S&S
S & S Co.
Advocates & Solicitors
Bar Council of India — Notice

Important Disclaimer & Notice

As per the rules of the Bar Council of India, advocates are not permitted to solicit work or advertise in any manner. By proceeding, you acknowledge that you are seeking information relating to S & S Co. of your own accord and that there has been no solicitation, advertisement or inducement by S & S Co. or any of its members.

The content of this website is provided solely for informational purposes and should not be construed as legal advice. S & S Co. shall not be liable for any consequence of any action taken by the user relying on material provided herein.

Any information shared through this website does not create an attorney-client relationship. Transmission of information herein is not intended to constitute, nor does receipt thereof constitute, an attorney-client relationship.

The contents of this website are the intellectual property of S & S Co. No part constitutes legal advice. Readers are requested to seek formal legal counsel before acting upon any information contained herein.
About Practice Areas Locations Legal Updates Legal News Team Blog Contact Us
Corporate Compliance & Data Protection · 13 September 2026

DPDP Act 2023 Compliance for Businesses: What Data Fiduciaries Must Do

A compliance-focused guide for Indian businesses acting as data fiduciaries under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 — core obligations, Significant Data Fiduciaries, and the compliance timeline.

By S&S Co. Advocates & Solicitors · Published 13 September 2026 · Informational content, not legal advice — see our disclaimer

The Framework: DPDP Act, 2023 and the DPDP Rules, 2025

The Digital Personal Data Protection Act, 2023 sets out India's data protection framework, built around the core relationship between a "data fiduciary" — broadly, any person or entity that determines the purpose and means of processing personal data — and a "data principal," the individual to whom the personal data relates. The Act's substantive machinery is operationalised through the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (published in the Gazette on 14 November 2025), which fill in the procedural and technical detail the Act itself leaves to delegated rule-making — notice formats, consent-manager registration, breach-notification mechanics, and the specific obligations that apply to entities designated as Significant Data Fiduciaries, among other things.

Any Indian business that collects, stores, or otherwise processes personal data of individuals — customers, employees, website visitors, or app users — in the ordinary course of its operations is very likely to fall within the Act's definition of a data fiduciary and should assume the framework applies unless a specific exemption is clearly available, rather than assuming it is too small or too narrowly focused to be covered.

Core Obligations Every Data Fiduciary Must Meet

The Act requires every data fiduciary to give data principals a clear, itemised notice describing what personal data is being collected and for what specific purpose, at or before the time consent is sought — a generic, catch-all privacy policy that does not clearly itemise the actual data and purposes involved is unlikely to satisfy this requirement. Consent obtained from the data principal must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action indicating agreement — the Act and Rules are designed to prevent the kind of consent architecture businesses have historically relied on, such as pre-ticked checkboxes, bundled consent clauses that make agreement to unrelated processing a condition of using a core service, or consent buried in dense, unreadable terms — and businesses should review their existing consent flows against this stricter standard rather than assuming an older privacy policy already complies.

Beyond notice and consent, a data fiduciary must implement reasonable security safeguards appropriate to the personal data it holds, to prevent personal data breaches, and must appoint a Grievance Officer to receive and respond to data principals exercising their rights under the Act — including rights to access information about their personal data, to correction and erasure, and to grievance redressal — within the timelines the Rules prescribe.

Heightened Obligations for Significant Data Fiduciaries

The Act allows the Central Government to designate certain data fiduciaries as "Significant Data Fiduciaries" — based on factors such as the volume and sensitivity of personal data processed, the risk to data principal rights, and other considerations the Act specifies — and entities so designated face a materially heavier compliance load. These heightened obligations include appointing a Data Protection Officer based in India, who is required to be responsible to the fiduciary's board or equivalent governing body and to act as the point of contact for grievance redressal; appointing an independent data auditor to periodically evaluate the fiduciary's compliance with the Act; and conducting a Data Protection Impact Assessment and periodic compliance audits as the Rules specify. Businesses that process large volumes of sensitive personal data, or that operate at a scale that could plausibly attract Significant Data Fiduciary designation, should track MeitY notifications on designation criteria closely, since the compliance uplift required on designation is substantial and is not something to address only after formal notification arrives.

Consent Managers and Record-Keeping

The framework also creates a role for registered Consent Managers — intermediaries through which a data principal can give, manage, review and withdraw consent across multiple data fiduciaries through a single, interoperable interface. Consent Managers registered under the framework are required to retain records of consents, notices and data-sharing activity for a minimum retention period the Rules specify (a period commonly cited at seven years, though businesses relying on this figure for their own compliance planning should confirm the current retention requirement against the DPDP Rules' actual text, since record-retention obligations of this kind are exactly the sort of technical detail that can be refined by subsequent notification).

Penalties for Non-Compliance

The Schedule to the DPDP Act sets substantial maximum monetary penalties for specified categories of non-compliance, reflecting the seriousness with which the framework treats data protection failures — including a maximum penalty in the region of Rs. 250 crore for failure to implement reasonable security safeguards resulting in a personal data breach, and a maximum penalty in the region of Rs. 200 crore for failure to notify the Data Protection Board and affected data principals of a personal data breach in the manner the Act requires. These figures represent statutory ceilings rather than fixed amounts automatically imposed, with the actual penalty in any given case determined by the Data Protection Board based on the nature, gravity and duration of the non-compliance, but the scale of the ceilings alone should be treated as a strong signal that data-breach preparedness and prompt breach notification need to be genuine operational priorities, not an afterthought.

The Compliance Timeline — Why "Notified" Does Not Mean "Fully in Force" Everywhere at Once

Not every obligation under the Act and Rules takes effect on a single date. Most of the day-to-day compliance obligations most businesses will actually need to operationalise — notice and consent mechanics, breach notification procedures, and data principal rights handling — are being phased in over a transition period, with full compliance across the framework's various provisions expected to be achieved by around mid-2027 based on the phased timeline the government has indicated. Businesses should not treat this phase-in as a reason to delay building the underlying compliance infrastructure — notice templates, consent flows, breach-response playbooks, vendor and processor contracts — since standing up genuinely compliant systems typically takes considerably longer than businesses expect, and the specific compliance deadline applicable to any given obligation should always be checked against the latest MeitY notification rather than assumed from an earlier general timeline.

Frequently Asked Questions

Does the DPDP Act apply to a small business that only collects basic customer data?

Very likely yes. The Act's definition of a data fiduciary is broad, covering any person or entity that determines the purpose and means of processing personal data, without a general small-business carve-out. A business that collects even basic customer or employee personal data should assume the framework applies to it and should not assume it is too small to be covered without confirming a specific applicable exemption.

What makes consent valid under the DPDP Act?

Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and preceded by a clear, itemised notice describing what data is collected and for what purpose. Pre-ticked boxes, bundled consent clauses that condition an unrelated service on unnecessary data processing, and consent buried in a dense, non-itemised privacy policy are unlikely to satisfy this standard.

What additional obligations apply to a Significant Data Fiduciary?

A data fiduciary designated as a Significant Data Fiduciary must appoint an India-based Data Protection Officer responsible to its governing body, appoint an independent data auditor, and conduct a Data Protection Impact Assessment and periodic compliance audits as the DPDP Rules specify. Designation criteria are set by the Central Government based on factors such as the volume and sensitivity of data processed and the risk to data principal rights.

What are the maximum penalties for a data breach under the DPDP Act?

The Schedule to the Act sets maximum penalties in the region of Rs. 250 crore for failure to implement reasonable security safeguards resulting in a breach, and in the region of Rs. 200 crore for failure to properly notify the Data Protection Board and affected data principals of a breach. These are statutory ceilings — the Data Protection Board determines the actual penalty in a given case based on the nature, gravity and duration of the non-compliance.

References & Further Reading

This article references the following statutory provisions. Readers should always verify current rules, fees and timelines against the applicable statute and rules as amended, since these are revised from time to time.

  1. Digital Personal Data Protection Act, 2023.
  2. Digital Personal Data Protection Rules, 2025, notified 13 November 2025 (Gazette publication 14 November 2025).
  3. Schedule to the Digital Personal Data Protection Act, 2023 (penalty provisions), and subsequent MeitY notifications on phased implementation and Significant Data Fiduciary designation criteria, which should be checked for the current position.
Get In Touch

Have a Question About
Corporate Compliance & Data Protection?

Tell us about your situation — we'll help you figure out the right next step.

Contact S&S Co. →

A full-service law firm headquartered in Noida, Delhi and Kolkata — commercial litigation, arbitration, corporate advisory and regulatory counsel across Delhi NCR, Kolkata and pan-India.

Practice

Commercial Litigation Arbitration All 14 Practice Areas

Locations

Noida All Locations

Firm

Team Legal Updates Legal News Blog Contact