Disclaimer

By clicking, "I Accept" below, you accept and acknowledge the following:

The purpose of this website is to provide general information and insights about TLH, Advocates & Solicitors, and not to advertise or solicit work in any manner whatsoever.

Please note that as per the Bar Council of India Rules, advocates in India are prohibited from advertising or soliciting work in any form or manner. You acknowledge that you are visiting this website at your discretion and that there has been no solicitation, invitation, or inducement of any sort whatsoever from TLH, Advocates & Solicitors or any of its professionals in relation to this website.

The content available on this website does not constitute legal or other professional advice and should not be substituted for advice relevant to particular circumstances.

The access and use of this website does not establish any fiduciary or other relationship between you and TLH, Advocates & Solicitors or any of its advocates.

Please read the ‘Terms of Use’ and our ‘Privacy Policy’ before accessing this website.

Blog default background
Blog
Information Technology

India’s DPDP Regime in its Implementation Phase

Authors:
George Varghese
Shreya Nair
July 30, 2026
5 min read
Share this post
Copied!

Part I: A Practical Introduction for Businesses

For several years, discussion of India’s digital economy has centered on the anticipation of a dedicated personal data protection framework. The enactment of the Digital Personal Data Protection Act, 2023[1] (“DPDP Act”) marked a significant legislative shift toward recognizing privacy and digital governance as central components of India’s regulatory architecture. With the introduction of the Digital Personal Data Protection Rules, 2025[2] (“DPDP Rules”), the framework has now entered what may be described as its implementation phase.

Much of the conversation has focused on consent notices, privacy policies and penalties. These are effectively the visible outputs of a larger exercise. The DPDP regime is, at its core, a governance framework. It expects businesses to understand how personal data moves through their organisation, who is responsible for it, and whether businesses are able to justify retaining said data at every stage of the journey.

Against this backdrop, the DPDP Act and the DPDP Rules signal the beginning of a broader transition in how businesses are expected to govern data across their operations. The practical question is whether these businesses understand how that data moves and whether appropriate governance mechanisms are in place for it.

1. Does the DPDP Regime Apply to Your Business?

The DPDP Act applies to digital personal data processed within India and, in certain circumstances, to information being processed outside India for goods or services offered to individuals located in India. Importantly, the framework is not restricted to a certain kind of business or company. A retail company maintaining customer databases, a healthcare provider handling patient records, a Global Capability Centre (“GCC”) processing employee information in India, or a manufacturing company using digital HR systems / CRM systems may all be processing personal data within the meaning of the Act.[3]

If your organisation collects, stores, shares, analyses, or uses personal information digitally in your business, the framework is likely relevant. Businesses should begin by asking a few fundamental questions:

1.1  What personal data do we collect?

1.2  Where is it stored?

1.3  Who has access to it?

1.4  Is it shared with third-party vendors?

1.5  Why do we collect it, and for how long do we retain it?

These questions enable organisations to identify unnecessary data collection, duplicate databases, legacy systems, and vendor relationships that may expose the business to operational and regulatory risk. Historically, privacy compliance often centred on lengthy privacy policies and broad consent language. The DPDP regime shifts the focus towards transparency, accountability and purpose-specific processing. Businesses should therefore be able to communicate, in clear and accessible language, what personal data is being collected, why it is required, how it will be used, and how individuals may exercise their rights, including the right to withdraw consent.[4]

Consider the journey of a typical customer. Personal data may be collected through a website, an app, a loyalty programme, and other such avenues, often within a single transaction. The challenge is ensuring that consent remains meaningful across each of these touchpoints. The practical takeaway herein is that privacy notices should be reviewed from the perspective of an ordinary user. If your average customer cannot easily understand how their data is being used, it may be time to revisit existing notices.

2. What Should Businesses Be Doing Now?

Although implementation of the DPDP framework will continue to evolve, businesses should not wait for regulatory enforcement / intervention before strengthening their internal governance.

2.1 Map your data: Develop a clear understanding of what personal data is collected, where it resides, how it flows across the organisation, and whether every stage of processing remains necessary. Data mapping often reveals redundant processes, duplicate repositories and excessive data retention that can be addressed proactively.

2.2 Review privacy notices and consent mechanisms: Privacy notices should be concise, transparent and reflect actual business practices. Consent should not be viewed as a one-time formality but as an ongoing process that enables individuals to understand how their personal data will be used and to withdraw consent with ease.

2.3 Reassess vendor arrangements: Most organisations rely extensively on third-party processors and vendors. Contracts should clearly allocate privacy obligations, prescribe appropriate security standards, establish breach notification procedures and address liability and indemnity in the event of a personal data breach.

2.4 Examine retention practices: Confirm that personal data is not retained beyond what is necessary for the stated purpose. Periodic reviews of retention schedules can reduce both regulatory exposure and cybersecurity risk.

2.5 Review incident response procedures: Once it is confirmed that personal data is not retained beyond what is necessary for the stated purpose, clearly document internal responsibilities, reporting lines and escalation procedures for personal data breaches.

2.6 Embed accountability across the organisation: Establishing clear governance structures and cross-functional ownership will be critical to demonstrating compliance under the DPDP regime.

Conclusion

The DPDP regime arrives at a time when businesses are collecting, analysing, and sharing more personal data than ever before. Compliance is therefore not limited to updating privacy policies or obtaining consent. It requires organisation to understand how personal data flows across their operations and to embed appropriate governance into everyday business practices. Businesses that begin this exercise early will be better positioned to meet regulatory expectations and strengthen customer trust, improve operational resilience and reduce long-term legal and commercial risk.


[1] The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Ministry of Law and Justice (Legislative Department), (11 August 2023) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf

[2] Digital Personal Data Protection (DPDP) Rules, 2025, Ministry of Electronics and Information Technology, (13 November 2025)  https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf

[3] Data Protection Day, India’s DPDP Regime at a Glance, Manupatra Academy (28 January 2026) https://www.manupatracademy.com/assets/pdf/legalpost/DPDP-Regime-at-a-Glance.pdf

[4] Section 6(4) of the DPDP Act, 2023 (“Act”).

No items found.

Footnotes

Share this post
Copied!

Latest posts

Information Technology
July 30, 2026
India’s DPDP Regime in its Implementation Phase
Read more
Arrow Right
Real Estate
July 30, 2026
Long Leases and RERA: When a Lease Is a Sale in Disguise
Read more
Arrow Right
Real Estate
July 15, 2026
Telangana Land Reforms (Ceiling on Agricultural Holdings) Act, 1973: History, Purpose, and Legal Framework
Read more
Arrow Right
Corporate Law
July 14, 2026
From a Landmark to a Locked Room: India’s First Section 245 Class Action and the Supreme Court’s Referral to Arbitration
Read more
Arrow Right
Deal Announcement
July 14, 2026
TLH, Advocates & Solicitors Advises Bijlibox India on Pre-Seed CCPS Fundraise
Read more
Arrow Right
Real Estate
July 14, 2026
Landowner’s Exoneration from Construction Delay Liability: Supreme Court's Authoritative Resolution in Sriganesh Chandrasekaran & Ors. V. M/S Unishire Homes LLP & Ors
Read more
Arrow Right
View All Blogs
Arrow Right