TDI City, Sector 117, Mohali, Punjab, India +91 98787 93377 support@darisham.in Mon–Sat: 9:00 AM – 6:00 PM
HomeAbout UsServices
Cybersecurity & Risk Management Digital Solutions & Enterprise Applications Policy & Government Advisory Talent & Staffing Solutions DPDP ComplianceCompliance & Regulatory AdvisoryExecutive Search & Leadership Hiring
Success StoriesInsightsCareers Contact Us
Digital Personal Data Protection Act, 2023

Navigate DPDP Compliance
with Confidence

India's landmark data protection law is now in force. We help organizations build practical, audit-ready compliance programs — from data discovery to breach response — without disrupting your operations.

10+
Compliance
Areas
₹250Cr
Max Penalty
per Breach
2023
Act
Enacted

What is the DPDP Act?
Why it matters now.

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data privacy legislation. It governs how organizations — called Data Fiduciaries — collect, process, store, and transfer personal data of individuals (Data Principals).

Non-compliance exposes organizations to financial penalties of up to ₹250 crore per violation, reputational damage, and regulatory scrutiny. With enforcement now active, the time to build a compliance program is today — not when a notice arrives.

Darisham Consulting helps you assess your current posture, identify gaps, and implement the controls and processes the Act requires — aligned with how your business actually works.

Talk to a DPDP Expert

Who does it apply to?

  • Any organization processing personal data of Indian citizens within India
  • Foreign businesses processing personal data in connection with offering goods or services to Indian residents
  • Startups and SMEs collecting customer or employee personal data digitally
  • E-commerce, fintech, healthtech, and edtech platforms handling large-scale data
  • Government bodies and public sector undertakings processing citizen data
  • Organizations designated as Significant Data Fiduciaries (SDF) face heightened obligations
The 10 Key Areas

DPDP Compliance Requirements

Click any requirement to see what it demands of your organization — and how we can help you meet it.

REQ 01
Consent Management
Section 6 — Data Fiduciary Obligation
  • Obtain free, informed, specific, and unambiguous consent before processing personal data
  • Maintain auditable records of when and how consent was obtained
  • Provide clear, easy mechanisms for users to withdraw consent at any time
  • Process only the data strictly necessary for the stated purpose
REQ 02
Privacy Notices
Section 5 — Notice Before Consent
  • Publish clear privacy notices before or at the time of data collection
  • Specify what personal data is collected and the exact purpose of processing
  • Explain individual rights, how to exercise them, and how to raise grievances
  • Document data retention periods and deletion timelines
REQ 03
Data Inventory & Classification
Foundational — Enables All Other Controls
  • Discover and map all personal data across apps, databases, cloud, and third-party systems
  • Build a living data inventory documenting what data exists and where
  • Classify data by sensitivity — personal, sensitive, and critical
  • Identify data flows including cross-border transfers
REQ 04
Data Subject Rights Management
Sections 11–13 — Rights of Data Principals
  • Build processes for individuals to access copies of their personal data
  • Enable correction of inaccurate or incomplete information
  • Implement data erasure workflows for when purpose is fulfilled
  • Maintain a grievance redressal mechanism with defined SLAs
REQ 05
Information Security Controls
Section 8(5) — Reasonable Security Safeguards
  • Implement technical and organizational safeguards proportionate to data sensitivity
  • Protect against unauthorized access, disclosure, alteration, or loss
  • Establish security monitoring, logging, and incident detection capabilities
  • Conduct regular vulnerability assessments and penetration tests (VAPT)
REQ 06
Data Retention & Deletion
Section 8(7) — Storage Limitation Principle
  • Define and document retention periods for all categories of personal data
  • Implement automated or process-driven deletion when purpose is fulfilled
  • Apply secure deletion standards that prevent data reconstruction
  • Maintain audit trails of data lifecycle from collection to deletion
REQ 07
Third-Party & Vendor Risk Management
Section 8(2) — Data Processor Obligations
  • Identify all vendors and data processors handling personal data on your behalf
  • Conduct risk assessments and security due diligence on third parties
  • Execute data processing agreements (DPAs) with appropriate contractual controls
  • Establish ongoing monitoring for vendor compliance posture
REQ 08
Breach Management & Reporting
Section 8(6) — Mandatory Notification Obligation
  • Establish procedures to detect, contain, and investigate personal data breaches
  • Notify the Data Protection Board and affected Data Principals upon breach
  • Document breach timelines, impact, and remediation steps
  • Conduct post-breach reviews and update controls to prevent recurrence
REQ 09
Children's Data Protection
Section 9 — Special Obligations for Minors
  • Implement verifiable parental consent before processing data of children under 18
  • Deploy age-verification mechanisms appropriate to the platform context
  • Prohibit tracking, behavioural monitoring, and targeted advertising at children
  • Restrict data sharing of children's data with third parties without explicit parental consent
REQ 10
Governance & Compliance Monitoring
Section 10 — Significant Data Fiduciary Obligations
  • Conduct periodic privacy assessments and internal compliance reviews
  • SDFs must appoint a Data Protection Officer (DPO) based in India
  • SDFs must perform independent annual data protection audits
  • SDFs must conduct Data Protection Impact Assessments (DPIAs) for high-risk processing
Self-Assessment Tool

Where does your organization stand?

Check off the areas your organization has addressed to see your current compliance coverage.

Compliance Coverage 0%
Consent collection & records in place
Privacy notices published and current
Data inventory and mapping completed
Data subject rights processes established
Security controls implemented and tested
Retention schedules and deletion automated
Vendor DPAs signed and assessed
Breach response plan documented and tested
Children's data controls in place (if applicable)
Privacy governance and monitoring program active

Get started: tick each area your organization has already addressed to reveal your coverage score.

Get a Full Assessment
How We Help

End-to-End DPDP Compliance Services

Darisham Consulting provides a complete suite of DPDP services — from the first assessment through ongoing monitoring — designed around your business context, not a generic checklist.

Data Discovery & Privacy Assessment

We identify and map all personal data flows across your systems — apps, databases, cloud, and third parties — and benchmark your current posture against DPDP requirements.

Consent Management Framework Design

We design and implement consent workflows, preference centres, and withdrawal mechanisms that are legally sound and user-friendly across web and mobile channels.

Policy Development & Documentation

We draft and review privacy policies, data processing agreements, retention schedules, and internal privacy standards aligned with DPDP obligations and your operational reality.

Security Control Implementation

We deploy the technical and organisational safeguards required under Section 8(5) — including access controls, encryption, VAPT, and security monitoring tailored to your data risk profile.

Vendor Risk Assessments & DPAs

We assess your data processor ecosystem for compliance risk, draft appropriate contractual controls, and build an ongoing vendor monitoring framework.

Breach Response Planning & Monitoring

We build and test your incident response playbook for personal data breaches, including notification workflows for the Data Protection Board and affected individuals, plus ongoing compliance monitoring.

Also included in our engagement:
Employee Awareness Programs DPO-as-a-Service DPIA Facilitation Regulatory Audit Support Ongoing Compliance Reviews Cross-Border Transfer Advisory

Ready to get DPDP-ready?

Book a free 45-minute DPDP readiness call with one of our compliance experts. We'll assess your current posture, identify your highest-priority gaps, and map out a practical path forward — no jargon, no pressure.

Book a Free Consultation Download DPDP Checklist Free assessment  ·  No obligation  ·  Expert-led