Institute
for India
Menu

DPDP Act & Data Localization

Compliance requirements under the Digital Personal Data Protection Act, 2023.

DPDP Risk Matrix

ViolationPenalty Cap
Failure to prevent data breach₹250 Crore (~$30M)
Failure to notify Data Protection Board₹200 Crore
Non-fulfillment of obligations toward Children₹200 Crore

The End of Unfettered Data Collection

The DPDP Act represents a paradigm shift. Unlike GDPR, it relies heavily on consent and contains fewer legitimate interest exemptions. It fundamentally changes how foreign entities collect B2C data in India.

Cross-Border Data Transfer

Unlike previous drafts that mandated strict local storage (data localization), the enacted DPDP allows cross-border transfer of personal data to any country, except those explicitly blacklisted by the Central Government via notification.

Significant Data Fiduciaries

Large tech platforms (based on volume/sensitivity of data) will be classified as Significant Data Fiduciaries (SDFs). They face heightened compliance, including mandatory appointment of a Data Protection Officer based in India and independent data audits.