INDIA’S PRIVACY FRAMEWORK: FROM POLICY TO PRACTICE
By Subha Subramanian, Associate
The principal substantive provisions of the Digital Personal Data Protection Act, 2023 (“Act”) and rules thereunder (“Rules”) will come into force on 13.05.2027, and businesses are racing to set in place systems and processes to protect personal data and comply with the new data protection framework.
A notable feature of the Act is that it does not merely prescribe a collection of do’s and don’ts. It requires organisations to establish mechanisms through which personal data is collected and used in a lawful and accountable manner. It also confers enforceable rights on Data Principals and requires organisations to put in place processes through which those rights can be exercised.
For organisations, compliance will require more than updating privacy policies or introducing new contractual provisions. It will require a clear understanding of how personal data is handled across the business and of the processes, systems and controls through which the organisation manages that data.
The emphasis must, therefore, shift from policy-level compliance to operational readiness. An organisation’s day-to-day business practices and technology systems must be capable of giving effect to the requirements of the Act and the Rules. These requirements must also be integrated into its relationships with employees, customers, vendors, service providers and other stakeholders.
This Note focuses on the practical steps that an organisation should take to achieve such operational readiness. It seeks to translate the requirements of the Act and the Rules into identifiable compliance workstreams, implementation measures and internal controls.
UNDERSTANDING THE DATA LIFECYCLE
Identify personal data processing activities: An effective DPDP compliance programme begins with a clear understanding of the personal data handled by the organisation and how that data moves through the business.
This requires organisations to look beyond a simple inventory of databases and identify the principal points at which personal data is collected or received, including through websites, applications, customer interactions, employee processes, CCTV systems, marketing activities and physical records that are subsequently digitised.
Record the purpose and basis for processing: For each processing activity, the organisation should understand whose personal data is involved, why it is being processed, the basis on which the processing takes place, where the data is stored, who has access to it, who it is shared with and how long it is retained.
Map data flows: The exercise should also extend beyond the organisation’s own systems, since vendors, cloud service providers, group companies and other third parties may form part of the same data lifecycle. The data map should therefore identify relevant third parties, capture where personal data is hosted, accessed or otherwise processed outside India, and assign responsibility for key processing activities to the appropriate business or system owners.
The result should be a reliable and current picture of how personal data is handled across the organisation. This provides the foundation for the wider compliance programme, including privacy notices and consent mechanisms, Data Principal rights, security safeguards, retention and erasure, cross-border data flows and third-party arrangements.
NOTICE AND CONSENT: THE FIRST POINT OF CONTACT
Identify collection and consent points: Once the organisation has mapped its data-processing activities, the next step is to review how individuals are informed about the use of their personal data and, where required, how their consent is obtained. Organisations should identify all points at which personal data is collected or consent is sought, including websites, applications, forms, employee processes and other channels.
Review and update notices: Personal data may be processed on the basis of consent or for certain legitimate uses permitted under the Act. Where consent is relied upon, every request for consent must be preceded or accompanied by a notice informing the Data Principal of the personal data proposed to be processed and the purpose of such processing. The notice must also describe the goods, services or uses enabled by the processing and explain how the Data Principal may withdraw consent, exercise her rights and make a complaint.
Implement compliant consent mechanism: Where consent is relied on as basis for processing personal data, the organisation should ensure that consent of Data Principal is obtained through a clear affirmative action, relating to the specified purpose and limited to personal data necessary for that purpose.
Implement consent withdrawal mechanism: Equally important is the ability to withdraw consent, and the withdrawal process should be comparable in ease to the process through which consent was originally given.
Maintain consent records: Appropriate records should also be maintained so that the organisation can demonstrate the notice provided, the consent obtained and any subsequent withdrawal or modification where required.
Address legacy data and existing consents: Organisations should additionally identify personal data that is already being processed on the basis of consent obtained before the relevant provisions of the Act come into force, since the Act requires existing Data Principals to be provided with prescribed information after commencement. This makes legacy data and existing consent arrangements part of the readiness exercise, rather than limiting the review to new collection activities.
DATA PRINCIPAL RIGHTS: AN OPERATIONAL PROCESS
Establish a rights-request mechanism: The Act gives individuals a range of rights in relation to their personal data, but these rights must be supported by workable internal processes.
Organisations should establish a clear mechanism through which Data Principals can submit requests and communicate the manner in which these rights may be exercised, including any information or identifiers required to locate and verify the relevant data.
Implement rights management procedures: Internal procedures should cover requests for information about the personal data being processed and the relevant processing activities, as well as requests for correction, completion, updating and erasure.
Responsibility for reviewing and responding to these requests should be clearly identified, and where personal data is held or processed by data processors, the organisation should have arrangements in place to coordinate with them and ensure that the necessary action can be taken.
Establish request verification and escalation procedures: The process should include appropriate verification, allocation of responsibility and escalation where required so that requests are handled consistently. Organisations should also provide a mechanism through which a Data Principal can nominate one or more individuals to exercise their rights in the event of death or incapacity.
BUILDING SECURITY INTO THE DATA LIFECYCLE
Implement reasonable security safeguards: Once an organisation has identified the personal data it processes and how that data moves through its operations, the next consideration is how that data is protected against compromise.
The Act requires reasonable security safeguards for personal data in the organisation’s possession or control, including personal data processed on its behalf by data processors, while the Rules provide further detail on the measures that may form part of this framework.
Implement data protection measures: The organisation’s security framework must include, at a minimum, appropriate technical and organisational measures of the nature specified under the Rules. The safeguards may include appropriate technical and organisational controls having regard to the nature of the personal data and the processing involved.
The Rules specifically contemplate measures such as encryption, obfuscation, masking and the use of virtual tokens, together with appropriate controls over access to computer resources and logging and monitoring mechanisms that enable unauthorised access to be detected and investigated.
Maintain backup and recovery measures: Security safeguards also extend to the continued availability and recovery of personal data. Organisations should maintain appropriate backup and recovery measures so that continued processing and restoration of access are possible where an incident affects the confidentiality, integrity or availability of personal data. Relevant security and processing records must also be retained for the periods prescribed under the Rules and any longer period required under other applicable laws.
These safeguards should operate as an ongoing part of the organisation’s data-protection framework rather than as a one-time exercise, with security controls periodically assessed and identified vulnerabilities or deficiencies appropriately addressed.
TRACKING CROSS-BORDER DATA FLOWS
Identify cross border processing: As part of understanding how personal data moves through the organisation, cross-border processing is an important area to consider. Personal data may be hosted, accessed, processed or transferred outside India through group entities, overseas service providers or other third parties, and these arrangements should therefore form part of the organisation’s broader data-mapping and governance framework.
Assess applicable transfer restrictions: The Rules permit personal data to be transferred outside India subject to requirements that may be specified by the Central Government in relation to making such data available to a foreign State or to persons or entities under its control. These requirements must also be considered alongside any sector-specific localisation or transfer restrictions that independently apply to the organisation.
Review overseas processing arrangements: Where personal data is processed or made available outside India, arrangements with overseas recipients and data processors should address appropriate data-protection and security requirements, including protection of the data, reporting of breaches and cooperation with the organisation in meeting applicable data-protection obligations.
ADDRESSING DATA PRINCIPAL GRIEVANCES
Establish grievance redressal mechanism: An effective grievance redressal mechanism is an important part of the organisation’s engagement with Data Principals. Organisations should provide a clearly identifiable means through which grievances concerning the processing of personal data may be raised and establish an internal process for receiving, allocating and responding to them.
Publish grievance process and contact details: The manner in which a grievance may be raised, together with the relevant business contact information, should be readily accessible to Data Principals. Responsibility for managing grievances should also be clearly identified so that complaints are appropriately reviewed and responses are coordinated.
The period specified by the organisation for grievance redressal must be reasonable and cannot exceed 90 days under the Rules.
RETENTION AND ERASURE: CLOSING THE DATA LIFECYCLE
Establish retention periods: Once the organisation has identified the personal data it processes, it must also consider how long that data needs to be retained and when it should be erased.
Retention periods should be linked to the purpose for which personal data is processed and take into account any applicable legal or regulatory requirements.
Where consent is withdrawn or the specified purpose is no longer being served, personal data should generally be erased unless its continued retention is required by applicable law.
Coordinate erasure with data processors: Erasure should extend beyond the organisation’s own systems. Where personal data has been made available to data processors, the organisation should ensure that applicable erasure requirements are implemented across the relevant processor systems and copies of the data so that retention and erasure operate consistently throughout the data lifecycle.
THIRD-PARTY PROCESSING: CONTRACTS AND OVERSIGHT
Identify data processors: Personal data is often processed not only by the organisation itself, but also by vendors and other third parties acting on its behalf.
The Act nevertheless places responsibility on the Data Fiduciary for processing undertaken on its behalf and requires data processors to be engaged under a valid contract.
Assess data processor safeguards: Organisations should therefore identify the third parties that process personal data on their behalf, the nature of the processing undertaken and the safeguards maintained by those parties. Processor contracts should, as appropriate, address the scope and purpose of processing, security safeguards, breach notification, assistance in responding to Data Principal rights, retention and erasure, and arrangements involving sub-processors or processing outside India.
CONCLUSION
Effective DPDP compliance requires organisations to translate the requirements of the Act and the Rules into their day-to-day operations.
The transition period should therefore be used to identify gaps, strengthen existing processes and develop a compliance framework that is practical, sustainable and capable of evolving with the organisation’s data-processing activities.


