DPDP India
Definition
DPDP India
DPDP India refers to the Digital Personal Data Protection Act 2023 and its 2025 Rules, the country’s first comprehensive personal data law. A fiduciary may engage a processor only under a valid contract, which makes outsourcing a documented act.
India spent more than a decade drafting this law. The Act passed in August 2023, and the rules that make it operable were notified in November 2025.
Commencement is staged rather than immediate — the data protection board came first, consent manager provisions follow, and the substantive compliance duties arrive later.
That timetable is the planning point. Organisations building Indian delivery capacity now are designing for obligations that bite before most contracts signed today will expire.
Key takeaways
- The Act uses data fiduciary and data processor rather than controller and processor.
- A fiduciary may engage a processor only under a valid contract.
- Compliance obligations commence in phases rather than all at once.
- Penalties are set in rupee amounts far above anything Indian privacy law carried before.
How it works
The Act assigns two roles. A data fiduciary determines the purpose and means of processing, while a data processor is any person who processes personal data on behalf of a Data Fiduciary, which is exactly what an outsourcing provider does.
The contract requirement is the operative sentence for anyone buying services. A fiduciary may engage a processor only under a valid contract, so an informal arrangement is not merely risky but non-compliant.
Cross-border transfer works by exception. Personal data may move to any country except those the central government restricts by notification, which is a permissive default compared with European practice.
| Concept | DPDP India | Familiar equivalent |
|---|---|---|
| Data fiduciary | Sets purpose and means | Controller |
| Data processor | Processes on instruction | Processor |
| Data principal | The individual | Data subject |
| Significant data fiduciary | Additional duties by designation | Large-scale controller |
| Transfer rule | Permitted unless restricted | Adequacy or safeguards |
Penalties are substantial. Financial consequences run to hundreds of crores, including Rs 250 crore for failure to take security measures to prevent data breaches.
The fiduciary carries the compliance burden — a processor’s failure is still a fiduciary’s problem, which is why the contract has to do real work rather than sit in a folder.
Examples
India hosts a vast share of the world’s outsourced data processing, and this Act reaches almost all of it. The four below are unremarkable engagements that each produced an awkward supervisory question.
A European insurer runs policy administration from Pune. The insurer is a controller under its own law and the Indian provider is a processor under both, so one arrangement answers to two regimes at once.
A domestic bank outsources collections calling to a Hyderabad vendor. The bank is the fiduciary, and the rules make the contract with that vendor a compliance artefact rather than a commercial one.
A global capability centre in Bengaluru processes employee data for group companies abroad. Intra-group does not mean out of scope, and the internal service agreement has to carry the same terms an external one would.
A health platform stores records with an Indian cloud provider. Because the platform sets the purpose, it remains the fiduciary — the cloud provider’s own certifications do not shift that role.
Related terms
Indian terminology differs from the European vocabulary buyers usually arrive with, and the gap causes real contract errors. Each term here overlaps at the edges, so the one line distinctions do work.
- GDPR outsourcing: the European processor contract, which is more prescriptive than this one.
- PDPA outsourcing: the Singapore regime, with its own intermediary concept.
- ISO 27701: the privacy certification providers offer as evidence of capability.
- India BPO: the delivery market this law now governs.
- Knowledge process outsourcing (KPO): higher-judgement work that often carries richer personal data.
- Global capability center (GCC): the captive model, which the Act treats no differently.
- Compliance outsourcing: contracting the compliance function rather than the processing.
FAQ
When do the obligations actually apply?
In phases from the November 2025 notification. Board provisions came first, consent manager duties follow after twelve months, and the main compliance obligations arrive later still.
Does the Act apply to processing outside India?
Yes, where the processing relates to offering goods or services to individuals in India. Location of the server is not the test.
Is a data processor directly liable?
The Act places obligations principally on the fiduciary. A processor’s exposure comes through its contract rather than through direct statutory duties.
Can we move Indian personal data offshore?
Generally yes. Transfers are permitted except to countries the government restricts by notification, which reverses the European default.
Does this replace the older IT Act rules?
It supersedes the earlier sensitive personal data rules for the matters it covers. Sector regulators still impose their own requirements on top.
What should buyers do before the deadline?
Fix the contracts first, because that obligation is unambiguous and cheap to meet compared with retrofitting it later.
Search Outsource Accelerator and focus on the providers who answer these questions in writing.







Independent




