India's DPDP Act 2025: What SaaS Companies Need to Know
TL;DR
- • India's Digital Personal Data Protection (DPDP) Act 2023 became enforceable in 2025
- • Applies to any company processing personal data of Indian residents — regardless of where you're incorporated
- • Penalties reach up to ₹250 crore (~$30M USD) per violation
- • Key obligations: lawful consent, data principal rights, fiduciary duties, breach notification within 72 hours
- • "Significant Data Fiduciaries" face additional AI governance and audit requirements
India has 1.4 billion people and one of the fastest-growing internet user bases in the world. If your SaaS product serves Indian users — or even processes data about Indian residents as part of a B2B workflow — India's Digital Personal Data Protection Act (DPDP Act) now applies to you. With penalties reaching ₹250 crore (approximately $30 million USD) per violation, this is not a regulation to treat as a checkbox.
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (formally known as "The Digital Personal Data Protection Act, 2023 — Act No. 22 of 2023") received presidential assent in August 2023 and began phased enforcement in 2025. It replaces the fragmented personal data provisions under the IT Act 2000 and its 2011 rules, creating India's first comprehensive data protection law.
The Act is overseen by the Data Protection Board of India (DPBI), an adjudicatory body with powers to investigate violations, impose penalties, and direct remediation. Unlike GDPR's multi-regulator model, the DPBI is the single national authority — streamlining enforcement but also concentrating authority.
The DPDP Act applies to the processing of "digital personal data" about "data principals" (individuals). Unlike GDPR, it does not cover legal persons or non-digital data unless such data is digitized.
Who Does It Apply To?
The Act has extraterritorial reach. It applies to:
- •Any entity that processes personal data within India
- •Any entity outside India that processes personal data in connection with offering goods or services to data principals in India
This means a US-headquartered SaaS company with Indian customers is fully subject to the DPDP Act. If you have a signup flow accessible to Indian residents, you process data "in connection with offering services" to them — regardless of where your servers sit.
Exemptions to Know
The Act exempts personal data processed for personal or domestic purposes, publicly available personal data, and data processed for certain state functions. Research, archiving, and statistical purposes may qualify for narrower exemptions if they serve the public interest. Cross-border data transfer restrictions are governed by a government-approved list of permitted countries — as of mid-2026, this list has not been fully finalized, so monitor the DPBI website actively.
Key Obligations for Data Fiduciaries
The DPDP Act uses the term "Data Fiduciary" for entities that determine the purpose and means of processing personal data (analogous to GDPR's "data controller"). Here are the primary obligations:
1. Lawful Consent
You must obtain free, specific, informed, unconditional, and unambiguous consent before processing personal data. The consent request must be presented in plain language in a standalone notice — bundled consent in terms of service is not sufficient. You must also allow consent withdrawal at any time, and withdrawal must be as easy as giving consent.
The Act does provide for "legitimate uses" without consent: employment processing, medical emergencies, state functions, and research — but commercial SaaS generally cannot rely on these exceptions.
2. Notice Requirements
Before or at the time of collecting personal data, you must provide a clear notice specifying: what personal data is being collected, the purpose of processing, how the data principal can exercise their rights, and how to contact the Data Protection Officer (if appointed). Notices must be available in English and in any of the 22 scheduled languages of India upon request.
3. Purpose Limitation and Data Minimization
Personal data may only be used for the stated purpose. You must not retain data longer than necessary for that purpose. The Act requires proactive data deletion — you cannot hold data indefinitely "just in case." This has significant implications for SaaS products that accumulate user data in logs and analytics systems.
4. Data Security
Data fiduciaries must implement "reasonable security safeguards" to prevent personal data breaches. While the Act does not prescribe specific technical standards, the government can issue rules specifying required safeguards. Aligning with ISO 27001 or SOC 2 controls provides a strong baseline defense that your security posture was reasonable.
5. Breach Notification
You must notify the Data Protection Board and affected data principals of any personal data breach within a prescribed timeframe. The draft rules indicate a 72-hour notification window to the DPBI — consistent with GDPR's standard. Your breach notification must describe what happened, what data was affected, and what remediation steps you're taking.
6. Data Processor Accountability
If you use sub-processors (cloud providers, analytics tools, CRM platforms) to process personal data on your behalf, you must have a contract with them that restricts processing to your instructions and requires equivalent security standards. Sub-processors in India are called "Data Processors" under the Act.
Data Principal Rights
Data principals (your users, if they're Indian residents) have the following rights under the Act:
Right to Information
Know what personal data is being processed and for what purpose
Right to Correction
Request correction of inaccurate or misleading personal data
Right to Erasure
Request deletion of personal data when it is no longer necessary for the stated purpose
Right to Grievance Redressal
Access a functional complaint mechanism and receive responses within reasonable time
Right to Nominate
Nominate another individual to exercise rights in the event of death or incapacity
Right to Withdraw Consent
Withdraw previously given consent at any time, with immediate effect
Unlike GDPR, the DPDP Act does not explicitly include a right to data portability or a right to object to automated decision-making. However, these may be addressed in subsequent rules issued by the central government. Monitor the Ministry of Electronics and Information Technology (MeitY) for updates.
Significant Data Fiduciaries: Higher Bar
The government may designate certain entities as "Significant Data Fiduciaries" (SDFs) based on the volume and sensitivity of data processed, the risk to data principals, and national security implications. SDFs face additional requirements:
- →Appoint a Data Protection Officer (must be an individual based in India)
- →Conduct periodic Data Protection Impact Assessments (DPIAs)
- →Undergo independent data audits by qualified auditors
- →Perform algorithmic accountability assessments if using AI/ML for significant decisions about data principals
The criteria for SDF designation have not been fully published as of this writing. Large platforms processing data of millions of Indian users (social media, fintech, e-commerce, healthcare) are most likely to be designated. If your product could be considered critical infrastructure or has outsized societal impact in India, plan for SDF requirements.
Penalty Structure
| Violation | Maximum Penalty |
|---|---|
| Failure to implement reasonable data security safeguards leading to a breach | ₹250 crore (~$30M) |
| Failure to notify the DPBI and affected data principals of a breach | ₹200 crore (~$24M) |
| Processing data of children without verifiable parental consent | ₹200 crore (~$24M) |
| Significant Data Fiduciary violations (DPO, DPIA, audit failures) | ₹150 crore (~$18M) |
| Violation of data principal rights obligations | ₹50 crore (~$6M) |
| Non-compliance with DPBI orders | ₹50 crore (~$6M) |
DPDP Act vs. GDPR: Key Differences
| Element | DPDP Act (India) | GDPR (EU) |
|---|---|---|
| Lawful bases | Consent + Limited legitimate uses | 6 bases (consent, contract, legal obligation, vital interest, public task, legitimate interest) |
| Right to portability | Not explicitly included | Explicitly included (Art. 20) |
| Data localization | Government can restrict cross-border transfers to specific countries | Adequacy decisions, SCCs, BCRs |
| DPO requirement | Only for Significant Data Fiduciaries | Required for many categories of processing |
| Maximum penalty | ₹250 crore (~$30M) | €20M or 4% of global annual turnover, whichever is higher |
| Breach notification window | Rules pending; 72 hours expected | 72 hours to supervisory authority |
DPDP Compliance Checklist for SaaS Companies
Need Help with DPDP Act Compliance? Check Out TruePrivacy
TruePrivacy.io is a dedicated privacy compliance platform built for Indian data protection regulations. It provides purpose-built tools for DPDP Act compliance including consent management, Data Principal rights automation, breach notification workflows, and Data Protection Board reporting — all tailored specifically for Indian regulatory requirements.
While LowerPlane handles your broader security compliance (SOC 2, ISO 27001, HIPAA), TruePrivacy complements it by focusing exclusively on India-specific privacy obligations under the DPDP Act — consent notices in scheduled Indian languages, Aadhaar-linked verification for Data Principal requests, and Significant Data Fiduciary compliance.
Visit TruePrivacy.ioReady to Simplify Your Compliance?
LowerPlane automates up to 80% of your compliance work across multiple frameworks.
Book a Demo