India’s Digital Personal Data Protection Act

A Preliminary Overview of Key Provisions, Scope, and Implications for Global Enterprises Download the Document

PUBLICIndia’s Digital Personal Data Protection ActKey Provisions, Scope and ImplicationsThe information contained in this document is for general informational purposes only and isprovided on the understanding that SAP is not engaged in rendering legal advice. SAP acceptsno liability for any actions taken in response to this resource. As such, it should not be used as asubstitute for legal or professional consultation.
On August 11, 2023, India published the Digital Personal Data Protection Act, 2023 (“IndiaDPDPA” or “Act”) in the Official Gazette, and the final rules of implementation were released on13th of November 2025. The Act is India’s first unified, comprehensive data protection law.ScopeThe India DPDPA applies to the processing of Digital Personal Data occurring within India where: Personal Data is collected in digital form; or Personal Data is collected in non-digital form and subsequently digitised.Like the GDPR, the India DPDPA has extraterritorial reach, applying to the processing of digital Personal Dataoutside India, when such processing is connected to any activity involving the offering of goods or services toData Principals (data subjects) in India.Key Definitions Personal Data: Any data about an identifiable individual. Unlike, the GDPR or other data protection andprivacy regimes, the India DPDPA does not provide a heightened protection for any special or sensitivecategories of personal data. Data Fiduciaries: Entities deciding how and why data is processed. Significant data fiduciaries, acategory to be further defined by the Central Government through notification based on the volume andrisks associated with Personal Data processing, have extra obligations (appointment of a DataProtection Officer in India, conducting Data Privacy Impact Assessments). Data Fiduciaries remainresponsible for the overall compliance with the Act. Data Processors: Entities like SAP that process data on behalf of fiduciaries under contract. Data Principals: Individuals with rights to notice, consent, access, correction, deletion, and grievanceredressal. Data Principals have the right to appoint a nominee to exercise their rights on their behalf, forexample, in the event of death or incapacity.SAP’s Preparedness for DPDPA ComplianceSAP recognizes the importance of the DPDPA and assigns due attention to aligning our data protection practiceswith its requirements. As the detailed implementing rules and timelines from the Government of India are finalizedand notified, we have proactively initiated several preparatory measures to ensure a smooth transition before thecompliance date approaches.Our current readiness efforts include: Assessment of existing data protection frameworks against the key principles of the DPDPA. GAP analysis and framework assessment of our current practices against the requirements of the DPDPA. Appointment of a DPO. Training and awareness programs to strengthen our teams’ understanding of the DPDPA. Monitoring further regulatory updates to ensure timely compliance with the final rules. Established procedures for handling Data Subject Rights requests, including access, correction, deletion,and objection, in alignment with global privacy regulations and contractual.
Customer DPDPA Frequently Asked Questions (FAQ)SAP’s Data Processing Agreement (DPA ensures compliance with major data protection laws, including India’sDPDPA, by embedding key privacy and security principles. Does SAP’s global Data Processing Agreement (DPA) help with DPDPA compliance?Yes. SAP’s DPA includes provisions for breach notification, Data Principal rights, data deletion, subprocessorcompliance, and security measuresall aligned with DPDPA requirements. Please read the DPA FAQs here:https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=d46da9fc-157f-0010-bca6-c68f7e60039b&page=7. How does SAP support fulfilling Data Principal’s Rights under the DPDPA?The SAP DPA includes provisions that enable Cloud Services to support customers in addressing DataPrincipal rights. Upon request, SAP will also reasonably cooperate with customers in handling inquiries fromData Principals or regulatory authorities regarding SAP’s processing of Personal Data or any Personal DataBreach. Are there data localization requirements under the DPDPA?No. The Act currently does not mandate local storage of personal data. How does SAP make sure to implement the necessary security measures as required by theDPDPA?Robust Security Measures for Cloud Services/Technical and Organiazational measures (TOMs) areembedded in SAP’s Data Processing Agreements and designed to safeguard customer data againstunauthorized access, loss, or misuse.To explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/3