

India’s DPDP Regime in its Implementation Phase
Part I: A Practical Introduction for Businesses
For several years, discussion of India’s digital economy has centered on the anticipation of a dedicated personal data protection framework. The enactment of the Digital Personal Data Protection Act, 2023[1] (“DPDP Act”) marked a significant legislative shift toward recognizing privacy and digital governance as central components of India’s regulatory architecture. With the introduction of the Digital Personal Data Protection Rules, 2025[2] (“DPDP Rules”), the framework has now entered what may be described as its implementation phase.
Much of the conversation has focused on consent notices, privacy policies and penalties. These are effectively the visible outputs of a larger exercise. The DPDP regime is, at its core, a governance framework. It expects businesses to understand how personal data moves through their organisation, who is responsible for it, and whether businesses are able to justify retaining said data at every stage of the journey.
Against this backdrop, the DPDP Act and the DPDP Rules signal the beginning of a broader transition in how businesses are expected to govern data across their operations. The practical question is whether these businesses understand how that data moves and whether appropriate governance mechanisms are in place for it.
1. Does the DPDP Regime Apply to Your Business?
The DPDP Act applies to digital personal data processed within India and, in certain circumstances, to information being processed outside India for goods or services offered to individuals located in India. Importantly, the framework is not restricted to a certain kind of business or company. A retail company maintaining customer databases, a healthcare provider handling patient records, a Global Capability Centre (“GCC”) processing employee information in India, or a manufacturing company using digital HR systems / CRM systems may all be processing personal data within the meaning of the Act.[3]
If your organisation collects, stores, shares, analyses, or uses personal information digitally in your business, the framework is likely relevant. Businesses should begin by asking a few fundamental questions:
1.1 What personal data do we collect?
1.2 Where is it stored?
1.3 Who has access to it?
1.4 Is it shared with third-party vendors?
1.5 Why do we collect it, and for how long do we retain it?
These questions enable organisations to identify unnecessary data collection, duplicate databases, legacy systems, and vendor relationships that may expose the business to operational and regulatory risk. Historically, privacy compliance often centred on lengthy privacy policies and broad consent language. The DPDP regime shifts the focus towards transparency, accountability and purpose-specific processing. Businesses should therefore be able to communicate, in clear and accessible language, what personal data is being collected, why it is required, how it will be used, and how individuals may exercise their rights, including the right to withdraw consent.[4]
Consider the journey of a typical customer. Personal data may be collected through a website, an app, a loyalty programme, and other such avenues, often within a single transaction. The challenge is ensuring that consent remains meaningful across each of these touchpoints. The practical takeaway herein is that privacy notices should be reviewed from the perspective of an ordinary user. If your average customer cannot easily understand how their data is being used, it may be time to revisit existing notices.
2. What Should Businesses Be Doing Now?
Although implementation of the DPDP framework will continue to evolve, businesses should not wait for regulatory enforcement / intervention before strengthening their internal governance.
2.1 Map your data: Develop a clear understanding of what personal data is collected, where it resides, how it flows across the organisation, and whether every stage of processing remains necessary. Data mapping often reveals redundant processes, duplicate repositories and excessive data retention that can be addressed proactively.
2.2 Review privacy notices and consent mechanisms: Privacy notices should be concise, transparent and reflect actual business practices. Consent should not be viewed as a one-time formality but as an ongoing process that enables individuals to understand how their personal data will be used and to withdraw consent with ease.
2.3 Reassess vendor arrangements: Most organisations rely extensively on third-party processors and vendors. Contracts should clearly allocate privacy obligations, prescribe appropriate security standards, establish breach notification procedures and address liability and indemnity in the event of a personal data breach.
2.4 Examine retention practices: Confirm that personal data is not retained beyond what is necessary for the stated purpose. Periodic reviews of retention schedules can reduce both regulatory exposure and cybersecurity risk.
2.5 Review incident response procedures: Once it is confirmed that personal data is not retained beyond what is necessary for the stated purpose, clearly document internal responsibilities, reporting lines and escalation procedures for personal data breaches.
2.6 Embed accountability across the organisation: Establishing clear governance structures and cross-functional ownership will be critical to demonstrating compliance under the DPDP regime.
Conclusion
The DPDP regime arrives at a time when businesses are collecting, analysing, and sharing more personal data than ever before. Compliance is therefore not limited to updating privacy policies or obtaining consent. It requires organisation to understand how personal data flows across their operations and to embed appropriate governance into everyday business practices. Businesses that begin this exercise early will be better positioned to meet regulatory expectations and strengthen customer trust, improve operational resilience and reduce long-term legal and commercial risk.
[1] The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Ministry of Law and Justice (Legislative Department), (11 August 2023) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
[2] Digital Personal Data Protection (DPDP) Rules, 2025, Ministry of Electronics and Information Technology, (13 November 2025) https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
[3] Data Protection Day, India’s DPDP Regime at a Glance, Manupatra Academy (28 January 2026) https://www.manupatracademy.com/assets/pdf/legalpost/DPDP-Regime-at-a-Glance.pdf
[4] Section 6(4) of the DPDP Act, 2023 (“Act”).