India's DPDP Act 2023 places direct legal obligations on every company that processes personal data — and in-house legal teams own the compliance architecture. Privacy policies, vendor contracts, data principal rights, and breach response all land on legal's desk.
The legal team's role in DPDP compliance is to design and own the company's data protection legal framework. This includes overhauling privacy policies and consent notices to meet DPDP Rule 3's itemised purpose-specific requirements, amending every vendor contract that involves personal data to include a DPDP-compliant Data Processing Agreement (DPA) under Rule 14, establishing Data Principal rights response processes with 30-day SLAs, and drafting the company's breach notification procedure for the Data Protection Board. Legal must also assess penalty exposure, appoint a Grievance Officer, and brief the board on DPDP obligations and enforcement risk ahead of the May 2027 deadline.
The DPDP Act 2023 and Rules 2025 create four concrete legal workstreams that in-house counsel must own — not delegate to IT or operations.
Most existing Indian privacy policies are non-compliant with DPDP. DPDP Rule 3 requires itemised, purpose-specific consent notices that are separate from Terms & Conditions. Bundling data consent into a standard T&C checkbox — the common IT Act-era practice — is no longer permissible. Each purpose for which personal data is collected must be individually disclosed and separately consented to. Legal must redraft privacy policies, consent flows, and cookie notices to meet this requirement before enforcement begins.
Every vendor contract that involves the processing of personal data must be amended to include a DPDP-compliant Data Processing Agreement (DPA) — mandated under DPDP Rule 14. This covers cloud providers, payroll processors, CRM vendors, recruitment platforms, background verification agencies, marketing automation tools, and any outsourced operations that touch employee or customer data. Generic data security clauses are insufficient — each DPA must specify categories of data, purposes, retention limits, sub-processing restrictions, and return or deletion obligations.
The DPDP Act grants every individual (Data Principal) rights to access their personal data, correct inaccuracies, and request erasure. Under the Rules, companies must respond within 30 days. Legal must design the DSAR (Data Subject Access Request) intake process, build a defensible legal basis matrix mapping each data category to its retention justification, and draft the escalation pathway to the Data Protection Board (DPB) for cases where requests are legitimately denied. A publicly named Grievance Officer must be appointed and accessible.
The DPDP Act requires that Data Fiduciaries notify the Data Protection Board (DPB) and affected individuals promptly following a personal data breach — without undue delay. Legal must draft the company's breach response procedure: classification criteria (what constitutes a notifiable breach), internal escalation chain, DPB notification format, individual notification template, and the legal hold/preservation protocol for any concurrent regulatory or court proceedings. Failure to notify carries a penalty of up to ₹200 crore.
Every company that processes personal data of Indian individuals needs these documents drafted and in place before enforcement begins. Tick them off one by one.
The Data Protection Board can impose financial penalties for each violation. Legal teams must brief the board and leadership on these exposure figures — they are not theoretical.
| Violation | Relevant Provision | Maximum Penalty |
|---|---|---|
| Failure to implement reasonable data security safeguards leading to a breach | Section 8(5) DPDP Act | ₹250 Crore |
| Failure to notify the DPB of a personal data breach | Section 8(6) DPDP Act | ₹200 Crore |
| Processing children's personal data without verifiable parental consent | Section 9 DPDP Act | ₹200 Crore |
| Non-compliance by a Significant Data Fiduciary (SDF) with additional obligations | Section 10 DPDP Act | ₹150 Crore |
| Obtaining invalid or non-compliant consent (bundled consent, vague purpose, etc.) | Section 6 DPDP Act | ₹50 Crore |
| Failure to provide a functioning Grievance Redressal mechanism | Section 13 DPDP Act | ₹10 Crore |
| Other contraventions of the Act or Rules | Schedule to DPDP Act | ₹50 Crore |
A practical three-step workplan for in-house legal teams that have to run DPDP alongside their existing workload — without a dedicated privacy team.
Start with a data inventory: what personal data does the company collect, from whom, for what purpose, and who has access to it? This maps all internal and external processing activities. Identify every vendor or partner that processes personal data on the company's behalf — this is the universe of contracts that require DPA amendments. Prioritise high-volume or high-risk processors (cloud infra, payroll, HR tech, CRM) for early amendment. The inventory also surfaces which data flows require fresh consent under DPDP Rule 3 and which can rely on a legitimate use basis. This step cannot be skipped — consent architecture and contract work both depend on it.
Using the data inventory as the foundation, draft or redraft all nine documents in the legal checklist. For privacy policy and consent notices, use a purpose-by-purpose structure: each row in your data inventory maps to a purpose statement, legal basis, and consent mechanism. For DPAs, start from a master template and customise for each processor's specific role, data categories, and sub-processor relationships. Simultaneously, draft the Breach Notification SOP — this must be ready to deploy immediately if an incident occurs, not drafted in the middle of a crisis. Brief the board with a penalty exposure summary and obtain board-level sign-off on the Privacy Policy.
DPDP compliance is not a one-time document exercise. Legal must operationalise ongoing compliance: set up a DSAR intake channel (dedicated email or web form), train customer-facing and HR teams on how to route rights requests, and build a 30-day response tracking system. Establish a privacy review checkpoint in the contract approval process so that new vendor contracts automatically trigger DPA review. Conduct annual consent audits to verify that consent records match current processing activities. Set a calendar reminder to review DPDP Rules updates — the Central Government retains broad power to issue additional subordinate legislation before May 2027.
Fixed-price tools and expert engagements that give legal teams the documents, analysis, and frameworks they need — without months of consulting retainers.
Tell us about your organisation and your most pressing DPDP legal question. We'll come prepared with a structured agenda specific to your sector and legal workload — not generic compliance advice.
Answers to the questions we hear most from in-house counsel, company secretaries, and compliance officers across Indian companies.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.