Skip to main content
DPDP Act 2023 · India

Avoid ₹250 crore exposure with safeguards you can evidence.

The DPDP Act sets penalties of up to ₹250 crore for failing to take reasonable security safeguards. Summit tests the systems that hold personal data and documents the fixes, so leadership can show its safeguards were real.

Human-led VAPT · NDA first · report in 48h

2023
the year the Act was passed, with Rules notified later and obligations phased in
₹250 cr
maximum penalty for failing to take reasonable security safeguards
6
core themes: notice, consent, purpose, safeguards, breach, rights
Phased
roughly 18 months of transition for most obligations after the Rules
Board and leadership view

Why the DPDP Act matters to your board

The work is technical. The consequences of getting India DPDP wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Customer trust and market access

Indian consumers and enterprise buyers expect clear consent and safe handling. Weak practice costs deals.

Penalty exposure

Penalties reach ₹250 crore for failing to take reasonable security safeguards. Documented testing is useful context.

Reputation after a breach

Breaches must be reported to the Data Protection Board and affected people. Tested safeguards lower that risk.

Phased deadlines and ownership

Obligations phase in over time. Starting now spreads the engineering work and avoids a rush.

Fit

Who should prepare

Indian SaaS and consumer apps

Any digital product collecting users’ personal data needs notice, consent and safeguards.

Fintech and lending platforms

High-volume personal and financial data makes security safeguards a priority.

Healthtech and edtech

Sensitive categories and children’s data bring extra scrutiny.

Global firms serving India

Offering services to people in India can bring you in scope from abroad.

Scope of work

What Summit delivers for India DPDP

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Safeguards, consent and breach processes compared with the Act and Rules for systems holding personal data.

Penetration testing

Human-led testing of apps, APIs and infrastructure, including vendor integrations.

Control validation

Checks that encryption, access control and logging operate as described.

Evidence pack

Dated reports and fix records that back up your reasonable safeguards claim.

Remediation support and retest

Fix guidance for engineers, then a retest confirming closure.

Board-ready report

Personal data risk, penalty exposure and progress for leadership.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical DPDP readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Map personal data

    Weeks 1 to 3

    Inventory what digital personal data you collect, why, where it is stored and which vendors touch it.

  2. 2

    Redo notice and consent

    Weeks 3 to 6

    Replace blanket consents with purpose-specific notices and make withdrawal simple.

  3. 3

    Add safeguards

    Months 2 to 3

    Apply encryption, access control, logging and backups to systems holding personal data.

  4. 4

    Test the safeguards

    Month 3

    Run a penetration test and fix findings, so “reasonable safeguards” has evidence behind it.

  5. 5

    Prepare breach and rights processes

    Months 3 to 4

    Build incident, notification and grievance workflows and rehearse them.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • An executive summary

    Where personal data is exposed and what to fix first.

  • A safeguards evidence file

    Reports and retest letters that show tested and improved safeguards.

  • A phased readiness roadmap

    Owners and milestones aligned to the Act’s phase-in.

  • A remediation tracker

    Each finding with an owner, severity and status.

  • Support through reviews

    The same Summit team stays with you through customer and regulatory questions.

The detail

What the DPDP Act actually is

The Digital Personal Data Protection Act, 2023 sets rules for processing digital personal data in India, and outside India when goods or services are offered to people in India. It calls the organisation that decides the purpose and means of processing a Data Fiduciary, and the person the data is about a Data Principal.

The core model is notice and consent. Fiduciaries must tell people what data they collect and why, obtain clear consent for that purpose, and collect no more than necessary. There are limited “legitimate uses” in which consent is not needed, and special care is expected for children’s data.

Section 8(5) requires a Data Fiduciary to protect personal data in its possession with reasonable security safeguards to prevent a personal data breach. Breaches must be reported to the Data Protection Board and affected individuals under the Rules. The Rules have been notified and obligations phase in over time, so confirm current dates before planning.

Key terms in plain English

Data Fiduciary
The party that determines why and how personal data is processed. Similar to a GDPR controller.
Data Principal
The individual whose personal data is processed.
Significant Data Fiduciary
A fiduciary designated by the government based on volume, sensitivity and risk, with extra duties.
Consent Manager
A registered entity that lets individuals give, manage and withdraw consent in one place.
Requirements

What fiduciaries are expected to do

A simplified walk through the duties that most often involve engineering and security teams. Confirm exact obligations against the Act and the Rules.

Notice

Clear notice and valid consent

Before processing, give a notice describing the data and purpose, and obtain consent that is free, specific, informed and unambiguous. Withdrawing consent should be as easy as giving it.

What it looks like in practice

  • Itemised notices in plain language
  • Consent records you can retrieve
  • Simple withdrawal in the product
Purpose

Use data only for the stated purpose

Process data only for the purpose it was collected for and erase it when it is no longer needed unless the law requires retention. This reduces both risk and breach impact.

What it looks like in practice

  • Retention schedules in code, not just policy
  • Deletion jobs with logs
  • Data inventory by purpose
8(5)

Section 8(5): reasonable security safeguards

Fiduciaries must protect personal data under their control, including data held by processors. Expect measures such as encryption, access control, monitoring, backups and regular security testing.

What it looks like in practice

  • Access control and encryption
  • Logging and monitoring that supports investigations
  • Penetration tests with fixes tracked
Breach

Reporting personal data breaches

If a personal data breach occurs, the Data Protection Board and each affected person must be informed in the form and time set by the Rules. You need to detect and scope incidents quickly to meet that duty.

What it looks like in practice

  • Detection and triage process
  • Contact paths to regulators and users
  • Post-incident reviews
Rights

Rights of Data Principals

People can request access to a summary of their data, correction, erasure and grievance redress, and can nominate someone to exercise rights on their behalf. A named contact and a working grievance process are expected.

What it looks like in practice

  • A published contact for questions and grievances
  • Request handling with timelines
  • Systems that can find and correct a person’s data
Where testing fits

How penetration testing supports India DPDP

The Act does not prescribe a test, but the standard is “reasonable security safeguards”. When something goes wrong, being able to show that you tested, found and fixed weaknesses is the strongest answer to whether your safeguards were reasonable.

Sec 8(5)

Reasonable security safeguards

A dated penetration test report plus a retest is concrete proof that safeguards were challenged and improved.

Processors

Safeguards across vendors

You remain responsible for data your processors handle. Testing integrations and APIs shows where data can leak.

Breach reduction

Lowering the chance of an incident

Finding broken access control and exposed endpoints before attackers do is the best way to avoid a reportable breach.

Penalty exposure

Mitigating enforcement risk

Penalties reflect the nature and gravity of the breach and the steps taken. Documented testing is useful context.

Avoid these

Common India DPDP mistakes, and how to avoid them

!

Treating consent as a banner

Consent must be specific to a purpose and easy to withdraw. A single “accept all” tick is a weak foundation.

!

No data inventory

You cannot protect, delete or report on data you cannot locate.

!

Forgetting processors

Fiduciaries remain accountable for what vendors do with personal data.

!

Waiting for the final deadline

Security and consent changes touch product and engineering. Start while the phase-in period is running.

FAQ

India DPDP questions, answered

Is the DPDP Act the same as GDPR?

They share ideas but differ in detail. The DPDP Act has fewer lawful grounds, a notice and consent centre, and a Data Protection Board model. Do not assume GDPR work transfers one to one.

Does the DPDP Act apply to foreign companies?

Yes, when they process digital personal data outside India in connection with offering goods or services to people in India.

What counts as reasonable security safeguards?

The Act and Rules set expectations such as encryption, access control, monitoring and backups. “Reasonable” depends on risk, so documented testing helps you justify your choices.

What are the DPDP penalties?

The Act sets a schedule of monetary penalties, up to ₹250 crore for failing to take reasonable security safeguards. The Board decides amounts case by case.

Is this legal advice?

No. It is general education. Summit focuses on security assessment, testing evidence and board-ready reporting, and stays with your team through reviews while your legal team interprets the Act.

Ready to get India DPDP sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →