Skip to main content
~20 Years — Continuous operations in cybersecurity, privacy, and compliance

DPDP Act Compliance for Indian Enterprises

The DPDP Rules 2025 were notified on 14 November 2025 and the Data Protection Board of India is now established. Indian data fiduciaries and processors must move from awareness to implementation, evidence, and audit readiness in FY26.

DPDP 2023
Act Coverage
India-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Security Brigade delivers end-to-end DPDP Act readiness combining legal and control mapping with technical validation across your applications, APIs, data flows, and vendor ecosystem. We make DPDP practical instead of abstract.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Which one are you

The Act works by role, and your obligations follow from which you hold

Most DPDP confusion resolves the moment an organisation establishes what it is in a given data flow, and large organisations are usually more than one.

Decides the purpose

Data Fiduciary

Anyone who, alone or with others, determines the purpose and means of processing personal data. This is the role that carries the consent obligations, the notice obligations, the security obligations and the breach duty. Most businesses are a Data Fiduciary for their own customers and employees.

Notified by government

Significant Data Fiduciary

A Data Fiduciary notified by the Central Government on factors including the volume and sensitivity of personal data processed and the risk to Data Principals. The additional obligations are concrete: a Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits.

Processes on instruction

Data Processor

Processes personal data on behalf of a Data Fiduciary under contract. The obligations reach you through that contract, not directly, which makes the contract the control and makes your customers’ audit rights the thing you will actually be tested against.

Registered with the Board

Consent Manager

An entity registered with the Data Protection Board that gives Data Principals a single point to give, manage, review and withdraw consent. Relevant if you intend to operate as one, and relevant to everyone else as a signal of how the Act expects consent to be evidenced.

The obligation everyone asks about

Reasonable security safeguards is an outcome, and outcomes are evidenced

Section 8(4) obliges a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach, and it states that as an outcome instead of as a control list. Organisations read that as vagueness. It is better read as an evidentiary standard: because no specific measure is named, what you will be asked for after an incident is the reasoning and the record. Which data you hold and where it flows. What you assessed the risk to be. Which safeguards you chose, when, and on what basis. Whether they were tested or merely assumed, and what you did when testing found something. That is why a certified information security management system, or a documented control framework with technical testing behind it, is worth more here than any single technology, because it is a record of decisions taken deliberately. The obligation also runs to your processors: the safeguard duty sits with the Fiduciary whoever operates the system, which is what makes vendor assessment a DPDP activity and not a procurement formality. Section 8(6) then sets the other half, requiring notification of a personal data breach to the Board and to each affected Data Principal in the form and manner prescribed. A breach duty is decided before the breach: whoever can declare an incident, whatever gets sent and whoever sends it either exists in writing or is invented under time pressure.

What changes for you

Obligations by role, and where each one is usually unmet

AreaWhat the Act asksWhere it is usually unmet
Notice and consent Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and the notice must describe the personal data and the purpose. Withdrawal must be as easy as giving it. Withdrawal. Systems are commonly built to capture consent and not to honour its removal downstream.
Data Principal rights Access to a summary of personal data processed, correction, completion, updating and erasure, grievance redressal, and nomination. Erasure across backups, logs, analytics stores and third parties: the copies nobody mapped.
Security safeguards Reasonable security safeguards to prevent a personal data breach, under section 8(4). Evidence, not controls. The measures usually exist; the record of why they were chosen and whether they were tested does not.
Breach notification Notification to the Data Protection Board and to each affected Data Principal, in the prescribed form and manner, under section 8(6). No rehearsed path. Note this runs alongside the CERT-In six-hour incident reporting duty, which is a separate obligation with its own clock.
Processors and vendors Processing by a Data Processor on behalf of a Fiduciary must be under a valid contract; the safeguard duty stays with the Fiduciary. Contracts signed, assurance never obtained. The duty does not move with the workload.
Significant Data Fiduciaries A Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits. Treating the DPO as a title instead of a function with authority and a reporting line.
The Act provides for penalties of up to INR 250 crore, imposed by the Data Protection Board, which is now established and operational.

Notice and consent

What the Act asks
Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and the notice must describe the personal data and the purpose. Withdrawal must be as easy as giving it.
Where it is usually unmet
Withdrawal. Systems are commonly built to capture consent and not to honour its removal downstream.

Data Principal rights

What the Act asks
Access to a summary of personal data processed, correction, completion, updating and erasure, grievance redressal, and nomination.
Where it is usually unmet
Erasure across backups, logs, analytics stores and third parties: the copies nobody mapped.

Security safeguards

What the Act asks
Reasonable security safeguards to prevent a personal data breach, under section 8(4).
Where it is usually unmet
Evidence, not controls. The measures usually exist; the record of why they were chosen and whether they were tested does not.

Breach notification

What the Act asks
Notification to the Data Protection Board and to each affected Data Principal, in the prescribed form and manner, under section 8(6).

Processors and vendors

What the Act asks
Processing by a Data Processor on behalf of a Fiduciary must be under a valid contract; the safeguard duty stays with the Fiduciary.

Significant Data Fiduciaries

What the Act asks
A Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits.
Where it is usually unmet
Treating the DPO as a title instead of a function with authority and a reporting line.

The Act provides for penalties of up to INR 250 crore, imposed by the Data Protection Board, which is now established and operational.

Cross-border, plainly

Section 16 is permissive, and your contract decides the rest

India-only processing is available and is honoured where you require it. Here is how the four positions actually differ.

Section 16 is permissive, and your contract decides the rest
StateWhat it meansWhat follows
The statutory position Section 16 permits transfer of personal data outside India to any country other than those restricted by the Central Government through notification. A permissive default. The practical work is knowing where your data goes and being able to say so, and not defending the transfer itself.
India-only, by requirement Your contract requires personal data, and access to it, to remain in India for the engagement. Delivered on that basis. We are an Indian entity with our delivery team in India, so this is the ordinary case instead of an exception that costs extra.
Access outside India, by agreement Personnel outside India may work on the engagement where you have agreed to it, which keeps follow-the-sun response and specialist coverage available. Happens on your agreement and is recorded. What matters for your own section 16 position is that the arrangement is documented and the jurisdictions are known.
Sub-processors nobody mapped SaaS tooling, analytics, support platforms and cloud regions chosen product by product over several years, each with its own location. This is where cross-border exposure actually sits for most organisations, and it is discovered by inventory, not by policy. It is also the part a Data Principal request will surface first.
Key
  • A decision you control
  • Undocumented until someone asks

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade delivers DPDP compliance through a proven methodology that combines privacy expertise with technical security validation. Each phase is tracked through our Lemon audit platform with full visibility for your compliance, legal, and technology teams.

Discovery
01

Applicability and Role Mapping

We determine your DPDP obligations by mapping your entity as Data Fiduciary, Processor, or both. We assess whether Significant Data Fiduciary criteria apply and identify all digital personal data processing activities across your organisation.

02

Data Discovery and Inventory

We build a comprehensive data inventory covering what personal data you collect, where it is stored, how it flows through systems and third parties, what processing purposes exist, and where cross-border transfers occur.

Testing
03

Gap Assessment

We assess your current state against every DPDP Act obligation: consent and notice mechanisms, Data Principal rights workflows, breach notification readiness, processor controls, child data handling, grievance redressal, retention and deletion, and security safeguards.

04

Technical Validation

Unlike advisory-only firms, Security Brigade validates privacy controls technically. Our B-52 framework and application security teams test consent flows, access controls, data exposure through APIs, insecure data handling, logging practices, deletion mechanisms, and data leakage paths.

Delivery
05

Remediation and Implementation

We deliver a prioritised remediation roadmap and support implementation: policy and procedure packs, consent and notice templates, Data Principal rights workflows, breach notification playbooks, processor due-diligence frameworks, and data retention and deletion plans.

06

Closure Validation

We perform a closure validation audit confirming all identified gaps are resolved, evidence is documented, and your organisation can demonstrate DPDP compliance to the Data Protection Board, sectoral regulators, enterprise customers, and board-level stakeholders.

"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Head of Platform Engineering, Fintech Unicorn
Head of Platform Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

The platform underneath

The instrument sets the cadence. B-52 is what runs at it.

Where the obligation is Indian, the question about any testing tool is what it holds, where it holds it and for how long. B-52 answers that directly instead of leaving it to a procurement questionnaire.

See the B-52 platform Built and run by Security Brigade

FAQ

DPDP, answered for the person who has to implement it

Roles, evidence and cross-border. Talk to our team about your data estate.

Contact us
Where does the DPDP Act stand today?+
The Digital Personal Data Protection Act, 2023 is in force and the DPDP Rules, 2025 were notified on 14 November 2025, giving the Act operational effect. The Data Protection Board of India is established. That makes this an implementation and evidence exercise instead of a monitoring one, and the practical starting point is a data inventory: most organisations cannot yet answer, in writing, what personal data they hold, where it flows and who processes it on their behalf.
What counts as reasonable security safeguards?+
Section 8(4) states the duty as an outcome, which means what you will be asked for is the reasoning and the record: what data you hold, what you assessed the risk to be, which safeguards you chose and why, whether they were tested or merely assumed, and what you did when testing found something. A documented control framework with technical testing behind it, or a certified ISMS, is worth more here than any individual product, because it evidences decisions, not assertions.
Are we a Significant Data Fiduciary?+
Only if the Central Government notifies you as one, on factors including the volume and sensitivity of personal data you process and the risk to Data Principals. The additional obligations are specific: a Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits. Assess the likelihood against your processing profile instead of waiting to be told, particularly if you operate at consumer scale or handle sensitive categories.
Can our data stay in India?+
Yes. Section 16 permits transfers to any country not restricted by Central Government notification, so the Act is permissive. Where your contract requires personal data and access to it to remain in India, we deliver the engagement on that basis. We are an Indian entity with our delivery team in India. Where you agree to it, personnel outside India may work on an engagement; that happens on your agreement, not by default.
How does this interact with CERT-In incident reporting?+
They are separate obligations with separate clocks and both can apply to the same incident. Section 8(6) requires notification of a personal data breach to the Data Protection Board and to each affected Data Principal in the prescribed form and manner. The CERT-In directions require cyber incidents to be reported within six hours of being noticed. A breach response plan that addresses one and not the other is half a plan, and the six-hour clock is the one that is lost while a process is being invented.
Does ISO 27001 help with DPDP?+
Substantially, for the security half. A certified ISMS gives you documented risk assessment, access control, incident management, supplier assurance and an audit trail, which is the evidence section 8(4) effectively asks you to be able to produce. It does not cover the consent, notice and Data Principal rights machinery, which is DPDP-specific work. Organisations doing both usually find the security evidence carries across almost entirely and the rights plumbing is the new build.

Start Your DPDP Compliance Journey Before Enforcement Catches Up

The DPDP Rules are notified, the Data Protection Board is operational, and Indian enterprises are expected to demonstrate compliance readiness. Do not wait for the first enforcement action to make headlines.

Typically responds within 1 business day · No commitment required

Request a Scoping Call