Digital Personal Data Protection Act, 2023

Your data register
is now a legal register.

Every company, society, trust, LLP and professional practice that touches an Indian's personal data is a Data Fiduciary under the DPDP Act — whether or not it ever meant to be. JurisTatva builds the notices, consent architecture, registers, policies and SOPs that turn that exposure into a documented, defensible compliance file.

0Mandatory Instruments
0hBoard Breach Notification
0CrMaximum Schedule Penalty
0dRights-Request Ceiling
DATA FIDUCIARY • DATA PRINCIPAL • CONSENT MANAGER • DPDP ACT 2023 •
DPDPCompliance Docket
FILE NO. JT/DPDP/2023
Section 3 read with Section 2(i)

The Act does not ask what kind of entity you are.

It asks whether you determine the purpose and means of processing digital personal data in India. A "person" under Sec. 2(s) includes companies, societies, trusts, LLPs, sole proprietors and unincorporated associations alike — for-profit or not.

Employee & HR Records

Payroll, PF/ESI, appraisals and contact data of staff and consultants — Sec. 5's notice duty applies to every Data Principal, including employees.

Members, Donors & Investors

Governing body, shareholder, donor and funder contact details — a not-for-profit or society structure gives no exemption.

Website, App & Event Data

Visitors, newsletter subscribers, webinar and training participants — every intake channel is a processing activity.

Vendor & Client Contacts

Any personal data shared with, or received from, processors and sub-processors under a service contract.

If any of the above sits in your systems today, you are already a Data Fiduciary under Chapter II of the Act — the only open question is how much of your compliance file exists in writing.
The JurisTatva DPDP Framework

44 mandatory instruments, organised into 7 layers.

Resolutions, registers, notices, consent forms, policies, agreements and SOPs — every "shall"-type obligation in the Act mapped to a specific deliverable.

Registers & Notices

Data mapping, consent logs, breach registers and the 8 statutory notices owed to every Data Principal.

Policies & Agreements

Master privacy policy, retention & breach policies, and the vendor DPAs that make processing enforceable.

Standard Operating Procedures

Step-by-step SOPs that keep every 72-hour, 48-hour and 90-day statutory clock auditable.

Explore the full framework →
What's At Stake

Non-compliance is priced in crores, not notices.

The Data Protection Board of India can impose these amounts directly.

₹250 Cr
Failure to take reasonable security safeguards to prevent a breach.
₹200 Cr
Failure to notify the Board and affected Data Principals of a breach.
₹200 Cr
Non-compliance with obligations relating to children's personal data.
₹50 Cr
Non-compliance with any other duty of the Data Fiduciary or Principal.
See breach-clock deadlines →
Frequently Asked

DPDP Act, 2023 — the questions people actually ask.

Who is a Data Fiduciary under the DPDP Act, 2023?

Any person — including a company, LLP, society, trust or sole proprietor — that determines the purpose and means of processing digital personal data in India is a Data Fiduciary under Section 2(i), regardless of whether it is for-profit or not-for-profit.

What is the deadline to notify a personal data breach?

A Data Fiduciary must notify the Data Protection Board of India and each affected Data Principal without delay, with a detailed report generally expected within 72 hours of becoming aware of the breach.

What is the maximum penalty under the DPDP Act?

The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, with separate bands of up to ₹200 crore and ₹50 crore for other categories of non-compliance.

How long to respond to a Data Principal's rights request?

Entities generally build their grievance redressal SOP around a 90-day outer limit for resolving a Data Principal's rights request or grievance.

What documents does a company need for DPDP compliance?

A defensible compliance file typically includes a data mapping register, consent notices and logs, a master privacy policy, retention and breach policies, vendor DPAs, and SOPs for breach, grievance and rights-request handling — JurisTatva's framework organises 44 such instruments across 7 layers.

Start With A Diagnostic

Find out exactly which of the 44 instruments you're missing.

A short diagnostic call maps your data flows against the DPDP checklist and tells you precisely where your exposure sits — before we quote a single rupee of fee.