The Digital Personal Data Protection Act: What Every Business Must Do Before the Rules Take Effect

A practical guide to consent, purpose limitation and breach-notification duties under India’s DPDP Act — and what to build into products now.

18 Mar 2026

By Kavita Reddy

Person reviewing privacy documents on a laptop

The Digital Personal Data Protection Act, 2023 is law; the Rules under it are expected shortly. Businesses that collect personal data — from HR records to app telemetry — should use this window to fix basics: know what you collect, why you collect it, and how you obtain consent.

Key duties under the Act

  • Consent and notice: Request consent for a specific purpose, describe it in clear language, and allow withdrawal and correction. Bundling unrelated purposes into a single consent will not comply.
  • Purpose limitation and storage: Keep data only for the stated purpose and delete it when the purpose is complete or consent is withdrawn.
  • Reasonable safeguards and breach reporting: Put technical and organisational measures in place and notify the Data Protection Board and affected individuals without undue delay when a breach occurs.
  • Processor contracts: If you use vendors to process data, engage them only under a written contract that binds them to the Act’s duties.

What to do this quarter

Map data flows, classify personal data, inventory consents and draft a retention schedule. Update privacy notices and internal policies, train product and support teams, and run a tabletop breach exercise. For new features, complete a short data-protection impact note before you build.

We are helping clients with fixed-scope gap reviews — data mapping, notice and consent rewrites, and processor addenda — so the Rule notification does not become a scramble.

This publication is provided for informational purposes only and does not constitute legal advice. The views expressed are those of the author and do not necessarily reflect the position of the firm.
Request a Consultation

← Back to all insights