DPDP Act (Digital Personal Data Protection Act, India)
India's data-protection law (2023) governing how organizations collect, process, store, and share the personal data of individuals in India, with consent, purpose limitation, and security obligations.
Why it matters
Any business holding customer phone numbers, addresses, or payment references is processing personal data. The DPDP Act matters because it converts good data hygiene from courtesy into legal obligation, with real penalties, and because customers increasingly choose vendors who can answer 'how do you protect my data' convincingly.
How it works
The Act centres on consent-based processing for defined purposes, obligations on 'data fiduciaries' (the entities deciding why and how data is processed) to secure data and honor rights such as correction and erasure, breach notification duties, and restrictions on retaining data beyond its purpose. Compliance in practice means knowing what personal data you hold, why, where, who can touch it, and being able to delete it on request.
A real-world example
A retail software vendor stores customer names and phone numbers for billing on behalf of shops. Under the DPDP lens, the vendor maps this data, restricts staff access by role, logs every access, keeps it hosted appropriately, and builds deletion workflows, so when a shop's customer invokes rights, the chain can actually comply.
Common mistakes
- ✗ Collecting data 'because it might be useful', purpose limitation forbids exactly this
- ✗ Keeping personal data in exports, chats, and spreadsheets outside governed systems
- ✗ Having no deletion path, rights you cannot execute are violations waiting
- ✗ Treating compliance as a legal document instead of an engineering property
Best practices
- ✓ Inventory personal data: what, where, why, who accesses it
- ✓ Minimize collection and retention to the stated purpose
- ✓ Enforce access by role, log access, and secure data in transit and at rest
- ✓ Design erasure and correction as product features, not manual heroics
Frequently asked questions
Does the DPDP Act apply to small businesses?
It applies to processing of digital personal data broadly, with certain obligations scaled by role and scale. Building on purpose limitation, security, and deletability is the safe posture at any size.
What is a data fiduciary versus a processor?
The fiduciary decides the purpose and means of processing; a processor acts on the fiduciary's instructions. Software vendors are often processors for their clients' customer data, contracts should reflect that.
Where should compliance start for a software product?
In architecture: role-scoped access, audit logs, encryption, data mapped to purpose, and deletion workflows. Paper policies follow engineering reality, not the reverse.
AEGIBIT builds DPDP-aware systems by default: data minimization, role-scoped access, immutable logs, and India-region hosting where it matters.
AEGIBIT's DPDP posture →Related concepts