DPDP Act Compliance for Indian Enterprises
The DPDP Rules 2025 were notified on 14 November 2025 and the Data Protection Board of India is now established. Indian data fiduciaries and processors must move from awareness to implementation, evidence, and audit readiness in FY26.
Security Brigade delivers end-to-end DPDP Act readiness combining legal and control mapping with technical validation across your applications, APIs, data flows, and vendor ecosystem. We make DPDP practical instead of abstract.
Trusted by India's leading enterprises
Which one are you
The Act works by role, and your obligations follow from which you hold
Most DPDP confusion resolves the moment an organisation establishes what it is in a given data flow, and large organisations are usually more than one.
Data Fiduciary
Anyone who, alone or with others, determines the purpose and means of processing personal data. This is the role that carries the consent obligations, the notice obligations, the security obligations and the breach duty. Most businesses are a Data Fiduciary for their own customers and employees.
Significant Data Fiduciary
A Data Fiduciary notified by the Central Government on factors including the volume and sensitivity of personal data processed and the risk to Data Principals. The additional obligations are concrete: a Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits.
Data Processor
Processes personal data on behalf of a Data Fiduciary under contract. The obligations reach you through that contract, not directly, which makes the contract the control and makes your customers’ audit rights the thing you will actually be tested against.
Consent Manager
An entity registered with the Data Protection Board that gives Data Principals a single point to give, manage, review and withdraw consent. Relevant if you intend to operate as one, and relevant to everyone else as a signal of how the Act expects consent to be evidenced.
The obligation everyone asks about
Reasonable security safeguards is an outcome, and outcomes are evidenced
Section 8(4) obliges a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach, and it states that as an outcome instead of as a control list. Organisations read that as vagueness. It is better read as an evidentiary standard: because no specific measure is named, what you will be asked for after an incident is the reasoning and the record. Which data you hold and where it flows. What you assessed the risk to be. Which safeguards you chose, when, and on what basis. Whether they were tested or merely assumed, and what you did when testing found something. That is why a certified information security management system, or a documented control framework with technical testing behind it, is worth more here than any single technology, because it is a record of decisions taken deliberately. The obligation also runs to your processors: the safeguard duty sits with the Fiduciary whoever operates the system, which is what makes vendor assessment a DPDP activity and not a procurement formality. Section 8(6) then sets the other half, requiring notification of a personal data breach to the Board and to each affected Data Principal in the form and manner prescribed. A breach duty is decided before the breach: whoever can declare an incident, whatever gets sent and whoever sends it either exists in writing or is invented under time pressure.
What changes for you
Obligations by role, and where each one is usually unmet
| Area | What the Act asks | Where it is usually unmet |
|---|---|---|
| Notice and consent | Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and the notice must describe the personal data and the purpose. Withdrawal must be as easy as giving it. | Withdrawal. Systems are commonly built to capture consent and not to honour its removal downstream. |
| Data Principal rights | Access to a summary of personal data processed, correction, completion, updating and erasure, grievance redressal, and nomination. | Erasure across backups, logs, analytics stores and third parties: the copies nobody mapped. |
| Security safeguards | Reasonable security safeguards to prevent a personal data breach, under section 8(4). | Evidence, not controls. The measures usually exist; the record of why they were chosen and whether they were tested does not. |
| Breach notification | Notification to the Data Protection Board and to each affected Data Principal, in the prescribed form and manner, under section 8(6). | No rehearsed path. Note this runs alongside the CERT-In six-hour incident reporting duty, which is a separate obligation with its own clock. |
| Processors and vendors | Processing by a Data Processor on behalf of a Fiduciary must be under a valid contract; the safeguard duty stays with the Fiduciary. | Contracts signed, assurance never obtained. The duty does not move with the workload. |
| Significant Data Fiduciaries | A Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits. | Treating the DPO as a title instead of a function with authority and a reporting line. |
| The Act provides for penalties of up to INR 250 crore, imposed by the Data Protection Board, which is now established and operational. | ||
Notice and consent
- What the Act asks
- Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and the notice must describe the personal data and the purpose. Withdrawal must be as easy as giving it.
- Where it is usually unmet
- Withdrawal. Systems are commonly built to capture consent and not to honour its removal downstream.
Data Principal rights
- What the Act asks
- Access to a summary of personal data processed, correction, completion, updating and erasure, grievance redressal, and nomination.
- Where it is usually unmet
- Erasure across backups, logs, analytics stores and third parties: the copies nobody mapped.
Security safeguards
- What the Act asks
- Reasonable security safeguards to prevent a personal data breach, under section 8(4).
- Where it is usually unmet
- Evidence, not controls. The measures usually exist; the record of why they were chosen and whether they were tested does not.
Breach notification
- What the Act asks
- Notification to the Data Protection Board and to each affected Data Principal, in the prescribed form and manner, under section 8(6).
Processors and vendors
- What the Act asks
- Processing by a Data Processor on behalf of a Fiduciary must be under a valid contract; the safeguard duty stays with the Fiduciary.
- Where it is usually unmet
- Contracts signed, assurance never obtained. The duty does not move with the workload.
Significant Data Fiduciaries
- What the Act asks
- A Data Protection Officer based in India, Data Protection Impact Assessments, and independent data audits.
- Where it is usually unmet
- Treating the DPO as a title instead of a function with authority and a reporting line.
The Act provides for penalties of up to INR 250 crore, imposed by the Data Protection Board, which is now established and operational.
Cross-border, plainly
Section 16 is permissive, and your contract decides the rest
India-only processing is available and is honoured where you require it. Here is how the four positions actually differ.
| State | What it means | What follows |
|---|---|---|
| The statutory position | Section 16 permits transfer of personal data outside India to any country other than those restricted by the Central Government through notification. | A permissive default. The practical work is knowing where your data goes and being able to say so, and not defending the transfer itself. |
| India-only, by requirement | Your contract requires personal data, and access to it, to remain in India for the engagement. | Delivered on that basis. We are an Indian entity with our delivery team in India, so this is the ordinary case instead of an exception that costs extra. |
| Access outside India, by agreement | Personnel outside India may work on the engagement where you have agreed to it, which keeps follow-the-sun response and specialist coverage available. | Happens on your agreement and is recorded. What matters for your own section 16 position is that the arrangement is documented and the jurisdictions are known. |
| Sub-processors nobody mapped | SaaS tooling, analytics, support platforms and cloud regions chosen product by product over several years, each with its own location. | This is where cross-border exposure actually sits for most organisations, and it is discovered by inventory, not by policy. It is also the part a Data Principal request will surface first. |
- A decision you control
- Undocumented until someone asks
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade delivers DPDP compliance through a proven methodology that combines privacy expertise with technical security validation. Each phase is tracked through our Lemon audit platform with full visibility for your compliance, legal, and technology teams.
Applicability and Role Mapping
We determine your DPDP obligations by mapping your entity as Data Fiduciary, Processor, or both. We assess whether Significant Data Fiduciary criteria apply and identify all digital personal data processing activities across your organisation.
Data Discovery and Inventory
We build a comprehensive data inventory covering what personal data you collect, where it is stored, how it flows through systems and third parties, what processing purposes exist, and where cross-border transfers occur.
Gap Assessment
We assess your current state against every DPDP Act obligation: consent and notice mechanisms, Data Principal rights workflows, breach notification readiness, processor controls, child data handling, grievance redressal, retention and deletion, and security safeguards.
Technical Validation
Unlike advisory-only firms, Security Brigade validates privacy controls technically. Our B-52 framework and application security teams test consent flows, access controls, data exposure through APIs, insecure data handling, logging practices, deletion mechanisms, and data leakage paths.
Remediation and Implementation
We deliver a prioritised remediation roadmap and support implementation: policy and procedure packs, consent and notice templates, Data Principal rights workflows, breach notification playbooks, processor due-diligence frameworks, and data retention and deletion plans.
Closure Validation
We perform a closure validation audit confirming all identified gaps are resolved, evidence is documented, and your organisation can demonstrate DPDP compliance to the Data Protection Board, sectoral regulators, enterprise customers, and board-level stakeholders.
"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
Dark Web Monitoring
12B+ breach records indexed; monitors Telegram, paste sites, criminal forums, and ransomware leak sites for credentials, leaked data, and threat actor mentions.
Find leaked data before regulators do.
Explore on ShadowMapBrand Protection
Detects phishing domains, fake mobile apps, social media impersonation, and domain squatting — with orchestrated takedowns.
Stop impersonation before customers fall for it.
Explore on ShadowMapThe platform underneath
The instrument sets the cadence. B-52 is what runs at it.
Where the obligation is Indian, the question about any testing tool is what it holds, where it holds it and for how long. B-52 answers that directly instead of leaving it to a procurement questionnaire.
FAQ
DPDP, answered for the person who has to implement it
Roles, evidence and cross-border. Talk to our team about your data estate.
Contact usWhere does the DPDP Act stand today?
What counts as reasonable security safeguards?
Are we a Significant Data Fiduciary?
Can our data stay in India?
How does this interact with CERT-In incident reporting?
Does ISO 27001 help with DPDP?
Start Your DPDP Compliance Journey Before Enforcement Catches Up
The DPDP Rules are notified, the Data Protection Board is operational, and Indian enterprises are expected to demonstrate compliance readiness. Do not wait for the first enforcement action to make headlines.
Typically responds within 1 business day · No commitment required
Our reading of the circulars