DPDP Act 2023: Companies Save ₹250 Crore with Compliance
India’s new Digital Personal Data Protection (DPDP) Act, 2023, coupled with its 2025 Rules, signals a significant shift in the nation’s digital economy. Companies can potentially save up to ₹250 crore by adhering to its mandates, according to Foresight Law Offices. The legislation moves India from a buyer beware approach to one built on accountability and trust.

The most immediate concern for businesses is Section 8(5) of the DPDP Act, which mandates reasonable security safeguards for all personal data under a company’s control. A breach of this obligation carries a penalty of up to ₹250 crore, as detailed in the Act’s Schedule. While substantive compliance for this section begins in May 2027, companies need to start implementing infrastructure now rather than waiting until the deadline approaches.

Who Actually Falls Under This Law

Section 3 of the Act defines its reach broadly. It applies to any entity handling digital personal data, regardless of turnover or financial status, including data collected digitally or digitized from offline sources.

The territorial scope extends well beyond India’s borders. Foreign companies processing data to offer goods or services to individuals in India are covered too, which means US-based streaming services or Singaporean airlines with Indian customers fall squarely within the law’s reach even without a physical presence in the country.

The scale behind this matters. India has over 900 million internet users, and its digital market is projected to reach one trillion dollars by 2026. That growth brings the same privacy breaches and cybersecurity threats other major digital economies have already faced, and the DPDP Act is India’s direct response to those risks.

The Seven Security Requirements

Rule 6 of the DPDP Rules 2025 outlines the mandatory safeguards companies must implement as a baseline, not a ceiling:

  • Data security measures including encryption, obfuscation, and masking
  • Strict access controls, such as Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC)
  • Real-time visibility and monitoring through systematic logs
  • Business continuity and recovery plans, primarily robust data backups
  • A mandated one-year log retention period for investigations
  • Contractual obligations binding vendors to the same security standards
  • Technical and organisational measures, including regular employee training and policy updates

That vendor requirement carries real weight. Data Fiduciaries are vicariously liable for any breach caused by their Data Processor, so even when a third-party cloud vendor is at fault, the data remains under the company’s control and the company bears the consequences. This makes verifying processor compliance a primary responsibility rather than a box to check once and forget.

The Act’s definition of lawful purpose also creates room for interpretation. It defines it as any purpose that is not expressly forbidden by law, language broad enough that the Data Protection Board could interpret it differently across cases and industries.

Hashlytics Take

The ₹250 crore penalty gets the headlines, but the “lawful purpose” clause is the part worth watching. Defining something as legal by default unless explicitly banned is a much looser standard than most global privacy frameworks use, and it hands the Data Protection Board significant discretion in how enforcement actually plays out. Companies treating this Act as a checklist of encryption and MFA requirements are solving half the problem. The real compliance risk sits in how that grey area gets tested once the Board starts ruling on real cases.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates