How to Write a DPDP-Compliant Data Protection Policy for Your Indian Company
The DPDP Act, 2023 turned 'we should have a privacy policy' into 'we must have a documented data protection framework'. Inspectors, investors, and customers are all asking the same question now: what exactly do you do with personal data, and how is it protected?
This guide walks through every section a DPDP-compliant data protection policy needs — with the clause-level substance, not fluff. You can adapt it directly for your company.
1. Purpose and Scope
Open the policy by stating who it covers and why it exists: the types of personal data the company processes (names, emails, phone numbers, addresses, employment data, transaction data, and any sensitive personal data), the legal basis (primarily consent under the DPDP Act), and the people it applies to (employees, customers, vendors, website users).
2. Consent and Notice Mechanism
The DPDP Act's cornerstone is consent. Your policy must define:
- How consent is captured (opt-in forms, checkboxes, digital records) — pre-ticked boxes are invalid
- What the privacy notice states (data collected, purpose, retention, rights) — in plain language, English and Hindi
- How consent withdrawal works and the timeline for data deletion after withdrawal
- How consent records are stored and made retrievable (audit trail with timestamps)
Consent is not a one-time checkbox — it must be demonstrable. Your CRM or signup flow should log consent events, versions of the notice shown, and withdrawal requests.
3. Purpose Limitation and Storage Limits
Data may only be processed for the purpose stated at collection. The policy must include:
- An approved purposes list (account creation, order fulfilment, payroll, support)
- Retention schedules per data category (e.g., financial records 8 years per tax law, customer data until account deletion)
- Automated deletion or anonymisation processes after retention expires
- A prohibition on repurposing data without fresh consent
4. Security Safeguards (The ₹250 Crore Section)
Failure to take reasonable security safeguards is the highest-penalty category under the DPDP Act — up to ₹250 crore. Your policy must document:
- Encryption at rest and in transit (256-bit AES; TLS 1.2+)
- Access controls: role-based access, least privilege, MFA for admins
- Logging and monitoring of access to personal data
- Vendor and subcontractor DPDP clauses in contracts
- Regular security testing and employee training
- Physical security for servers/offices holding personal data
If you store legal documents or client data, zero-knowledge encryption — where even the platform cannot read your files — is the strongest safeguard. The Lexacore Legal Vault uses exactly that architecture.
5. Breach Response Protocol
Your policy must define, in advance, what happens when a breach occurs:
- Who detects and who declares a breach (incident commander)
- Notification to the Data Protection Board — with the penalty for silence up to ₹200 crore, speed is everything
- Notification to affected Data Principals with breach details and remediation steps
- Documentation and post-incident review to prevent recurrence
6. Data Principal Rights
Under the DPDP Act, individuals have the right to: access their data, request correction, request erasure, withdraw consent, nominate a representative to exercise rights after their death, and seek grievance redressal. Your policy must assign owners and SLAs for each right — typically 30 days for responses.
7. Governance: DPO and Audits
Name the data protection officer (mandatory for Significant Data Fiduciaries, recommended for all), define the audit cadence (annual minimum), and record training. Attach the policy to employee onboarding and vendor agreements.
Your data protection policy is a living document. Update it when processing changes, when DPDP rules are notified, or after any incident. Pair it with ongoing monitoring — ComplianceRadar tracks DPDP developments in real time, and our full DPDP guide keeps the obligations current.
Next step: review your existing contracts for DPDP clauses with ContractIQ, or draft compliant data-processing schedules with LexCounsel AI. Try the demo first — no signup.