DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

The Company Secretary is increasingly the governance owner of DPDP compliance inside an organisation — the person who ensures the board is informed, that data-protection policies are formally approved and minuted, that the Grievance Officer role is properly constituted, and that DPDP risk appears in the board's risk register. The DPDP Act 2023 does not name the Company Secretary, but its accountability model makes DPDP a board-level governance matter, and CS professionals are well placed to run it. This checker assesses your organisation's DPDP governance readiness from a Company Secretary's perspective.

DPDP for Company Secretaries — Board & Governance Readiness

DPDP compliance is a board-level governance matter, and the Company Secretary is often its natural owner. Check your organisation's DPDP governance readiness.

Check your DPDP governance readiness

DPDP governance checklist for Company Secretaries

Why DPDP compliance is a board-level governance matter

The DPDP Act 2023 places accountability for compliance squarely on the data fiduciary — the organisation — and that accountability ultimately sits with its board and senior management. Unlike a purely operational IT task, DPDP compliance touches consent architecture, security safeguards, breach response, vendor contracts, and the constitution of the Grievance Officer and (for Significant Data Fiduciaries) the Data Protection Officer. These are governance decisions with budget, risk and disclosure implications, which is exactly the terrain a Company Secretary is trained to steward.

For that reason the Company Secretary is emerging as a natural owner of DPDP governance: ensuring the board formally considers and approves a compliance approach, that data-protection risk enters the risk register, that policies are properly owned and reviewed, and that the organisation can demonstrate due diligence if the Data Protection Board ever asks. Board-approved, minuted oversight is not bureaucratic box-ticking — it is the documented foundation of a defensible position under an accountability-based law.

What a Company Secretary should put in place before May 2027

A practical DPDP governance foundation has four pillars a Company Secretary can drive. First, a formal, minuted board decision that adopts a DPDP compliance approach and allocates budget and ownership. Second, data-protection risk added to the enterprise risk register with a named owner and a reporting cadence so it is governed like any other material risk. Third, data-protection policies brought under version control with clear ownership and a scheduled review cycle. Fourth, a properly constituted and published Grievance Officer, and — where the organisation is likely a Significant Data Fiduciary — the DPO, DPIA and independent-audit obligations planned for.

Niti Bharat works with Company Secretaries and boards to build exactly this governance layer: board papers, a DPDP risk-register entry, a policy governance framework, and the readiness reporting a board needs to show it exercised oversight. With enforcement expected around May 2027, establishing demonstrable board-level governance now is one of the highest-leverage things a Company Secretary can do to protect the organisation and its directors.

Get the CS DPDP governance pack (free)

A PDF with a board-paper outline for DPDP, a risk-register entry template, a policy-governance checklist, and a Grievance Officer constitution note — built for Company Secretaries.

Frequently Asked Questions

Does the DPDP Act require a Company Secretary to do anything specifically?+
The Act does not name the Company Secretary. However, its accountability model makes DPDP compliance a board-level governance matter, and the CS is well placed to own the governance layer — board approval, risk-register tracking, policy governance and constituting the Grievance Officer — even though the specific statutory roles it names are the Data Fiduciary, Grievance Officer and, for larger entities, the Data Protection Officer.
Should DPDP compliance go to the board?+
Yes. Because accountability rests with the organisation and, ultimately, its board and senior management, a formal minuted board decision on the DPDP compliance approach, ownership and budget is a strong governance practice. It demonstrates the due diligence expected under an accountability-based law and protects directors.
Who should be the Grievance Officer — can it be the Company Secretary?+
The Grievance Officer must be a contactable point for Data Principals, published and responsive. It can be an appropriate senior individual, and in some organisations the Company Secretary or their office may take or oversee the role, provided it is properly constituted, published and given a governance reporting line. The key is that it is formally set up, not left informal.
What is a Significant Data Fiduciary and why does it matter for governance?+
A Significant Data Fiduciary is an organisation the government designates based on factors like the volume and sensitivity of data it processes. Such entities have extra obligations — appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and undergoing independent audits — which are significant governance commitments a Company Secretary should plan for if designation is likely.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Incident Response Tabletop Exercise GuideDPDP Interim Measures & Interim OrdersDPDP Onboarding Checklist for TeamsVendor Privacy AssessmentSee all Reference & Checklists tools →📝 Consent Manager Registration DPDP📝 DPDP Apply to Employee Data HR