pvtltd.co
compliance

What the DPDPA 2023 really demands beyond a privacy policy

India’s Digital Personal Data Protection Act, 2023 requires more than a posted privacy policy. Learn the consent, breach‑notification, children’s data and penalty rules that affect every private limited company.

C

CA Harun Raaj

pvtltd.co

Legal basis: Digital Personal Data Protection Act, 2023 (DPDPA) — Sections 2–10 and Schedule 1; Digital Personal Data Protection Rules, 2025 — Rules 6–12 (notified by MeitY, 13 November 2025). Effective: phased implementation — Data Protection Board provisions live from November 2025; Section 6(9) from November 2026; remaining provisions from 13 May 2027. Source: https://iapp.org/news/a/with-rules-finalized-india-s-dpdpa-takes-force. Last reviewed by CA Harun Raaj: September 2026.

The problem: “we have a privacy policy” is not compliance

A Bengaluru‑based B2B SaaS startup sends product‑update emails to 30,000 users. When a user complained to the Data Protection Board, the company produced its privacy policy and the terms‑of‑service checkbox signed at signup. Under the DPDPA, neither document constitutes valid consent for marketing communications – each processing purpose needs a separate, affirmative, revocable consent.

The Board’s investigation also uncovered:

  • No documented breach‑response procedure.

  • Minors accessing the platform without verifiable parental consent.

  • No easy way for users to withdraw consent without deleting their account.

Schedule 1 of the Act allows penalties of up to ₹200 crore for breach‑notification gaps and for violations involving children’s data.

Who is covered: the Data Fiduciary threshold

Section 2 defines a Data Fiduciary as any person who determines the purpose and means of processing personal data – the same role as a “Data Controller” under GDPR. If your private limited company decides why and how it collects customer, user or employee data, you are a Data Fiduciary.

The Act applies to:

  • Processing of digital personal data within India (Section 3(1)(a)).

  • Processing of digital personal data outside India when it relates to offering goods or services to individuals in India (Section 3(1)(b)).

There is no turnover or employee‑count threshold – even a company with ten customers becomes a Data Fiduciary the moment it stores their contact details.

What the law actually requires

Consent that works

Section 6 outlines five pillars of valid consent:
  • Free – service access cannot be conditioned on unrelated data processing.
  • Specific – each purpose (order fulfilment, marketing, analytics) needs its own consent.
  • Informed – preceded by a notice as per Section 7.
  • Unconditional – no bundling with unrelated terms.
  • Unambiguous – a clear affirmative action; pre‑ticked boxes or silence do not count.

Section 7 notice must contain:

  • Identity and contact details of the Data Fiduciary.

  • Categories of personal data to be processed.

  • Purpose(s) of processing.

  • Rights of the Data Principal and how to exercise them.

  • How to withdraw consent and the grievance process.

A checkbox next to “I accept the Terms of Service” and a footer‑linked privacy policy both fail these requirements.

Consent‑manager framework

Rule 11 of the DPDP Rules, 2025 creates Consent Managers – entities registered with the Data Protection Board that act as a single point of contact for users to give, manage, review and withdraw consent across multiple Data Fiduciaries. Registration must be completed by November 2026 (12 months after the Rules notification).

Start‑ups typically choose one of two paths:

  • Build an in‑house consent‑management system that meets the Act’s standards.

  • Integrate a registered Consent Manager’s solution and rely on them for consent handling.

If you intend to manage consent on behalf of other fiduciaries, registration is mandatory.

Security safeguards & breach notification

Section 8(5) obliges every Data Fiduciary to implement reasonable security safeguards. “Reasonable” is judged against data volume, sensitivity and prevailing industry standards – the Act does not prescribe a specific ISO or SOC certification.

Rule 6, DPDP Rules, 2025 sets the breach‑notification timeline:

  • Within 72 hours – notify the Data Protection Board.

  • Within 7 days – submit a preliminary report.

  • Within 30 days – submit a detailed report.

  • Without delay – inform affected Data Principals.

Any breach triggers the notification duty, regardless of its size, and failure to notify attracts a separate penalty under Schedule 1.

Processing children’s data – the strictest tier

Section 9 applies to data of children (under 18 years). It requires:
  • Verifiable parental consent before any processing – a simple “are you 18?” button does not suffice.
  • No processing likely to cause a detrimental effect on a child’s wellbeing.
  • No tracking or monitoring of children’s behaviour.
  • No targeted advertising directed at children.

If a child accesses your platform, the obligations kick in immediately, even if the product is not marketed to children.

Significant Data Fiduciaries (SDFs)

The Central Government may designate certain fiduciaries as Significant Data Fiduciaries based on data volume, sensitivity, national‑security risk, electoral data or impact on fundamental rights (Section 10). SDFs must:
  • Appoint a Data Protection Officer resident in India.
  • Appoint an independent Data Auditor.
  • Conduct periodic Data Protection Impact Assessments (DPIAs).

Most start‑ups will not be SDFs at launch, but firms handling health, financial or large‑scale behavioural data should monitor government notifications.

What happens when you don’t comply: Schedule 1 penalties

The Data Protection Board (Section 18) can levy fines up to the amounts shown below. Penalties are maximums per violation; the Board considers gravity, duration, nature of data and repeat offences (Section 32).
BreachMaximum Penalty
Failure to implement security safeguards – Section 8(5)₹250 crore
Failure to notify Board/principals of a breach – Section 8(6)₹200 crore
Non‑compliance with children’s data obligations – Section 9₹200 crore
Non‑compliance with Significant Data Fiduciary obligations – Section 10₹150 crore
Non‑compliance with any other provision – Schedule 1₹50 crore

Even a defective consent notice can attract a ₹50 crore penalty, underscoring the financial risk for founders.

Step‑by‑step DPDPA compliance roadmap (before May 2027)

  • Run a data‑mapping exercise – list every personal data category, purpose, legal basis, access rights and retention period.
  • Rebuild consent architecture – replace bundled T&C checkboxes with purpose‑specific consent flows and a “manage consent” panel.
  • Rewrite privacy notices – include the five items required by Section 7, placed before the consent action, in plain language.
  • Create a breach‑response SOP – assign roles for detection, Board notification, reporting and user communication; conduct quarterly tabletop drills.
  • Address children’s data – implement robust age verification and verifiable parental consent, or restrict access to verified adults.
  • Update vendor/processor agreements – flow‑down DPDPA obligations to cloud providers, analytics tools, email platforms and payment gateways.
  • Appoint a grievance officer – publish a named contact (not a generic email) in the privacy notice and commit to a 30‑day response window.
  • Review annually – align the DPDPA review with your statutory audit cycle (September‑October) to capture new processing activities.

DPDPA compliance now belongs in the same annual‑compliance package that includes ROC filings, statutory audit and GST reconciliation.

Key point: A simple privacy‑policy link or bundled T&C checkbox does not meet the DPDPA’s consent requirements for marketing or other data processing.

I'm CA Harun Raaj. If this affects your company's compliance calendar, reach out.

---

See Also

Frequently asked questions

Does the DPDPA apply to B2B companies that don't have retail users?

Yes. The Act covers any processing of digital personal data in India, including employee, contractor, client‑contact and platform‑user data, regardless of whether the individuals are consumers (Section 3).

Do we have to wait until May 2027 to start DPDPA compliance?

No. The Data Protection Board has been operational since November 2025, and complaints can be filed now. Building compliant systems in 2026 puts you in a stronger position if an investigation begins.

Are cloud providers like Google Analytics and AWS subject to the DPDPA?

You remain the Data Fiduciary; providers are data processors. Under the Act you must ensure they process data only on your documented instructions and include DPDPA flow‑down clauses in your contracts (Section 8).

What consent mechanism satisfies the DPDPA for marketing emails?

Section 6 requires a separate, affirmative, unbundled consent for each purpose. A purpose‑specific opt‑in toggle placed after a clear notice (Section 7) meets the requirement; a generic T&C checkbox does not.

How soon must we notify the Board after a data breach?

Rule 6 of the DPDP Rules, 2025 mandates notification to the Data Protection Board within 72 hours of becoming aware of the breach, followed by a 7‑day preliminary report and a 30‑day detailed report.

What are the penalties for failing to obtain verifiable parental consent for children’s data?

Section 9 requires verifiable parental consent for processing data of individuals under 18. Non‑compliance can attract a maximum penalty of ₹200 crore under Schedule 1.

When must a company register as a Consent Manager?

Rule 11 of the DPDP Rules, 2025 requires Consent Managers to register with the Data Protection Board within 12 months of the Rules notification, i.e., by November 2026.

What extra obligations do Significant Data Fiduciaries face?

If designated under Section 10, an SDF must appoint a resident Data Protection Officer, an independent Data Auditor, and conduct periodic Data Protection Impact Assessments.

Topics:digital personal data protection actDPDPA compliance stepsIndian data privacy consentprivacy policy vs consent Indiadata protection board penaltieschildren data protection Indiasignificant data fiduciary requirementsdata breach notification India

Ready to incorporate or sort your compliance?

Our team handles every filing. You focus on building.