01Program

DPDP Act compliance services: data protection readiness for Data Fiduciaries in India

Readiness for the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules: knowing what personal data you hold and why, notice and consent that meet the Act, processes for Data Principal requests, grievances and breaches, and the reasonable security safeguards the Act requires. Legal interpretation stays with your counsel; the operating program is our work.

Name
DPDP Act Compliance
Line
01 · Cybersecurity
Type
Outcome program, combines several practices

01The problem

The DPDP Act turns data protection from a policy into an operating duty.

The DPDP Act applies to any organization that processes digital personal data in India, and to processing outside India connected with offering goods or services to people in India. It makes the Data Fiduciary accountable for purpose limitation, notice and consent, the rights of Data Principals, erasure when the purpose is served, breach notification to the Data Protection Board of India and to affected individuals, and reasonable security safeguards. Penalties for failing to maintain those safeguards reach INR 250 crore per instance.

The DPDP Rules, 2025 set the timetable and the detail: how notices are worded, how consent managers operate, what a breach notice must contain and when, the duties of Significant Data Fiduciaries, and verifiable parental consent for children’s data. Most organizations discover that the hard part is not the policy but the data map and the processes behind it.

02Scope

What the DPDP Act compliance program covers.

  • Applicability and role assessment

    Whether you act as Data Fiduciary or Data Processor for each processing activity, whether the Significant Data Fiduciary criteria could apply, and which obligations follow.

  • Personal data inventory and mapping

    What personal data is collected, from whom, on what basis, where it is stored and processed, who it is shared with and when it is erased.

  • Notice and consent design

    Notices in the form the Act and Rules require, consent capture and withdrawal that is as easy as giving it, and records that show consent for each purpose.

  • Data Principal rights and grievance process

    Workflows for access, correction, erasure, nomination and grievance redressal, with identity verification and response tracking.

  • Reasonable security safeguards

    Encryption, access control, logging, backup and monitoring assessed against the Act’s safeguards duty and implemented with your technology teams.

  • Breach notification readiness

    Detection, assessment and notification procedures for the Board and affected Data Principals on the timelines in the Rules, rehearsed in a tabletop exercise.

  • Processor contracts and third parties

    Contract terms, due diligence and oversight for the Data Processors and vendors that handle personal data on your behalf.

  • Significant Data Fiduciary obligations

    Data Protection Officer support, data protection impact assessments and the periodic audit the Act requires of entities so designated.

03Approach

How a DPDP Act compliance engagement runs.

The DPDP Act, 2023 and the DPDP Rules, 2025, read alongside ISO/IEC 27701 for privacy information management and the security controls of ISO/IEC 27001. Organizations already working to GDPR reuse much of that program, and we map the differences. Related requirements, including CERT-In directions and [SEBI CSCRF](/services/cybersecurity/sebi-cscrf-compliance), are listed under [compliance frameworks](/services/cybersecurity/compliance-frameworks).

  1. Map

    Build the personal data inventory with the teams that collect and use the data. Everything else depends on it.

  2. Assess

    Compare current notices, consent, retention, security and vendor arrangements against the Act and the Rules. Findings are rated by exposure and by effort.

  3. Design

    Notices, consent flows, retention schedules, rights and grievance workflows and breach procedures, sized to the organization.

  4. Implement

    Changes made to applications, forms, data stores and contracts with your product, engineering and legal teams. Onion development and data security teams can carry out the technical work.

  5. Operate and evidence

    Consent records, request logs, retention actions and training recorded as they happen, so an inquiry from the Board or a customer can be answered from records.

04Outcomes

What the DPDP Act compliance program is built to achieve.

  • A personal data inventory and processing map with owners
  • Notices, consent mechanisms and consent records that meet the Act and Rules
  • Working processes for Data Principal requests, grievances and erasure
  • Security safeguards assessed, implemented and evidenced
  • A breach notification procedure that has been rehearsed
  • Processor contracts and vendor oversight in place

When this work fits

  • Companies processing personal data of individuals in India, as Data Fiduciaries or Data Processors
  • Organizations with a GDPR program that need to map the differences for India
  • Businesses collecting children’s data or likely to meet Significant Data Fiduciary criteria
  • SEBI, RBI or IRDAI regulated entities adding data protection to an existing compliance program

05Questions

DPDP Act compliance: questions we are asked

Any organization processing digital personal data within India, and processing outside India connected with offering goods or services to Data Principals in India. The Act applies regardless of size. The extra duties for Significant Data Fiduciaries apply to entities the government notifies on criteria such as the volume and sensitivity of data processed.

The DPDP Act relies on consent and a defined set of legitimate uses rather than GDPR’s six lawful bases, applies only to digital personal data, has no special-category data concept, and routes grievances through the Data Fiduciary first and then the Data Protection Board of India. Breach notification goes to the Board and to every affected Data Principal. A GDPR program is a strong start; the data map, notices, consent records and breach process need India-specific work.

The Act was passed in August 2023 and the DPDP Rules, 2025 set a phased timetable, with the Data Protection Board constituted first and most obligations on Data Fiduciaries following over the subsequent months. The data mapping, notice redesign and process work take longest, so organizations are starting now rather than waiting for the final date. We confirm the current timetable at scoping, and your counsel confirms the legal position.

The Act requires a Data Protection Officer only for Significant Data Fiduciaries, along with an independent data auditor and periodic data protection impact assessments. Every Data Fiduciary must publish the contact of a person who can answer questions about its processing and must operate a grievance process. We help you decide whether the Significant Data Fiduciary criteria could apply and set up the roles either way.

No. We design and implement the operating program: the data inventory, notices, consent, rights and breach processes, security safeguards and records. Interpretation of the Act and the Rules for your circumstances stays with your legal counsel, and we work alongside them.

Working with us

What every engagement rests on.

Non-disclosure agreements
Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
Least-privilege access
The minimum access the work requires, tied to named individuals and removed when the work ends.
Telemetry stays in your tenant
In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
End of engagement
Access is handed back, and your information is returned or deleted as agreed with you.

Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India