DPDP Act 2023

The Digital Personal Data Protection Act 2023 creates binding legal obligations for every organisation that collects, processes, or stores the personal data of Indian citizens — regardless of where they are headquartered. Nectarix brings the legal depth, technical expertise, and delivery capability to make your organisation fully compliant — and to keep it that way.

₹250Cr

MAXIMUM PENALTY

72hr

BREACH NOTIFICATION

8

PRINCIPAL OBLIGATIONS

Global

EXTRA-TERRITORIAL REACH

Understanding the DPDP Act 2023

The Digital Personal Data Protection Act 2023 is the most significant piece of data governance legislation India has ever enacted. For the first time, India has a comprehensive, enforceable legal framework governing how organisations collect, use, store, share, and delete the personal data of Indian citizens — with meaningful financial penalties for non-compliance and a dedicated enforcement body, the Data Protection Board of India, with independent adjudicatory power.
The Act applies to every organisation — Indian or foreign — that processes the personal data of Indian data principals in connection with any activity, whether digital or digitised. There is no sector exemption, no size threshold, and no grace period for ignorance. Organisations that process personal data have obligations. Those obligations are now law.
What makes the DPDP Act uniquely demanding is not just the breadth of its obligations — it is the depth of the operational change it requires. Consent must be specific, informed, and granular. Data processing must be limited to the purpose for which consent was obtained. Personal data must be deleted when the purpose is fulfilled. Children's data requires verifiable parental consent. These are not policy commitments. They are legal requirements with enforcement teeth.

Consent Management

Free, specific, informed, unconditional, and unambiguous consent required. Separate consent for each purpose. Easy withdrawal mechanism mandatory.

Purpose Limitation

Personal data may only be processed for the specific purpose for which consent was obtained. Secondary use requires fresh consent.

Data Minimisation

Only personal data necessary for the stated purpose may be collected. No speculative or precautionary data collection permitted.

Storage Limitation & Erasure

Personal data must be erased when the purpose is fulfilled or consent withdrawn. Retention periods must be defined and enforced technically.

Security Safeguards

Reasonable security measures to prevent personal data breaches. Breach notification to the Board and data principals within 72 hours.

Children's Data

Verifiable parental consent required for processing data of children under 18. No behavioural tracking or targeted advertising directed at children.

Data Principal Rights

Rights to access, correction, erasure, grievance redressal, and nomination. Mechanisms to fulfil these rights within prescribed timelines mandatory.

Significant Data Fiduciaries

Organisations designated as SDFs face additional obligations: Data Protection Officer, periodic audits, Data Protection Impact Assessments (DPIA).
– Engagement Process

From first call to fully protected

We believe the engagement process is as important as the technology. How we work with you determines whether the outcome is genuinely transformative or merely compliant. Our process is designed to eliminate ambiguity, build trust early, and ensure that every decision is made with complete information.

01

DPDP Readiness Assessment

A comprehensive baseline assessment of your organisation's current state against the full obligations of the DPDP Act 2023. We map your data flows, inventory your personal data processing activities, assess your consent mechanisms, evaluate your security posture, and identify every gap between your current position and full compliance — with a prioritised remediation roadmap.
Personal Data Inventory
Data Flow Mapping
Consent Mechanism Audit

02

Consent Management Architecture

Designing and implementing a DPDP-compliant consent management framework — covering consent collection, storage, versioning, withdrawal, and audit trail — across your digital touchpoints and backend systems. We work across legal, product, and technology teams to build consent infrastructure that is legally robust and operationally practical.
Consent Notice Design
Granular Purpose Mapping
Consent Withdrawal

03

Data Governance Framework

Building the policies, procedures, roles, and controls that constitute a functioning DPDP compliance programme — including the appointment and empowerment of the Data Protection Officer, establishment of the grievance redressal mechanism, vendor management framework for data processors, and the internal governance structures that make compliance self-sustaining.
DPO Role Design & Support
Privacy Policy & Notices
Vendor / Processor Management

04

Technical Controls & Security

Implementing the technical security controls required by the DPDP Act's security safeguard obligations — from data discovery and classification through encryption, access control, DLP, and the breach detection and response capability required to meet the 72-hour notification obligation. Our cybersecurity practice integrates directly for seamless technical delivery.
Data Discovery & Classification
DSPM Implementation
Encryption & Masking

05

Sector- Specific Compliance

Navigating the intersection of DPDP Act obligations with sector-specific regulatory requirements — RBI Master Directions, SEBI CSCRF, IRDAI guidelines, CERT-In incident reporting, and the Health Data Management Policy. We build a unified control framework that satisfies all applicable regulators simultaneously.
RBI IT Framework
SEBI CSCRF
IRDAI Guidelines

06

Managed DPDP Compliance

For organisations who want ongoing DPDP compliance management as a service. Nectarix operates as your embedded data privacy team — monitoring regulatory developments, maintaining your compliance posture, managing consent records, handling data principal requests, preparing for audits, and updating controls as the Rules evolve.
Regulatory Change Monitoring
Quarterly Compliance Reviews
Data Principal Request Mgmt

Team Depth & Expertise

DPDP compliance sits at the intersection of law, technology, and organisational design. Most firms approach it from one direction. Nectarix brings both — legal rigour and technical delivery — in a single, integrated team.
Our DPDP consulting practice is led by practitioners with backgrounds spanning enterprise cybersecurity, data governance, Indian regulatory compliance, legal advisory, and the technical implementation of privacy controls at scale. We have studied the Act, its legislative history, the draft Rules, the TRAI and MeitY consultations that shaped it, and the international frameworks — GDPR, PDPA, PIPEDA — from which it draws.
More importantly, we have delivered technology and compliance programmes in the exact sectors where DPDP risk is highest — financial services, healthcare, technology platforms, and government. Our cybersecurity practice integrates directly into our DPDP work — because data protection is ultimately a security problem as much as a legal one. The team that designs your consent framework is the same team that implements the DLP controls, the breach detection system, and the 72-hour notification playbook.

Delivery Methodology

DPDP compliance is an operational transformation — across data systems, consent flows, vendor contracts, security controls, and governance structures — that must be delivered with legal precision and technical rigour simultaneously. Our six-phase methodology ensures nothing is assumed, nothing is skipped, and every commitment we make is one we can evidence.

01 - DISCOVER

02 — ASSESS

03 — DESIGN

04 — IMPLEMENT

05 — VALIDATE

06 — SUSTAIN

Scroll to Top