India's landmark legislation reshaping how organisations collect, process, and protect personal data. Understand your obligations, protect your users, and build lasting digital trust.
In 2017, the Supreme Court of India declared privacy a fundamental right under Article 21 — setting the stage for comprehensive data protection legislation. Six years later, the vision became law.
Supreme Court identifies privacy as a fundamental right under Article 21
President Droupadi Murmu grants assent to the DPDP Act
Balancing individual data protection with lawful business processing
The DPDP Act casts a wide net — covering organisations of every size and geography that touch Indian personal data.
Any entity processing digital personal data within India — from government bodies to private enterprises.
Organisations outside India offering goods or services to Indian citizens are equally bound by the Act.
Public and private sectors alike — startups, SMEs, and multinationals — must align their data practices.
The DPDP Act establishes three distinct roles, each carrying specific rights and responsibilities in the data ecosystem.
The individual whose personal data is being processed. They hold the right to consent, access, correction, and grievance redressal.
The entity determining the purpose and means of data processing. They bear primary accountability for compliance.
Entities processing data on behalf of a Fiduciary, bound by contractual obligations and oversight requirements.

Consent under the DPDP Act is not a checkbox — it is a legally significant, informed decision by the Data Principal. Section 6 sets a high bar for how organisations must seek and manage approval.
Approval must be specific, informed, and unambiguous — no pre-ticked boxes or vague language.
Organisations must explain what data is collected, why, and how it will be used.
Individuals retain the legal right to withdraw consent at any time, with minimal friction.
Compliance is not just a legal exercise — it demands concrete operational changes led by security and privacy teams.
Map and classify all personal data flows across your organisation and third-party vendor landscape. Know what you hold, where it lives, and who accesses it.
Implement rigorous audit trails and establish clear breach notification protocols aligned with DPDP timelines and regulatory expectations.
Define risk-appropriate governance frameworks for data processors and vendors handling personal data on your behalf.
A structured sprint to move from awareness to action — building a privacy programme that stands up to scrutiny.
Move beyond paper policies. Embed privacy into processes, contracts, and technology stacks.
Prioritise actionable metrics to reduce organisational risk and demonstrate progress to leadership.
Build foundations for a cross-border data strategy aligned with DPDP requirements and business goals.

NITI Aayog's DEPA framework goes beyond compliance — it reimagines data as a tool for citizen empowerment and economic growth through secure, consent-based sharing ecosystems.
Individuals control who accesses their data and for what purpose.
Organisations that embrace DEPA turn compliance into a market differentiator.
The organisations that thrive will be those that treat privacy not as a burden, but as a core business value.
Shift from reactive, defensive compliance to forward-looking data governance that anticipates risk.
Demonstrate measurable privacy maturity to strengthen stakeholder and investor trust.
Foster an organisational culture where privacy enhances brand reputation and market value.
Compliance is a journey — and ManageEngine is with you at every step. From CXO-level guidance to automated enforcement, we help you build a transparent, trusted enterprise.
Access our comprehensive eBook featuring executive checklists, risk frameworks, and actionable DPDP compliance roadmaps designed for leadership teams.
Automate consent management, audit trails, breach detection, and policy enforcement — turning DPDP obligations into streamlined, technology-driven workflows.
Beyond explicit consent, the DPDP Act outlines specific scenarios where consent is 'deemed' to be given. This provision supports critical data processing activities that are necessary for public interest, legal compliance, or essential services, striking a balance between privacy and functionality.
Processing data that the Data Principal voluntarily provides for a specific purpose, where such processing is necessary to fulfil that purpose.
Processing data for employment-related purposes, including recruitment, termination, or providing benefits to employees.
Data processing required for public good, such as national security, crime prevention, or responding to public emergencies.
Processing necessary for medical treatment during emergencies or for public health initiatives, especially during epidemics.
Processing data to comply with any law in force or to adhere to a court order or judgment.
Section 8 of the Digital Personal Data Protection Act, 2023 gives Data Principals meaningful control over their personal data. These rights help individuals access, correct, delete, and manage their information, while also ensuring accountability through grievance redressal and nomination rights.
Access personal data held by the Data Fiduciary and understand how it is being used.
Request correction, update, or completion of inaccurate or incomplete personal data.
Seek deletion of personal data when it is no longer necessary or when retention is no longer justified.
Raise complaints and receive timely resolution through the Data Fiduciary's grievance mechanism.
Nominate another person to exercise rights on the Data Principal's behalf after death or incapacity.
Rule 6 mandates that Data Fiduciaries implement reasonable security safeguards to prevent personal data breaches. This is a foundational operational requirement covering:
Encryption, obfuscation, masking, or virtual tokens to protect personal data
Appropriate measures to control access to computer resources used by Data Fiduciaries and Data Processors
Audit logs, monitoring, and review to detect unauthorized access, investigate incidents, and prevent recurrence
Reasonable measures for continued processing if data confidentiality, integrity, or availability is compromised (e.g., data backups)
Maintain logs and personal data for one year minimum (or as required by law) to enable detection, investigation, and remediation
Include appropriate security safeguard provisions in contracts with Data Processors
Implement effective technical and organizational measures to ensure security safeguards are observed
This rule applies to all personal data in possession or under control of the Data Fiduciary, including data processed by Data Processors on their behalf.
Rule 7 of the Digital Personal Data Protection Act, 2023 sets out mandatory breach notification requirements. A Data Fiduciary must act without delay to inform both affected Data Principals and the Data Protection Board of India, with strict timelines and specific information requirements.
Key principle: Data Fiduciaries must erase personal data when the specified purpose is no longer being served, unless retention is required by law.
48-hour notice: At least 48 hours before the erasure period completes, the Data Fiduciary must inform the Data Principal.
Start your DPDP compliance journey with clarity and confidence. Connect with us to understand what matters, implement the right controls, and move from awareness to action.
Navigating the DPDP,
Digital Personal Data Protection Act, 2023