Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

DPDP Act compliance, for Indian obligations.

A DPDP Act compliance consultant in India is dealing with a regime that is genuinely different from GDPR, not a translation of it. The Digital Personal Data Protection Act, 2023 is built around notice and consent, it introduces the Consent Manager, it treats verifiable parental consent for children as a hard requirement, and its penalties are set per duty in a Schedule rather than as a percentage of turnover.

If you have already done GDPR work, a great deal transfers: the data inventory, the security measures, the rights machinery. What does not transfer is the specific shape of Indian obligations: the itemised notice, the grievance redressal officer, the reporting of every personal data breach without a risk threshold, and the additional duties that attach if you are notified as a Significant Data Fiduciary.

We work from the data inventory outward, the same way, and build the obligations the Act actually imposes on a Data Fiduciary. Where you also serve EU customers, run it alongside GDPR on one governance layer; where you want it certifiable, ISO 27701 is the management system.

Why you need it

01 / 06

Why the DPDP Act needs its own programme.

01

Consent is the centre of gravity.

The Act is built around consent as the primary ground for processing, supported by an itemised notice describing the personal data and the purpose, available in English and in the Eighth Schedule languages. Consent must be free, specific, informed, unconditional, unambiguous and as easy to withdraw as to give.

02

Every breach is reportable.

The Act requires a Data Fiduciary to give intimation of a personal data breach to the Data Protection Board and to each affected Data Principal. There is no materiality threshold of the kind GDPR provides, which makes detection and an actual reporting process a compliance requirement rather than a good practice.

03

Children's data has strict conditions.

Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. Any consumer service with users under eighteen has to solve this deliberately.

04

Significant Data Fiduciaries carry more.

Entities notified as Significant Data Fiduciaries must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic data protection impact assessments and audits. Whether you are notified depends on volume, sensitivity and risk factors under the Act.

Instrument

02 / 06

What each duty is worth, under the Schedule.

The Schedule to the Act sets a separate maximum penalty for each duty. Select the ones you could not evidence today.

What we deliver

03 / 06

What we deliver.

01

Data mapping and classification

Every category of digital personal data you process, its source, purpose, recipients, storage location and retention, and a determination of your role as Data Fiduciary or Data Processor for each activity, since the duties differ.

02

Notice and consent architecture

Itemised notice meeting the Act's requirements, consent capture that is specific to purpose, withdrawal that is as easy as giving and actually propagates through your systems, and a consent record that can be produced as evidence. Includes readiness for Consent Manager integration.

03

Data principal rights

Procedures for the rights the Act grants (access to information about processing, correction, completion, updating and erasure, grievance redressal, and nomination) with the timelines tracked and responses evidenced.

04

Grievance redressal

A published, working grievance mechanism with a responsible person, defined response timelines, and records. A Data Principal must exhaust this before approaching the Data Protection Board, which makes it both an obligation and your first line of defence.

05

Breach detection and intimation

The detection capability to know a breach has occurred, and the process to give intimation to the Board and to affected Data Principals, because a reporting obligation without monitoring behind it cannot be met.

06

Significant Data Fiduciary readiness

Where you are notified or expect to be: an India-based Data Protection Officer, independent data auditor arrangements, periodic data protection impact assessments and audits, and the additional governance those duties imply.

How we run it

04 / 06

Six steps.

  1. 01

    Data mapping and classification

    Identifying and classifying the digital personal data you collect, process and store, with data flows and a Fiduciary or Processor determination per activity. Interview-led, because the flows that matter are rarely documented.

    Weeks 1-4
  2. 02

    Implement privacy safeguards

    Reasonable security safeguards to prevent a personal data breach (encryption, access control, logging, retention and deletion) proportionate to the data and evidenced, since the Act imposes this as a distinct duty with its own penalty.

    Months 1-3
  3. 03

    Update notices and policies

    Itemised notices describing the personal data and the purpose, available in English and the Eighth Schedule languages, with internal policies that make the notice accurate.

    Month 2
  4. 04

    Obtain and manage consent

    Consent capture meeting the Act's standard, granular by purpose, recorded as evidence, withdrawable as easily as given, with the downstream deletion and processing-stop that withdrawal implies.

    Months 2-3
  5. 05

    Rights and grievance redressal

    Request handling for access, correction, erasure and nomination, plus a published grievance mechanism with a named responsible person and tracked timelines.

    Month 3
  6. 06

    Monitoring and audits

    Periodic review of processing against consent and notice, breach detection and reporting readiness, and, for Significant Data Fiduciaries, impact assessments and independent audits on the required cadence.

    Ongoing

Key benefits

05 / 06

What changes after.

Consent is evidenced, not assumed

A record of what each Data Principal was told and agreed to, when, and what happened when they withdrew, which is the evidence the Board would ask for.

Breach reporting is possible

Detection and a defined intimation process, so an obligation that applies to every breach can actually be met rather than discovered as a gap during one.

Complaints resolve before they escalate

A working grievance mechanism handles issues internally, which is both a duty under the Act and the step a Data Principal must exhaust first.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Legislation

  • Digital Personal Data Protection Act, 2023
  • The Schedule (penalties by duty)
  • Draft DPDP Rules

Privacy operations

  • Data inventory and classification
  • Consent record and withdrawal register
  • Retention and deletion schedule

Rights and grievance

  • Data principal request workflow
  • Grievance redressal register
  • Nomination handling

Breach readiness

  • Detection and monitoring coverage
  • Intimation procedure and templates
  • Incident record

Mapping

  • GDPR
  • ISO/IEC 27701
  • ISO/IEC 27001:2022

Included in this service

Data privacy governance

Also

Most Indian organisations of any scale are not facing the DPDP Act alone. They have EU customers under GDPR, perhaps Californian users, and sector rules from the RBI, SEBI or IRDAI on top. Running a separate programme for each is how privacy teams end up maintaining four inventories that disagree.

The governance layer underneath is common: one data inventory serving every regime, a privacy risk methodology and register, ownership of personal data assigned by business function, retention and deletion enforced technically, privacy review embedded in product delivery, and vendor and sub-processor governance for everyone downstream.

Built once, each regime becomes a gap analysis against that baseline. The DPDP Act's distinct requirements (itemised notice, the consent architecture, grievance redressal, breach intimation without a threshold) are then additions to a known position rather than the start of another discovery exercise.

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about the DPDP Act.

Who does the DPDP Act apply to?
It applies to the processing of digital personal data within India, whether collected digitally or digitised afterwards. It also applies to processing outside India where that processing is in connection with offering goods or services to Data Principals in India. Certain processing is outside its scope, including personal data made publicly available by the Data Principal themselves and processing for personal or domestic purposes.
How is it different from GDPR?
The structure differs more than the intent. The DPDP Act is built around consent and legitimate uses rather than GDPR's six lawful bases; it introduces the Consent Manager as a registered intermediary; it requires intimation of every personal data breach without GDPR's risk threshold; and it sets penalties per duty in a Schedule rather than as a percentage of turnover. It also has no separate special-category regime, but treats children's data with specific strictness. Your GDPR data inventory and security work transfers; the notice, consent and grievance mechanics do not.
What are the penalties?
The Schedule to the Act sets a separate maximum for each duty, with the highest maxima attaching to failure to take reasonable security safeguards to prevent a breach and to failure to give breach intimation. The Data Protection Board determines the actual amount under section 33(2), taking into account factors including the nature and gravity of the breach and any mitigating action taken. The instrument on this page walks through the Schedule duty by duty.
Are we a Significant Data Fiduciary?
You are one only if the Central Government notifies you as such, based on factors set out in the Act including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, and impact on the sovereignty and integrity of India, electoral democracy, security of the State and public order. Organisations processing large volumes of personal data at consumer scale should plan for the additional duties (an India-based DPO, an independent data auditor, and periodic impact assessments and audits) rather than wait to be told.
What should we do first?
The data inventory, always. Until you know what digital personal data you hold, where it came from, why you have it, who you share it with and how long you keep it, you cannot write an accurate notice, cannot scope consent, cannot serve a correction or erasure request and cannot assess a breach. Everything else in the Act depends on it, and it is also the artefact that transfers to every other privacy regime you will face.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.