Data Strategy Briefing — India Digital Personal Data Protection Act Assent
India's President gave assent to the Digital Personal Data Protection Act on 11 August 2023, establishing a national consent-led privacy regime, cross-border transfer controls, and penalty framework that organizations processing Indian data must now implement.
India's Digital Personal Data Protection Act (DPDP Act) received presidential assent on 11 August 2023. The law introduces a consent-centric framework, defines obligations for data fiduciaries and significant data fiduciaries, and empowers the Data Protection Board to levy penalties for noncompliance. It also sets conditions for cross-border transfers, with government notifications defining approved jurisdictions.
What changed
- Data fiduciaries must secure consent (or rely on limited legitimate uses) for processing and provide withdrawal, access, and correction rights to data principals.
- Significant data fiduciaries face additional duties: DPIAs, independent audits, appointing a Data Protection Officer based in India, and grievance redressal mechanisms.
- Cross-border transfers are allowed unless restricted by government notification; penalties can reach billions of rupees for violations.
Why it matters
- Enterprises handling Indian personal data must implement consent management, notice updates, and withdrawal handling aligned with the DPDP Act.
- Vendors and cloud providers need to evaluate whether they qualify as significant data fiduciaries and prepare for audits, DPIAs, and local representation.
- Cross-border data strategies must track forthcoming whitelists/blacklists to determine whether data localization or regional processing is required.
Action checklist
- Inventory Indian personal data flows, update privacy notices, and deploy consent/withdrawal workflows that log signals for auditability.
- Assess whether you meet significant data fiduciary thresholds and prepare DPIA templates, board reporting, and DPO appointment plans.
- Monitor government notifications on permitted destinations and refresh contracts and technical controls for transfers accordingly.
Continue in the Data Strategy pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Data Interoperability Engineering Guide — Zeph Tech
Engineer interoperable data exchanges that satisfy the EU Data Act, Data Governance Act, European Interoperability Framework, and ISO/IEC 19941 portability requirements.
-
Data Stewardship Operating Model Guide — Zeph Tech
Establish accountable data stewardship programmes that meet U.S. Evidence Act mandates, Canada’s Directive on Service and Digital, and OECD data governance principles while…
-
Data Strategy Operating Model Guide — Zeph Tech
Design a data strategy operating model that satisfies the EU Data Act, EU Data Governance Act, U.S. Evidence Act, and Singapore Digital Government policies with measurable…




