A general starting point for any organisation (a “Data Fiduciary”) preparing for the Digital Personal Data Protection Act, 2023. It sets out the basics most organisations should have in place. This is not legal advice, and it is not a complete list of obligations; what applies depends on your organisation and how it processes personal data.
Map your data — identify what personal data you collect, why, where it is stored, how long you keep it, and who it is shared with.
Confirm your legal basis — ensure you have valid consent, or another lawful basis recognised by the Act, for each processing activity.
Design your consent architecture — obtain consent through a clear affirmative action, keep a record of what each person agreed to and when, and make withdrawing consent as easy as giving it.
Give clear notice — tell individuals, in plain language, what personal data you collect and the purpose of processing, and how they can withdraw consent or raise a complaint.
Build a data-principal rights workflow — a defined way to receive and act on requests to access, correct, complete, update, and erase personal data, and to handle nominations, within a reasonable time.
Publish a point of contact — the business contact details of a Data Protection Officer (where applicable) or of a responsible person who can answer questions about how personal data is processed.
Set up a grievance-redressal mechanism — a readily available channel for individuals to raise concerns about how their data is handled, with someone accountable for responding.
Put processor agreements in place — a valid contract wherever a third party processes personal data on your behalf, requiring them to meet the same protections (including erasure on your instruction).
Implement reasonable security safeguards to protect the personal data in your possession or control against a breach.
Prepare a breach-response plan — how you will contain, assess, document, notify the Data Protection Board and affected individuals, and review a personal data breach.
Define retention and erasure — erase personal data once consent is withdrawn or the purpose is no longer being served (whichever is earlier), unless the law requires you to retain it, and ensure your processors erase it too.
Prepare policies and train your people — a privacy notice, an internal data-protection framework, and basic training for everyone who handles personal data.
Assess whether you are a Significant Data Fiduciary — if notified as one, additional obligations apply, such as appointing a Data Protection Officer and an independent data auditor, and undertaking Data Protection Impact Assessments.
Take special care with children’s data — the Act sets additional requirements, including verifiable parental consent and limits on tracking and targeted advertising directed at children.
Prefer a quick self-check first? Try the DPDP Readiness Scorecard. For explainers on each of these areas, see the DPDP Act notes in Knowledge Resources. Obligations under the DPDP Act, 2023 are being brought into force in phases.