Shieldra Compliance · DPDP Compliance

DPDP Act 2023: Complete Compliance Guide

Everything your organization needs to know to become DPDP-ready

1. Introduction to the DPDP Act

The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy law. It governs how organizations collect, process, store, and share the personal data of individuals located in India, regardless of where the processing organization is based.

2. Who Must Comply

Any Data Fiduciary or Data Processor handling the personal data of individuals in India falls within scope. This includes domestic businesses, multinational companies serving Indian customers, government bodies, and not-for-profit organizations that process personal data at scale.

3. Core Obligations

Organizations must obtain , specific, informed and revocable consent before processing personal data; process data only for the stated purpose; implement reasonable security safeguards; maintain accurate records; and notify both the Data Protection Board and affected individuals promptly in the event of a breach.

4. Rights of Data Principals

Individuals have the right to access information about how their data is processed, request correction or erasure, nominate a representative, withdraw consent at any time, and seek grievance redressal through the Data Protection Board.

5. Enforcement Timeline

The Act is being implemented in phases. Basic rules and registration requirements took effect first, followed by the consent manager framework, with full enforcement — including the complete penalty regime — to follow. Organizations should not wait for full enforcement to begin building compliant processes.

6. Penalties for Non-Compliance

The Data Protection Board can levy financial penalties of up to Rs. 250 Crore per instance for serious violations, including failure to implement reasonable security safeguards or to report data breaches in a timely manner.