India's DPDP Act, 2023 — Advisory Specialists

Navigate India's
new era of data
protection
with clarity.

DPDP Consultancy is a dedicated advisory firm helping organisations across India interpret, implement and operationalise the Digital Personal Data Protection Act. From board-level strategy to technical controls — we translate statute into practice.

Featured Focus

The Rules are here. Is your organisation ready?

Compliance is no longer theoretical. We help you build defensible, evidence-backed data protection programmes that stand up to scrutiny by the Data Protection Board of India.

§ DPDP Act 2023 / 2025 Rules
Risk & Penalties — Up to ₹250 Crore

The cost of
non-compliance
has never been higher.

Penalties under the DPDP Act can reach ₹250 crore per instance — and the reputational damage of a poorly handled breach can far exceed the statutory fine. A structured gap assessment today is the cheapest insurance you will ever buy.

Penalty Exposure

₹250 Cr. Maximum per contravention.

Failure to take reasonable security safeguards, delayed breach notification, and violations of children's data rules all carry significant financial penalties under the Act.

Schedule · DPDP Act Data Protection Board
End-to-End Advisory · Six Focused Services

From diagnosis
to defensible
compliance

we handle it all.

Gap assessments, DPO-as-a-Service, policy drafting, role-based training, 24×7 incident response, and data mapping. One specialist team covering the entire DPDP compliance lifecycle for your organisation.

Our Practice

100% focused on India's DPDP Act.

Not a generalist firm bolting privacy onto a broader offering. A dedicated team backed by DPCS Consulting LLP, working only on DPDP Act compliance for organisations serving Indian data principals.

Specialist Focus NDA Engagements
Consent Management Data Fiduciary Obligations Data Principal Rights Cross-Border Transfers Breach Notifications Significant Data Fiduciary Consent Management Data Fiduciary Obligations Data Principal Rights Cross-Border Transfers Breach Notifications Significant Data Fiduciary
100%
DPDP-Focused Practice
30min
Free Initial Consultation
24×7
Incident Response Support
NDA
Backed Engagements
Republic of
India · Act
No. 22 / 2023
2023
Digital Personal Data Protection Act

“An Act to provide for the processing of digital personal data...”

Enacted 11 August 2023 · Draft DPDP Rules released for consultation 2025. A landmark reform of India's privacy landscape.

About the Legislation

A watershed moment for Indian data protection.

The Digital Personal Data Protection Act, 2023 is India's first standalone, comprehensive privacy statute. It governs how Data Fiduciaries — any entity determining the purpose and means of processing personal data — collect, store, use and share the digital personal data of Data Principals located in India.

With the Draft DPDP Rules and the constitution of the Data Protection Board of India, enforcement has arrived. Non-compliance can attract penalties up to ₹250 crore per instance. Beyond fines, the reputational and operational cost of a poorly handled breach is significant.

01

Extraterritorial Reach

Applies to processing outside India if it relates to offering goods or services to Data Principals within India.

02

Consent-First Framework

Free, specific, informed, unconditional and unambiguous consent — with a clear, itemised purpose notice.

03

New Rights for Individuals

Access, correction, erasure, grievance redressal and the right to nominate — all operational and time-bound.

04

Sectoral & SDF Obligations

Significant Data Fiduciaries face enhanced duties: DPIAs, independent audits and a dedicated Data Protection Officer.

What We Do

End-to-end DPDP advisory, delivered by specialists.

Six focused services covering the entire compliance lifecycle — from diagnosing where you stand today to running the programme on your behalf tomorrow.

/ 01

DPDP Audit & Gap Assessment

A structured diagnostic of your current data-handling practices, mapped clause-by-clause against the Act and Rules. You receive a prioritised remediation roadmap with effort estimates.

Enquire
/ 02

DPO as a Service

Outsource your Data Protection Officer function to experienced practitioners. Suited for Significant Data Fiduciaries and mid-market firms that need competence without a full-time hire.

Enquire
/ 03

Privacy Policy & Notice Drafting

Plain-language, legally sound privacy notices, consent forms, vendor DPAs, retention schedules and internal policies — drafted for your specific business model and data flows.

Enquire
/ 04

Training & Awareness

Role-based training for boards, legal, product, engineering, HR and customer-support teams. Delivered in-person or virtual, with assessments, certificates and ongoing refreshers.

Enquire
/ 05

Incident & Breach Response

24×7 retainer for suspected breaches. We guide containment, forensic triage, regulator notification within statutory timelines and communications to affected Data Principals.

Enquire
/ 06

Data Mapping & Inventory

Discover, classify and document every flow of personal data across your systems, vendors and jurisdictions. The foundation of every downstream compliance obligation.

Enquire
Our Method

A four-phase engagement, calibrated to your risk profile.

We don't sell templates. Every engagement starts with understanding your business, your data, and your regulatory exposure — then builds outward from there.

Phase I · Discover

Understand your data, business and risk.

Stakeholder interviews, systems walkthrough, vendor review and a preliminary data-flow map. We learn how data actually moves through your organisation — not how the org chart says it does.

Phase II · Diagnose

Gap assessment against the DPDP Act & Rules.

Clause-by-clause evaluation of current practices. You receive a heat-mapped report identifying legal, operational and technical gaps, with each finding rated by severity and remediation effort.

Phase III · Design & Deploy

Build the compliance programme.

Drafting of policies, consent architecture, DPIA frameworks, vendor contracts and grievance mechanisms. Training rolled out to relevant teams. Technical controls implemented alongside your engineering partners.

Phase IV · Defend & Sustain

Ongoing vigilance and evidence.

Quarterly reviews, DPO support, incident response readiness, regulator liaison, and an audit-ready evidence trail. Compliance is a posture, not a project.

Who We Serve

If you process personal data of anyone in India — the Act applies to you.

Our clients range from venture-backed startups preparing for scale, to listed enterprises with complex group structures, to global firms serving Indian users.

BFSI & NBFCs

Banks, insurers, fintechs and NBFCs handling large volumes of financial personal data.

SaaS & Tech

B2B and B2C platforms, analytics firms, AI companies, and anyone processing at scale.

Healthcare & Pharma

Hospitals, diagnostic chains, telemedicine and pharma — where sensitive health data is central.

Retail & E-commerce

Direct-to-consumer brands, marketplaces and hospitality — handling rich behavioural data.

Global Firms with India Nexus

Non-Indian companies offering goods or services to data principals within India.

EdTech & Children's Services

Products serving minors — subject to stricter consent, verification and processing rules.

HR & Staffing

HR tech, background verification firms, and large employers processing workforce data.

Startups & Scale-ups

Founders building compliant from day one — avoiding costly retrofits at Series B.

The statute is written.
The Rules are arriving.

There is a narrow window between now and active enforcement. The organisations that use it well will find compliance a competitive asset, not a cost centre.

Start with a diagnostic
Common Questions

Answers to what we hear most.

If your question isn't here, a 30-minute introductory consultation is the fastest way to get a clear answer on your specific situation.

The Act received Presidential assent on 11 August 2023. Different provisions are being notified in phases. The Draft DPDP Rules, released for public consultation in 2025, operationalise the statute — and once finalised, most substantive obligations will have a short transition window. Treating compliance as urgent is now appropriate.

Yes. The Act applies to any Data Fiduciary processing digital personal data, with no blanket turnover or headcount exemption. Certain obligations are eased for startups via notification, but the baseline duties — consent, purpose limitation, security, breach notification, grievance redressal — apply to almost everyone.

Both are consent-centric and rights-based, and a mature GDPR programme is a strong starting point. But the DPDP Act has distinctive features: the Consent Manager framework, specific rules for children and persons with disabilities, a dedicated Data Protection Board, and different cross-border transfer mechanics. Mapping, not copy-pasting, is required.

The Act prescribes financial penalties up to ₹250 crore for certain breaches (e.g. failure to take reasonable security safeguards). The Data Protection Board of India adjudicates. Beyond fines, the reputational damage, operational disruption and civil exposure from a poorly handled incident typically exceed the statutory penalty.

A DPO is mandatory for Significant Data Fiduciaries (to be notified by the Central Government based on volume, sensitivity, risk and other factors). Even non-SDFs benefit from a designated, competent point of contact for Data Principal queries and regulator interaction. Our DPO-as-a-Service is built for exactly this.

For a typical mid-market organisation, a focused gap assessment takes 3 to 6 weeks depending on complexity, number of business units, and vendor ecosystem. We can accelerate on request — and for very small teams, we offer a condensed 10-day diagnostic.

Get in Touch

Let's discuss your DPDP journey.

A confidential, no-obligation 30-minute consultation. We'll help you understand where you stand and what your next three steps should look like.

Office
71/9, D H Road, Kolkata-700008
By appointment
Hours
Mon — Sat
10:00 – 19:00 IST
Parent Firm
DPCS Consulting LLP
DPDP Consultancy is a sister concern.
Free · No Obligation · 30 Minutes

Request a consultation

We typically respond within one business day. Your details are used solely to respond to this enquiry and are not shared with third parties.

Book Free Consultation