DPDP Act 2023: the part nobody tells you

Over the past year, more and more conversations with CIOs and founders across Delhi NCR have started the same way: “Our lawyer says the DPDP Act applies to us. What do we actually have to do?” The question has two halves. One half is legal, and that belongs to your counsel. The other half is engineering — and it is usually the half that turns out to be broken when I look under the bonnet.

What the Digital Personal Data Protection Act, 2023 demands is the ability to know where personal data lives, prove who can reach it, detect when it leaves, and report a breach inside a tight window. Every one of those is an infrastructure problem before it is a legal one.

DPDP Act consultant in India — data protection readiness by Sanjay Seth

If you are looking for a DPDP Act consultant in India, the most useful thing I can tell you is this: you cannot protect personal data you cannot find.

What the DPDP Act actually demands, in plain terms

I will not recite the Act section by section — your lawyer can do that. What I will do is translate the obligations into the questions your IT team will be asked to answer.

Consent and purpose limitation

Personal data may be processed only for a purpose the individual consented to, and that consent must be specific, informed and withdrawable. Your systems need to know why each store of personal data exists. If marketing is quietly reusing the database support collected for warranty claims, that is a purpose-limitation problem no firewall will fix — but a data map will expose it.

Breach notification — to the Board and to affected individuals

When a personal data breach occurs, you must notify the Data Protection Board of India and every affected data principal, and the clock the DPDP Rules set is short. It is also the obligation that changes what “good enough” monitoring means — more below.

Significant data fiduciaries

The government can notify certain organisations as significant data fiduciaries based on the volume and sensitivity of data they handle. If that is you, the bar rises: an independent data auditor, a Data Protection Officer based in India, and periodic data protection impact assessments — with the auditor expecting evidence your controls actually operate, not policy PDFs.

Penalties that get board attention

The Schedule to the Act allows penalties of up to ₹250 crore per instance for the most serious failures — including failure to take reasonable security safeguards and failure to notify a breach. When the Board asks what was “reasonable”, the answer will be your firewall rules and access logs, not your privacy policy.

Why DPDP is a security-engineering problem

Most DPDP readiness consultant engagements I am brought into begin with a legal gap analysis already done. The gaps are real, but stated in legal language: “personal data processing lacks documented purpose.” Turning that into something an engineer can fix is where programmes stall. The sequence that works is the unglamorous one:

  • Find the data first. Discovery and mapping across databases, file shares, SaaS tools, backups and endpoints. Every organisation I assess has personal data in places nobody authorised — a test database cloned from production, logs nobody realised captured Aadhaar numbers.
  • Then wall it off. Segmentation around the stores that matter, so a compromised reception PC cannot reach the customer database.
  • Then watch it. Detection tuned to the data stores, so a breach is something you learn about in hours, not from a journalist.

None of this is exotic. It is the same discipline I apply in every firewall audit — the DPDP Act simply adds a statutory deadline and a penalty schedule.

What a DPDP readiness engagement covers

A DPDP Act 2023 compliance readiness engagement with me falls into four blocks. I do the architecture and hands-on assessment; for managed delivery, my team at PJ Networks’ compliance services practice runs it day to day.

1. Data discovery and mapping

A structured sweep of where personal data is collected, stored, processed and shared — including shadow databases and forgotten exports. The output is a data map your legal team can hang consent records on and your IT team can hang controls on.

2. Access control and segmentation

Reviewing who and what can reach each personal data store, then redesigning zones, firewall policy and identity controls so access is least-privilege and auditable. Usually the largest remediation item I find.

3. Breach-detection and notification runbook

A documented, rehearsed path from “something looks wrong” to “notification sent” — naming who declares a breach, who talks to the Board and to affected individuals, and what evidence the monitoring stack must produce.

4. Vendor and processor contracts

If your payroll runs on a SaaS platform or your backups sit with a third party, their failure is your breach under the Act. I verify what access processors actually have and whether the controls match the contracts; your counsel handles the drafting.

The breach-notification clock changes your monitoring requirements

This is the point I press hardest, because it is the most underestimated. Before DPDP, slow detection was an internal risk decision. Now it is a compliance failure in the making: if your first indication of a breach arrives a month late, you notify the Board late, and every affected individual learns about it later than the law expects.

In practical terms, the notification window means centralised logs from systems holding personal data, alerting that someone actually reads around the clock, and retention long enough to reconstruct what happened. If that is not realistic in-house, a managed SOC is the honest answer — my team runs exactly that through PJ Networks.

The gaps I find again and again

The organisations I assess are rarely negligent; they carry years of infrastructure that predates the law. The pattern is consistent:

  • Shadow databases. Production clones in dev, exports on analysts’ machines, “temporary” stores that became permanent. Until the data map finds them, they are unmonitored breach sources.
  • No one owns the obligation. The Act does not force every organisation to appoint a DPO, but someone must be answerable when the Board writes to you. In most mid-size companies I meet, that person does not exist.
  • Retention never enforced. Data kept “just in case” forever is data you must protect, breach-notify and defend. Deletion schedules exist on paper, nowhere in the backup rotation.
  • Untested incident paths. A breach runbook that has never been rehearsed is a hypothesis, not a plan.

One honest note: I am not your lawyer

I am a security architect, not an advocate. Whether a processing activity is lawful, whether your consent notice meets the standard, whether you qualify as a significant data fiduciary — those are questions for your counsel. What I do is make the infrastructure defensible: the data map, the segmentation, the monitoring, the evidence trail that lets your lawyer answer the Board with facts. More about my approach on my homepage.

How I work

Assess. Data discovery, an audit of access and segmentation around personal data stores, and a review of detection capability against the notification window. You get a gap report written for counsel and engineers alike.

Architect. A target design — zones, least-privilege access, log centralisation, retention enforcement, the breach runbook — sequenced so the highest-risk gaps close first.

Deploy. Hands-on remediation with your team: firewall policy, identity controls, monitoring rules, deletion jobs. I work at the console, not from a slide deck.

Operate. Controls decay. Ongoing review, breach-runbook drills, and — where you want it run for you — managed compliance and monitoring through my team at PJ Networks.

Frequently asked questions

Does the DPDP Act apply to small companies?

Yes. The Act applies to any organisation that processes digital personal data in India, regardless of size — there is no small-business exemption. What changes with size and data sensitivity is whether you are notified as a significant data fiduciary, which carries additional duties such as a DPO and independent audits. The core obligations — consent, reasonable security safeguards, breach notification — apply to a twenty-person firm as much as to a large enterprise.

What are the penalties under the DPDP Act?

The Schedule to the Act provides for penalties of up to ₹250 crore per instance for the most serious failures, including failing to take reasonable security safeguards to prevent a breach and failing to notify the Data Protection Board and affected individuals. Lesser failures carry lower but still material penalties. In practice, the penalty conversation is what finally gets boards to fund the security work.

Do we need to appoint a Data Protection Officer?

Only if you are notified as a significant data fiduciary — then an India-based DPO reporting to your board is mandatory. For everyone else, the Act does not require a formally titled DPO. Even so, I advise every client to name one accountable person: when a breach happens and the notification clock starts, “nobody was clearly responsible” is the worst possible answer to give the Board.

What is a significant data fiduciary?

It is a designation the central government can apply based on factors such as the volume and sensitivity of personal data you process and the risk to data principals’ rights. If you are notified, your obligations expand: an India-based DPO, an independent data auditor, and periodic data protection impact assessments. If you process personal data at scale, build towards that standard before the notification arrives.

How is DPDP different from GDPR?

The family resemblance is strong — consent, purpose limitation, breach notification, individual rights — but there are real differences. DPDP covers digital personal data with a narrower scope. Breach notification goes to every affected individual as well as the Board. There is no legitimate-interests basis in the GDPR sense, though the Act allows certain specified legitimate uses. GDPR compliance is a head start, but consent flows and breach runbooks still need rework.

Where do we start with DPDP compliance?

Start with the data map. Commission a discovery exercise to find where personal data actually lives — including the places nobody authorised — before writing a single policy. Then prioritise the engineering: segment the sensitive stores, centralise logging on them, and write the breach-notification runbook. A readiness assessment that delivers the map and gap report is the sensible first step, and it is typically weeks, not months.

Start with an honest assessment

If the DPDP Act has landed on your desk and you are not sure where your infrastructure stands, the fastest way to find out is a working session: your environment, your data flows, my thirty years of knowing where personal data hides. Book a working session and we will map the gaps before the Data Protection Board maps them for you. Based in Delhi, working with enterprises across India.