What is India's DPDP Act?
The Digital Personal Data Protection (DPDP) Act 2023 is India's comprehensive data protection law — the equivalent of GDPR for India. It governs how organisations collect, process, store and transfer personal data of Indian citizens. The Act became enforceable in stages from 2024, with full compliance mandatory by 2026. Any organisation handling personal data of Indian citizens — regardless of where the organisation is headquartered — must comply.
Key requirements under DPDP
Data Protection Officer (DPO): Significant Data Fiduciaries (large-scale data processors) must appoint a DPO. The DPO is responsible for compliance, grievance redressal and liaison with the Data Protection Board of India. This role is creating significant demand for professionals with both legal/compliance and cybersecurity knowledge.
Consent framework: Organisations must obtain explicit, informed consent before collecting personal data. Consent must be purpose-specific — collecting data for one purpose and using it for another is prohibited. Consent must be revocable at any time.
Security obligations: Data Fiduciaries must implement "reasonable security safeguards" to prevent personal data breaches. While the Act does not prescribe specific technical standards, the DPDP Rules reference ISO 27001, NIST and RBI's cybersecurity framework as guidelines.
Breach notification: Data breaches must be notified to the Data Protection Board and affected data principals within a prescribed timeframe. Failure to notify is itself a violation.
Penalties — ₹250 crore maximum
The DPDP Act imposes penalties of up to ₹250 crore per violation. Key penalty categories: failure to implement security safeguards (up to ₹250 crore), failure to notify breaches (up to ₹200 crore), non-compliance with Data Protection Board orders (up to ₹150 crore). These are per-instance penalties — multiple violations in a single breach can accumulate significantly.
How cybersecurity programs help with DPDP compliance
The IIM Indore AI & Cybersecurity Programme explicitly covers DPDP Act compliance as part of its governance module — one of the few IIM programs that directly addresses India's current regulatory framework. For organisations preparing for DPDP compliance, upskilling management teams on both the legal obligations and technical controls is essential. The IIM Nagpur Cyber Security Management & Data Science programme also covers data governance frameworks applicable to DPDP. See all programs at cybercourse.in/programs.
Find the right program for your profile
Free advisor matches you in 20 minutes.
Get free counselling →