DPDP Act full enforcement begins May 2027 · — days remaining
DPDP Act, 2023 · A guide for business owners

Understanding the Digital Personal Data Protection Act.

India's DPDP Act governs how organisations collect, use, store and protect personal data. It applies across industries and affects businesses of every size that handle information relating to individuals.

The question is not how large your organisation is. It is:
"Do we collect, store, process or share personal data?"
What is this?

A practical guide.

Understand what the DPDP Act means in plain language and how it affects modern organisations.

Does it apply?

Find out quickly.

Learn whether your organisation is likely to be affected and what questions you should already be asking.

How do we begin?

Start with facts.

Discover the journey from data discovery and gap assessment to implementation and governance.

For many organisations, the challenge is not whether they possess data. It is understanding where that data exists, how it moves through the organisation, who can access it, and whether the organisation can demonstrate responsible governance when required.

This guide answers some of the most common questions business owners, management teams and decision-makers are asking as they begin their DPDP journey.

01

What is the DPDP Act?

What is the Digital Personal Data Protection Act, 2023?

It is India's principal law governing the processing of personal data in digital form. It establishes obligations for organisations that collect and use personal information, and provides rights to the individuals whose data is being processed. The Act seeks to create a framework in which organisations can continue to operate and innovate while ensuring that personal information is handled responsibly.

Why was the Act introduced?

Modern organisations collect and process significant amounts of information every day through websites, mobile applications, employee records, financial transactions, customer interactions, healthcare systems and third-party platforms. As businesses become increasingly digital, personal information moves across departments, vendors, cloud platforms and external service providers. The DPDP Act introduces a common framework to govern these activities transparently and accountably.

What problem is the Act trying to solve?

Personal data is often spread across multiple systems, teams and external providers. Over time, businesses may lose visibility into:

The DPDP Act encourages organisations to understand and manage these questions systematically.

Does the DPDP Act replace cybersecurity laws?

No

Cybersecurity and data protection are closely related, but they are not the same thing. Cybersecurity focuses on protecting systems, devices and networks from unauthorised access, attacks and technical failures. The DPDP Act focuses on how organisations collect, use, retain, share and govern personal data throughout its lifecycle. Strong cybersecurity is important, but it is only one part of a broader compliance framework.

What is personal data?

Personal data is any information that relates to an identifiable individual. Examples may include names, addresses, email IDs, mobile numbers, PAN and Aadhaar details, photographs, salary records, medical reports, banking information, customer identifiers, employee records and location information. The definition extends beyond customer data it may include information relating to employees, contractors, patients, students and vendors.

02

Does the DPDP Act apply to my organisation?

Is the Act only for large companies?

No

Applicability does not depend on the size of an organisation. A large enterprise and a small firm may both process significant amounts of personal information. The relevant question is not how many employees you have, but whether you collect, store, use or share personal data.

Is it relevant only to banks and hospitals?

No

Banks, insurers and healthcare institutions often process sensitive information but personal data is handled across finance, manufacturing, education, consulting, logistics, retail and professional services alike.

Does it apply to startups, partnerships and proprietorships?

It may

Startups, LLPs, family-run businesses and proprietorships collect customer, employee, vendor and operational data through websites, accounting systems, payroll platforms and third-party software. The form of the business matters less than the nature of the data being processed.

Does it affect manufacturers, schools and service providers?

Yes

Manufacturers hold employee, supplier, logistics and customer records. Educational institutions process student and parent information. Professional firms handle financial, identity and payroll records. Every organisation should understand how personal information enters and moves through its business.

Industries likely to be affected
  • Banking and financial services · insurance
  • Healthcare and pharmaceuticals
  • Chartered accountancy and advisory
  • Manufacturing · logistics and transportation
  • E-commerce and quick commerce · retail
  • Telecommunications · software and technology
  • Education · HR and payroll services
  • Consulting and professional services

The question is not "How large is my organisation?" it is "Do we collect, store, process or share personal data?"

03

What does this mean for my organisation?

For many organisations, DPDP readiness begins with visibility. Before implementing new technologies or policies, organisations should understand the information they already possess and how it moves across their operations.

Questions to be able to answer
  1. What personal information do we hold?
  2. Why did we collect it?
  3. Where is it stored?
  4. Which teams can access it?
  5. Which vendors and service providers receive it?
  6. How long do we retain it?
  7. What agreements govern its use?
  8. How do we respond if something goes wrong?

In many cases, organisations already have security measures, contracts and internal processes in place. The challenge is often not the absence of controls, but the ability to demonstrate them clearly and consistently. DPDP readiness is not simply about deploying technology it is about ensuring that the use of personal information remains transparent, controlled and accountable.

04

Where do we stand today?

Most organisations are not starting from zero. They may already have information security measures, employment policies, vendor agreements, operational procedures, retention practices, audit controls and regulatory obligations in place.

The first step is understanding where these measures exist and identifying the areas that require greater clarity. To assist with this, Yorix Digital Partners has developed sector specific self-assessment questionnaires designed for different industries and operating environments. These assessments examine:

Most organisations already possess elements of compliance. The challenge is rarely the complete absence of controls it is demonstrating those controls consistently across people, processes and technology.

05

What does the compliance journey look like?

Many organisations assume compliance begins with the purchase of software. In reality, it begins with understanding. The journey typically unfolds in stages.

1

Understand your data

Know what personal data you hold, where it originates, why it was collected, who uses it, and how long it remains relevant. Without this visibility, meaningful governance is difficult.

2

Understand your systems

Personal information rarely resides in a single location. It exists across enterprise applications, accounting systems, CRM platforms, email, HR and payroll software, cloud services, shared drives and employee devices.

3

Understand your vendors

Payroll providers, software vendors, cloud platforms, consultants, logistics partners and managed service providers may all receive data. Understand what is shared externally and the responsibilities attached to it.

4

Build governance

Technology alone cannot create accountability. Effective governance requires defined policies, standard operating procedures, ownership, retention practices, escalation mechanisms and incident response.

5

Implement practical controls

Once visibility and governance are established, strengthen the controls that support them technical, operational, contractual or organisational. The objective is not complexity; it is consistency.

6

Continuously improve

Compliance is not a one-time exercise. Businesses, teams, vendors and systems change. The organisations that adapt treat privacy and governance as an ongoing discipline, not a project with a fixed end date.