Infosek
INFOSEK

DPDP Act 2023: What Fintechs and SaaS Companies Must Do Now

India's Digital Personal Data Protection Act 2023 has specific obligations for fintechs and SaaS companies. Here's what you need to implement — and what the penalties are for non-compliance.

DPDP Act 2023: What Fintechs and SaaS Companies Must Do Now

What Is the DPDP Act?

The Digital Personal Data Protection Act 2023 is India's comprehensive data protection legislation. It was enacted by Parliament and received Presidential assent in August 2023. The Act establishes the rights of individuals (Data Principals) regarding their personal data and the obligations of organisations that collect and process it (Data Fiduciaries and Data Processors). The Act applies to processing of digital personal data within India, and also to processing outside India where the personal data of Indian residents is involved.

Data Fiduciary vs Data Processor: What Are You?

This distinction is critical and often confused:

Consent Management Requirements

The DPDP Act is built around informed, freely given, specific, and unambiguous consent. For fintechs, this is operationally significant:

Purpose Limitation and Data Minimisation

Two core DPDP principles that fintechs frequently underestimate:

Children's Data Rules for Fintechs

The DPDP Act has strict provisions for processing data of children (under 18). Before processing a child's data, a Data Fiduciary must obtain verifiable parental consent. Fintechs with consumer-facing apps must implement age verification. Behavioural monitoring and targeted advertising to children is prohibited. This is a practical challenge for fintechs — particularly those with general consumer apps that minors might access.

Cross-Border Data Transfer Restrictions

Rule 15 permits personal data to be transferred outside India, subject to the Data Fiduciary meeting any requirements the Central Government specifies by general or special order in respect of making that data available to a foreign State, or to a person or entity under the control of or an agency of such a State. Separately, Rule 13(4) requires a Significant Data Fiduciary to ensure that personal data specified by the Central Government — on the recommendations of a committee it constitutes — is not transferred outside India, along with the traffic data pertaining to its flow. Transfers remain possible, but the constraints now sit in the Rules rather than in expectation.

Security Safeguards Required

The DPDP Act requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. While the Act does not prescribe specific controls, aligning with ISO 27001 is widely accepted as demonstrating reasonable safeguards. Practically, this means:

Data Breach Notification Timeline

Rule 7 of the DPDP Rules 2025 now sets this out, and it is a two-stage obligation rather than the single 72-hour deadline most summaries describe. On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay, and separately intimate the Data Protection Board without delay with a description of the breach. It must then give the Board detailed information within seventy-two hours of becoming aware, or within a longer period if the Board allows on a written request. Both clocks start on awareness, not on completing the investigation, so the response procedure has to exist beforehand. Full breakdown of Rule 7 here.

Penalties: What Is at Stake?

The DPDP Act prescribes significant financial penalties for non-compliance, enforced by the Data Protection Board:

The DPDP Act is not the GDPR. It is India's own framework, designed for Indian realities. Importing GDPR compliance frameworks wholesale may leave significant gaps — particularly around consent architecture, data localisation, and the role of the Data Protection Board.

Infosek Team

What Fintechs Must Do Now

Common questions

What must fintechs do to comply with the DPDP Act?

Build a lawful basis for each processing activity, give a notice that meets Rule 3, implement the minimum security safeguards in Rule 6 including access control and logging retained for one year, erase personal data once the specified purpose is no longer served under Rule 8, and be able to handle Data Principal rights requests under Rule 14.

What are the penalties under the DPDP Act?

The Schedule to the Act sets maximums of up to 250 crore rupees for failing to take reasonable security safeguards, up to 200 crore for failing to notify a personal data breach, up to 200 crore for breaching the obligations relating to children, and up to 150 crore for breaching the additional obligations of a Significant Data Fiduciary.

Topics DPDP Act

Get your DPDP readiness assessment today.

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment