Back to articles
DPDP Act

The DPDP Act 2023: A Founder's Overview

A plain-English walkthrough of India's Digital Personal Data Protection Act — who it applies to, what changes, and what founders must do first.

March 12, 2025 9 min read Vrushali Borade

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive, horizontal data protection law. Enacted in August 2023 after nearly six years of legislative iteration — from the Justice Srikrishna Committee report to the withdrawn 2019 Bill — it establishes a single framework governing how digital personal data of individuals in India may be collected, stored, used and shared.

The Act applies to any business — Indian or foreign — that processes the digital personal data of individuals located in India, whether that data is collected online or digitised after being collected offline. Extra-territorial reach is explicit: an overseas SaaS company selling to Indian consumers is squarely within scope, regardless of where its servers sit.

Certain narrow exemptions apply — for purely personal or domestic use, publicly available data made public by the individual themselves, and specified research or statistical processing — but every consumer-facing business, employer and B2B platform handling contact data will fall within the Act's regime.

Immediate Priorities for Founders

The immediate priorities for any founder are fourfold. First, map every touchpoint where personal data is collected — website forms, mobile apps, CRM imports, HR systems, vendor tools — and record the purpose, retention period and downstream processors for each.

Second, refresh your privacy notice and consent flows so they meet Section 5's plain-language, itemised requirements, and rebuild your cookie banners and signup forms to capture granular, unbundled consent.

Third, appoint a Data Protection Officer or grievance officer whose contact details are prominently published, and stand up a rights-request intake mechanism with defined SLAs.

Fourth, put a breach-response playbook in place. Notification to the Data Protection Board is mandatory for every personal data breach — there is no severity threshold — and rehearsed workflows make the difference between a controlled disclosure and a regulatory escalation.

Penalties under Schedule 1 can reach ₹250 crore per instance for failure to secure personal data, ₹200 crore for failure to notify a breach, and ₹150 crore for breaches of children's data obligations. Compliance is a board-level concern, not an IT ticket.

How WIN Legal Advisors Can Help

We run a fixed-scope DPDP Readiness Assessment that produces a data map, gap analysis against the Act and draft Rules, refreshed notices and consent flows, a breach-response playbook and a board-ready compliance roadmap — typically within four to six weeks.

Book a consultation to scope your organisation's exposure and build a defensible compliance posture before enforcement begins.

OverviewFoundersCompliance

Have questions on this topic?

Book a confidential consultation with Vrushali Borade.

Book Consultation