India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) changes how every business in Gwalior — from a coaching class in Morar to a manufacturer on Bhind Road — must handle personal data. Here is a plain-English primer on what the law requires and what to do about it now.
What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 is India’s first comprehensive law on the processing of personal data. Passed by Parliament in August 2023, it governs how personal data — any information that can identify an individual — is collected, stored, used, shared and deleted. It applies to personal data processed in digital form, and to non-digital data that is later digitised.
The Act draws clear inspiration from the European Union’s GDPR (General Data Protection Regulation, in force since 2018). Both laws share the same core principles: lawful and fair processing, purpose limitation, data minimisation, storage limitation, accuracy, security, and accountability. If your business already complies with GDPR for European customers, you have done much of the structural work for DPDP. The differences are in detail — definitions, thresholds, enforcement mechanism and the role of the Data Protection Board of India.
For most Gwalior businesses, the practical takeaway is this: the days of casually collecting customer details on a paper form, typing them into an Excel file on a desktop, and never thinking about it again are ending. Every business that handles personal data — which is essentially every business — now has affirmative obligations.
Who Does It Apply To?
The DPDP Act applies broadly. It covers:
- Any “Data Fiduciary” — the entity that determines why and how personal data is processed. That includes companies, partnerships, proprietorships, societies, trusts, and the government.
- Processing of personal data undertaken in India, regardless of where the Data Fiduciary is incorporated.
- Processing outside India if it is undertaken in connection with offering goods or services to individuals in India (similar to GDPR’s extraterritorial scope).
- “Significant Data Fiduciaries” — a category notified by the government based on volume, sensitivity and risk — face additional obligations like appointing a Data Protection Officer, an independent data auditor, and conducting Data Protection Impact Assessments.
There is no minimum turnover or employee threshold for the base obligations. A 5-person retail shop in Lashkar that maintains a customer database is a Data Fiduciary under the Act. A Gwalior coaching class collecting student Aadhaar numbers, parent phone numbers and addresses is a Data Fiduciary. A clinic maintaining patient records is a Data Fiduciary and likely a Significant Data Fiduciary given the sensitivity of health data.
Key Obligations for Businesses
The DPDP Act places seven core obligations on every Data Fiduciary:
- Lawful basis — process personal data only with consent, or for certain “legitimate uses” expressly permitted (e.g., voluntarily provided data, state functions, employment-related processing).
- Purpose limitation — collect only what is necessary for the stated purpose, and use it only for that purpose.
- Data minimisation — collect only what is necessary; do not stockpile “just in case”.
- Storage limitation — retain data only as long as needed for the purpose, then delete it.
- Accuracy — take reasonable steps to ensure personal data is accurate and up to date.
- Security safeguards — protect data with reasonable technical and organisational measures (encryption, access controls, logging).
- Accountability — be able to demonstrate compliance, including through privacy notices, records of processing, and breach documentation.
Data Principals (the individuals whose data is processed) also have clear rights under the Act: the right to information about processing, the right to correction and erasure, the right of grievance redressal, and the right to nominate. Every business must provide a clear and accessible mechanism to exercise these rights.
Consent & Data Collection
Consent is the centrepiece of the DPDP Act. Valid consent must be free, specific, informed, unconditional, and unambiguous — with a clear affirmative action. A pre-ticked box does not count. A long legal document buried in the footer does not count. The request must clearly state what personal data is being collected, the purpose of processing, and what the consequences of withdrawing consent are.
Warning — consent must be revocable and granular. Under DPDP, a Data Principal can withdraw consent at any time, with the same ease as it was given. If your business collects customer phone numbers “for order delivery” and then uses them for marketing WhatsApp messages, that is a violation — marketing needs separate, opt-in consent. Bundling consent (“tick this box to agree to everything”) is explicitly prohibited. Audit every form, every WhatsApp opt-in, every lead capture — and split consents by purpose.
For Gwalior SMEs, the practical changes are typically: rewrite privacy notices in plain language, separate “service delivery” consent from “marketing” consent, add a clear “withdraw consent” option (typically a reply STOP on WhatsApp or an unsubscribe link in email), and start tracking consent records so you can prove when and how consent was obtained.
Data Breach Response
The DPDP Act introduces a mandatory breach notification obligation. If a personal data breach occurs — unauthorised access, disclosure, alteration, or loss of personal data — the Data Fiduciary must, on becoming aware of it, notify the Data Protection Board of India and each affected Data Principal. The notification must describe the breach, its likely consequences, the measures taken and proposed to mitigate it, and the steps the affected individuals should take.
The Act and the draft rules require this notification to be made “without delay” and in any case within a prescribed period. The draft rules published in January 2025 propose a 72-hour window for notifying the Board — broadly in line with GDPR. For a Gwalior business without an incident response plan, meeting that timeline is impossible. The plan has to exist before the breach, not during it.
If you suspect a cybercrime — phishing, ransomware, unauthorised fund transfer — call the national cybercrime helpline at 1930 (or file a complaint at cybercrime.gov.in). The helpline is run by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs and is the first point of escalation for many incidents. For technical containment, contact your IT security partner immediately.
Penalties for Non-Compliance
The DPDP Act’s penalty regime is among the most stringent in the world. The Data Protection Board can levy monetary penalties of up to ₹250 crore per instance for breaches of the Act’s obligations. The maximum penalties by violation are:
- Failure to take reasonable security safeguards to prevent personal data breaches — up to ₹250 crore.
- Failure to notify the Board of a breach — up to ₹200 crore.
- Non-compliance with children’s data provisions — up to ₹200 crore.
- Non-compliance with additional obligations of Significant Data Fiduciaries — up to ₹150 crore.
- Failure to comply with any other provision of the Act — up to ₹50 crore.
These figures are maximums per instance, not maximums per company per year. The Board considers the nature, gravity and duration of the breach, the type and nature of personal data affected, the repetitive nature of the breach, and whether the fiduciary acted in good faith. The amounts are deliberately high enough to make compliance a board-level concern.
Practical Steps to Compliance
For most Gwalior SMBs, full DPDP compliance is a 4–8 week project, not a multi-year transformation. The sequence we recommend:
- Data audit. Inventory every place personal data is collected, stored and processed — CRM, billing software, spreadsheets, WhatsApp groups, paper registers. You cannot protect what you do not know you have.
- Purpose mapping. For each data set, document the purpose of processing, the lawful basis (consent or legitimate use), retention period, and sharing with third parties.
- Privacy notice. Publish a clear, plain-language privacy notice on your website and at the point of data collection. State what you collect, why, how long you keep it, who you share it with, and how to complain.
- Consent rebuild. Replace bundled consent with granular opt-in. Build a consent record (timestamp, IP, version of notice shown). Add a one-click withdrawal mechanism.
- Security baseline. Encrypt data at rest and in transit, enforce multi-factor authentication on all admin accounts, restrict access on a need-to-know basis, log access to personal data, and patch on a defined schedule. See our backup & DR best practices article for the resilience side of this.
- Incident response plan. Write down — and rehearse — who does what in the first hour of a breach: isolate, investigate, assess notification triggers, notify the Board, notify affected individuals, and engage a cyber-forensics partner.
- Vendor management. Flow down DPDP obligations to every vendor that touches personal data on your behalf — cloud providers, email marketing tools, payment gateways, IT support partners — via written data processing terms.
- Training. Brief every employee who handles personal data — accounts team, sales, support, reception — on the basics: what personal data is, what they can and cannot do with it, and how to spot and report a breach.
Compliance is not a one-time project; it is an ongoing discipline. The businesses that handle it well are the ones that treat personal data as a liability to be minimised, not an asset to be hoarded. For most Gwalior SMEs, getting the basics right — minimal collection, explicit consent, real security, and a written breach plan — covers 80% of the risk.