India's Digital Personal Data Protection Act 2023 creates board-level accountability, personal director liability, and penalties up to ₹500 crore. This brief tells you what decisions only you can make — and what must be on your board agenda before May 2027.
The DPDP Act 2023 is India's comprehensive data privacy law that applies to every company processing the personal data of Indian individuals — making it a near-universal corporate obligation. CEOs and directors can face personal liability where non-compliance is attributable to their neglect or consent, and the company faces cumulative penalties of up to ₹500 crore. With enforcement beginning May 13, 2027, boards have approximately 12 months to designate ownership, approve budgets, govern vendor risk, and sign off on incident response protocols — decisions that cannot be delegated below the board level.
Most boards have delegated DPDP to a compliance or tech team. Here is why that is insufficient — and what only the board can decide.
The DPDP Act 2023 includes provisions that hold individuals in charge of, and responsible for, the conduct of the company personally liable where a violation is attributable to their neglect or consent. This extends to the CEO, MD, and executive directors. A board that knowingly underfunds DPDP compliance or ignores regulatory warnings cannot later argue it was unaware. Personal liability means personal prosecution — not just a corporate fine — making this a governance issue at the highest level.
The DPDP Act sets a maximum cumulative penalty of ₹500 crore per Data Fiduciary. Individual violations carry separate maximums: ₹250 crore for a data breach caused by inadequate security safeguards, ₹200 crore for failure to notify the Data Protection Board of a breach, and ₹50 crore for consent violations. For any mid-market or growth-stage company, a single serious breach could be existential. The board must quantify this exposure and ensure the compliance investment is proportionate to the risk — not left to a budget line that legal or tech can cut.
Full DPDP enforcement begins May 13, 2027. For most mid-market companies, a realistic implementation timeline — from readiness assessment through documentation, consent architecture, vendor contracts, and staff training — is 6 to 9 months. That leaves a shrinking window. Companies that begin in January 2027 will be rushing through implementation without adequate time for testing and remediation. Board-level prioritisation is the only mechanism that guarantees the right resources, timelines, and cross-functional coordination are in place before enforcement begins.
Under the DPDP Act, the Data Fiduciary — your company — remains legally responsible for any personal data processed by third-party Data Processors (vendors, cloud providers, SaaS platforms, payroll processors, marketing agencies). A data breach at a vendor is your regulatory event, not theirs. The board must approve a vendor risk governance framework that includes DPDP contractual requirements in all data processor agreements — and this cannot be limited to new contracts. Existing agreements must be reviewed and updated before enforcement begins.
These four decisions require board-level authority or resource allocation. They cannot be safely delegated — and their absence creates personal liability exposure.
Designate a named internal owner for DPDP compliance: this can be your General Counsel, CTO, COO, or a senior Compliance Officer. The DPDP Champion is responsible for driving the implementation programme, reporting progress to the board quarterly, and serving as the primary internal contact for the Data Protection Board if an inquiry arises. The Act requires a Grievance Officer (for handling Data Principal requests) to be designated and publicly named on your website — the DPDP Champion can hold this role. Without a named owner, compliance remains everyone's responsibility and therefore no one's. The board should formally record this appointment in its minutes and set a reporting cadence before Q3 2026.
For a mid-market company (100–2,000 employees), a realistic DPDP compliance budget for the first 12 months is ₹2 lakh to ₹5 lakh. This covers: a readiness assessment (₹75,000–₹2 lakh), privacy policy and documentation overhaul (₹50,000–₹1 lakh), vendor contract amendments (₹25,000–₹50,000), and an annual review retainer (₹50,000). This investment should be benchmarked against your penalty exposure — not against the cost of doing nothing. A company with ₹250 crore of penalty exposure spending ₹3 lakh to eliminate that risk is a 1000:1 return on compliance investment. The CFO should present this framing at the board meeting where DPDP budget is approved.
The board must formally approve a Vendor Risk Governance Framework that: (a) requires all new data processor contracts to include a DPDP-compliant Data Processing Agreement (DPA), (b) mandates review and amendment of all existing contracts involving personal data processing before May 2027, (c) establishes an annual vendor risk review process, and (d) requires vendors to notify your company of any breach within a defined window (typically 24–48 hours). The list of key data processors — payroll, HRMS, CRM, cloud, analytics, marketing automation — should be tabled at the same board meeting. This is now a board agenda item, not a procurement checklist item.
The DPDP Act requires notification to the Data Protection Board "without undue delay" following a data breach — and the Rules define a specific timeline. The board must approve a Breach Response Protocol before a breach occurs, covering: (a) internal escalation thresholds (what size breach triggers CEO and board notification), (b) the Data Protection Board notification process and responsible officer, (c) customer (Data Principal) communication templates, (d) media response guidelines, and (e) external legal and PR contacts. Boards that improvise breach response without pre-approved protocols face compounded penalties for delayed notification — currently up to ₹200 crore for failure to notify the Board. A breach during enforcement is one of the most credible ways a company faces maximum penalty exposure.
Enter your annual revenue to contextualise the maximum penalty as a percentage of your business scale. This is not a legal determination — it is a board-level risk framing tool.
Enter your approximate annual revenue and employee count to see how DPDP penalty exposure compares to your business metrics.
Maximum DPDP Penalty Exposure
This is a high-level risk framing tool. Actual penalties depend on the nature, gravity, and duration of the violation as assessed by the Data Protection Board. Engage a compliance advisor for a formal risk assessment.
If your board has not yet received a DPDP update from management, these are the questions to raise at your next meeting. Unsatisfactory answers are early warning signals.
Management should be able to name a specific person — not a team or a job title. If the answer is "we are evaluating options," the board should set a 30-day deadline and add it to the next board pack as a closed item.
Every DPDP compliance programme starts with a data inventory. If management cannot produce a data flow map covering customers, employees, and third-party processors, the organisation does not yet have the foundation required for compliance — regardless of what else has been done.
Management should be able to produce a list of data processors and confirm the status of DPA amendments. If any major vendor (payroll, HRMS, CRM, cloud infrastructure) is missing a DPA, that is an immediate risk that should be remediated before enforcement. The board should set a deadline for completion.
The answer should reference a written, board-approved Breach Response Protocol with named individuals, decision thresholds, and regulator notification steps. If the answer is "we would work it out," the board needs to commission a protocol before the next meeting — not after an incident occurs.
The CFO should present the budget alongside the maximum penalty exposure so the board can assess proportionality. A compliance budget sized against last year's IT spending without reference to regulatory risk is not adequate governance. The board should formally approve the budget and confirm it is sufficient for the scope of remediation required.
Boards that plan backwards from May 2027 have time. Boards that wait until early 2027 will be compressing a 6–9 month programme into 3 months — and accepting that risk knowingly.
Fixed-price tools and board-ready deliverables. Start with a readiness score, escalate to a gap analysis, or go straight to a board presentation deck.
Tell us about your organisation and your board's current DPDP awareness. We will prepare a concise, business-language briefing — no legal jargon — ready for your next board meeting.
Plain-language answers to the questions we hear most from CEOs, MDs, CFOs, and board directors.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.