DPDP Act & Data Localization
Compliance requirements under the Digital Personal Data Protection Act, 2023.
DPDP Risk Matrix
| Violation | Penalty Cap |
|---|---|
| Failure to prevent data breach | ₹250 Crore (~$30M) |
| Failure to notify Data Protection Board | ₹200 Crore |
| Non-fulfillment of obligations toward Children | ₹200 Crore |
The End of Unfettered Data Collection
The DPDP Act represents a paradigm shift. Unlike GDPR, it relies heavily on consent and contains fewer legitimate interest exemptions. It fundamentally changes how foreign entities collect B2C data in India.
Cross-Border Data Transfer
Unlike previous drafts that mandated strict local storage (data localization), the enacted DPDP allows cross-border transfer of personal data to any country, except those explicitly blacklisted by the Central Government via notification.
Significant Data Fiduciaries
Large tech platforms (based on volume/sensitivity of data) will be classified as Significant Data Fiduciaries (SDFs). They face heightened compliance, including mandatory appointment of a Data Protection Officer based in India and independent data audits.
Research Index
- Foreign Direct Investment (FDI) Policy Map
- Company Incorporation Timeline & Structure
- Corporate Tax & Transfer Pricing
- Production Linked Incentives (PLI)
- Industrial Corridors & Logistics
- Structuring Joint Ventures
- Profit Repatriation & Forex Laws
- Labor Codes & Employment Mandates
- Special Economic Zones (SEZ) & IFSC
- Statutory Compliance Calendar
- State-Level Subsidies & Incentives
- Intellectual Property Protection
- Employment & Business Visas
- ESG & BRSR Mandates
- Return to Overview
Need Execution Support?
Our operations desk handles complex FDI routing and compliance setup.
Contact Advisory Desk →