DPDP Act 2023

India’s data protection law applies to you.

The Digital Personal Data Protection Act 2023 is activity-based, not sector-based. There is no industry carve-in and no opt-out: if you process the digital personal data of people in India, you are a Data Fiduciary. Here is what that obliges you to do, and where CyberLetics fits.

security Check your exposure free See pricing

DPDPA 2023 is included from the Starter plan.

Scope

Who it applies to

The law keys on Data Principals within the territory of India, not on citizenship. Section 3 reaches processing outside India where it relates to offering goods or services to people in India.

Does the DPDP Act apply to you? If you collect personal data from people in India, offer goods or services to people in India, or store or process that data anywhere, you are a Data Fiduciary. Citizenship and server location are irrelevant.Do you collect personal datafrom people in India?names, emails, phone, AadhaarYESDo you offer goods or servicesto people in India?wherever you are incorporatedYESDo you store or process itanywhere at all?cloud, on-prem or a vendorYESANY ONE IS ENOUGHYou are a Data Fiduciary under the ActCitizenship and server location are irrelevant

The Act applies if any one of these is true: you collect personal data (names, emails, phone numbers, Aadhaar) from people in India; you offer goods or services to people in India, wherever you are incorporated (Section 3); or you store or process that data anywhere, in the cloud, on-premise or through a vendor. If so you are a Data Fiduciary under the Act. Citizenship and server location are irrelevant.

Timeline

The window is already open

Most teams need 6–12 months to remediate. Count back from May 2027, not forward from today.

DPDP enforcement timeline: Rules notified 13 November 2025; active supervision by the Board from 13 November 2026; full penalties of up to 250 crore rupees per breach from 13 May 2027.13 Nov 2025Rules notifieddone - the clock started13 Nov 2026Active supervisionthe Board starts enforcing13 May 2027Full penaltiesup to ₹250 Cr per breach12 months6 months

The Rules were notified on 13 November 2025 and the clock started then. The Data Protection Board moves to active supervision on 13 November 2026, and full penalties of up to ₹250 crore per breach apply from 13 May 2027. Most teams need 6 to 12 months to remediate.

The obligations

What the Act actually requires

The operative duties sit in Sections 4 to 16. These are the ones that translate into work for a small or mid-sized business.

Section Requirement What it means in practice
S.4 Lawful purpose Process personal data only for a lawful purpose, with consent or a permitted legitimate use. No purpose, no processing.
S.5 Notice Before or at the time of seeking consent, tell the person what data you want, the purpose, how to withdraw, and how to complain to the Board. Available in English and the Eighth Schedule languages.
S.6 Consent Must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the stated purpose. It must be as easy to withdraw as it was to give.
S.7 Legitimate uses A closed list where consent is not required — including data voluntarily given for a stated purpose, employment purposes, medical emergencies and legally mandated disclosures.
S.8(1) Accuracy Where the data is used to make a decision affecting the person, or is shared with another Fiduciary, ensure it is complete, accurate and consistent.
S.8(2) Security safeguards Take reasonable technical and organisational measures to prevent a breach. This is the clause behind the largest penalty in the Act.
S.8(4) Retention and erasure Erase personal data once the purpose is served and retention is no longer required by law — and cause your Processors to do the same.
S.8(5) Accountability You remain responsible for compliance even where processing is carried out by a Processor on your behalf. Contracts do not transfer the duty.
S.8(6) Breach notification On becoming aware of a personal data breach, notify the Board and every affected Data Principal. The Rules require intimation without delay, followed by detailed particulars to the Board within 72 hours.
S.9 Children’s data Anyone under 18 requires verifiable parental consent. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. Stricter than GDPR, which uses 13–16.
S.10 Significant Data Fiduciaries If notified as an SDF, you additionally need a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments.
S.11 Right to access On request, give the person a summary of their data, the processing activities, and the identities of other Fiduciaries it has been shared with.
S.12 Correction and erasure Provide a route to correct, complete, update and erase personal data.
S.13 Grievance redressal Publish a readily available means of grievance redressal and respond within the prescribed period. This must exist before a complaint reaches the Board.
S.14 Right to nominate Let a Data Principal nominate someone to exercise their rights in the event of death or incapacity.
S.16 Cross-border transfer Transfer outside India is permitted except to countries the Central Government restricts by notification. Sector regulators may impose stricter limits.
S.17 Exemptions Notably S.17(1)(d): processing the data of non-Indian Data Principals under a contract with a foreign entity is largely outside the Act — the carve-out India’s IT-services and BPO sector relies on.

The stakes

Penalties are assessed per breach of obligation

Schedule 1 sets the maximum penalty the Data Protection Board may impose. These become live at hard enforcement on 13 May 2027.

₹250 Cr

Failure to take reasonable security safeguards — S.8(2)

₹200 Cr

Failure to notify a personal data breach — S.8(6)

₹200 Cr

Breach of the children’s-data obligations — S.9

₹150 Cr

Breach of the additional Significant Data Fiduciary duties — S.10

₹50 Cr

Breach of any other provision of the Act

How CyberLetics helps

From “we should probably do this” to an evidenced position

CyberLetics ships 13 DPDPA 2023 controls mapped to the operative sections, alongside the consent, ROPA and data-request machinery the Act actually requires.

How CyberLetics keeps you compliant: connect your systems, signals are collected every six hours, each becomes an immutable SHA-256 evidence snapshot, controls are evaluated against it, and your live score and a read-only auditor view update automatically.Connectyour systemsAWS, M365, devicesSignalscollectedevery six hoursEvidencesnapshotSHA-256, immutableControlevaluatedpass or fail, with proofLivescoreread-only auditor view

Connect your systems (AWS, Microsoft 365, devices). Signals are collected every six hours. Each becomes an evidence snapshot with a SHA-256 checksum that cannot be edited. Controls are evaluated as pass or fail with that proof attached. Your score updates live and your auditor gets a read-only view of the controls, evidence and history.

inventory_2

A pre-loaded control library

13 controls mapped to Sections 4 to 16. Start from a checklist, not a blank page.

verified_user

Evidence that cannot be quietly edited

Every item is snapshotted with a SHA-256 checksum. Nothing changes after the fact.

sync

Evidence collected for you

Connect Microsoft 365 or AWS. Re-checked every six hours, written to the trail.

monitoring

A live score, not an annual scramble

Every control has a status and a history. Watch the number move.

assignment

Policies, risks and remediation in one place

Policy templates, a risk register and remediation tasks tied to controls.

group

Read-only access for your auditor

A scoped read-only view for your assessor. No screenshots by email.

info What CyberLetics does not do

CyberLetics is not a law firm and this page is not legal advice. We help you implement, evidence and monitor controls; whether your specific processing is lawful under the DPDP Act is a judgement your counsel has to make. We do not act as your Consent Manager (a role requiring registration with the Board), we do not notify the Board on your behalf, and using CyberLetics does not by itself make you compliant.

See where you stand before November

Start with a free website scan, or open a 14-day trial and work the DPDPA control set end to end.

security Scan my site free Start 14-day trial

Also covered

ISO 27001:2022 →

The certifiable information security management standard. 30 Annex A controls shipped.

SOC 2 Type II →

The attestation US buyers ask for. 18 common criteria shipped.