DPDP Act, 2023: From Legal Obligation to Operational Readiness
Author by: Rashi Anand Suri
A post-webinar legal and implementation perspective from Upscale Legal and G-Info Technology Solutions Pvt. Ltd. (GISPL)
Webinar: “DPDP Act Compliance: End-to-End Readiness & Implementation” | 14 August 2026
Introduction
For most organisations, DPDP compliance will not fail because the organisation has never heard of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). The harder problem is more ordinary: the organisation may not know, with sufficient confidence, where personal data is collected, which systems hold it, who can access it, which vendors receive it, how consent is recorded, or whether a request from a Data Principal can actually be fulfilled.
That is where the discussion around the Digital Personal Data Protection Act, 2023 has moved. The statute establishes the legal framework; the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) add operational detail; and organisations now have to work out what those requirements mean for their own data, contracts, systems and people.
This was the focus of the webinar “DPDP Act Compliance: End-to-End Readiness & Implementation”, conducted by Upscale Legal and G-Info Technology Solutions Pvt. Ltd. (GISPL) on 14 August 2026. The discussion brought together two perspectives that are closely connected in practice: Upscale Legal’s legal and regulatory perspective, and GISPL’s information-security and implementation perspective. The distinction is important. Legal advice may identify an obligation, but the organisation still has to translate that obligation into a process, a contractual arrangement, a system control or an internal responsibility. Equally, a technical control does not, by itself, establish that every legal requirement has been addressed.
A note on the current regulatory position
The DPDP Act received Presidential assent on 11 August 2023. The Central Government’s commencement notification was issued on 13 November 2025 and published in the Gazette on 14 November 2025. It adopts a phased commencement structure. Certain provisions came into force on publication; specified provisions are to commence one year after publication; and the larger substantive set of provisions is to commence eighteen months after publication.
The DPDP Rules, 2025 follow the same broad approach. Rules 1, 2 and 17 to 21 came into force on publication; Rule 4 is to come into force one year after publication; and Rules 3, 5 to 16, 22 and 23 are to come into force eighteen months after publication.
That distinction should be kept clear when discussing compliance. The fact that the Rules have been notified does not mean that every substantive provision is already operative. At the same time, organisations should not treat the phased commencement period as a reason to defer preparation. A meaningful compliance exercise may require data mapping, contractual review, policy changes, system configuration, rights-management processes, security controls and employee training.
1. The first question is applicability
A DPDP exercise should begin with the organisation’s facts, not with a template privacy policy.
Section 3 of the DPDP Act sets out the territorial application of the legislation. In broad terms, the Act applies to the processing of digital personal data within India in the circumstances specified by the statute and may also apply to certain processing outside India where such processing is connected with offering goods or services to Data Principals in India.
The organisation’s role also matters. A Data Fiduciary is the person who determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary.
That distinction becomes important when reviewing technology providers, outsourcing arrangements and other third-party relationships. The applicability assessment should also consider whether specific provisions may apply to the organisation—for example, provisions concerning children’s personal data or the additional obligations applicable to a Significant Data Fiduciary.
This is fundamentally a legal assessment. The organisation should understand its processing activities and then determine which statutory obligations attach to them.
2. Before reviewing the privacy policy, understand the data
One of the practical difficulties in data protection work is that organisations often know their systems individually but do not have a sufficiently complete picture of how personal data moves between them.
Consider a relatively ordinary customer journey. A person provides information through a website. The information enters a CRM. A marketing platform may receive part of it. A third-party service provider may process another element. Records may subsequently be archived.
The same problem appears in employee data, recruitment, customer support, finance and other business functions.
For legal counsel, this matters because questions about purpose, notice, consent, retention, disclosure and Data Principal rights cannot be answered properly without understanding the underlying processing activity.
Data mapping is therefore not simply an IT exercise. The implementation framework discussed during the webinar included data discovery, mapping and classification to establish visibility into the organisation’s data environment.
This implementation perspective also aligns with GISPL’s information-security background. GISPL describes its services around information-security audits, cybersecurity assessments and protection of information assets, networks and applications, and identifies itself as a CERT-In empanelled security auditor.
3. Notice and consent require more than revised wording
The DPDP Act places specific requirements around notice and consent. Section 5 addresses notice, while Section 6 addresses consent. Where consent is relied upon, the statutory framework requires consent to satisfy specified conditions, including that it be free, specific, informed and unambiguous and involve a clear affirmative action.
The DPDP Rules provide further detail. Rule 3 requires the notice to be presented independently and in clear and plain language. It must include, at a minimum, an itemised description of the personal data and the specified purpose or purposes of processing. It must also provide the means through which the Data Principal may withdraw consent, exercise rights and make a complaint to the Board.
For organisations, this raises a more practical question: Does the actual data-collection process correspond with the notice?
That requires examining the point at which information is collected—not merely the privacy policy page. A legal review should consider what information is being collected, for what purpose, what is communicated to the Data Principal, how consent is captured and evidenced, and how withdrawal operates.
A carefully drafted notice cannot, by itself, correct a process that operates differently from the notice.
4. A privacy policy is one document, not the compliance programme
A privacy policy may be an important part of DPDP compliance. It is not, however, a substitute for the broader governance framework.
Depending on the organisation’s activities, the compliance framework may need to address data protection responsibilities; consent management; retention and deletion; Data Principal rights; grievance handling; vendor and processor arrangements; breach response; and internal escalation and accountability.
The important issue is whether these documents correspond with the organisation’s actual practices.
For example, if an organisation’s policy states that information will be deleted after a specified period, it should be possible to identify the systems in which that information is held and the process through which deletion is effected. Similarly, if a contract requires a processor to report a security incident, there should be an internal mechanism through which that notification is received, assessed and escalated.
5. Data Principal rights have to work in practice
The DPDP Act provides Data Principals with specified rights, including rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination.
For organisations, the practical difficulty begins when a right is actually exercised.
Suppose a Data Principal requests correction of information. Who receives the request? How is the request verified? Which system contains the authoritative record? Does a processor hold the same information? Who confirms that the correction has been completed? What evidence is retained?
These are operational questions, but they have a direct legal consequence.
A compliance review should therefore examine the entire rights-management process rather than simply checking whether the organisation’s privacy policy mentions Data Principal rights. One useful way to test readiness is to take a hypothetical rights request and follow it through the organisation.
6. Children’s personal data requires specific attention
Section 9 of the DPDP Act establishes specific requirements concerning the processing of children’s personal data, including requirements relating to verifiable parental consent and restrictions on certain processing activities.
The Rules provide additional detail concerning verification mechanisms.
Organisations whose products or services are likely to be used by children should therefore consider more than the wording of a privacy notice. Age-related processes, parental consent, product design, communications and the systems used to implement those processes may all require examination.
7. Significant Data Fiduciaries: an assessment, not an assumption
The DPDP Act provides a separate framework for Significant Data Fiduciaries (“SDFs”). Section 10 sets out additional obligations for entities notified as SDFs, including requirements relating to a Data Protection Officer, an independent data auditor and specified assessments and audits.
An organisation should not assume that it is an SDF merely because it maintains a large database or processes information that it considers sensitive. The statutory framework contemplates consideration of factors including the volume and nature of personal data processed, the risk to the rights of Data Principals and other specified factors.
SDF status therefore requires a proper legal assessment against the applicable framework.
8. Vendor contracts are part of the data-protection picture
Most organisations do not process personal data entirely within their own infrastructure. Cloud providers, SaaS platforms, HR technology providers, CRM vendors, outsourcing partners and other service providers may process information on behalf of a Data Fiduciary.
The contractual review should therefore go beyond a generic confidentiality clause.
Depending on the relationship, it may be appropriate to consider provisions concerning the purpose and scope of processing; confidentiality; security safeguards; incident reporting; sub-processing; assistance with Data Principal rights; retention and deletion; and other responsibilities between the parties.
The legal character of the third party should also be examined carefully. Simply calling an organisation a “vendor” or “processor” in a contract does not, without more, resolve the legal analysis.
9. Security safeguards and breach response must be connected
Section 8 of the DPDP Act addresses obligations of Data Fiduciaries concerning reasonable security safeguards and personal-data breaches. The DPDP Rules provide additional detail concerning security safeguards and breach-related requirements.
The practical lesson is straightforward: breach response should be designed before an incident occurs.
An organisation should have clarity about how an incident is detected; who receives the initial escalation; how it is assessed; when Legal is involved; how technical containment is coordinated; what regulatory notifications may be required; how affected individuals are addressed where applicable; and what documentation is retained.
The Rules prescribe specific notification requirements, including requirements concerning notification to the Board and communication to affected Data Principals in the circumstances specified by the Rules.
This is an area where the respective roles of Legal and information security are particularly clear. GISPL’s published work includes cybersecurity testing, security assessments and information-security auditing. Upscale Legal’s role in the joint framework is to address the legal and regulatory implications of incidents and the organisation’s response.
10. Training should reflect the work people actually do
Employees are often directly involved in collecting, accessing, sharing or deleting personal data. Training therefore needs to be relevant to the role.
A marketing team may need to understand consent and communications. HR may need to understand employee and recruitment data. Procurement may need to identify data-processing issues in vendor arrangements. IT and security teams may require more detailed guidance on access controls, incident escalation and technical safeguards. Senior management, meanwhile, needs visibility into accountability, risk and organisational readiness.
The webinar framework contemplated organisation-wide awareness, role-based training and management-level briefings. The objective should be to build understanding into everyday processes rather than treat data protection as an annual compliance module.
11. Readiness should be demonstrated, not assumed
A compliance programme should ultimately be capable of being tested.
That does not necessarily mean conducting an exhaustive audit of every system. It means selecting the areas that matter and checking whether the documented position corresponds with actual practice.
Examples include checking whether the privacy notice matches information collected through the website; whether a Data Principal request can be routed to the appropriate team; whether consent and its withdrawal can be evidenced; whether relevant vendor agreements contain appropriate provisions; whether an incident can be escalated through a defined process; and whether employees understand their responsibilities.
The webinar’s final stage was framed as compliance validation and readiness assessment, including review of policies, controls and processes. That is a more meaningful measure of readiness than the number of documents sitting in a compliance folder.
A practical starting point for organisations
There is no single DPDP implementation sequence that will suit every organisation. A hospital, an e-commerce business, a financial institution, an educational institution and a technology company may all process personal data, but their processing activities, systems and risk profiles will differ.
A useful starting assessment can nevertheless ask six basic questions:
- What personal data does the organisation process, and for what purposes?
- Which systems, business functions and third parties handle that data?
- What notices and consent mechanisms are currently used?
- Can applicable Data Principal requests be received and fulfilled through a documented process?
- What would happen if a personal-data incident were detected today?
- Who is responsible for bringing the legal, operational and technical aspects together?
The answers provide a more useful starting point than simply asking whether an organisation is “DPDP compliant”. They show where legal interpretation is required, where existing processes may need to change and where technology or security controls need to be examined.
The Upscale Legal–GISPL approach
The joint approach presented by Upscale Legal and GISPL during the 14 August 2026 webinar was based on the intersection of law, technology and operations.
Upscale Legal addresses the legal and regulatory layer: applicability, interpretation of the DPDP framework, privacy and consent documentation, contractual and Data Processing Agreement review, SDF/DPO/DPIA considerations where applicable, and breach and regulatory readiness.
GISPL brings an information-security and implementation perspective. Its published services include cybersecurity compliance, information-security audits, vulnerability and security testing, and other measures aimed at protecting information assets, networks and applications. GISPL also identifies itself as a CERT-In empanelled security auditor.
The value of bringing these perspectives together is practical. A legal team may identify a requirement relating to security safeguards. The organisation then has to determine what safeguards are appropriate, where they need to be implemented and how their operation can be evidenced. Similarly, a security team may identify a vulnerability. The organisation may then need to determine whether the vulnerability has legal or regulatory consequences and what response is required.
DPDP compliance therefore sits neither exclusively with Legal nor exclusively with IT. It sits within the organisation’s wider governance of personal data.
Conclusion
The Digital Personal Data Protection Act, 2023 has established the statutory foundation for India’s digital personal-data protection framework. The notification of the DPDP Rules, 2025 has added significant operational detail, while the phased commencement structure provides organisations with time to prepare.
That preparation should begin with the organisation’s actual processing environment. Where is personal data collected? Why is it collected? Who receives it? How is consent managed? How are Data Principal rights handled? Which vendors process the information? What safeguards protect it? What happens when something goes wrong?
Those questions lead to the legal analysis that matters.
The 14 August 2026 webinar conducted by Upscale Legal and GISPL reinforced the importance of bringing legal, information-security and operational perspectives together. The objective is not simply to produce a set of documents. It is to establish a defensible understanding of the organisation’s obligations and a practical means of meeting them.
For organisations beginning their DPDP journey—or reassessing work already undertaken—the appropriate first step is therefore a structured assessment of applicability, data processing, governance, contractual arrangements, Data Principal rights, security safeguards and incident readiness. The resulting gaps can then be prioritised according to the organisation’s legal obligations, risk profile and operational realities.
Frequently Asked Questions
What is the Digital Personal Data Protection Act, 2023?
The Digital Personal Data Protection Act, 2023 is India’s statutory framework governing the processing of digital personal data and establishing rights, duties and obligations for Data Principals and Data Fiduciaries.
Are the DPDP Rules, 2025 currently in force?
The Rules were notified on 13 November 2025 and published on 14 November 2025, but their provisions have phased commencement dates. Rules 1, 2 and 17–21 came into force upon publication; Rule 4 is scheduled to commence one year later; and Rules 3, 5–16, 22 and 23 are scheduled to commence eighteen months after publication.
Is consent required for every processing activity under the DPDP Act?
No. Section 4 provides for processing for a lawful purpose where the Data Principal has given consent or where the processing falls within the statutory framework of certain legitimate uses. The appropriate legal basis should be assessed for the particular processing activity.
Is a privacy policy sufficient for DPDP compliance?
No. A privacy policy is one component of a broader compliance framework. Depending on the organisation and its processing activities, compliance may also involve data mapping, notice and consent, Data Principal rights, governance, processor arrangements, security safeguards, breach response and validation.
What is a Data Fiduciary?
A Data Fiduciary is a person who, alone or together with others, determines the purpose and means of processing personal data.
What is a Data Processor?
A Data Processor processes personal data on behalf of a Data Fiduciary. Whether a particular third party falls within this role should be assessed from the actual relationship and processing activities.
What should an organisation do before the substantive DPDP provisions commence?
The appropriate starting point is an applicability and gap assessment. Depending on the organisation, this may involve data mapping, review of notices and consent mechanisms, vendor-contract review, rights-management processes, breach preparedness, security assessment, training and remediation planning.
What role does GISPL play in DPDP compliance?
GISPL brings an information-security and implementation perspective, including cybersecurity assessment, information-security auditing, testing and security controls. GISPL states on its website that it is a CERT-In empanelled security auditor.
What role does Upscale Legal play?
Upscale Legal provides the legal and regulatory advisory perspective, including applicability assessment, privacy and consent review, contractual and DPA review, SDF/DPO/DPIA considerations where applicable, and legal and regulatory readiness in relation to personal-data incidents.
About the Webinar
DPDP Act Compliance: End-to-End Readiness & Implementation – 14 August 2026
The webinar brought together Upscale Legal and G-Info Technology Solutions Pvt. Ltd. (GISPL) to examine DPDP compliance from both legal/regulatory and implementation/information-security perspectives. The webinar framework covered applicability, data mapping, governance, privacy and consent, Data Principal rights, vendor management, breach response, training, technical safeguards and compliance validation.
Legal Disclaimer
This article is intended for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. The Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 and related notifications, directions and regulatory developments should be read in their current form. The application of the law may vary depending upon the nature of the organisation, its processing activities, contractual arrangements and other applicable legal or regulatory requirements. Organisations should obtain legal advice based on their particular facts and circumstances before taking compliance decisions.












