India’s Digital Personal Data Protection Act
PUBLIC
India’s Digital Personal Data Protection Act
Key Provisions, Scope and Implications
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
India’s Digital Personal Data Protection Act
Key Provisions, Scope and Implications
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
On August 11, 2023, India published the Digital Personal Data Protection Act, 2023 (“India
DPDPA” or “Act”) in the Official Gazette, and the final rules of implementation were released on
13th of November 2025. The Act is India’s first unified, comprehensive data protection law.
Scope
The India DPDPA applies to the processing of Digital Personal Data occurring within India where:
• Personal Data is collected in digital form; or
• Personal Data is collected in non-digital form and subsequently digitised.
Like the GDPR, the India DPDPA has extraterritorial reach, applying to the processing of digital Personal Data
outside India, when such processing is connected to any activity involving the offering of goods or services to
Data Principals (data subjects) in India.
Key Definitions
• Personal Data: Any data about an identifiable individual. Unlike, the GDPR or other data protection and
privacy regimes, the India DPDPA does not provide a heightened protection for any special or sensitive
categories of personal data.
• Data Fiduciaries: Entities deciding how and why data is processed. Significant data fiduciaries, a
category to be further defined by the Central Government through notification based on the volume and
risks associated with Personal Data processing, have extra obligations (appointment of a Data
Protection Officer in India, conducting Data Privacy Impact Assessments). Data Fiduciaries remain
responsible for the overall compliance with the Act.
• Data Processors: Entities like SAP that process data on behalf of fiduciaries under contract.
• Data Principals: Individuals with rights to notice, consent, access, correction, deletion, and grievance
redressal. Data Principals have the right to appoint a nominee to exercise their rights on their behalf, for
example, in the event of death or incapacity.
SAP’s Preparedness for DPDPA Compliance
SAP recognizes the importance of the DPDPA and assigns due attention to aligning our data protection practices
with its requirements. As the detailed implementing rules and timelines from the Government of India are finalized
and notified, we have proactively initiated several preparatory measures to ensure a smooth transition before the
compliance date approaches.
Our current readiness efforts include:
• Assessment of existing data protection frameworks against the key principles of the DPDPA.
• GAP analysis and framework assessment of our current practices against the requirements of the DPDPA.
• Appointment of a DPO.
• Training and awareness programs to strengthen our teams’ understanding of the DPDPA.
• Monitoring further regulatory updates to ensure timely compliance with the final rules.
• Established procedures for handling Data Subject Rights requests, including access, correction, deletion,
and objection, in alignment with global privacy regulations and contractual.
DPDPA” or “Act”) in the Official Gazette, and the final rules of implementation were released on
13th of November 2025. The Act is India’s first unified, comprehensive data protection law.
Scope
The India DPDPA applies to the processing of Digital Personal Data occurring within India where:
• Personal Data is collected in digital form; or
• Personal Data is collected in non-digital form and subsequently digitised.
Like the GDPR, the India DPDPA has extraterritorial reach, applying to the processing of digital Personal Data
outside India, when such processing is connected to any activity involving the offering of goods or services to
Data Principals (data subjects) in India.
Key Definitions
• Personal Data: Any data about an identifiable individual. Unlike, the GDPR or other data protection and
privacy regimes, the India DPDPA does not provide a heightened protection for any special or sensitive
categories of personal data.
• Data Fiduciaries: Entities deciding how and why data is processed. Significant data fiduciaries, a
category to be further defined by the Central Government through notification based on the volume and
risks associated with Personal Data processing, have extra obligations (appointment of a Data
Protection Officer in India, conducting Data Privacy Impact Assessments). Data Fiduciaries remain
responsible for the overall compliance with the Act.
• Data Processors: Entities like SAP that process data on behalf of fiduciaries under contract.
• Data Principals: Individuals with rights to notice, consent, access, correction, deletion, and grievance
redressal. Data Principals have the right to appoint a nominee to exercise their rights on their behalf, for
example, in the event of death or incapacity.
SAP’s Preparedness for DPDPA Compliance
SAP recognizes the importance of the DPDPA and assigns due attention to aligning our data protection practices
with its requirements. As the detailed implementing rules and timelines from the Government of India are finalized
and notified, we have proactively initiated several preparatory measures to ensure a smooth transition before the
compliance date approaches.
Our current readiness efforts include:
• Assessment of existing data protection frameworks against the key principles of the DPDPA.
• GAP analysis and framework assessment of our current practices against the requirements of the DPDPA.
• Appointment of a DPO.
• Training and awareness programs to strengthen our teams’ understanding of the DPDPA.
• Monitoring further regulatory updates to ensure timely compliance with the final rules.
• Established procedures for handling Data Subject Rights requests, including access, correction, deletion,
and objection, in alignment with global privacy regulations and contractual.