Priya Sharma
CTO
With the Digital Personal Data Protection Act's rules now taking effect, Indian businesses have a narrowing window to fix consent flows, data retention, and breach reporting in their software. A practical, engineering-focused compliance checklist.
The Digital Personal Data Protection Act, 2023 (DPDP Act) marks India's first comprehensive, cross-sector data protection law, and with its rules now progressively coming into force, Indian businesses — and any global company processing Indian users' data — have a narrowing window to move from policy intent to working software. Unlike some earlier voluntary guidance, the DPDP Act carries real financial penalties, reaching up to ₹250 crore for serious breaches of data protection obligations, which has moved this firmly onto CTO and product leadership agendas.
The DPDP Act requires consent to be free, specific, informed, unconditional and unambiguous, communicated in clear and plain language, with an option in English and each language listed in the Eighth Schedule of the Constitution. For most Indian software products, this means the existing 'accept our terms' checkbox pattern doesn't meet the bar.
Businesses notified as Significant Data Fiduciaries (based on volume and sensitivity of data processed, among other factors) face additional obligations: appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, and independent data audits. Growing platforms should model whether their trajectory puts them into this category before it becomes an urgent, reactive project.
“The businesses handling DPDP well aren't the ones treating it as a one-time legal review. They've built consent, access, and deletion as product features — because under this Act, that's exactly what they are.”
— Priya Sharma, CTO, Alliance Corporation
Unlike some frameworks with a harm-based threshold, the DPDP Act requires notification to the Data Protection Board and affected data principals for personal data breaches without the same materiality carve-outs — making breach detection and reporting readiness a baseline requirement, not a judgment call made after the fact.
Alliance Corporation builds DPDP-ready custom software and consent management systems for Indian businesses. Talk to our team about a DPDP compliance architecture review.
Priya Sharma
CTO · Alliance Corporation
Part of the Alliance Corporation leadership team, shaping technology strategy across AI, cloud and enterprise software for clients in 50+ countries.