The Digital Personal Data Protection Act: What Every Business Must Do Before the Rules Take Effect
A practical guide to consent, purpose limitation and breach-notification duties under India’s DPDP Act — and what to build into products now.
18 Mar 2026
The Digital Personal Data Protection Act, 2023 is law; the Rules under it are expected shortly. Businesses that collect personal data — from HR records to app telemetry — should use this window to fix basics: know what you collect, why you collect it, and how you obtain consent.
Key duties under the Act
- Consent and notice: Request consent for a specific purpose, describe it in clear language, and allow withdrawal and correction. Bundling unrelated purposes into a single consent will not comply.
- Purpose limitation and storage: Keep data only for the stated purpose and delete it when the purpose is complete or consent is withdrawn.
- Reasonable safeguards and breach reporting: Put technical and organisational measures in place and notify the Data Protection Board and affected individuals without undue delay when a breach occurs.
- Processor contracts: If you use vendors to process data, engage them only under a written contract that binds them to the Act’s duties.
What to do this quarter
Map data flows, classify personal data, inventory consents and draft a retention schedule. Update privacy notices and internal policies, train product and support teams, and run a tabletop breach exercise. For new features, complete a short data-protection impact note before you build.
We are helping clients with fixed-scope gap reviews — data mapping, notice and consent rewrites, and processor addenda — so the Rule notification does not become a scramble.