DPDP Act Compliance: A Practical Roadmap for Businesses
India's Digital Personal Data Protection (DPDP) Act creates binding obligations for any business — a "Data Fiduciary" — that processes personal data of individuals in India. Here's a practical roadmap to get ready.
Who it applies to
Any organisation deciding how and why personal data is processed, including foreign companies handling data of people in India. Larger or higher-risk fiduciaries may face additional obligations.
Core obligations
- Process data only with clear, informed consent for a specified purpose
- Provide a plain-language privacy notice
- Honour data-principal rights (access, correction, erasure, grievance)
- Implement reasonable security safeguards
- Report personal-data breaches
- Delete data when the purpose is served
Consent and children
Consent must be free, specific, informed and revocable. Processing children's data needs verifiable parental consent, with limits on tracking and targeted advertising.
A step-by-step roadmap
- Data mapping: inventory what personal data you collect, why, and where it flows
- Notices & consent: rewrite privacy notices and build a consent mechanism
- Rights process: set up channels for access, correction and erasure requests
- Security: apply access controls, encryption and vendor safeguards
- Breach plan: define detection, reporting and response steps
- Governance: assign accountability and train staff
Penalties
Non-compliance can attract significant financial penalties, so early readiness protects both budget and reputation.
Statura helps you map data, draft notices and build consent and breach processes for DPDP readiness.