DPDP Act 2023

What the DPDP Act
actually asks you to do.

A plain-English walkthrough of India's Digital Personal Data Protection Act, obligation by obligation, written for the people who have to implement it rather than the people who litigate it.

Questions

The things people ask us

Does the DPDP Act apply to my company if we only have customers abroad?

It applies to personal data processed in India, and to processing outside India where that processing is in connection with offering goods or services to Data Principals in India. A company incorporated in India processing Indian users' data is squarely in scope. A company abroad with Indian users is also in scope for that processing.

Is consent the only lawful basis under DPDP?

No. Consent is the primary basis, but the Act also allows processing for certain legitimate uses, including where the Data Principal voluntarily provides data for a specified purpose, and for specified state functions, employment purposes, medical emergencies and disasters. Legitimate uses are narrower than the GDPR's legitimate interests and should not be treated as an equivalent.

What languages does the notice have to be available in?

The notice must be available in English or any language listed in the Eighth Schedule to the Constitution of India, which covers 22 languages. In practice this means offering the notice in the languages your users actually read, and being able to show which language a given person was shown.

Do we need a Data Protection Officer?

Only Significant Data Fiduciaries are required to appoint a DPO, who must be based in India and report to the board or equivalent. Every Data Fiduciary, however, must publish contact details for a person who can answer questions about processing, and must have a grievance redressal mechanism.

How is this different from the GDPR work we already did?

The obligations rhyme but the mechanics differ. DPDP has no equivalent of legitimate interests as a general basis, requires notice in Eighth Schedule languages, introduces the Consent Manager as a registered intermediary, and puts the burden of proving notice and consent squarely on the Data Fiduciary. Your GDPR controls are a strong starting point but not a complete answer.

Book a walkthrough

See what fires before anyone says yes.

Run the free scan on your own domain. Two passes, one before consent and one after, with every cookie, tracker and fingerprinting call named against the obligation it touches.