DPDP Act 2023: What Fintechs and SaaS Companies Must Do Now
India's Digital Personal Data Protection Act 2023 has specific obligations for fintechs and SaaS companies. Here's what you need to implement — and what the penalties are for non-compliance.
What Is the DPDP Act?
The Digital Personal Data Protection Act 2023 is India's comprehensive data protection legislation. It was enacted by Parliament and received Presidential assent in August 2023. The Act establishes the rights of individuals (Data Principals) regarding their personal data and the obligations of organisations that collect and process it (Data Fiduciaries and Data Processors). The Act applies to processing of digital personal data within India, and also to processing outside India where the personal data of Indian residents is involved.
Data Fiduciary vs Data Processor: What Are You?
This distinction is critical and often confused:
- Data Fiduciary: Any entity that alone or in conjunction with others determines the purpose and means of processing personal data. If you decide what data to collect, why to collect it, and what to do with it — you are a Data Fiduciary. Most fintechs with direct customer relationships are Data Fiduciaries.
- Data Processor: An entity that processes personal data on behalf of a Data Fiduciary. SaaS companies that process data for their clients (the Data Fiduciaries) are typically Data Processors. Data Processors have fewer direct obligations under the Act but must operate under a contract with the Data Fiduciary that protects the data.
- Significant Data Fiduciary (SDF): DPDP Act introduces SDFs — fiduciaries that process large volumes of sensitive data or data with national security implications. SDFs face enhanced obligations including mandatory Data Protection Officers and data protection impact assessments.
Consent Management Requirements
The DPDP Act is built around informed, freely given, specific, and unambiguous consent. For fintechs, this is operationally significant:
- Consent must be obtained before processing personal data (except for certain specified legitimate uses)
- Consent must be granular — bundled consents for unrelated purposes are not compliant
- Data Principals must be able to withdraw consent as easily as they gave it
- A consent artefact must be maintained showing what consent was given, when, and for what purpose
- If consent is withdrawn, the Data Fiduciary must stop processing and delete the data (unless another legal basis exists)
Purpose Limitation and Data Minimisation
Two core DPDP principles that fintechs frequently underestimate:
- Purpose limitation: Data collected for one purpose cannot be used for another without fresh consent. If you collect KYC data for loan applications, you cannot use it for marketing a new insurance product without a separate consent.
- Data minimisation: Collect only the data that is necessary for the stated purpose. Broad data collection "just in case it's useful later" is not compliant.
Children's Data Rules for Fintechs
The DPDP Act has strict provisions for processing data of children (under 18). Before processing a child's data, a Data Fiduciary must obtain verifiable parental consent. Fintechs with consumer-facing apps must implement age verification. Behavioural monitoring and targeted advertising to children is prohibited. This is a practical challenge for fintechs — particularly those with general consumer apps that minors might access.
Cross-Border Data Transfer Restrictions
Rule 15 permits personal data to be transferred outside India, subject to the Data Fiduciary meeting any requirements the Central Government specifies by general or special order in respect of making that data available to a foreign State, or to a person or entity under the control of or an agency of such a State. Separately, Rule 13(4) requires a Significant Data Fiduciary to ensure that personal data specified by the Central Government — on the recommendations of a committee it constitutes — is not transferred outside India, along with the traffic data pertaining to its flow. Transfers remain possible, but the constraints now sit in the Rules rather than in expectation.
Security Safeguards Required
The DPDP Act requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. While the Act does not prescribe specific controls, aligning with ISO 27001 is widely accepted as demonstrating reasonable safeguards. Practically, this means:
- Encryption of personal data at rest and in transit
- Access controls limiting who can access personal data
- Regular security testing (VAPT)
- Incident response procedures for data breaches
- Data retention and deletion policies with enforcement mechanisms
Data Breach Notification Timeline
Rule 7 of the DPDP Rules 2025 now sets this out, and it is a two-stage obligation rather than the single 72-hour deadline most summaries describe. On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay, and separately intimate the Data Protection Board without delay with a description of the breach. It must then give the Board detailed information within seventy-two hours of becoming aware, or within a longer period if the Board allows on a written request. Both clocks start on awareness, not on completing the investigation, so the response procedure has to exist beforehand. Full breakdown of Rule 7 here.
Penalties: What Is at Stake?
The DPDP Act prescribes significant financial penalties for non-compliance, enforced by the Data Protection Board:
- Up to ₹250 crore — failure to take reasonable security safeguards to prevent a personal data breach, under section 8(5)
- Up to ₹200 crore — failure to give the Board or affected Data Principals notice of a personal data breach, under section 8(6)
- Up to ₹200 crore — breach of the additional obligations in relation to children, under section 9
- Up to ₹150 crore — breach of the additional obligations of a Significant Data Fiduciary, under section 10
- Up to ₹50 crore — breach of any other provision of the Act or the rules made under it
- Up to ₹10,000 — breach of the duties of a Data Principal under section 15
The DPDP Act is not the GDPR. It is India's own framework, designed for Indian realities. Importing GDPR compliance frameworks wholesale may leave significant gaps — particularly around consent architecture, data localisation, and the role of the Data Protection Board.
Infosek Team
What Fintechs Must Do Now
- Consent framework: Audit all consent collection touchpoints — app sign-up, KYC, marketing — and redesign them for DPDP compliance
- Privacy notice: Update your privacy policy to meet DPDP requirements (clear, simple, accessible)
- Data inventory: Map all personal data you collect, process, store, and share. You cannot protect what you have not inventoried.
- Vendor agreements: Update all data processing agreements with third parties (payment processors, cloud providers, LSPs) to include DPDP-compliant clauses
- Breach SOP: Build and test a personal data breach response procedure, including notification to the Data Protection Board
- Children's data: If your platform might be accessed by under-18s, implement age verification and parental consent mechanisms
- Data minimisation audit: Review current data collection practices and eliminate fields that cannot be justified by a specific processing purpose
Common questions
What must fintechs do to comply with the DPDP Act?
Build a lawful basis for each processing activity, give a notice that meets Rule 3, implement the minimum security safeguards in Rule 6 including access control and logging retained for one year, erase personal data once the specified purpose is no longer served under Rule 8, and be able to handle Data Principal rights requests under Rule 14.
What are the penalties under the DPDP Act?
The Schedule to the Act sets maximums of up to 250 crore rupees for failing to take reasonable security safeguards, up to 200 crore for failing to notify a personal data breach, up to 200 crore for breaching the obligations relating to children, and up to 150 crore for breaching the additional obligations of a Significant Data Fiduciary.
Get your DPDP readiness assessment today.
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment