loader image
DPDPA HUB
DPDPA Compliance Deadline: 281 Days Left until 13 May 2027 GET ASSESSED →

India's Data Privacy Law Is Here. Is Your Organisation Ready?

The Digital Personal Data Protection Act 2023 (DPDPA) is now in force. Every organisation that collects, processes, or shares personal data of Indian citizens must comply — or face penalties of up to ₹250 crore per instance of non-compliance.

Zorixx is a specialist DPDPA consultation and implementation firm — combining legal compliance knowledge, technical implementation skills, and deep sector expertise across BFSI, insurance, fintech, manufacturing, and healthcare.

India's Data Privacy Law Is Here. Is Your Organisation Ready?

The Digital Personal Data Protection Act 2023 (DPDPA) is now in force. Every organisation that collects, processes, or shares personal data of Indian citizens must comply — or face penalties of up to ₹250 crore per instance of non-compliance.

Zorixx is a specialist DPDPA consultation and implementation firm — combining legal compliance knowledge, technical implementation skills, and deep sector expertise across BFSI, insurance, fintech, manufacturing, and healthcare.

Up to ₹250 crore

Penalty for breach of significant obligations

Up to ₹250 crore

Penalty for non-implementation of security safeguards

Up to ₹200 crore

Penalty for breach of child data protections

Who is affected?

Every entity processing personal data of Indian citizens

WHAT IS THE DPDPA?

The Digital Personal Data Protection Act 2023 is India’s comprehensive data protection legislation, enacted to protect the personal data of Indian citizens (Data Principals) and establish obligations for entities that process such data (Data Fiduciaries and Data Processors).

KEY DPDPA OBLIGATIONS

ZORIXX DPDPA IMPLEMENTATION JOURNEY

Phase 1: Discover (Weeks 1–2)

Personal data discovery and inventory. Data flow mapping. Legal basis analysis. Vendor/processor mapping.

Phase 2: Assess (Weeks 3–4)

Gap assessment against all DPDPA obligations. Risk-rated gap register. Penalty exposure quantification.

Phase 3: Design (Weeks 5–8)

Consent framework design. Privacy governance structure. Retention schedule. Breach response framework. Policy and notice drafting.

Phase 4: Implement (Weeks 9–16)

Consent management implementation. Security safeguards implementation. Data Principal rights fulfilment processes. DPO onboarding support.

Phase 5: Train (Week 17)

Organisation-wide DPDPA awareness training. Role-specific training for data handlers, IT, legal, HR teams.

Phase 6: Monitor & Sustain (Ongoing)

Quarterly compliance health check. Annual re-assessment. Consent audit. Breach response drill. Regulatory update monitoring.

Banking, Financial Services & Insurance

BFSI entities are among the highest-risk categories under DPDPA — processing enormous volumes of sensitive financial, health, and identification data. They also operate under multiple overlapping regulators (RBI, SEBI, IRDAI) creating a complex compliance environment.

Zorixx BFSI DPDPA Package: Includes DPDPA readiness assessment + sector-specific consent framework + BFSI-tailored policy library + regulatory overlap analysis (RBI/SEBI/IRDAI vs DPDPA)

Insurance Specific DPDPA Requirements
  • Policyholder health data — highest-risk category; specific consent for processing
  •  Claims data processing — purpose limitation; no use for underwriting without consent
  •   Nominee data — Rights to nomination under DPDPA align with nomination in insurance
  •  Re-insurer data sharing — Data Processor agreement requirements
  •  Broker data practices — consent for contacting policy seekers
  •  ISNP customer data — platform-specific consent design for online insurance distribution
SWIFT Security Controls Assessment (CSCF)

SWIFT CSCF v2025 — 22 mandatory controls assessment

  • 9 advisory controls assessment
  • SWIFT interface and infrastructure security review
  • Operator access controls and four-eye principle verification
  • Payment transaction flow security review
Manufacturing & Enterprise
  •  Employee personal data — payroll, HR data, biometric attendance data
  •  Customer data — warranty registration, service records, CRM data
  • Supplier and vendor data — personal data in procurement processes

Frequently asked questions

DPDPA applies to any entity that processes digital personal data of Indian citizens — whether the processing occurs in India or outside India. There is no minimum turnover or size threshold.

Unlike earlier frameworks, DPDPA does not define a separate 'sensitive personal data' category. However, the government can notify certain categories as requiring higher protection — expected to include health, financial, biometric, and children's data.

DPO is mandatory only for 'Significant Data Fiduciaries' notified by the government. However, all organisations should designate a data protection point of contact for grievance redressal.

DPDPA allows cross-border data transfers to countries that will be notified by the government. Until that list is published, transfers should be reviewed against contractual safeguards and Data Principal consent.

Penalties range from ₹10,000 to ₹250 crore depending on the nature and severity of the violation. The Data Protection Board adjudicates complaints and determines penalties.

For a mid-size organisation, a full implementation typically takes 12–20 weeks depending on the complexity of data flows and the number of systems involved. Zorixx's phased approach allows you to achieve baseline compliance quickly while building toward full compliance.

WHAT IS THE DPDPA?

DPDPA Readiness Checklist (Free)

40-point checklist covering all DPDPA obligations. Download and assess your current compliance status.

DPDPA Compliance Roadmap Template (Free)

Phased implementation roadmap template. Customise for your organisation.

DPDPA Penalty Exposure Calculator (Free)

Estimate your penalty exposure based on data volumes and compliance gaps.

DPDPA for BFSI — White Paper

Deep-dive on DPDPA obligations for banks, NBFCs, insurance companies, and fintechs. Includes RBI/SEBI/IRDAI overlap analysis.

DPDPA vs GDPR — Comparison Guide

Side-by-side comparison for organisations with both Indian and EU data processing.

Children's Data Under DPDPA — Implementation Guide

Practical guide for edtech, gaming, and digital platforms serving users under 18.

Zorixx Assistant