Digital Personal Data Protection Act, 2023
No. The Act applies to every organization processing digital personal data, irrespective of the industry. Hospitals, schools, manufacturers, banks, startups, NGOs, and government entities may all fall within its scope.
KGS Insight: DPDP is a cross-sector law, not an IT law.
Not directly. However, if personal data is collected in physical form and subsequently digitized, the Act applies to such digital processing.
KGS Insight: Many organizations wrongly assume that paper records are completely outside the scope of DPDP.
Yes. The Act may apply where personal data is processed outside India in connection with offering goods or services to individuals within India.
KGS Insight: Organizations providing digital services to Indian users should evaluate their DPDP obligations even if processing occurs overseas.
No. The DPDP Act governs personal data. Data that has been irreversibly anonymized and can no longer identify an individual generally falls outside its scope.
Yes. The status depends on Government notification and the applicable statutory criteria, not merely on the size or age of the organization.
Yes. Employee information such as payroll details, attendance records, performance data, CCTV footage, and HR records may constitute personal data under the Act.
No. Organizations must comply with the DPDP Act in addition to applicable sectoral laws, regulations, contractual obligations, and professional standards.
KGS Insight: DPDP complements sectoral regulations; it does not replace them.
Only information relating to an identifiable individual qualifies as personal data. Whether an individual can be identified directly or indirectly is an important consideration.
No. Effective DPDP implementation requires collaboration across legal, compliance, IT, cybersecurity, HR, operations, procurement, and business teams.
KGS Insight: DPDP is an enterprise-wide governance framework, not just a legal project.
The Act envisages that the Data Principal should first utilize the organization's grievance redressal mechanism before approaching the Board, where applicable.
KGS Insight: An effective internal grievance process can significantly reduce regulatory complaints.
No. The nomination enables the nominee to exercise rights under the DPDP Act. It does not create inheritance, succession, ownership, or contractual rights.
Many organizations focus on collecting consent but fail to establish operational processes for handling access requests, corrections, grievances, nominations, and identity verification.
KGS Insight: Compliance is measured not only by how personal data is collected but also by how effectively organizations respond to Data Principal requests.
The Act does not prescribe a specific mode of obtaining consent. However, organizations should maintain verifiable records demonstrating that valid consent was obtained.
KGS Insight: If consent cannot be demonstrated, it becomes difficult to establish compliance.
Organizations should not assume consent merely because an individual does not object or continues to use a service.
Organizations should carefully evaluate whether marketing activities fall within any legitimate use. In many cases, consent may still be the appropriate basis.
No. Where personal data is proposed to be processed for a new purpose, organizations should evaluate whether fresh consent or another lawful basis is required.
Not always. A single notice may cover multiple related processing activities, provided it clearly explains all relevant purposes.
Yes. Organizations should be able to demonstrate that the applicable notice was provided before or at the time of processing.
The organization should cease processing personal data based on that consent unless another lawful basis under the Act applies.
It is a process that enables the organization to reasonably verify that consent has been provided by the child's parent or lawful guardian.
Organizations should review whether existing admission processes satisfy the requirements relating to verifiable consent and appropriate documentation.compliance
Organizations should exercise heightened caution when deploying AI systems involving children's personal data and ensure compliance with applicable legal requirements.
No. Only the situations specifically covered under Section 7 qualify as legitimate uses.
No. The DPDP Act does not impose a general prohibition on transferring personal data outside India. However, such processing remains subject to restrictions that may be notified by the Central Government.
KGS Insight: DPDP follows a "transfer permitted unless restricted" approach, unlike some international privacy laws.
Yes. If personal data is stored, accessed, or otherwise processed outside India, it may constitute cross-border processing.
No. However, organizations should conduct appropriate vendor due diligence and monitor any restrictions notified by the Central Government.
No. Encryption is an important security safeguard but does not alter the applicability of legal requirements relating to cross-border processing.
No. Section 17 provides limited exemptions from specified provisions of the Act in defined circumstances. It is not a blanket exemption from all obligations.
KGS Insight: Every exemption should be interpreted narrowly and documented appropriately.
Organizations often confuse Section 7 (Legitimate Uses) with Section 17 (Exemptions) or apply Section 17 without proper legal assessment and documentation.
KGS Insight: Always determine the lawful basis for processing first, then assess whether a specific exemption under Section 17 applies.
No. Section 17 applies only where the statutory conditions are satisfied. Routine business activities should generally rely on consent or another lawful basis under the Act.
No. Organizations should ensure that the investigation falls within the statutory scope of prevention, detection, investigation, or prosecution of an offence or contravention of law and maintain supporting documentation.
Yes. The applicable exemption, supporting facts, legal basis, approvals, and review dates should be documented.
No. Section 17 does not remove the need for responsible governance, reasonable security safeguards, or internal accountability.
KGS Insight: Exemptions reduce certain statutory obligations; they do not eliminate sound privacy governance.
Organizations should maintain:
- Privacy policies and notices.
- Consent records.
- Data inventories.
- Records of Processing Activities (ROPA).
- Incident and breach registers.
- Vendor agreements.
- Data retention records.
- Training records.
- Internal audit reports.
Providing incomplete, inconsistent, or unsupported information. Every statement made before the Board should be supported by documentary evidence.
Organizations should establish a mature privacy governance program, maintain comprehensive documentation, conduct regular audits, respond promptly to grievances and incidents, train employees, and continuously review compliance practices.
KGS Insight: The strongest defense before the Board is not a legal argument but demonstrable accountability supported by evidence.
Yes. The DPDP Act empowers the Central Government to call for information from a Data Fiduciary or intermediary for purposes connected with the implementation of the Act.
KGS Insight: Organizations should maintain accurate and up-to-date compliance records to respond efficiently to such requests.
Organizations should comply with the DPDP Act as well as other applicable sector-specific laws and regulations. Compliance should be evaluated holistically rather than in isolation.
Many organizations complete an initial implementation project but fail to monitor subsequent legal and regulatory developments, resulting in outdated compliance program.
KGS Insight: A privacy program should include a formal process for tracking legislative and regulatory changes.
Yes. Organizations should conduct periodic reviews of their privacy governance framework, policies, notices, contracts, security safeguards, training program, vendor management processes, and incident response procedures to ensure continued compliance.
DPDP compliance is not a static legal requirement. It is an evolving governance framework that requires continuous monitoring, periodic updates, management commitment, and integration with the organization's overall risk and compliance program.
KGS Insight: Organizations that treat privacy governance as a continuous improvement program are better positioned to respond to legal, technological, and business changes.
Yes. Organizations should assess and monitor third-party processors to ensure appropriate privacy and security controls are maintained.ges.
Treating DPDP as only a consent management exercise. Effective compliance requires governance across the entire data lifecycle, including notices, lawful processing, security safeguards, retention, vendor management, children's data, and accountability.
Organizations should activate their incident response process, assess the impact, and comply with applicable notification requirements under the Act and Rules.
No. Reporting a breach demonstrates compliance with notification obligations, but the Board may still examine whether appropriate security safeguards and governance measures were in place.
KGS Insight: Timely reporting is important, but prevention remains the primary objective.
No. The Board will consider the circumstances of each case, including the organization's preparedness, response, cooperation, and corrective actions before determining the appropriate outcome.
Organizations should maintain evidence such as Privacy Notices, consent records, data inventories, Records of Processing Activities (ROPA), vendor agreements, data retention records, security policies, breach registers, employee training records, audit reports, and internal approvals.
KGS Insight: Good documentation often becomes the strongest evidence of accountability.
No. Organizations should focus on building sustainable compliance and responsible data governance. Strong governance not only reduces regulatory risk but also strengthens stakeholder trust and business resilience.
KGS Insight: The objective of the DPDP Act is responsible processing of personal data, not the collection of penalties.
Yes. The DPDP Act applies irrespective of the size of the organization. However, the circumstances of each case will be considered while determining the appropriate regulatory response.
Section 35 provides protection for actions taken in good faith under the Act. However, organizations should not assume that merely claiming good faith is sufficient. Appropriate governance, documentation, and reasonable diligence remain essential.
In many cases, enforcement is linked not only to the incident itself but also to inadequate governance, weak security safeguards, poor documentation, ineffective response mechanisms, or failure to demonstrate accountability.
Organizations should adopt a proactive compliance program that includes privacy governance, documented policies, employee awareness, vendor management, incident response planning, periodic audits, and continuous monitoring.
KGS Insight: The strongest defense against penalties is demonstrable compliance rather than reactive compliance after an incident occurs.
Yes. The DPDP Act applies irrespective of the size of the organization. However, the Board considers the facts of each case while determining the appropriate regulatory response.