Data protection
DPDP Act compliance: the eight duties that carry a penalty
The Digital Personal Data Protection Act, 2023 does not levy one fine for “non-compliance”. It prices specific failures, separately, and the largest number in it is attached to the duty most organisations assume they already meet.
Start with the Schedule, not the Act
Most DPDP Act compliance India projects begin by reading the Act front to back and then arguing about definitions. There is a faster route. Turn to the Schedule at the end, which lists what the Data Protection Board can actually penalise and how much each failure is worth, and work backwards from there. It is a two-page list, and it is the closest thing the Act has to a prioritised roadmap.
Read that way, the picture is blunt. The single largest maximum, ₹250 crore, attaches to a failure to take reasonable security safeguards to prevent a personal data breach. Not to consent. Not to notice. To security. A company with immaculate consent flows and an unpatched perimeter is exposed to the biggest number in the statute.
The duties, in the order they will hurt
1. Reasonable security safeguards: section 8(5)
The Act does not enumerate the controls, which is the part that unsettles people. In practice, a Board asking whether your safeguards were reasonable will ask the questions any auditor asks: is access reviewed, is multi-factor authentication enforced, are logs collected and read, are backups restored on a schedule, was the estate patched. If you are running an ISO 27001 programme, most of this is already evidenced. If you are not, this is the gap with the largest number next to it.
2. Breach notification: section 8(6)
You must notify both the Board and every affected Data Principal. This is assessed separately from the breach itself, which means a single incident can produce two contraventions: one for the safeguards that failed, and one for the notification that came late or never came at all. The practical consequence is that your incident response plan needs a notification track with named owners and a clock, not a paragraph saying “legal will advise”.
3. Children's data: section 9
Verifiable parental consent for anyone under eighteen, and no tracking, behavioural monitoring or targeted advertising directed at children. Eighteen is a higher bar than most global products are built to. If your service can be used by a school, a coaching centre or a family, this applies to you whether or not you consider yourself a children's product.
4. Significant Data Fiduciary duties: section 10
If the government notifies you as significant (based on volume and sensitivity of data, risk to rights, and impact on sovereignty and public order) you additionally need a Data Protection Officer based in India and answerable to the board, an independent data auditor, and periodic Data Protection Impact Assessments. You will not get long to arrange those after the notification arrives.
5. Everything else: the catch-all
Notice, consent, purpose limitation, accuracy, erasure when the purpose ends, grievance redressal, and written contracts with every processor. Individually unglamorous; collectively the bulk of the work. This is where a GDPR programme gives you a genuine head start, because the underlying obligations rhyme even where the wording does not.
What evidence actually proves each duty
A duty you cannot evidence is a duty you have not met, and this is where most readiness assessments fail. For each obligation, ask what document you would hand over on the day you were asked:
- Notice: the notice text, its version history, and a screenshot of where it appears in the flow.
- Consent: consent records with timestamps, and a withdrawal mechanism as easy to use as the one that gave consent.
- Purpose limitation: a records-of-processing register mapping each dataset to its stated purpose.
- Erasure: a retention schedule, plus deletion logs proving it runs.
- Security: access reviews, patch records, log retention, tested restores, and a current VAPT report with verified closure.
- Grievance redressal: a published channel, and response records against a stated time.
None of that is exotic. Almost all of it exists in a mature organisation as a by-product of doing the work. The gap is usually not the control; it is that nobody has ever been asked to produce the proof, so nobody kept it.
The three exposures we find most often
First, shadow processors. The analytics SDK inside the mobile app, the customer-support tool with an email integration, the marketing platform holding an exported contact list. Device identifiers and behavioural data are personal data; each of these is a processor, and each needs a contract. See third-party risk management for how we scope this.
Second, data with no owner. A five-year-old S3 bucket of exported reports, a legacy database nobody migrated, a shared drive of scanned KYC documents. Erasure obligations apply to data you forgot you had, and so do the safeguards.
Third, the notification clock. Organisations that have never run a tabletop discover during a real incident that nobody knows who signs off on telling the Board, or how affected principals would even be contacted. That is a rehearsal problem, and rehearsal is cheap.
Where to start this quarter
Map what personal data you hold and why. You cannot do anything else without it. Then close the security gaps with the largest number attached, then build the notification path, then fix consent and notice. In that order. It is not the order the Act is written in, but it is the order the penalties are weighted in.
Our DPDP Act compliance service runs exactly this sequence, and the readiness assessment at the end of it is free.
Written by the Aphelion Cyber team. No statistic on this page is ours unless it is sourced on the page itself.