Understanding the DPDPA: Key Principles
At its core, the DPDPA is built on principles that will feel familiar to anyone who has navigated GDPR — but with distinctly Indian characteristics in scope, enforcement, and implementation.
Consent as the Foundation — The DPDPA mandates that personal data can only be processed based on clear, informed, and affirmative consent from the Data Principal (the individual). Consent must be specific to the purpose, freely given, and easily withdrawable. This means organisations need to overhaul legacy consent mechanisms — blanket terms-of-service checkboxes will no longer suffice.
Purpose Limitation and Data Minimisation — Data can only be collected and processed for the specific purpose for which consent was obtained. Organisations must also limit collection to what is strictly necessary. For enterprises accustomed to hoarding data "just in case," this requires a fundamental mindset shift and robust data lifecycle management.
Rights of the Data Principal — Individuals have the right to access their personal data, correct inaccuracies, erase data, and nominate someone to exercise these rights on their behalf. Organisations need systems capable of responding to these requests accurately and within prescribed timescales.
Data Fiduciary Obligations — Entities processing personal data (Data Fiduciaries) bear significant responsibilities — from implementing appropriate security safeguards to reporting breaches to the Data Protection Board of India. Significant Data Fiduciaries face additional obligations, including appointing a Data Protection Officer (DPO) based in India and conducting periodic Data Protection Impact Assessments (DPIAs).
Cross-Border Data Transfers — The DPDPA allows data transfers to countries not restricted by the Government of India, moving away from the earlier draft's data localisation mandates. However, organisations must track where data flows and ensure compliance across jurisdictions.