India’s Digital Personal Data Protection Act

A Preliminary Overview of Key Provisions, Scope, and Implications for Global Enterprises Ladda ner dokumentet

PUBLICIndia’s Digital Personal Data Protection ActKey Provisions, Scope and ImplicationsThe information contained in this document is for general informational purposes only and isprovided on the understanding that SAP is not engaged in rendering legal advice. SAP acceptsno liability for any actions taken in response to this resource. As such, it should not be used as asubstitute for legal or professional consultation.
On August 11, 2023, India published the Digital Personal Data Protection Act, 2023 (“IndiaDPDPA” or “Act”) in the Official Gazette, and the final rules of implementation were released on13th of November 2025. The Act is India’s first unified, comprehensive data protection law.ScopeThe India DPDPA applies to the processing of Digital Personal Data occurring within India where: Personal Data is collected in digital form; or Personal Data is collected in non-digital form and subsequently digitised.Like the GDPR, the India DPDPA has extraterritorial reach, applying to the processing of digital Personal Dataoutside India, when such processing is connected to any activity involving the offering of goods or services toData Principals (data subjects) in India.Key Definitions Personal Data: Any data about an identifiable individual. Unlike, the GDPR or other data protection andprivacy regimes, the India DPDPA does not provide a heightened protection for any special or sensitivecategories of personal data. Data Fiduciaries: Entities deciding how and why data is processed. Significant data fiduciaries, acategory to be further defined by the Central Government through notification based on the volume andrisks associated with Personal Data processing, have extra obligations (appointment of a DataProtection Officer in India, conducting Data Privacy Impact Assessments). Data Fiduciaries remainresponsible for the overall compliance with the Act. Data Processors: Entities like SAP that process data on behalf of fiduciaries under contract. Data Principals: Individuals with rights to notice, consent, access, correction, deletion, and grievanceredressal. Data Principals have the right to appoint a nominee to exercise their rights on their behalf, forexample, in the event of death or incapacity.SAP’s Preparedness for DPDPA ComplianceSAP recognizes the importance of the DPDPA and assigns due attention to aligning our data protection practiceswith its requirements. As the detailed implementing rules and timelines from the Government of India are finalizedand notified, we have proactively initiated several preparatory measures to ensure a smooth transition before thecompliance date approaches.Our current readiness efforts include: Assessment of existing data protection frameworks against the key principles of the DPDPA. GAP analysis and framework assessment of our current practices against the requirements of the DPDPA. Appointment of a DPO. Training and awareness programs to strengthen our teams’ understanding of the DPDPA. Monitoring further regulatory updates to ensure timely compliance with the final rules. Established procedures for handling Data Subject Rights requests, including access, correction, deletion,and objection, in alignment with global privacy regulations and contractual.