix inaccurate data
  • Deletion: Have their data erased (with exceptions for legal compliance)
  • Portability: Get their data in a machine-readable format
  • Grievance Redressal: Appeal if their rights are violated

6. Data Protection Officer (DPO)

You must appoint a DPO (or outsource this role) if you:

  • Process large volumes of personal data
  • Process sensitive data categories
  • Conduct automated decision-making

7. Data Processor Agreements

If third parties process your data (cloud providers, email services, analytics platforms), you must have written agreements specifying:

  • What data they process
  • How they secure it
  • How long they retain it
  • Their obligations under DPDP

8. Breach Notification

If personal data is breached, you must notify:

  • Affected individuals within 72 hours
  • The Data Protection Board (in cases of significant risk)

Documentation is required for audit purposes.

Penalties for Non-Compliance

DPDP enforcement is strict:

ViolationPenalty
General violationsUp to ₹5 crore or 5% of annual revenue (whichever is higher)
Serious violationsUp to ₹250 crore or 20% of annual revenue (whichever is higher)
Sensitive data mishandlingUp to ₹250 crore

Criminal penalties (imprisonment) apply in cases involving repeated non-compliance, negligence, or intentional violations.

DPDP vs GDPR: Key Differences

AspectDPDPGDPR
Geographic scopeIndian residents' dataEU residents' data
ConsentExplicit consent requiredConsent + legal basis
FinesUp to ₹250 CrUp to €20 million or 4% revenue
DPORequired for specific casesRequired for public authorities & large processors
Data breach72-hour notification72-hour notification

DPDP is simpler and more prescriptive than GDPR but equally binding for Indian companies.

Who Needs to Comply?

  1. Indian companies collecting Indian residents' data
  2. Global companies with Indian users
  3. Startups even with small user bases
  4. SMBs processing customer data

Key Takeaway

DPDP is not a future concern—it's already active. Companies found non-compliant face massive fines, forced platform shutdowns, and criminal liability for leadership.

The time to prepare is now.


Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Consult a qualified data protection lawyer for your specific situation.

Next Step: Start your free DPDP compliance assessment

Share this article
Cor Advance Solutions

Ready to Transform Your Business?

Let's discuss how these insights apply to your specific challenges.

Get in Touch