Data protection in India is governed primarily by the Digital Personal Data Protection Act, a landmark statute that fundamentally reshapes how organisations collect, process and store personal data of Indian residents. For international businesses operating in India or handling data of Indian citizens from abroad, the Act creates binding obligations that carry significant financial penalties for non-compliance. This guide covers the legal framework, key obligations, enforcement landscape, cross-border data transfer rules, and practical steps every organisation should take to achieve compliance.
The legal framework governing data protection in India
India';s data protection regime rests on several legal instruments, with the Digital Personal Data Protection Act - referred to throughout this guide as the DPDP Act - forming the centrepiece. The DPDP Act was enacted by Parliament and received presidential assent, establishing a comprehensive framework for the processing of digital personal data. It replaces the earlier, patchwork regime under the Information Technology Act and its associated rules, which had governed data handling since the early part of this century.
The DPDP Act introduces a consent-based model for data processing. Organisations - termed "Data Fiduciaries" under the Act - must obtain free, specific, informed and unambiguous consent from individuals, called "Data Principals," before processing their personal data. The consent mechanism must be presented in plain language and must be as easy to withdraw as it is to give. This requirement alone demands a significant overhaul of how most businesses currently manage user consent flows, privacy notices and data collection forms.
Alongside the DPDP Act, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules remain relevant for certain categories of sensitive data, including financial information, health records and biometric data. Organisations handling such categories face a higher standard of care. The Reserve Bank of India and the Securities and Exchange Board of India have also issued sector-specific data localisation and security directives that operate in parallel with the DPDP Act.
The Act establishes the Data Protection Board of India as the primary enforcement authority. The Board has the power to investigate complaints, conduct inquiries and impose financial penalties. It operates as a digital-first body, meaning most proceedings and filings are conducted electronically, which is a deliberate design choice to enable faster resolution of complaints.
Key obligations for Data Fiduciaries under the DPDP Act
The DPDP Act places a structured set of obligations on Data Fiduciaries, which are any entities that determine the purpose and means of processing personal data. These obligations apply to both Indian-incorporated entities and foreign organisations that process personal data of individuals located in India in connection with any activity offering goods or services to them.
Consent and notice requirements. Before collecting personal data, a Data Fiduciary must provide a notice that clearly describes what data is being collected, the purpose of processing, and the rights available to the Data Principal. The notice must be available in English and in any of the languages listed in the Eighth Schedule to the Indian Constitution, upon request. A common mistake among foreign companies entering the Indian market is to simply translate their existing GDPR-compliant privacy notice without adapting it to the specific language and structural requirements of the DPDP Act.
Data minimisation and purpose limitation. A Data Fiduciary may collect only the personal data necessary for the specified purpose and must not retain it beyond the period required to fulfil that purpose. Once the purpose is served and there is no legal obligation to retain the data, it must be erased. In practice, many organisations underestimate the operational complexity of building automated deletion workflows, particularly for legacy systems that were not designed with data lifecycle management in mind.
Security safeguards. Every Data Fiduciary must implement reasonable security safeguards to prevent personal data breaches. The Act does not prescribe a specific technical standard, but regulators and courts have historically referenced ISO 27001 and similar frameworks as benchmarks. In the event of a personal data breach, the Data Fiduciary must notify the Data Protection Board and affected Data Principals promptly. The notification obligation is triggered regardless of whether the breach was caused by the fiduciary directly or by a Data Processor acting on its behalf.
Significant Data Fiduciaries. The central government has the power to designate certain entities as Significant Data Fiduciaries based on the volume and sensitivity of data processed, potential risk to Data Principals, national security implications and other factors. Entities so designated face additional obligations, including the appointment of a Data Protection Officer based in India, the engagement of an independent data auditor, and the conduct of periodic Data Protection Impact Assessments. This tiered approach mirrors the logic of high-risk processing under GDPR, though the criteria and thresholds are determined by the Indian government rather than set out in the statute itself.
Children';s data. Processing personal data of children - defined as individuals under eighteen years of age - requires verifiable parental consent. Data Fiduciaries are prohibited from tracking or behavioural monitoring of children and from targeting advertising at them. A non-obvious requirement is that the obligation to verify age and obtain parental consent applies even when the service is not specifically directed at children, if the fiduciary has reason to believe a child may be using it.
Cross-border data transfers and localisation requirements
Cross-border data transfers are one of the most commercially significant aspects of data protection in India, particularly for multinational groups that centralise data processing in regional or global hubs outside the country.
The DPDP Act takes a relatively permissive approach to cross-border transfers compared to earlier legislative proposals. Personal data may be transferred to countries or territories notified by the central government as permissible destinations. The government publishes a list of permitted jurisdictions, and transfers to unlisted countries are not automatically prohibited but require additional scrutiny and, in some cases, contractual safeguards or explicit consent. In practice, founders should consider that the list of permitted countries is subject to revision, and organisations should build transfer mechanisms that can be updated without requiring a full redesign of their data architecture.
Sector-specific localisation requirements remain in force and operate independently of the DPDP Act. The Reserve Bank of India requires that payment system data be stored exclusively within India. The Insurance Regulatory and Development Authority of India and other financial regulators have issued similar directives for their respective sectors. Foreign businesses in fintech, insurance and healthcare must therefore map their data flows carefully to ensure that sector-specific rules are satisfied in addition to the general DPDP Act requirements.
A common mistake made by international legal teams is to treat India';s data transfer rules as broadly equivalent to the GDPR';s Chapter V mechanism. The two regimes differ in structure, permitted transfer tools and the role of regulatory approval. Relying on standard contractual clauses designed for GDPR compliance will not, by itself, satisfy Indian requirements.
For multinational groups, the most practical approach is to conduct a data mapping exercise that identifies all personal data of Indian residents, the legal basis for processing, the location of processing and storage, and the applicable transfer mechanism. This exercise should be revisited whenever the government updates the list of permitted transfer destinations or issues new sector-specific guidance.
If your organisation processes personal data of Indian residents across multiple jurisdictions and needs clarity on how to structure compliant transfer arrangements, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Rights of Data Principals and enforcement mechanisms
The DPDP Act grants Data Principals a meaningful set of rights that organisations must be operationally prepared to honour. Understanding these rights is essential for building compliant data handling processes.
Right to access and correction. A Data Principal may request a summary of the personal data held about them and information about the entities with whom it has been shared. They may also request correction of inaccurate or outdated data and erasure of data that is no longer necessary for the original purpose. Data Fiduciaries must respond to such requests within a reasonable timeframe, and the Act empowers the government to prescribe specific timelines by regulation.
Right to grievance redressal. Every Data Fiduciary must establish a grievance redressal mechanism and designate a point of contact for Data Principals. If a complaint is not resolved to the Data Principal';s satisfaction, they may escalate to the Data Protection Board. The Board has the power to summon parties, call for documents and issue binding directions.
Right to nominate. In a provision unique to the Indian framework, Data Principals may nominate another individual to exercise their data rights in the event of death or incapacity. This reflects the broader Indian legal tradition of recognising family and succession interests in personal affairs.
Penalties for non-compliance. The DPDP Act sets out a tiered penalty structure. Breaches of obligations relating to children';s data and failure to implement adequate security measures attract the highest penalties. Failure to notify the Board of a personal data breach and non-compliance with the Board';s directions also carry substantial financial consequences. The penalties are expressed as upper limits, and the Board has discretion to determine the appropriate amount based on the nature, gravity and duration of the breach, the number of affected Data Principals, and whether the fiduciary took steps to mitigate harm. In general terms, the maximum penalties are significant enough to represent a material financial risk for large organisations.
Enforcement posture. The Data Protection Board is a newly constituted body, and its enforcement posture will develop over time as it processes its first wave of complaints and investigations. Organisations that establish robust compliance programmes early are better positioned to demonstrate good faith in any regulatory inquiry. A non-obvious risk is that enforcement may initially focus on high-profile breaches involving large volumes of data, but the Board';s digital-first design means that individual complaints can be filed and escalated with relatively low friction.
Practical compliance steps for international businesses
Achieving compliance with data protection in India requires a structured programme rather than a one-time documentation exercise. The following steps reflect the practical experience of organisations that have worked through the DPDP Act';s requirements.
Conduct a data inventory. Map all personal data of Indian residents that your organisation collects, processes or stores. Identify the legal basis for each processing activity, the retention period, the location of storage and any third parties with whom the data is shared. This inventory forms the foundation of every subsequent compliance step.
Review and update consent mechanisms. Audit existing consent flows, privacy notices and cookie banners to ensure they meet the DPDP Act';s requirements for specificity, clarity and ease of withdrawal. Pay particular attention to bundled consent, which the Act does not permit. Each purpose must be consented to separately.
Assess Significant Data Fiduciary status. Evaluate whether your organisation is likely to be designated as a Significant Data Fiduciary. If so, begin planning for the appointment of an India-based Data Protection Officer, the selection of an independent data auditor, and the implementation of a Data Protection Impact Assessment process.
Review cross-border transfer arrangements. Identify all transfers of Indian personal data to locations outside India. Verify that the destination countries are on the government';s permitted list or that appropriate safeguards are in place. Update data processing agreements with vendors and group entities to reflect Indian requirements.
Establish a breach response plan. Define internal escalation procedures for identifying and assessing personal data breaches. Ensure that the plan includes timelines for notifying the Data Protection Board and affected Data Principals, and that it assigns clear responsibilities to named individuals.
Train staff. Employees who handle personal data must understand their obligations under the DPDP Act. Training should cover consent collection, data minimisation, breach identification and the process for responding to Data Principal requests. Many underestimate the time required to embed these practices across large or geographically dispersed organisations.
Scenario: a global e-commerce company. A multinational retailer selling goods to Indian consumers through a localised website must obtain valid consent before collecting browsing data for personalisation. It must provide a privacy notice in English and, on request, in scheduled Indian languages. If it uses a cloud provider based outside India, it must verify that the cloud provider';s country is a permitted transfer destination. If it processes data of users who may be minors, it must implement age verification and parental consent mechanisms.
Scenario: a B2B software provider. A foreign software-as-a-service company that processes personal data of Indian employees on behalf of Indian corporate clients acts as a Data Processor. Its contracts with Indian clients must include provisions that allow the client to meet its DPDP Act obligations, including audit rights, breach notification obligations and data deletion requirements. The processor must also implement security safeguards that meet the standard required by the Act.
Interaction with global privacy frameworks
Many international businesses operating in India are already subject to other privacy regimes, most commonly the European Union';s General Data Protection Regulation and, for businesses with a US nexus, the California Consumer Privacy Act. Understanding how the DPDP Act interacts with these frameworks helps organisations build efficient, unified compliance programmes rather than managing entirely separate systems.
The DPDP Act shares several structural features with GDPR, including the consent-based processing model, data minimisation, purpose limitation and individual rights. However, there are meaningful differences. The DPDP Act does not recognise legitimate interests as a standalone legal basis for processing, which is one of the most commonly used bases under GDPR. Organisations that rely heavily on legitimate interests for their European processing will need to identify an alternative basis - typically consent or a statutory obligation - for the same activities when they involve Indian personal data.
The DPDP Act also does not include an equivalent to GDPR';s data portability right in its current form, and its approach to automated decision-making is less prescriptive than GDPR';s Article 22. Conversely, the nomination right for deceased or incapacitated Data Principals has no direct GDPR equivalent and requires separate operational planning.
For businesses subject to CCPA, the differences are more pronounced. CCPA operates on an opt-out model for the sale of personal information, whereas the DPDP Act requires opt-in consent for most processing. The categories of sensitive data, the rights available to individuals and the enforcement mechanisms differ substantially. Organisations should resist the temptation to treat their CCPA compliance programme as a template for India.
In practice, the most efficient approach for multinational organisations is to build a privacy programme around the most demanding requirements across all applicable regimes and then identify jurisdiction-specific adjustments. India';s consent requirements and children';s data rules are among the strictest globally and should anchor the design of any unified programme.
---
Frequently asked questions
Does the DPDP Act apply to foreign companies with no physical presence in India?
The DPDP Act applies to the processing of digital personal data of individuals located in India, regardless of where the processing entity is incorporated or physically located. A foreign company that offers goods or services to Indian residents - even without a local office, subsidiary or representative - falls within the Act';s scope if it processes their personal data in connection with that activity. This extraterritorial reach is similar in logic to GDPR';s Article 3(2), though the specific conditions differ. Foreign companies should not assume that the absence of a local entity exempts them from compliance. The Data Protection Board can investigate complaints involving foreign entities, and the reputational and commercial consequences of a public enforcement action can be significant even before any financial penalty is imposed.
How long does it take to build a compliant data protection programme in India?
The timeline depends heavily on the size and complexity of the organisation, the volume of personal data processed and the maturity of existing privacy practices. For a mid-sized international business with established GDPR compliance, adapting to the DPDP Act typically requires several months of focused effort, covering data mapping, consent mechanism redesign, contract updates and staff training. For organisations starting from a lower baseline, the process can take considerably longer. Organisations that have been designated or are likely to be designated as Significant Data Fiduciaries face additional obligations - including appointing an India-based Data Protection Officer and engaging an independent auditor - that add further time and cost. Starting the assessment process early, rather than waiting for enforcement to begin, is the most effective way to manage the timeline.
What is the difference between a Data Fiduciary and a Data Processor under the DPDP Act?
A Data Fiduciary is any entity that determines the purpose and means of processing personal data. A Data Processor is any entity that processes personal data on behalf of a Data Fiduciary. The distinction matters because the primary compliance obligations under the DPDP Act - consent, notice, rights fulfilment, breach notification to the Board - rest with the Data Fiduciary. A Data Processor';s obligations are largely contractual, flowing from the agreement with the Data Fiduciary. However, a Data Processor must still implement adequate security safeguards and must notify the Data Fiduciary of any breach promptly so that the fiduciary can meet its own notification obligations. In many B2B arrangements, the same entity may act as a Data Fiduciary for some processing activities and as a Data Processor for others, which requires careful analysis of each data flow.
---
Conclusion
Data protection in India has entered a new phase with the DPDP Act establishing clear, enforceable obligations for both domestic and international organisations. The framework is consent-driven, rights-focused and backed by a dedicated enforcement body. Businesses that invest in structured compliance now will be better positioned as enforcement matures and as the government issues implementing regulations that fill in the Act';s remaining details.
VLO Law Firms advises international clients on data protection matters in India. We can assist with DPDP Act compliance assessments, consent mechanism design, cross-border transfer structuring, Data Protection Officer arrangements and contract reviews. To request a consultation, contact: info@vlolawfirm.com