PrivacyIndia

DPDPA compliance

Digital Personal Data Protection Act (India)

India's Digital Personal Data Protection Act (DPDPA) sets obligations for organisations processing personal data — around consent, purpose, security and accountability. Pelta helps you turn DPDPA obligations into managed controls with linked evidence, so data protection becomes an ongoing program rather than a one-off exercise.

Who it's for

Does DPDPA apply to you?

  • Organisations processing personal data of individuals in India
  • Data fiduciaries building a DPDPA program
  • Teams aligning DPDPA with ISO 27001 and other frameworks

What the DPDPA governs

The Digital Personal Data Protection Act is India's dedicated data protection law. It governs the processing of digital personal data and sets obligations around lawful processing, notice and consent, purpose limitation, security safeguards, and the rights of the individuals whose data you hold.

The Act uses its own vocabulary. The individual is the data principal. The organisation deciding why and how data is processed is the data fiduciary. An entity processing on a fiduciary's behalf is a data processor. Certain fiduciaries may be notified as Significant Data Fiduciaries, carrying additional obligations.

Key DPDPA roles
TermWho it meansCore responsibility
Data PrincipalThe individual the personal data relates toHolds rights over their data
Data FiduciaryThe organisation determining purpose and means of processingCarries the primary compliance obligations
Data ProcessorAn entity processing on a fiduciary's behalfProcesses only per the fiduciary's instructions
Significant Data FiduciaryA fiduciary notified as significant, based on prescribed factorsAdditional obligations such as audits and impact assessments
Whether you are a Significant Data Fiduciary, and the exact obligations and timelines that apply to you, depend on official notifications and rules. Confirm your position with qualified counsel — this page is a general overview, not legal advice.

The core obligations

Most DPDPA programmes come down to being able to answer four questions convincingly: what personal data do we hold, on what lawful basis, how is it protected, and how do we honour individual rights?

  • Notice and consent: give a clear notice of what you collect and why, and obtain consent where required — with withdrawal as easy as giving it.
  • Purpose limitation: use personal data only for the purpose it was collected for.
  • Data minimisation and retention: collect only what you need, and erase it when the purpose is served.
  • Security safeguards: protect personal data with reasonable security measures.
  • Breach notification: report personal data breaches in line with the prescribed process.
  • Data principal rights: enable access, correction, erasure and grievance redressal.
  • Children's data: apply additional care where the data principal is a child.
  • Processor oversight: bind processors contractually and oversee how they handle data.
Building a DPDPA programme

Discover

Inventory personal data

Map flows

Systems & processors

Lawful basis

Notice & consent

Safeguard

Security controls

Enable rights

Requests & grievances

Evidence

Prove it continuously

How DPDPA compares to GDPR

If you already run a GDPR programme, much of the groundwork transfers — data inventory, purpose limitation, security safeguards and rights handling all have counterparts. But DPDPA is its own law with its own definitions, consent mechanics and enforcement, so mapping rather than assuming is the safer approach.

Common pitfalls to avoid

  • Starting with policies instead of a data inventory — you cannot protect or justify data you have not mapped.
  • Treating consent as a one-time checkbox rather than a record you must maintain and honour on withdrawal.
  • Overlooking processors and sub-processors that handle personal data on your behalf.
  • Assuming a GDPR programme transfers unchanged, without mapping to DPDPA's specific obligations.
  • Building controls without an evidence trail, so you can meet obligations but cannot demonstrate that you do.
How Pelta helps

Run DPDPA on one connected platform

Obligations as controls

Translate DPDPA requirements into a managed control set with clear ownership.

Evidence-backed

Link each obligation to the evidence that demonstrates it.

Privacy risk

Assess and track privacy risk alongside your wider risk register.

Reuse controls

Share controls and evidence with ISO 27001, GDPR and other privacy-adjacent frameworks.

DPDPA FAQs

Who does the DPDPA apply to?+

The DPDPA applies to the processing of digital personal data of individuals (data principals) in India, with the primary obligations falling on data fiduciaries. Confirm the current rules and your role under the Act.

What is a data fiduciary under the DPDPA?+

A data fiduciary is the person or organisation that determines the purpose and means of processing personal data — broadly equivalent to a controller under GDPR. It carries the primary compliance obligations.

What is a Significant Data Fiduciary?+

A fiduciary notified as significant based on prescribed factors such as data volume and sensitivity. Significant Data Fiduciaries carry additional obligations, which may include audits, impact assessments and appointing a data protection officer.

What rights do data principals have?+

Broadly, rights to access information about their data, seek correction and erasure, and access grievance redressal. Confirm the current scope of rights and the process for honouring them under the applicable rules.

How is DPDPA different from GDPR?+

Both protect personal data and share principles like purpose limitation and security, but DPDPA is India's own law with its own definitions, consent mechanics and enforcement. Much GDPR groundwork transfers, but obligations should be mapped rather than assumed.

What is the hardest part of DPDPA compliance?+

For most teams it is operationalising and continuously evidencing the obligations — consent records, data principal requests, processor oversight and security safeguards — rather than understanding the principles themselves.

How does Pelta support DPDPA?+

Pelta maps DPDPA obligations to controls, keeps evidence linked, and lets you manage privacy risk continuously — reusing controls that overlap with frameworks like ISO 27001 and GDPR.

See DPDPA compliance on Pelta

Operationalise India's DPDPA on Pelta — map obligations to controls, evidence your data protection posture, and manage privacy risk continuously.