India’s $1 Trillion Digital Goal: Navigating Risks Under the DPDP Act

thelawmonitor
4 Min Read
India's $1 Trillion Digital Goal: Navigating Risks Under the DPDP Act

India’s Ambitious Digital Economy Target

As India sets its sights on achieving a $1 trillion digital economy by 2030, the recently enacted Digital Personal Data Protection (DPDP) Act, 2023, together with the anticipated DPDP Rules, 2025, heralds a significant transformation in corporate liability within the country. This regulatory evolution transitions from a focus on simple policy compliance to stringent statutory fiduciary responsibility.

Regulatory Timeline and Boardroom Challenges

With the principal operational rules set to fully take effect on May 13, 2027, corporate boardrooms must immediately address both legal and operational mandates. Managing compliance effectively involves aligning corporate workflows with statutory deadlines, which include:

  • November 13, 2025: Commencement of initial administrative and framework rules.
  • November 13, 2026: Activation of Rule 4, the Consent Manager Framework.
  • May 13, 2027: Full enforcement of the rules.

Viewing May 13, 2027, as merely a deferred deadline exposes enterprises to considerable regulatory risk. Comprehensive data mapping across the organization, amending vendor agreements, restructuring notice procedures, and establishing defensible audit trails necessitate an extended lead time.

Re-engineering Data Systems

The DPDP framework significantly alters the landscape by replacing broad, bundled consent agreements with clear, statutory consent obligations. Key components include:

  • Rule 3 Notice Requirement: Data Fiduciaries must issue an itemized, standalone notice before requesting consent, detailing the specific categories of personal data collected and their intended processing purposes. This notice must be accessible in English and any of the 22 scheduled Indian languages as mandated by the Eighth Schedule.
  • Legacy Data Compliance: As per Section 6, Data Fiduciaries handling legacy datasets collected prior to the Act must issue retrospective notices to existing Data Principals before the operational deadline.
  • Consent Manager Intermediary: Under Rule 4, Data Principals can grant, review, or withdraw consent via Board-registered Consent Managers, who act as intermediaries between the individual and the Data Fiduciary.

Financial Liabilities and Compliance Risks

The DPDP Schedule outlines statutory financial penalties for non-compliance, including:

  • Failure to implement reasonable security safeguards (Section 8(5)): Up to ₹250 crore.
  • Failure to notify the Board and affected principals of a breach (Section 8(6)): Up to ₹200 crore.
  • Contraventions relating to children’s personal data (Section 9): Up to ₹200 crore.
  • Breach of Significant Data Fiduciary (SDF) duties (Section 10): Up to ₹150 crore.

The Data Protection Board evaluates these penalties, considering mitigating factors and contemporaneous evidence. To safeguard the enterprise, companies should conduct documented risk assessments, maintain continuous system logging under Rule 6, and develop tested breach-notification protocols.

About the Author

Bhumi Sharma is an Associate at Foresight Law Offices India.

Disclaimer: The views expressed in this article are those of the author and do not necessarily reflect the views of Bar & Bench.

If you wish to have your Deals, Columns, or Press Releases published on Bar & Bench, please complete the form available here.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *