INDIA · DPDP ACT 2023

DPDP compliance for Indian companies.

Everything you need to meet the DPDP Act 2023 — Privacy Center, DSR inbox, consent records, breach workflow, and audit proof.

No credit card required. Privacy Center live in 15 minutes.

SECTION 33 PENALTY SCHEDULE

What non-compliance actually costs.

The Data Protection Board can impose penalties per violation — not per company per year.

ViolationSectionMax penalty
Failure to take reasonable security safeguardsSection 8(1)₹250 Crore
Failure to notify DPBI of data breachSection 8(6)₹200 Crore
Non-fulfillment of obligations for children's dataSection 9₹200 Crore
Non-fulfillment of Significant Data Fiduciary obligationsSection 10₹150 Crore
Breach of any other provision of the ActSection 33₹50 Crore
Breach of voluntary undertaking to the BoardSection 33₹50 Crore
Maximum aggregate per entitySection 33(2)₹500 Crore (~$60M)

YOUR OBLIGATIONS

Six things the DPDP Act requires.

Grievance Officer

Section 13

Appoint and publish a named officer. Every data principal has the right to raise a grievance. 30-day resolution window.

Consent records

Sections 6–7

Granular, purpose-specific consent. Must be withdrawable at any time, with records maintained.

Privacy notice

Section 5

Clear notice before data collection, in plain language, stating purpose and rights.

Data principal rights

Sections 11–13

Right to access, correct, and erase personal data. Respond within 30 days.

Breach response

Section 8

Notify the Data Protection Board and affected persons. Mandatory for significant data fiduciaries.

Data inventory

Accountability

Know what personal data you hold, why, and for how long. Required for RoPA and DPIA.

HOW CONDUIT COVERS EACH OBLIGATION

One workspace. Every requirement.

DPDP ObligationHow Privacy Conduit covers it
Grievance OfficerGrievance workflow with SLA enforcement and Section 13 case tagging.
Consent recordsConsent records module: granted, withdrawn, expired, purpose-tagged.
Privacy noticePrivacy Center with jurisdiction-specific notice and right descriptions.
Data principal rightsDSR inbox with 30-day SLA clock and automatic overdue escalation.
Breach responseBreach workflow with DPBI notification template and 72-hour countdown.
Data inventoryData inventory, RoPA export, and DPIA generator in one workspace.

FREQUENTLY ASKED

DPDP Act, answered.

What is the Digital Personal Data Protection (DPDP) Act 2023?
The DPDP Act 2023 is India’s comprehensive data protection law. It governs how organisations (data fiduciaries) collect, process, and store the personal data of individuals (data principals), and gives those individuals enforceable rights over their data.
What rights do data principals have under the DPDP Act?
Under Sections 11–13, data principals have the right to access a summary of their personal data, the right to correction and erasure, the right to nominate, and the right to grievance redressal. Companies must act on these requests within a reasonable, defined period.
How long does a company have to respond to a DPDP request?
Data fiduciaries are expected to respond to data principal requests and resolve grievances within 30 days. Privacy Conduit runs a 30-day SLA clock on every request with automatic overdue escalation.
What are the penalties for DPDP non-compliance?
The Data Protection Board of India can impose penalties per violation under Section 33 — up to ₹250 crore for failing to take reasonable security safeguards, and an aggregate cap of ₹500 crore per entity. Penalties are assessed per violation, not per company per year.
Do Indian companies need to appoint a Grievance Officer?
Yes. Section 13 requires data fiduciaries to appoint and publish a named Grievance Officer that every data principal can contact, with a 30-day resolution window for grievances.

GET STARTED

Start your DPDP workspace today.

Privacy Center live in 15 minutes. Full DPDP compliance toolkit included.