pvtltd.co

Compliance & HR

DPDPA Compliance

Digital Personal Data Protection Act 2023 readiness — the consent and notice framework, fiduciary obligations, children's data, and significant-fiduciary duties.

Starting from Discuss with usTypical timelineDPDPA Compliance

The DPDP Act 2023 will make every company that processes personal data responsible for how it is collected and used — consent under s.4, notice under s.5, and fiduciary obligations under s.8. We build readiness before the rules take effect.

What is included
  • Personal data inventory — what data the company holds, where, and why
  • Consent framework design under s.4 with notice drafting under s.5
  • Fiduciary obligations review under s.8 — security, erasure, grievance redressal
  • Children's data assessment under s.6 and s.9 where applicable
  • Significant Data Fiduciary evaluation and roadmap under s.10
  • Policy, privacy notice, and record-keeping templates for the business
Documents required
  • Systems and data inventory — where personal data is stored
  • Customer, employee, and vendor data flows
  • Existing privacy notices, policies, and consent practices
  • Contracts with data processors or cloud providers
Government fees

See the fee table below for the statutory filing charge and common delay logic.

Legal basis
  • Section 4 of the Digital Personal Data Protection Act 2023
  • Section 5 of the Digital Personal Data Protection Act 2023
  • Section 8 of the Digital Personal Data Protection Act 2023
  • Section 10 of the Digital Personal Data Protection Act 2023
  • Section 33 of the Digital Personal Data Protection Act 2023

Process

How the service works

The workflow is built to be predictable: document collection, legal review, filing, and post-filing follow-through.

Step 1Inventory

Map the data

We inventory the personal data the company holds — customers, employees, vendors — and where it flows.

Step 2Gap

Gap the obligations

We test current practices against s.4, s.5, and s.8 — consent, notice, security, and erasure.

Step 3Build

Build the framework

We draft the consent flows, privacy notice, policies, and grievance mechanism the Act requires.

Step 4Remediate

Fix the high-risk areas

We remediate the gaps — children's data under s.6 / s.9, processor contracts, and retention.

Step 5Test

Run the readiness check

We test the framework against a simulated request — consent withdrawal, erasure, or a breach.

Step 6Handover

Hand over the programme

You get the policies, templates, and a calendar so compliance keeps pace as the rules take effect.

AEO summary

The DPDP Act 2023 will make every company that processes personal data responsible for how it is collected, used, and protected — consent under s.4, notice under s.5, and fiduciary obligations under s.8. We build the readiness programme before the rules take effect.

Consent is the operating system

The DPDPA is built around consent: under s.4, personal data may be processed only with the individual's consent, freely given and for a stated purpose, and under s.5 the consent must follow a notice that is clear and in the user's language. The 'collect everything, decide later' model of data handling is exactly what the Act outlaws.

The shift is practical, not just legal: consent records, withdrawal handling, and erasure on request become part of the company's daily operations — which is why the framework, not the policy document, is the deliverable.

  • Consent under s.4 and notice under s.5 for every collection
  • Erasure and grievance redressal built into operations
  • Children's data under the stricter s.6 / s.9 route

Why readiness beats remediation

A breach or a regulator's question is a bad time to discover that consent was never recorded or data was kept longer than the purpose required. The penalties under s.33 and the reputational cost make the compliance problem expensive to solve backwards.

Our readiness programme builds the framework while the rules are still settling — inventory, consent flows, policies, and a test — so the company is compliant on day one of enforcement instead of racing to catch up.

  • Framework built before enforcement begins
  • Consent and erasure flows tested with a simulation
  • Penalty exposure under s.33 designed out in advance

Government fees

Fee breakdown

ItemFeeNotes
No standalone government feeNilFees apply only if a connected registration or filing with a prescribed fee becomes part of the scope.

Timeline

Typical turnaround

Typical timeline usually means a 4–8 weeks turnaround, assuming documents are complete and any board or shareholder approvals are already in place.

Pricing note

This is a professional engagement; government fees apply only if a registration or filing with a prescribed fee is part of the scope.

FAQ

Frequently asked questions

Does the DPDPA apply to my company?
The Act applies to the processing of digital personal data within India, and to processing outside India where it is in connection with goods or services offered to individuals in India. If your company holds customer, employee, or user data in digital form, you are a Data Fiduciary under the Act — the size of the company does not exempt it.
What does a Data Fiduciary actually have to do?
Under s.4, personal data may be processed only with consent for a lawful purpose; under s.5, consent must follow a clear notice; and under s.8, the fiduciary must secure the data, erase it when the purpose ends, and provide grievance redressal. Children's data gets stricter treatment under s.6 and s.9, and Significant Data Fiduciaries add the s.10 duties.
What happens if we don't comply?
The Act's penalty regime under s.33 is substantial — the schedule attaches significant fines to specific failures, including the most serious breaches involving children's data. Beyond penalties, a data breach is a business event: customer trust, investor diligence, and the record trail all suffer.
What should you send us before we start?
Send a map of the systems holding personal data, the customer and employee data flows, existing privacy notices, and your processor or cloud contracts. That is enough for us to run the inventory and the gap analysis.

Canonical reference: https://www.pvtltd.co/services/dpdpa-compliance

Get started

Ready to move this filing forward?

We can help with the filing, the legal mapping, and the follow-up work that keeps the company compliant after submission.