What the DPDPA governs
The Digital Personal Data Protection Act is India's dedicated data protection law. It governs the processing of digital personal data and sets obligations around lawful processing, notice and consent, purpose limitation, security safeguards, and the rights of the individuals whose data you hold.
The Act uses its own vocabulary. The individual is the data principal. The organisation deciding why and how data is processed is the data fiduciary. An entity processing on a fiduciary's behalf is a data processor. Certain fiduciaries may be notified as Significant Data Fiduciaries, carrying additional obligations.
| Term | Who it means | Core responsibility |
|---|---|---|
| Data Principal | The individual the personal data relates to | Holds rights over their data |
| Data Fiduciary | The organisation determining purpose and means of processing | Carries the primary compliance obligations |
| Data Processor | An entity processing on a fiduciary's behalf | Processes only per the fiduciary's instructions |
| Significant Data Fiduciary | A fiduciary notified as significant, based on prescribed factors | Additional obligations such as audits and impact assessments |
The core obligations
Most DPDPA programmes come down to being able to answer four questions convincingly: what personal data do we hold, on what lawful basis, how is it protected, and how do we honour individual rights?
- Notice and consent: give a clear notice of what you collect and why, and obtain consent where required — with withdrawal as easy as giving it.
- Purpose limitation: use personal data only for the purpose it was collected for.
- Data minimisation and retention: collect only what you need, and erase it when the purpose is served.
- Security safeguards: protect personal data with reasonable security measures.
- Breach notification: report personal data breaches in line with the prescribed process.
- Data principal rights: enable access, correction, erasure and grievance redressal.
- Children's data: apply additional care where the data principal is a child.
- Processor oversight: bind processors contractually and oversee how they handle data.
Discover
Inventory personal data
Map flows
Systems & processors
Lawful basis
Notice & consent
Safeguard
Security controls
Enable rights
Requests & grievances
Evidence
Prove it continuously
How DPDPA compares to GDPR
If you already run a GDPR programme, much of the groundwork transfers — data inventory, purpose limitation, security safeguards and rights handling all have counterparts. But DPDPA is its own law with its own definitions, consent mechanics and enforcement, so mapping rather than assuming is the safer approach.
Common pitfalls to avoid
- Starting with policies instead of a data inventory — you cannot protect or justify data you have not mapped.
- Treating consent as a one-time checkbox rather than a record you must maintain and honour on withdrawal.
- Overlooking processors and sub-processors that handle personal data on your behalf.
- Assuming a GDPR programme transfers unchanged, without mapping to DPDPA's specific obligations.
- Building controls without an evidence trail, so you can meet obligations but cannot demonstrate that you do.