In short

  • The Act applies regardless of size, and applies to foreign processing connected with offering goods or services to people in India.
  • Start with an inventory of what personal data you hold. Every other obligation depends on it.
  • Notice and consent are the core: consent must be free, specific, informed, unconditional and unambiguous, and as easy to withdraw as to give.
  • Children's data is the sharpest edge — verifiable parental consent below eighteen, and no behavioural advertising directed at children.
  • Implementation has been phased. Check what is actually in force when you read this.

On timing

The Digital Personal Data Protection Act, 2023 was passed in 2023, and its provisions have been brought into effect in stages, with subordinate rules and transition periods. Because that timetable has shifted more than once, this guide deliberately avoids stating which obligations are live on any particular date. Treat what follows as an account of the scheme, and verify the commencement position at the time you act.

Who it applies to

The Act governs the processing of digital personal data — personal data in digital form, or in non-digital form subsequently digitised. It applies to processing within India, and to processing outside India where that processing is in connection with offering goods or services to individuals in India.

There is no small-business exclusion. The Act does empower the Central Government to exempt notified classes of data fiduciary, including startups, from specified provisions — but that is a targeted exemption from particular obligations, not a general carve-out, and it is not something to assume applies to you.

The three roles

  • Data principal — the individual the data is about.
  • Data fiduciary — whoever determines the purpose and means of processing. For your customers and employees, that is you.
  • Data processor — someone who processes on a fiduciary's behalf. Your analytics tool, payroll provider, email service or hosting provider.

The distinction matters because responsibility to the individual generally remains with the fiduciary. Outsourcing the processing does not outsource the obligation, which is why written terms with vendors who touch personal data are part of the work rather than an afterthought.

The default basis for processing is consent, and the Act sets a demanding standard for it. Consent must be free, specific, informed, unconditional and unambiguous, signified by a clear affirmative action, and limited to the personal data necessary for the stated purpose.

Some consequences of that, in the terms a founder will meet them:

  • Pre-ticked boxes and consent bundled into acceptance of terms do not meet the standard.
  • Consent to one purpose does not carry over to another. Collecting an email address to deliver a service is not consent to send marketing.
  • Withdrawal must be as easy as giving consent was. A one-click sign-up with a written-request-only unsubscribe does not work.
  • Notice must accompany or precede the request, in clear and plain language, and must be available in English and in the languages set out in the Eighth Schedule to the Constitution.

The notice itself has to describe the personal data collected, the purpose of processing, how the individual may exercise their rights, and how they may complain to the Data Protection Board. A privacy notice copied from another company fails on the first of these, because it describes data handling you do not carry out — which is worse than having no notice at all, since it is a statement about your own practices that is untrue.

Processing without consent

The Act recognises a set of "legitimate uses" where consent is not required. The two that matter most to an ordinary business are personal data voluntarily provided by the individual for a purpose for which they have not indicated an objection, and processing for employment purposes — which covers a good deal of ordinary HR processing without needing employee consent for each step.

The obligations that catch small teams out

Purpose limitation and erasure

Data may be processed for the purpose for which it was collected, and must generally be erased once that purpose is no longer being served and retention is not required by law. This is difficult for organisations that have never deleted anything, and it is worth designing a retention position before the volume becomes unmanageable.

Accuracy and security

Reasonable security safeguards to prevent a breach are a positive obligation, not a best practice. The Act's schedule of penalties treats failure to take reasonable security safeguards as the most serious default, with a maximum penalty running to ₹250 crore. That figure is a ceiling for the most egregious case rather than a likely outcome for a small business, but it indicates where the legislature placed the emphasis.

Breach notification

A personal data breach must be notified to the Data Protection Board and to each affected individual. Deciding what to do about a breach at the moment it happens is the worst time to work it out; a short written procedure settled in advance is one of the cheapest things on this list.

Grievance redressal

There must be a means for individuals to raise grievances, with a response within the prescribed period, and a published point of contact. For a small company this can be a monitored address and a documented process — but it has to exist and it has to work.

Children's data

The most demanding part of the Act for consumer businesses. Processing personal data of a child — anyone under eighteen — requires verifiable consent of a parent or lawful guardian. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited. Any product that plausibly has users under eighteen needs to have thought about age assurance, and "our terms say users must be eighteen" is not by itself an answer.

Cross-border transfer

The Act permits transfer of personal data outside India except to territories restricted by notification of the Central Government. That is a more permissive starting position than some other regimes, but it is subject to any sectoral requirement that applies to you — financial services regulation, for instance, has its own localisation requirements that operate independently.

Significant data fiduciaries

Organisations notified as significant data fiduciaries carry additional obligations, including appointment of a data protection officer based in India, an independent data auditor and periodic impact assessments. Most early-stage companies will not be in this category, but a business handling large volumes of sensitive data should keep the possibility in view.

What individuals can ask you for

  • A summary of the personal data being processed and the processing activities undertaken.
  • Correction, completion, updating and erasure of their personal data.
  • Access to a grievance redressal mechanism.
  • To nominate another person to exercise their rights in the event of death or incapacity.

In practice this means being able to find everything you hold about one person, which is straightforward if you have an inventory and close to impossible if you do not.

Where to start

In this order, and no other. Most of the compliance products sold to founders begin at step four, which is why they rarely produce anything useful.

  1. Inventory. What personal data do you collect, from whom, for what purpose, where does it sit, who else touches it, and how long do you keep it? A spreadsheet is entirely adequate. Nothing else can be done properly until this exists.
  2. Basis. For each item, record why you are entitled to process it — consent, or a legitimate use under the Act.
  3. Collection points. Fix the notice and consent flow wherever data is actually collected: sign-up, checkout, contact form, job application.
  4. Notice. Write one that describes what you actually do, in language a user can follow.
  5. Vendors. Put written terms in place with the processors who handle personal data for you.
  6. Procedures. A breach response note, a grievance address, and a retention and deletion position.
  7. Children. If your product may have users under eighteen, deal with it deliberately rather than by disclaimer.

A note on proportion

A five-person company does not need the compliance apparatus of a bank, and building one is a way of spending money without reducing risk. What it does need is to know what it holds, to have told people the truth about it, to be able to answer a request, and to have decided in advance what it will do if something goes wrong. That is a realistic first pass, and it puts a small organisation ahead of most of its peers.

Disclaimer

This guide is general information about Indian law and is not legal advice. The Digital Personal Data Protection Act, 2023 is being brought into force in stages and is supplemented by subordinate rules; the position in force when you read this may differ from the position described. Reading this creates no advocate–client relationship.

Written by Sparsh Goel, Advocate, New Delhi, who has advised a non-profit organisation on compliance under this Act and has written on it previously in the Indraprastha Law Review. If you are working out what the Act means for your organisation, you are welcome to get in touch.