DPDP Act 2023
India’s data protection law applies to you.
The Digital Personal Data Protection Act 2023 is activity-based, not sector-based. There is no industry carve-in and no opt-out: if you process the digital personal data of people in India, you are a Data Fiduciary. Here is what that obliges you to do, and where CyberLetics fits.
DPDPA 2023 is included from the Starter plan.
Scope
Who it applies to
The law keys on Data Principals within the territory of India, not on citizenship. Section 3 reaches processing outside India where it relates to offering goods or services to people in India.
The Act applies if any one of these is true: you collect personal data (names, emails, phone numbers, Aadhaar) from people in India; you offer goods or services to people in India, wherever you are incorporated (Section 3); or you store or process that data anywhere, in the cloud, on-premise or through a vendor. If so you are a Data Fiduciary under the Act. Citizenship and server location are irrelevant.
Timeline
The window is already open
Most teams need 6–12 months to remediate. Count back from May 2027, not forward from today.
The Rules were notified on 13 November 2025 and the clock started then. The Data Protection Board moves to active supervision on 13 November 2026, and full penalties of up to ₹250 crore per breach apply from 13 May 2027. Most teams need 6 to 12 months to remediate.
The obligations
What the Act actually requires
The operative duties sit in Sections 4 to 16. These are the ones that translate into work for a small or mid-sized business.
| Section | Requirement | What it means in practice |
|---|---|---|
S.4 |
Lawful purpose | Process personal data only for a lawful purpose, with consent or a permitted legitimate use. No purpose, no processing. |
S.5 |
Notice | Before or at the time of seeking consent, tell the person what data you want, the purpose, how to withdraw, and how to complain to the Board. Available in English and the Eighth Schedule languages. |
S.6 |
Consent | Must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the stated purpose. It must be as easy to withdraw as it was to give. |
S.7 |
Legitimate uses | A closed list where consent is not required — including data voluntarily given for a stated purpose, employment purposes, medical emergencies and legally mandated disclosures. |
S.8(1) |
Accuracy | Where the data is used to make a decision affecting the person, or is shared with another Fiduciary, ensure it is complete, accurate and consistent. |
S.8(2) |
Security safeguards | Take reasonable technical and organisational measures to prevent a breach. This is the clause behind the largest penalty in the Act. |
S.8(4) |
Retention and erasure | Erase personal data once the purpose is served and retention is no longer required by law — and cause your Processors to do the same. |
S.8(5) |
Accountability | You remain responsible for compliance even where processing is carried out by a Processor on your behalf. Contracts do not transfer the duty. |
S.8(6) |
Breach notification | On becoming aware of a personal data breach, notify the Board and every affected Data Principal. The Rules require intimation without delay, followed by detailed particulars to the Board within 72 hours. |
S.9 |
Children’s data | Anyone under 18 requires verifiable parental consent. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. Stricter than GDPR, which uses 13–16. |
S.10 |
Significant Data Fiduciaries | If notified as an SDF, you additionally need a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments. |
S.11 |
Right to access | On request, give the person a summary of their data, the processing activities, and the identities of other Fiduciaries it has been shared with. |
S.12 |
Correction and erasure | Provide a route to correct, complete, update and erase personal data. |
S.13 |
Grievance redressal | Publish a readily available means of grievance redressal and respond within the prescribed period. This must exist before a complaint reaches the Board. |
S.14 |
Right to nominate | Let a Data Principal nominate someone to exercise their rights in the event of death or incapacity. |
S.16 |
Cross-border transfer | Transfer outside India is permitted except to countries the Central Government restricts by notification. Sector regulators may impose stricter limits. |
S.17 |
Exemptions | Notably S.17(1)(d): processing the data of non-Indian Data Principals under a contract with a foreign entity is largely outside the Act — the carve-out India’s IT-services and BPO sector relies on. |
The stakes
Penalties are assessed per breach of obligation
Schedule 1 sets the maximum penalty the Data Protection Board may impose. These become live at hard enforcement on 13 May 2027.
Failure to take reasonable security safeguards — S.8(2)
Failure to notify a personal data breach — S.8(6)
Breach of the children’s-data obligations — S.9
Breach of the additional Significant Data Fiduciary duties — S.10
Breach of any other provision of the Act
How CyberLetics helps
From “we should probably do this” to an evidenced position
CyberLetics ships 13 DPDPA 2023 controls mapped to the operative sections, alongside the consent, ROPA and data-request machinery the Act actually requires.
Connect your systems (AWS, Microsoft 365, devices). Signals are collected every six hours. Each becomes an evidence snapshot with a SHA-256 checksum that cannot be edited. Controls are evaluated as pass or fail with that proof attached. Your score updates live and your auditor gets a read-only view of the controls, evidence and history.
A pre-loaded control library
13 controls mapped to Sections 4 to 16. Start from a checklist, not a blank page.
Evidence that cannot be quietly edited
Every item is snapshotted with a SHA-256 checksum. Nothing changes after the fact.
Evidence collected for you
Connect Microsoft 365 or AWS. Re-checked every six hours, written to the trail.
A live score, not an annual scramble
Every control has a status and a history. Watch the number move.
Policies, risks and remediation in one place
Policy templates, a risk register and remediation tasks tied to controls.
Read-only access for your auditor
A scoped read-only view for your assessor. No screenshots by email.
info What CyberLetics does not do
CyberLetics is not a law firm and this page is not legal advice. We help you implement, evidence and monitor controls; whether your specific processing is lawful under the DPDP Act is a judgement your counsel has to make. We do not act as your Consent Manager (a role requiring registration with the Board), we do not notify the Board on your behalf, and using CyberLetics does not by itself make you compliant.
See where you stand before November
Start with a free website scan, or open a 14-day trial and work the DPDPA control set end to end.
Also covered