DPDP Act 2023 — Indian IT Companies ke liye Compliance Guide
India's Digital Personal Data Protection Act 2023 effective 2026. Consent management, data fiduciary obligations, penalties up to ₹250 crore. Is your business ready?
MICS Team··7 min read
DPDP Act 2023 — India Ka New Data Privacy Law
Digital Personal Data Protection (DPDP) Act 2023 India ka landmark data privacy legislation hai. 2026 mein iske provisions fully effective ho rahe hain — every business jo Indians ka personal data process karta hai, comply karna zaroori hai.
#
DPDP Act Kya Hai?
DPDP Act Indian citizens ke personal data ke liye rights establish karta hai aur businesses ke liye obligations define karta hai. Europe ke GDPR jaisa, lekin India ke liye.
Key Provisions:
1. Consent Requirement
Kisi bhi Indian ka personal data collect karne se pehle explicit, informed consent lena mandatory hai. "I agree to T&C" checkboxes enough nahi hain — specific, granular consent chahiye.
2. Data Fiduciary Obligations
Jo business data collect karta hai wo "Data Fiduciary" hai. Obligations:
- Data ko stated purpose se aage use mat karo
- Data accurate aur up-to-date rakho
- Breach ke 72 hours mein authorities ko report karo
3. Data Principal Rights
Indian citizens ke rights:
- Right to access their data
- Right to correction
- Right to erasure ("Right to be forgotten")
- Right to grievance redressal
4. Cross-border Data Transfer
Personal data India se bahar transfer karne ke liye government approval ya whitelist required ho sakti hai.
#
Penalties
DPDP Act ki violations ke liye penalties:
- Data breach without notification: ₹200 crore tak
- Non-compliance with obligations: ₹250 crore tak
- Repeated violations: Additional penalties
#
Kaun Apply Hoga?
- Any company collecting Indian users' data
- Websites with Indian visitors
- Apps with Indian users
- NBFCs, banks, hospitals — sab
#
Compliance Checklist
Website/App:
- ☐ Cookie consent banner
- ☐ Privacy policy (DPDP compliant)
- ☐ Data collection purpose clearly stated
- ☐ Opt-out mechanism
Business Process:
- ☐ Data inventory — kya collect karte ho?
- ☐ Consent management system
- ☐ Data breach response plan
- ☐ Data retention policy
Technical:
- ☐ Encryption at rest and transit
- ☐ Access controls
- ☐ Audit logs
- ☐ Data deletion capability
#
MICS DPDP Compliance Services
MICS aapke business ko DPDP Act compliance ke liye ready karta hai:
1. DPDP Audit — Current data practices ka assessment
2. Privacy Policy Update — DPDP compliant policy drafting
3. Consent Management — Technical implementation
4. Staff Training — Team ko educate karna
5. Ongoing Monitoring — Quarterly compliance review
Pricing: Project-based, starting ₹25,000
Abhi free consultation book karein — penalties se bachein.
DPDPComplianceData PrivacyIndia
Is Mein Help Chahiye?
MICS ke experts se free 30-min consultation lein — koi commitment nahi.