Skip to main content
AEGIBIT
← AEGIBIT Glossary

DPDP Act (Digital Personal Data Protection Act, India)

India's data-protection law (2023) governing how organizations collect, process, store, and share the personal data of individuals in India, with consent, purpose limitation, and security obligations.

Why it matters

Any business holding customer phone numbers, addresses, or payment references is processing personal data. The DPDP Act matters because it converts good data hygiene from courtesy into legal obligation, with real penalties, and because customers increasingly choose vendors who can answer 'how do you protect my data' convincingly.

How it works

The Act centres on consent-based processing for defined purposes, obligations on 'data fiduciaries' (the entities deciding why and how data is processed) to secure data and honor rights such as correction and erasure, breach notification duties, and restrictions on retaining data beyond its purpose. Compliance in practice means knowing what personal data you hold, why, where, who can touch it, and being able to delete it on request.

A real-world example

A retail software vendor stores customer names and phone numbers for billing on behalf of shops. Under the DPDP lens, the vendor maps this data, restricts staff access by role, logs every access, keeps it hosted appropriately, and builds deletion workflows, so when a shop's customer invokes rights, the chain can actually comply.

Common mistakes

Best practices

Frequently asked questions

Does the DPDP Act apply to small businesses?

It applies to processing of digital personal data broadly, with certain obligations scaled by role and scale. Building on purpose limitation, security, and deletability is the safe posture at any size.

What is a data fiduciary versus a processor?

The fiduciary decides the purpose and means of processing; a processor acts on the fiduciary's instructions. Software vendors are often processors for their clients' customer data, contracts should reflect that.

Where should compliance start for a software product?

In architecture: role-scoped access, audit logs, encryption, data mapped to purpose, and deletion workflows. Paper policies follow engineering reality, not the reverse.

AEGIBIT builds DPDP-aware systems by default: data minimization, role-scoped access, immutable logs, and India-region hosting where it matters.

AEGIBIT's DPDP posture

Related concepts