Plan deliberately

We process personal data and need to comply with the data-protection law

What does the statute actually require of a business like ours, and what should be built first

First orientation

India's data-protection statute imposes duties on businesses that process personal data, built around notice, consent or another lawful ground, security, retention limits and grievance handling, with obligations scaling for larger and more sensitive processing. Parts of the regime arrive through delegated legislation, so compliance is built in the present tense and maintained against a moving text.

What is at stake

Building nothing invites enforcement exposure and contract failure, since counterparties increasingly demand compliance in writing. Building from templates invites a paper program that collapses at the first incident, audit or dispute.

Orientation, not advice. This page cannot see your documents, your dates or your record, and any of them can change the position. Treat it as a map of the terrain, then verify the route on your facts before acting. The disclaimer applies to everything here.

Reading the situation

Data-protection law asks a business to be able to prove, at any moment, that it knows what personal data it holds, why it may hold it, and what it does when something goes wrong. Everything else in a compliance program is machinery serving those three proofs.

Why data flows come before documents

A privacy notice describes reality, so reality must be established first. The mapping exercise, which data enters through which doors, lives in which systems, moves to which vendors and leaves by which deletions, is where every serious program begins. It is also where the surprises live, and finding them in a mapping exercise is cheaper than finding them in an incident.

Building against a moving text

The statute is in force in architecture, while parts of its machinery arrive through rules notified over time. Sound compliance therefore carries dates. Which obligations bind today, which are announced but not yet operational, and which practices are adopted because they are prudent rather than mandated. The practice keeps that three-way distinction explicit in every deliverable, so the program can absorb each new notification without rebuilding.

The incident is the exam

Preparation is judged in the first hours after something goes wrong. A rehearsed sequence, an owner with authority, counsel involved early enough to protect privilege, and communications that state facts without manufacturing admissions. The practice supports that sequence as counsel, and the businesses that fare best are the ones that wrote it down in peacetime.

Four readings

The same issue, four seats at the table

For the person handling it

Start from your real data flows, not from a policy template. What personal data enters the business, from whom, stored where, shared with whom, deleted when. Compliance is a description of this reality with obligations attached.

For management

Assign ownership and budget, because this is an operating obligation, not a one-time document. Incident response in particular fails without a named owner and a rehearsed sequence.

For compliance

Map processing to lawful grounds and notices, version every policy, and keep evidence of consent and grievance handling. In this field the record of compliance is the compliance.

For practitioners

Track the statute together with its rules as actually notified, and date-stamp advice accordingly. Distinguish duties in force, duties awaiting operationalisation, and prudent practice, and say which is which.

Governing sources

What governs this situation

  1. Digital Personal Data Protection Act, 2023

    Statute · Binding weight

    The principal statute imposing duties on those who process digital personal data in India.

  2. Rules and notifications under the statute

    Notification · Administrative guidance weight

    The delegated legislation that operationalises registration, breach reporting and other mechanics as it is notified.

Weight describes how strongly a source controls the answer. Binding sources decide it, while persuasive and administrative sources shape how it is applied.

Qualifications

What could change this answer

  1. Rules and notifications that operationalise parts of the regime over time
  2. The scale and sensitivity of the processing, which can raise the obligation tier
  3. Whether processing involves children or other specially protected categories
  4. Cross-border transfer conditions applicable to your data flows
  5. Sectoral regulation that adds requirements on top of the general statute

A first orientation is a starting point, not a conclusion. Any of the factors above can move the answer, which is why the practice verifies the source before advising.

Preserve your position

Immediate preservation steps

Ticks stay on this device only. Print this list or save it as a PDF for your file. Steps taken early are the ones that preserve options later.

If you bring this to the practice
  1. The practice maps your obligations against your actual flows, in writing
  2. A conflict check runs before internal documentation is taken
  3. You receive a build sequence with what is required now versus later
  4. Documents are drafted to match operations, then operations adjusted where needed

Bring the actual document, not a diagnosis

Describe what has arrived or what is at stake, in general terms, with the dates. The practice replies with what it needs to check, and a conflict check comes before any confidential detail.

Before you write. Please do not send confidential documents, case papers or privileged detail until the practice has completed a conflict check and confirmed in writing that it can act. A first message should describe the issue in general terms only.

Letters & Spirit

Before you continue

As required by the rules of the Bar Council of India, this website is not an advertisement or solicitation of work. By choosing Enter you acknowledge four things.