Corporate Compliance Under the DPDP Act, 2023.
This article is written by Urmila More, pursuing an LL.B. from Nalanda College of Law, Mumbai.
The Digital Personal Data Protection Act, 2023, represents an evolution in the regulatory regime for corporations in India. Until now, Indian companies have had to deal with piecemeal obligations under the provisions of the Information Technology Act, 2000, various sectoral laws, contractual obligations, and company policy related to cybersecurity. The DPDP Act creates a comprehensive legislative framework concerning digital personal data and makes corporations that decide the purpose and means of digital data processing legally bound. As far as corporate compliance goes, the DPDP Act is not just another privacy law; rather, it is a governance law that obliges companies to transform their approach towards data collection, consent, notices, security, vendors, breaches, data retention, and grievance handling.
Under the provisions of the Act, digital personal data processing inside and outside India becomes subject to regulation if the offer of goods or services is made to individuals located in India. The DPDP Act also creates several new definitions, including Data Principal, Data Fiduciary, Data Processor, consent, legitimate use, personal data breach, and Significant Data Fiduciary. These definitions have consequences for a compliance framework of the following industries: technology, fintech, e-commerce, health-tech, ed-tech, SaaS, digital marketing, finance, and human resources management.
The article discusses compliance requirements of the corporation in relation to the DPDP Act, 2023, with emphasis on implementation. In particular, it looks at the obligations of the Data Fiduciaries, consent and notice provisions, data minimisation, data security measures, protection of children's data, vendor contracts, data transfer across borders, breach management, penalties, and corporate governance requirements. The article emphasises that compliance in relation to the DPDP Act should be seen not only as a process but rather as an ongoing activity. It concludes with recommendations on how to develop a practical compliance program.
DISCLAIMER: The views and opinions expressed in this research article, submitted by students and/or other contributors in their personal capacity, are solely those of the author(s) and do not, in any manner whatsoever, reflect or represent the views, opinions, advice, or official position of PACTEDGE LEGAL LLP (“PACTEDGE”). PACTEDGE makes no representations or warranties, whether express or implied, as to the completeness, accuracy, reliability, or currency of any facts, data, analysis, or legal propositions contained herein and shall not, to the fullest extent permitted by applicable law, be liable for any loss, injury, damage, or consequence arising directly or indirectly from any reliance placed upon this publication. The entire contents of this research article, including without limitation its text, structure, compilation, selection and arrangement of material, are and shall remain the exclusive intellectual property of PACTEDGE LEGAL LLP, protected under applicable copyright and other intellectual property laws. No part of this publication may be copied, reproduced, stored in a retrieval system, transmitted, adapted, published, communicated to the public, distributed, or otherwise made available in any form or by any means, whether electronic, digital, mechanical, photocopying, recording or otherwise, nor shared or reposted on any platform or medium, without the prior written consent of PACTEDGE LEGAL LLP; any unauthorised use shall constitute infringement and may attract civil and/or criminal consequences, without prejudice to any other rights or remedies available to PACTEDGE LEGAL LLP in law or equity.
Comments