India’s Digital Personal Data Protection Act
PUBLIC
India’s Digital Personal Data Protection Act
Key Provisions, Scope and Implications
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
India’s Digital Personal Data Protection Act
Key Provisions, Scope and Implications
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
On August 11, 2023, India published the Digital Personal Data Protection Act, 2023 (“India
DPDPA” or “Act”) in the Official Gazette, and the final rules of implementation were released on
13th of November 2025. The Act is India’s first unified, comprehensive data protection law.
Scope
The India DPDPA applies to the processing of Digital Personal Data occurring within India where:
• Personal Data is collected in digital form; or
• Personal Data is collected in non-digital form and subsequently digitised.
Like the GDPR, the India DPDPA has extraterritorial reach, applying to the processing of digital Personal Data
outside India, when such processing is connected to any activity involving the offering of goods or services to
Data Principals (data subjects) in India.
Key Definitions
• Personal Data: Any data about an identifiable individual. Unlike, the GDPR or other data protection and
privacy regimes, the India DPDPA does not provide a heightened protection for any special or sensitive
categories of personal data.
• Data Fiduciaries: Entities deciding how and why data is processed. Significant data fiduciaries, a
category to be further defined by the Central Government through notification based on the volume and
risks associated with Personal Data processing, have extra obligations (appointment of a Data
Protection Officer in India, conducting Data Privacy Impact Assessments). Data Fiduciaries remain
responsible for the overall compliance with the Act.
• Data Processors: Entities like SAP that process data on behalf of fiduciaries under contract.
• Data Principals: Individuals with rights to notice, consent, access, correction, deletion, and grievance
redressal. Data Principals have the right to appoint a nominee to exercise their rights on their behalf, for
example, in the event of death or incapacity.
SAP’s Preparedness for DPDPA Compliance
SAP recognizes the importance of the DPDPA and assigns due attention to aligning our data protection practices
with its requirements. As the detailed implementing rules and timelines from the Government of India are finalized
and notified, we have proactively initiated several preparatory measures to ensure a smooth transition before the
compliance date approaches.
Our current readiness efforts include:
• Assessment of existing data protection frameworks against the key principles of the DPDPA.
• GAP analysis and framework assessment of our current practices against the requirements of the DPDPA.
• Appointment of a DPO.
• Training and awareness programs to strengthen our teams’ understanding of the DPDPA.
• Monitoring further regulatory updates to ensure timely compliance with the final rules.
• Established procedures for handling Data Subject Rights requests, including access, correction, deletion,
and objection, in alignment with global privacy regulations and contractual.
DPDPA” or “Act”) in the Official Gazette, and the final rules of implementation were released on
13th of November 2025. The Act is India’s first unified, comprehensive data protection law.
Scope
The India DPDPA applies to the processing of Digital Personal Data occurring within India where:
• Personal Data is collected in digital form; or
• Personal Data is collected in non-digital form and subsequently digitised.
Like the GDPR, the India DPDPA has extraterritorial reach, applying to the processing of digital Personal Data
outside India, when such processing is connected to any activity involving the offering of goods or services to
Data Principals (data subjects) in India.
Key Definitions
• Personal Data: Any data about an identifiable individual. Unlike, the GDPR or other data protection and
privacy regimes, the India DPDPA does not provide a heightened protection for any special or sensitive
categories of personal data.
• Data Fiduciaries: Entities deciding how and why data is processed. Significant data fiduciaries, a
category to be further defined by the Central Government through notification based on the volume and
risks associated with Personal Data processing, have extra obligations (appointment of a Data
Protection Officer in India, conducting Data Privacy Impact Assessments). Data Fiduciaries remain
responsible for the overall compliance with the Act.
• Data Processors: Entities like SAP that process data on behalf of fiduciaries under contract.
• Data Principals: Individuals with rights to notice, consent, access, correction, deletion, and grievance
redressal. Data Principals have the right to appoint a nominee to exercise their rights on their behalf, for
example, in the event of death or incapacity.
SAP’s Preparedness for DPDPA Compliance
SAP recognizes the importance of the DPDPA and assigns due attention to aligning our data protection practices
with its requirements. As the detailed implementing rules and timelines from the Government of India are finalized
and notified, we have proactively initiated several preparatory measures to ensure a smooth transition before the
compliance date approaches.
Our current readiness efforts include:
• Assessment of existing data protection frameworks against the key principles of the DPDPA.
• GAP analysis and framework assessment of our current practices against the requirements of the DPDPA.
• Appointment of a DPO.
• Training and awareness programs to strengthen our teams’ understanding of the DPDPA.
• Monitoring further regulatory updates to ensure timely compliance with the final rules.
• Established procedures for handling Data Subject Rights requests, including access, correction, deletion,
and objection, in alignment with global privacy regulations and contractual.
Customer DPDPA Frequently Asked Questions (FAQ)
SAP’s Data Processing Agreement (DPA ensures compliance with major data protection laws, including India’s
DPDPA, by embedding key privacy and security principles.
• Does SAP’s global Data Processing Agreement (DPA) help with DPDPA compliance?
Yes. SAP’s DPA includes provisions for breach notification, Data Principal rights, data deletion, subprocessor
compliance, and security measures—all aligned with DPDPA requirements. Please read the DPA FAQs here:
https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=d46da9fc-157f-0010-bca6-
c68f7e60039b&page=7.
• How does SAP support fulfilling Data Principal’s Rights under the DPDPA?
The SAP DPA includes provisions that enable Cloud Services to support customers in addressing Data
Principal rights. Upon request, SAP will also reasonably cooperate with customers in handling inquiries from
Data Principals or regulatory authorities regarding SAP’s processing of Personal Data or any Personal Data
Breach.
• Are there data localization requirements under the DPDPA?
No. The Act currently does not mandate local storage of personal data.
• How does SAP make sure to implement the necessary security measures as required by the
DPDPA?
Robust Security Measures for Cloud Services/Technical and Organiazational measures (TOMs) are
embedded in SAP’s Data Processing Agreements and designed to safeguard customer data against
unauthorized access, loss, or misuse.
To explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/3
SAP’s Data Processing Agreement (DPA ensures compliance with major data protection laws, including India’s
DPDPA, by embedding key privacy and security principles.
• Does SAP’s global Data Processing Agreement (DPA) help with DPDPA compliance?
Yes. SAP’s DPA includes provisions for breach notification, Data Principal rights, data deletion, subprocessor
compliance, and security measures—all aligned with DPDPA requirements. Please read the DPA FAQs here:
https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=d46da9fc-157f-0010-bca6-
c68f7e60039b&page=7.
• How does SAP support fulfilling Data Principal’s Rights under the DPDPA?
The SAP DPA includes provisions that enable Cloud Services to support customers in addressing Data
Principal rights. Upon request, SAP will also reasonably cooperate with customers in handling inquiries from
Data Principals or regulatory authorities regarding SAP’s processing of Personal Data or any Personal Data
Breach.
• Are there data localization requirements under the DPDPA?
No. The Act currently does not mandate local storage of personal data.
• How does SAP make sure to implement the necessary security measures as required by the
DPDPA?
Robust Security Measures for Cloud Services/Technical and Organiazational measures (TOMs) are
embedded in SAP’s Data Processing Agreements and designed to safeguard customer data against
unauthorized access, loss, or misuse.
To explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/3