D-WINGS Consulting LLP
DPDP UPDATES

The DPDP Act, 2023: What It Actually Requires of a Data Fiduciary

D-WINGS Consulting LLP · 10 March 2026

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive personal data protection legislation, and it changes the compliance posture required of any organisation — Indian or foreign — that processes the digital personal data of individuals in India.

The core roles. The Act defines a Data Principal (the individual the data belongs to), a Data Fiduciary (the organisation that determines the purpose and means of processing — typically your organisation), and a Data Processor (anyone processing data on the Fiduciary’s behalf, such as an outsourced vendor). A Significant Data Fiduciary — a category notified by the government based on factors like data volume and sensitivity — carries additional obligations, including appointing a Data Protection Officer based in India and undergoing periodic data protection impact assessments and audits.

What changes operationally for a Data Fiduciary:

Where this intersects with existing frameworks. Organisations already running an ISO/IEC 27001 ISMS have a head start — access control, encryption, breach detection and incident response are already control domains under Annex A. The gap is usually not technical controls but governance evidence: documented consent flows, a data inventory mapped to purpose and legal basis, a breach notification runbook with named owners, and a grievance-handling process that can demonstrate compliance if the Data Protection Board asks.

Practical starting point. A DPDP readiness assessment typically begins with a data mapping exercise — what personal data is collected, from whom, why, where it is stored, and who it is shared with — before any policy is drafted. Without that map, a privacy policy is a document, not a control.

Have a question on this?

Talk to an Expert