DPDP Act Compliance — India's Data Law, Solved for Global Companies
India's Digital Personal Data Protection Act creates obligations that look familiar to GDPR-compliant companies — and penalties, up to ₹250 crore per breach, that demand more than a copy-pasted European program.
A2 Consultants translates your existing privacy posture into DPDP compliance: what carries over, what does not, and what India specifically requires — consent architecture, grievance mechanisms, and breach reporting on Indian timelines.
The DPDP Act's reach is deliberately extraterritorial: it applies to processing of Indian personal data in connection with offering goods or services to persons in India, wherever the processor sits. A SaaS company in Berlin, a retailer in New York, and a group HR system in Singapore can all be within scope without any Indian entity. Enforcement will be graduated — but the statute's penalty ceiling signals how seriously India intends the regime.
GDPR alumni hold real advantages and real blind spots. The Act's consent-centricity is stricter than GDPR's flexible lawful bases; 'legitimate interest' as Europeans know it does not exist. Verifiable parental consent for children's data, prescribed breach notification to both the Board and affected individuals, and consent-manager infrastructure are Indian constructions with no European template. Compliance means adaptation, not translation.
Who we serve
Global companies with Indian customers or users; multinationals processing Indian employee data in group systems; technology platforms and SaaS providers serving India; and foreign companies whose Indian vendors and captives process personal data on their behalf.
The outcomes we deliver
- A defensible gap assessment: exactly where GDPR-grade controls fall short of DPDP requirements.
- Consent and notice architecture implemented in your actual products and HR processes — not just policy documents.
- Cross-border data flows mapped and validated against India's transfer framework.
- Breach-response readiness: reporting obligations, escalation paths, and rehearsed playbooks.
- Engineering-ready requirements: consent flows, retention rules, and rights-handling specified at the level your product and IT teams can actually build.
How we work
- Assess. Data inventory, applicability analysis, and gap assessment against the Act and its rules.
- Design. Consent flows, notices, grievance redressal, and processor contracts.
- Implement. Policy rollout, DPO/contact arrangements, and employee training.
- Sustain. Regulatory monitoring, audits, and Significant Data Fiduciary obligations as designated.
Why A2 Consultants
We advise foreign companies across their full Indian compliance stack, so DPDP obligations are implemented alongside — not in conflict with — employment, IT, and contractual realities. We track the Act's rules and Board practice as they evolve, so your program adjusts by memo — not by re-engagement.
Frequently asked questions
Does the DPDP Act apply to foreign companies with no Indian entity?
Yes, if you process digital personal data in connection with offering goods or services to individuals in India. An overseas e-commerce site serving Indian customers, or a global app with Indian users, is in scope regardless of corporate presence. Obligations include valid notice and consent, purpose limitation, breach notification, and honoring data principals' rights. Foreign companies should assume applicability first and scope down on evidence, not hope.
How does DPDP differ from GDPR for a company already GDPR-compliant?
Perhaps 60–70% of a mature GDPR program carries over — data mapping, security, vendor management, rights processes. The differences bite in specific places: consent is effectively the primary basis for most commercial processing; children's data requires verifiable parental consent with restrictions on tracking; breach notification is broader; and Significant Data Fiduciaries face Indian-specific audit, DPIA, and DPO obligations. A gap assessment against the Act, rather than an assumed equivalence, is the correct starting point.
Can personal data be transferred out of India under the DPDP Act?
The Act permits cross-border transfer by default, subject to a government blacklist of restricted jurisdictions — the inverse of GDPR's whitelist logic. But sectoral rules still bite: RBI's payments data localisation and similar mandates survive the Act. Transfers also remain subject to general obligations, so contracts with foreign recipients need DPDP-aligned terms. We map each flow against both the Act and sectoral overlays before certifying it as clean.
When does DPDP enforcement actually begin, and how should we time our compliance program?
The Act is law, with obligations operationalised progressively through rules and the Data Protection Board's establishment. Waiting for the final enforcement date is a false economy: consent architecture, data mapping, and vendor repapering take quarters to implement, and retrofitting consent for data already collected is far harder than capturing it correctly now. The rational sequence is gap assessment immediately, high-risk builds this year, and refinement as rules crystallise — we track the regulatory calendar so your program paces it.
Processing Indian personal data? Commission a DPDP gap assessment before enforcement reaches you.