Home / DPDP & Data Privacy

Flagship practice

Data protection,
argued as law.

The Digital Personal Data Protection Act, 2023 is the most consequential compliance obligation to reach Indian boardrooms in a decade — and the one most often delegated to the wrong function. Incept Legal runs it as a dedicated legal practice.

Most DPDP programmes fail on the same four points.

We are frequently asked to review a compliance programme that has already been built — usually by a technology vendor, sometimes by an internal privacy team working from a European template. The gaps recur with striking consistency.

i

Consent is treated as a banner, not a legal basis

The Act requires consent that is free, specific, informed, unconditional and unambiguous, with a clear affirmative action, accompanied by a notice that stands on its own. A cookie banner bolted onto a website does not discharge an obligation that attaches to every processing activity across the organisation — including the ones that never touch the website.

ii

The GDPR is imported wholesale

India’s Act is not a translation of the GDPR. There is no category of sensitive personal data, no legitimate interests basis in the European sense, a materially different approach to cross-border transfers, and a set of “certain legitimate uses” with no direct European analogue. Programmes built on European assumptions over-comply in expensive places and under-comply in dangerous ones.

iii

Nothing is documented to an evidentiary standard

The question that matters is not whether you complied. It is what you could produce to the Data Protection Board, eighteen months later, to demonstrate that you did. Records of consent, notices as served, retention decisions and security measures need to survive being read by an adjudicating authority, not merely exist on a shared drive.

iv

The contract chain is left untouched

A Data Fiduciary remains responsible for compliance even where processing is carried out by a processor on its behalf. If your vendor agreements were signed before 2023 and have not been revisited, your legal exposure sits with parties you no longer have leverage over.

11 August 2023

The DPDP Act receives assent

India’s first standalone data protection statute becomes law, replacing the narrow regime under Section 43A of the Information Technology Act and the 2011 SPDI Rules. The Act is passed with its substantive provisions to be brought into force by notification.

3 January 2025

Draft DPDP Rules released for consultation

The Ministry of Electronics and Information Technology publishes draft Rules for public comment, setting out the operational detail the Act had left open: the form of notice, the registration and obligations of Consent Managers, security safeguards, breach intimation, retention periods and the machinery of the Data Protection Board.

14 November 2025 — Phase 1

The Rules are notified, and the Board is constituted

The DPDP Rules are notified with a phased commencement. Rules 1, 2 and 17 to 21 take effect immediately, formally establishing the Data Protection Board of India and the machinery around it. The substantive obligations on Data Fiduciaries do not yet bite — but the clock on them starts here.

14 November 2026 — Phase 2

The Consent Manager ecosystem

Rule 4 comes into effect. Registration and operational integration for Consent Managers become mandatory, and the intermediary layer between Data Principals and Data Fiduciaries becomes a live part of the architecture rather than a provision on paper.

14 May 2027 — Phase 3

Full enforcement

The core Rules — 3, 5 to 16, 22 and 23 — come into force. Notice, consent, Data Principal rights, retention and erasure, security safeguards, breach intimation and the obligations of Significant Data Fiduciaries all become operative, and penalty enforcement becomes fully active.

Between now and then

What has to be true by the end of it

Notices served in the prescribed form and in the Eighth Schedule languages. Consent records capable of being produced years later. Retention and erasure operating automatically. A Data Protection Officer or published contact. Breach intimation ready to run to the Board and to affected Data Principals. Processor contracts renegotiated. For Significant Data Fiduciaries, a DPO resident in India, an independent data auditor and completed impact assessments.

The substantive provisions come into force eighteen months after Phase 1, on 14 May 2027. That is a shorter run-up than it sounds for an organisation that has to inventory its processing first.

Ongoing

Enforcement

The Data Protection Board of India adjudicates complaints and breaches and may impose monetary penalties under the Schedule to the Act — up to INR 250 crore for a failure to take reasonable security safeguards, and up to INR 200 crore for a failure to notify a breach.

Whether the Act reaches you is rarely the close question. What it demands of you is.

How the DPDP Act applies to different categories of organisation
If you are…The Act reaches you when…The first questions we ask
An Indian company processing digital personal data Always, in respect of personal data collected in digital form, or collected on paper and later digitised. What processing activities exist across the group, and which of them were never inventoried because they sit outside the product?
A foreign company with Indian users You process personal data outside India in connection with any activity related to offering goods or services to Data Principals within India. Who is the Data Fiduciary as a matter of fact, and does your Indian entity have the authority its contracts assume?
A processor or service provider You process on behalf of a Data Fiduciary, under a valid contract. Your obligations flow through that contract — and your commercial risk with it. What have you already promised your customers, and can you actually perform it at the scale you sold?
A business handling children’s data Any Data Principal under eighteen. Verifiable parental consent is required, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. How do you know a user is an adult, and would that method satisfy a regulator asked to test it?
Likely to be a Significant Data Fiduciary The Central Government notifies you, or a class you fall within, having regard to volume and sensitivity of data, risk to Data Principals, and risk to electoral democracy, security and public order. If the notification issued tomorrow, how long would it take to appoint a DPO in India and complete an independent audit?

This table is a summary written for orientation. It is not legal advice and it is not a substitute for advice on your facts.

The Incept DPDP Readiness Framework

Six stages. Each produces a document you can hand to a board, a regulator or an acquirer — not a slide deck.

Stage 01

Discover & map

Every processing activity, by business purpose rather than by system: what personal data is collected, from whom, why, where it travels, who else touches it and how long it survives. The output is a record of processing that a lawyer wrote and an engineer can verify.

Stage 02

Ground each activity in law

Consent, or one of the certain legitimate uses. This is the stage most programmes skip, and the one that determines everything downstream — because the notice, the retention period and the rights you must honour all follow from the basis you selected.

Stage 03

Notice & consent architecture

Notices drafted to satisfy the Act and the Rules, including availability in the languages of the Eighth Schedule; consent captured through a clear affirmative action; withdrawal made as easy as the giving; and the whole exchange logged so it can be produced years later.

Stage 04

Rights, retention & erasure

Operational routes for access, correction, erasure, grievance redressal and nomination, with defined turnaround times. Retention schedules that delete by default, because the Act requires erasure once the purpose is no longer being served.

Stage 05

Security, vendors & transfers

Reasonable security safeguards documented as a legal position, not only a technical one. Processor contracts brought into line. Cross-border transfers assessed against the restrictions in force, and against what your sectoral regulator separately requires of you.

Stage 06

Governance & assurance

A DPO or published contact, a breach playbook rehearsed before it is needed, board reporting that is short enough to be read, and — for Significant Data Fiduciaries — impact assessments and independent audits scoped to withstand review.

What clients instruct us to do

Advisory

  • DPDP applicability and gap assessments
  • Records of processing and data mapping, led by counsel
  • Privacy notices, consent flows and withdrawal mechanics
  • Data Protection Impact Assessments
  • Retention and erasure policy, drafted to the statute
  • Children’s data and age-assurance strategy
  • Cross-border transfer positions, including sectoral localisation

Transactional & contentious

  • Data processing agreements and vendor renegotiation
  • Privacy due diligence on acquisitions and investments
  • Consent Manager engagement and onboarding terms
  • Personal data breach response and intimation to the Board
  • Representation before the Data Protection Board of India
  • Regulatory correspondence and voluntary undertakings
  • Board and engineering-team training that is actually attended

Adjacent regimes we run alongside DPDP

IT Act & Intermediary Rules CERT-In Directions RBI data storage SEBI cyber-resilience IRDAI Telecom & DoT GDPR interface Consumer protection Employment & monitoring

An engineer who reads the statute.

Data protection advice in India tends to be written by lawyers who have never shipped software, for engineers who have never read a statute. The distance between those two rooms is where compliance programmes quietly fail.

Rohan Kaushal read Mathematics and Computing at IIT Delhi and spent sixteen years building technology companies before he came to the bar. He is the firm’s specialist in this area for that reason: a notice obligation becomes a question about which screen and which event, a retention period becomes a deletion routine that has to run across production, analytics and backups, and a consent record becomes a schema someone has to design.

Mandates are conducted by the partner leading them, with Rohan carrying the technical analysis and the drafting that follows from it. Where a matter becomes contentious — a Board proceeding, an appeal — it moves into the firm’s tribunal and appellate practice without leaving the building.

Partly, and in an unhelpfully uneven way. A GDPR programme will have given you a data inventory, a rights process and vendor terms — genuine head starts. But the DPDP Act diverges on points that matter operationally: it has no separate category of sensitive personal data, no legitimate interests basis of the European kind, a shorter and differently framed list of permitted non-consent uses, its own notice content and language requirements, and a fundamentally different architecture for cross-border transfers. In practice we find European-derived programmes are over-engineered on records and under-built on notice, consent evidence and children’s data.

The DPDP Act itself does not impose general data localisation. It permits transfer of personal data outside India except to territories the Central Government restricts by notification — a negative-list approach, which is more permissive than the position many organisations assume.

The complication is that the Act expressly preserves stricter obligations imposed by other laws. If you are regulated by the RBI, or operate in telecom, insurance or certain government-facing sectors, localisation requirements may apply to you regardless of what the DPDP Act permits. The transfer position has to be built sector-first.

The Schedule to the Act sets ceilings rather than fixed amounts: up to INR 250 crore for failing to take reasonable security safeguards to prevent a personal data breach; up to INR 200 crore for failing to notify a breach, and the same ceiling for breaches of the children’s data obligations; up to INR 150 crore for breaches of the additional obligations of Significant Data Fiduciaries; and a residuary ceiling of INR 50 crore.

The Board determines the amount having regard to the nature and gravity of the breach, the type of data affected, whether it was repetitive, what was gained or avoided, what mitigation was undertaken and the effect of the penalty on the person. The mitigation limb is the one worth building for in advance — it is where a documented, rehearsed programme pays for itself.

For a single-entity business with a contained product, a gap assessment and remediation plan typically runs six to eight weeks, with implementation support over the following quarter. For a group with multiple entities, legacy systems and a long vendor tail, the mapping stage alone can take that long.

We would rather scope honestly than quote a number that requires us to skip Stage 01. The first conversation is free and usually tells us which of these you are.

Yes, and we prefer to. We are not a technology reseller and we have no product to sell you. Where a consent management platform, a data discovery tool or a DSR workflow is already in place, our role is to establish whether what it does actually discharges the legal obligation — and to write the configuration requirements your team implements.

Call first; write less. Our immediate priorities are to establish what personal data is involved and whose, to preserve the evidence, to determine the intimation obligations that have been triggered — the DPDP Act is not the only one, and CERT-In timelines are considerably shorter — and to bring the response under privilege where that is available.

For urgent incidents, use the phone numbers on our contact page rather than the enquiry form.

Start a conversation

Tell us the problem.
We will tell you, plainly,
where you stand.

Whether it is a tariff order to be appealed, a hearing already listed, or a notice that has just been served, we will tell you where you stand before you instruct us.