HomeAnalyticsGuidesData Protection Compliance in India: Legal Framework and Obligations

Data Protection Compliance in India: Legal Framework and Obligations

A European technology company launching a consumer app in India discovers, weeks before go-live, that its existing GDPR-aligned privacy programme does not satisfy India's distinct data protection requirements. Consent mechanisms built for European users must be redesigned. Data transfer arrangements with overseas processors need fresh legal grounding. The clock is running, and the cost of delay – in regulatory exposure and lost market entry timing – is measurable.

Data protection compliance in India is governed primarily by digital personal data protection legislation that establishes obligations for data fiduciaries and data processors handling the personal data of individuals in India. The regime requires verifiable consent, specific privacy notices, and – for significant data fiduciaries – the appointment of a Data Protection Officer (DPO) and the conduct of periodic data protection impact assessments. Compliance timelines for a mid-sized international business typically range from eight to sixteen weeks for a baseline programme.

This guide walks through the procedural steps, documentary requirements, common errors by foreign businesses, cost considerations, and a decision checklist for matching your compliance approach to your specific business scenario in India.

India's data protection legal regime: the regulatory setting

India's data protection system has undergone significant change in recent years. The country's primary digital personal data protection legislation – passed after more than a decade of legislative development – establishes a consent-first model for processing personal data. It applies to any entity that processes personal data of individuals located in India, regardless of where that entity is established.

The regime introduces two core categories of actors. A data fiduciary – equivalent in function to a data controller under GDPR compliance frameworks – determines the purpose and means of processing. A data processor processes data on behalf of the fiduciary. Both carry distinct obligations, though the fiduciary bears primary accountability to the regulator.

The Data Protection Board of India (DPB) serves as the supervisory authority. It receives complaints, investigates breaches, and has authority to impose financial penalties. The Board operates independently and is empowered to act on complaints from data principals – the individuals whose data is processed.

India's data protection legislation interacts with several other regulatory bodies. The Securities and Exchange Board of India (SEBI) governs data handling obligations for listed entities and market intermediaries. The Reserve Bank of India (RBI) imposes data localisation requirements specifically for payment system data. Entities incorporated under Indian corporate legislation (the Companies Act 2013) also carry information governance obligations enforced through the corporate registry system. Foreign businesses must map all of these overlapping requirements before designing their compliance architecture.

A client accustomed to GDPR compliance structures will find similarities in India's consent-based approach. However, several differences carry practical consequence. India's regime does not recognise legitimate interests as a lawful basis for processing personal data. Consent is the primary – and for most private-sector processing, the only – valid ground. This has direct implications for how international businesses structure their data processing agreements and user-facing consent mechanisms.

For businesses operating at the intersection of data and artificial intelligence, India's emerging AI regulation adds a further layer of consideration. Our analysis of AI and technology law in India addresses how algorithmic processing of personal data sits within both the data protection and the AI regulatory systems.

Step-by-step compliance procedure: from assessment to ongoing obligations

The following steps reflect the sequence a foreign business should follow when building a data protection compliance programme for Indian operations. Each step carries specific documentary requirements and timing indicators.

Step 1 – Data mapping and scope assessment (weeks 1–2)

Begin by identifying all categories of personal data your business collects, processes, stores, or transfers in connection with Indian residents. This includes data collected through websites, mobile applications, customer service channels, HR systems for Indian employees, and third-party data received from processors or partners. The output is a data inventory that captures: data category, processing purpose, legal basis (almost always consent in India), storage location, retention period, and whether data is transferred outside India.

A non-obvious risk at this stage is the treatment of employee data. Many foreign businesses assume their standard employment data policies – drafted for home-jurisdiction compliance – extend automatically to Indian operations. Under Indian employment legislation and data protection rules, specific consent obligations apply to employee personal data. Failing to obtain valid consent from Indian employees at the point of onboarding is a common and consequential error.

Step 2 – Consent mechanism design and privacy notice drafting (weeks 2–4)

India's data protection legislation sets out specific requirements for a valid consent mechanism. Consent must be free, specific, informed, unconditional, and unambiguous. It must be obtained through a clear affirmative act. Pre-ticked boxes and bundled consents are not valid. Where processing involves children's data – defined by age thresholds in the legislation – verifiable parental consent is mandatory.

Privacy notices must be provided in plain language. The legislation explicitly requires that notices be made available in languages listed in the Indian constitution's eighth schedule, on request. International businesses that operate solely in English must build a multilingual notice capability into their compliance architecture from the outset, not as a retrofitted addition.

The consent mechanism must also include a straightforward withdrawal pathway. The technical and procedural ease of withdrawal must be at least equivalent to the ease of giving consent. Many businesses underestimate the user experience engineering required to meet this standard.

Step 3 – Data processing agreements and third-party governance (weeks 3–6)

Every data fiduciary that engages a data processor must enter into a written data processing agreement. This agreement must define the scope of processing, prohibit the processor from sub-processing without authorisation, and establish security obligations. The standard contractual templates used for GDPR compliance need material revision for Indian law – the legal bases, regulatory references, and supervisory authority details differ significantly.

Third-party governance also requires an audit of existing vendor contracts. A foreign company that has been sharing Indian user data with overseas analytics, marketing, or cloud-storage vendors under a GDPR data transfer arrangement must reassess that arrangement under Indian data transfer rules. India's legislation establishes a framework for cross-border data transfer – the government may notify certain jurisdictions as approved destinations, and transfers to non-notified jurisdictions require additional safeguards.

Step 4 – Significant data fiduciary assessment (weeks 4–6)

The government is empowered to designate certain entities as significant data fiduciaries (SDFs) based on volume of data processed. Sensitivity of that data, risk to data principals. Additionally, potential impact on national security or public order. SDFs face heightened obligations: mandatory DPO appointment, mandatory Data Protection Impact Assessments, and periodic audits by an independent data auditor.

An international business should conduct a self-assessment against SDF criteria at an early stage. The consequences of operating as an undesignated SDF – if the DPB later determines that designation was warranted – are substantial. Acting proactively to document the analysis reduces regulatory exposure. Engaging a data protection specialist in India to conduct this assessment is advisable for any business processing data at scale.

Step 5 – Breach response procedure and DPB notification protocol (weeks 5–8)

India's data protection legislation requires notification of personal data breaches to the Data Protection Board and, in specified circumstances, to affected data principals. The legislation does not specify a fixed notification window in the same manner as GDPR compliance frameworks, but rules issued under the legislation are expected to establish specific timelines. Businesses should design breach response procedures that can meet a 72-hour internal escalation standard, with a documented decision-making pathway for DPB notification.

A common error is treating breach notification as a standalone IT function. In practice, the DPB will assess not only the technical response but also the adequacy of the business's pre-existing security measures. Indian courts – in related contexts including proceedings before the National Company Law Tribunal (NCLT) and under the Arbitration and Conciliation Act in commercial disputes involving data obligations – have confirmed that documented security standards are material to liability assessments. Maintaining evidence of your security posture is as important as the breach notification itself.

Step 6 – Ongoing obligations: rights fulfilment and annual review (continuous)

Data principals in India hold rights to access information about their data, correct inaccurate data, erase data in defined circumstances, and nominate a representative for data-related decisions upon death or incapacity. Businesses must build operationally functional rights-fulfilment processes – not merely policy statements – before going live with Indian operations.

Annual review of the compliance programme is a governance minimum. Data inventories drift as products evolve. Consent mechanisms become outdated as processing purposes change. Vendor relationships change, introducing new processors. A documented annual review cycle, with evidence of corrective action, significantly strengthens a business's position in any DPB inquiry.

To receive a tailored assessment of your data protection compliance obligations in India, contact us at info@ferrazwhitmore.com.

Common errors by foreign businesses and how to avoid them

International businesses entering India with an existing GDPR compliance programme frequently make a set of characteristic errors. Understanding these errors before they occur is materially cheaper than remediation.

Treating GDPR compliance as sufficient. The most widespread assumption is that a business that complies with the GDPR compliance regime automatically satisfies Indian data protection requirements. This is incorrect in several important respects. The legal basis landscape differs fundamentally – legitimate interests, widely relied upon in European operations, is not available in India. Consent architecture must be rebuilt, not repurposed. Transfer mechanisms differ. Supervisory authority relationships differ. Businesses that copy their European data protection documentation into Indian templates without substantive revision are building a compliance programme on a flawed foundation.

Overlooking sector-specific RBI and SEBI requirements. A fintech company entering India may achieve compliance with general data protection legislation while remaining non-compliant with RBI payment data localisation rules. This require that certain categories of payment system data be stored exclusively within India. Similarly, a business raising capital or listing securities in India must account for SEBI's information governance requirements. Compliance with general data protection legislation does not discharge sector-specific obligations.

Underestimating the consent re-solicitation burden. A business that has been operating in India under a pre-legislation framework. relying on broad terms-of-service provisions rather than specific consent. faces a retroactive consent re-solicitation obligation for existing data. Re-engaging an existing user base to obtain compliant consent is operationally demanding and carries attrition risk. Many businesses underestimate both the timeline and the resource requirement for this exercise.

Neglecting the data localisation question for non-payment data. While RBI localisation rules specifically target payment data, India's digital personal data protection legislation preserves the government's power to restrict cross-border data transfers by notification. Businesses that assume free cross-border data flow – because no restriction has yet been notified for their data category – must monitor the regulatory position continuously. Building systems on the assumption of unrestricted transfer creates future migration costs if restrictions are later imposed.

Failing to document the DPO appointment process. For businesses that may qualify as significant data fiduciaries, the DPO appointment is not merely an administrative step. The DPO must be based in India, must have sufficient seniority and independence, and must have a documented reporting line to senior management. International businesses that appoint a European or Singapore-based privacy officer as their nominal Indian DPO – without ensuring that person meets the India-specific criteria – create a gap between formal compliance and operational reality.

For businesses operating across multiple jurisdictions, comparing approaches is instructive. Our guide to data protection compliance in the UAE illustrates how a different high-growth jurisdiction addresses consent, transfer, and supervisory authority obligations – a useful reference for businesses managing multi-market programmes.

Decision checklist: matching your compliance approach to your business scenario

The appropriate compliance architecture depends on the nature and scale of your Indian operations. Use the following framework to identify which obligations apply and which steps are most time-critical for your situation.

Scenario A – Foreign company with no Indian legal entity, collecting data from Indian users online

India's data protection legislation applies to you. You process personal data of individuals in India, triggering fiduciary obligations regardless of your place of incorporation. Priority actions: design a compliant consent mechanism before launch, draft an India-specific privacy notice, review data transfer arrangements, and assess whether your data volumes approach SDF thresholds.

Scenario B – Foreign company establishing an Indian subsidiary under corporate legislation (Companies Act 2013)

Your subsidiary is a data fiduciary in its own right. Employee data consent, customer data processing agreements, and the interaction with NCLT governance requirements for corporate records all require attention. Timeline for baseline compliance before operational launch: ten to fourteen weeks. Key risk: assuming the parent company's group privacy policy extends automatically to the Indian subsidiary without local adaptation.

Scenario C – Financial services or fintech business subject to RBI oversight

You carry both the general data protection obligations and the specific RBI data localisation requirements. These must be addressed as a combined programme. Treating them sequentially – completing data protection compliance first, then addressing RBI requirements – creates rework. A single data architecture review that accounts for both regimes from the outset is more efficient and reduces the risk of building systems that require structural modification.

Scenario D – Listed entity or entity with Indian capital market exposure subject to SEBI

SEBI's information governance and cybersecurity requirements layer on top of the general data protection regime. Material non-public information handling, insider trading controls, and data security standards prescribed by SEBI all interact with the data protection compliance programme. A unified governance approach – rather than separate compliance silos – is strongly advisable.

Before initiating your India compliance programme, verify:

  • Whether your data processing involves personal data of individuals located in India (scope trigger)
  • Whether you process children's personal data, triggering additional consent obligations
  • Whether your data volumes, data sensitivity, or business sector bring you within SDF criteria
  • Whether you transfer personal data outside India, and whether target jurisdictions are approved destinations
  • Whether sector-specific rules from RBI, SEBI, or other regulators apply alongside general data protection legislation

For a preliminary review of your compliance position in India, email info@ferrazwhitmore.com.

Frequently asked questions

Q: Does the Digital Personal Data Protection Act apply to foreign companies processing Indian citizens' data?

A: Yes. India's digital personal data protection legislation applies to any entity that processes the personal data of Indian residents, regardless of where that entity is incorporated or headquartered. A foreign company collecting data from Indian users through an app, website, or service falls within scope. Legal advice from a lawyer in India familiar with cross-border data flows is essential before market entry.

Q: How long does it take to implement a data protection compliance programme in India?

A: A baseline compliance programme – covering consent mechanisms, privacy notices, data processing agreements, and internal policies – typically takes between eight and sixteen weeks for a mid-sized international business. Timeline depends heavily on the volume and sensitivity of data processed, the number of third-party processors involved, and whether cross-border data transfer restrictions apply to the company's operations.

Q: Is a Data Protection Officer mandatory for all businesses operating in India?

A: India's data protection legislation requires significant data fiduciaries – a category defined by factors such as volume of data processed, sensitivity, and potential societal impact – to appoint a Data Protection Officer. Not every business in India meets this threshold. However, many international companies voluntarily appoint a DPO or equivalent contact person as a governance best practice, even before a formal obligation arises. Engaging a law firm in India with experience in this area helps businesses assess their designation risk accurately.

About Ferraz & Whitmore

Ferraz & Whitmore is an international law firm based in Lisbon, advising business clients across 46 jurisdictions. Our team combines Portuguese civil law expertise with English common law tradition to deliver cross-border legal solutions in data protection compliance, privacy programme design, and regulatory advisory. Our data protection practice supports international businesses entering India with end-to-end compliance architecture – from consent mechanism design and data processing agreements through to significant data fiduciary assessments and breach response protocols. The firm's Asia-Pacific and Middle East practice includes practitioners with experience across Indian regulatory systems, including interactions with sector-specific bodies such as SEBI and RBI. As an international law firm advising clients in India, we work with technology companies, financial services groups, and multinational corporations that need a single point of coordination across multiple legal systems. To discuss your data protection compliance requirements in India, contact us at info@ferrazwhitmore.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Ferraz & Whitmore assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@ferrazwhitmore.com.