The DPDP Act, 2023: a practical compliance overview for Indian businesses
Notice, consent, data-principal rights and breach notification — what the Digital Personal Data Protection Act requires of businesses processing personal data.
The core obligations
Under the Digital Personal Data Protection Act, 2023, entities processing personal data must give notice of the purpose of processing, obtain consent where processing is not for a legitimate use, and honour the rights of data principals to access, correct and erase their data.
Practical readiness steps
Map the data you hold, issue role-based notices, update privacy policies and consent mechanisms, implement breach detection and a notification process, and document vendor obligations through data-processing agreements.
What most companies miss
The absence of a data inventory, unclear retention timelines, and consent designed as an afterthought. Compliance is an operational exercise, not a single policy document.
This note is general information, not legal advice.
