DPDP Act 2023
The Digital Personal Data Protection Act 2023 creates binding legal obligations for every organisation
that collects, processes, or stores the personal data of Indian citizens — regardless of where they are
headquartered. Nectarix brings the legal depth, technical expertise, and delivery capability to make
your organisation fully compliant — and to keep it that way.
₹250Cr
MAXIMUM PENALTY
72hr
BREACH NOTIFICATION
8
PRINCIPAL
OBLIGATIONS
Global
EXTRA-TERRITORIAL
REACH
Understanding the DPDP Act 2023
The Digital Personal Data Protection Act 2023 is the most significant piece of data governance
legislation India has ever enacted. For the first time, India has a comprehensive, enforceable legal
framework governing how organisations collect, use, store, share, and delete the personal data of Indian
citizens — with meaningful financial penalties for non-compliance and a dedicated enforcement body,
the Data Protection Board of India, with independent adjudicatory power.
The Act applies to every organisation — Indian or foreign — that processes the personal data of Indian
data principals in connection with any activity, whether digital or digitised. There is no sector exemption,
no size threshold, and no grace period for ignorance. Organisations that process personal data have
obligations. Those obligations are now law.
What makes the DPDP Act uniquely demanding is not just the breadth of its obligations — it is the depth
of the operational change it requires. Consent must be specific, informed, and granular. Data processing
must be limited to the purpose for which consent was obtained. Personal data must be deleted when the
purpose is fulfilled. Children's data requires verifiable parental consent. These are not policy
commitments. They are legal requirements with enforcement teeth.
Consent Management
Free, specific, informed, unconditional, and unambiguous consent required. Separate consent
for each purpose. Easy withdrawal mechanism mandatory.
Purpose Limitation
Personal data may only be processed for the specific purpose for which consent was obtained.
Secondary use requires fresh consent.
Data Minimisation
Only personal data necessary for the stated purpose may be collected. No speculative or
precautionary data collection permitted.
Storage Limitation & Erasure
Personal data must be erased when the purpose is fulfilled or consent withdrawn. Retention
periods must be defined and enforced technically.
Security Safeguards
Reasonable security measures to prevent personal data breaches. Breach notification to the
Board and data principals within 72 hours.
Children's Data
Verifiable parental consent required for processing data of children under 18. No behavioural
tracking or targeted advertising directed at children.
Data Principal Rights
Rights to access, correction, erasure, grievance redressal, and nomination. Mechanisms to
fulfil these rights within prescribed timelines mandatory.
Significant Data Fiduciaries
Organisations designated as SDFs face additional obligations: Data Protection Officer, periodic
audits, Data Protection Impact Assessments (DPIA).
– Engagement Process
From first call to fully protected
We believe the engagement process is as important as the technology. How we work with you determines whether the outcome is genuinely transformative or merely compliant. Our process is designed to eliminate ambiguity, build trust early, and ensure that every decision is made with complete information.
01
DPDP Readiness Assessment
A comprehensive baseline assessment of your organisation's current state
against the full obligations of the DPDP Act 2023. We map your data flows,
inventory your personal data processing activities, assess your consent
mechanisms, evaluate your security posture, and identify every gap between your
current position and full compliance — with a prioritised remediation roadmap.
Personal Data Inventory
Data Flow Mapping
Consent Mechanism Audit
02
Consent Management Architecture
Designing and implementing a DPDP-compliant consent management
framework — covering consent collection, storage, versioning, withdrawal, and
audit trail — across your digital touchpoints and backend systems. We work
across legal, product, and technology teams to build consent infrastructure that is
legally robust and operationally practical.
Consent Notice Design
Granular Purpose Mapping
Consent Withdrawal
03
Data Governance Framework
Building the policies, procedures, roles, and controls that constitute a
functioning DPDP compliance programme — including the appointment and
empowerment of the Data Protection Officer, establishment of the grievance
redressal mechanism, vendor management framework for data processors, and
the internal governance structures that make compliance self-sustaining.
DPO Role Design & Support
Privacy Policy & Notices
Vendor / Processor Management
04
Technical Controls & Security
Implementing the technical security controls required by the DPDP Act's security
safeguard obligations — from data discovery and classification through encryption,
access control, DLP, and the breach detection and response capability required to
meet the 72-hour notification obligation. Our cybersecurity practice integrates
directly for seamless technical delivery.
Data Discovery & Classification
DSPM Implementation
Encryption &
Masking
05
Sector- Specific Compliance
Navigating the intersection of DPDP Act obligations with sector-specific
regulatory requirements — RBI Master Directions, SEBI CSCRF, IRDAI
guidelines, CERT-In incident reporting, and the Health Data Management Policy.
We build a unified control framework that satisfies all applicable regulators
simultaneously.
RBI IT Framework
SEBI CSCRF
IRDAI Guidelines
06
Managed DPDP Compliance
For organisations who want ongoing DPDP compliance management as a
service. Nectarix operates as your embedded data privacy team — monitoring
regulatory developments, maintaining your compliance posture, managing
consent records, handling data principal requests, preparing for audits, and
updating controls as the Rules evolve.
Regulatory Change Monitoring
Quarterly Compliance Reviews
Data
Principal Request Mgmt
Team Depth & Expertise
DPDP compliance sits at the intersection of law, technology, and
organisational design. Most firms approach it from one direction.
Nectarix brings both — legal rigour and technical delivery — in a single,
integrated team.
Our DPDP consulting practice is led by practitioners with backgrounds spanning enterprise
cybersecurity, data governance, Indian regulatory compliance, legal advisory, and the technical
implementation of privacy controls at scale. We have studied the Act, its legislative history, the draft
Rules, the TRAI and MeitY consultations that shaped it, and the international frameworks — GDPR,
PDPA, PIPEDA — from which it draws.
More importantly, we have delivered technology and compliance programmes in the exact sectors
where DPDP risk is highest — financial services, healthcare, technology platforms, and government.
Our cybersecurity practice integrates directly into our DPDP work — because data protection is
ultimately a security problem as much as a legal one. The team that designs your consent framework
is the same team that implements the DLP controls, the breach detection system, and the 72-hour
notification playbook.
Delivery Methodology
DPDP compliance is an operational transformation — across data systems, consent flows, vendor
contracts, security controls, and governance structures — that must be delivered with legal precision and
technical rigour simultaneously. Our six-phase methodology ensures nothing is assumed, nothing is
skipped, and every commitment we make is one we can evidence.
01 - DISCOVER
- Personal data inventory across all systems
- Data flow mapping — collection to deletion
- Data principal categories identification
- Third-party processor inventory
- Cross-border transfer identification
- Deliverable: Data Landscape Report
02 — ASSESS
- Gap analysis against 8 DPDP obligations
- Consent mechanism evaluation
- Security safeguard assessment
- Children's data risk review
- SDF designation assessment
- Deliverable: Gap & Risk Report
03 — DESIGN
- Consent architecture design
- Governance framework design
- DPO role & mandate design
- Data retention & erasure policy
- Privacy notice drafting
- Deliverable: Compliance Blueprint
04 — IMPLEMENT
- Consent management platform deploy
- Data classification & DSPM rollout
- DLP & access control implementation
- Breach detection & response build
- Staff training programme delivery
- Deliverable: Live compliance controls
05 — VALIDATE
- Control effectiveness testing
- Consent flow & penetration testing
- Data principal rights exercise test
- 72-hour breach response drill
- Independent compliance audit
- Deliverable: Audit-ready evidence pack
06 — SUSTAIN
- Regulatory change monitoring
- Quarterly compliance reviews
- Annual DPDP audit support
- Data principal request management
- Incident response (privacy) retainer
- Deliverable: Continuous compliance