Customer trust and market access
Indian consumers and enterprise buyers expect clear consent and safe handling. Weak practice costs deals.
The DPDP Act sets penalties of up to ₹250 crore for failing to take reasonable security safeguards. Summit tests the systems that hold personal data and documents the fixes, so leadership can show its safeguards were real.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting India DPDP wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Indian consumers and enterprise buyers expect clear consent and safe handling. Weak practice costs deals.
Penalties reach ₹250 crore for failing to take reasonable security safeguards. Documented testing is useful context.
Breaches must be reported to the Data Protection Board and affected people. Tested safeguards lower that risk.
Obligations phase in over time. Starting now spreads the engineering work and avoids a rush.
Any digital product collecting users’ personal data needs notice, consent and safeguards.
High-volume personal and financial data makes security safeguards a priority.
Sensitive categories and children’s data bring extra scrutiny.
Offering services to people in India can bring you in scope from abroad.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Safeguards, consent and breach processes compared with the Act and Rules for systems holding personal data.
Human-led testing of apps, APIs and infrastructure, including vendor integrations.
Checks that encryption, access control and logging operate as described.
Dated reports and fix records that back up your reasonable safeguards claim.
Fix guidance for engineers, then a retest confirming closure.
Personal data risk, penalty exposure and progress for leadership.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Inventory what digital personal data you collect, why, where it is stored and which vendors touch it.
Replace blanket consents with purpose-specific notices and make withdrawal simple.
Apply encryption, access control, logging and backups to systems holding personal data.
Run a penetration test and fix findings, so “reasonable safeguards” has evidence behind it.
Build incident, notification and grievance workflows and rehearse them.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Where personal data is exposed and what to fix first.
Reports and retest letters that show tested and improved safeguards.
Owners and milestones aligned to the Act’s phase-in.
Each finding with an owner, severity and status.
The same Summit team stays with you through customer and regulatory questions.
The Digital Personal Data Protection Act, 2023 sets rules for processing digital personal data in India, and outside India when goods or services are offered to people in India. It calls the organisation that decides the purpose and means of processing a Data Fiduciary, and the person the data is about a Data Principal.
The core model is notice and consent. Fiduciaries must tell people what data they collect and why, obtain clear consent for that purpose, and collect no more than necessary. There are limited “legitimate uses” in which consent is not needed, and special care is expected for children’s data.
Section 8(5) requires a Data Fiduciary to protect personal data in its possession with reasonable security safeguards to prevent a personal data breach. Breaches must be reported to the Data Protection Board and affected individuals under the Rules. The Rules have been notified and obligations phase in over time, so confirm current dates before planning.
A simplified walk through the duties that most often involve engineering and security teams. Confirm exact obligations against the Act and the Rules.
Before processing, give a notice describing the data and purpose, and obtain consent that is free, specific, informed and unambiguous. Withdrawing consent should be as easy as giving it.
Process data only for the purpose it was collected for and erase it when it is no longer needed unless the law requires retention. This reduces both risk and breach impact.
Fiduciaries must protect personal data under their control, including data held by processors. Expect measures such as encryption, access control, monitoring, backups and regular security testing.
If a personal data breach occurs, the Data Protection Board and each affected person must be informed in the form and time set by the Rules. You need to detect and scope incidents quickly to meet that duty.
People can request access to a summary of their data, correction, erasure and grievance redress, and can nominate someone to exercise rights on their behalf. A named contact and a working grievance process are expected.
The Act does not prescribe a test, but the standard is “reasonable security safeguards”. When something goes wrong, being able to show that you tested, found and fixed weaknesses is the strongest answer to whether your safeguards were reasonable.
A dated penetration test report plus a retest is concrete proof that safeguards were challenged and improved.
You remain responsible for data your processors handle. Testing integrations and APIs shows where data can leak.
Finding broken access control and exposed endpoints before attackers do is the best way to avoid a reportable breach.
Penalties reflect the nature and gravity of the breach and the steps taken. Documented testing is useful context.
Consent must be specific to a purpose and easy to withdraw. A single “accept all” tick is a weak foundation.
You cannot protect, delete or report on data you cannot locate.
Fiduciaries remain accountable for what vendors do with personal data.
Security and consent changes touch product and engineering. Start while the phase-in period is running.
They share ideas but differ in detail. The DPDP Act has fewer lawful grounds, a notice and consent centre, and a Data Protection Board model. Do not assume GDPR work transfers one to one.
Yes, when they process digital personal data outside India in connection with offering goods or services to people in India.
The Act and Rules set expectations such as encryption, access control, monitoring and backups. “Reasonable” depends on risk, so documented testing helps you justify your choices.
The Act sets a schedule of monetary penalties, up to ₹250 crore for failing to take reasonable security safeguards. The Board decides amounts case by case.
No. It is general education. Summit focuses on security assessment, testing evidence and board-ready reporting, and stays with your team through reviews while your legal team interprets the Act.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.