Engineering hubs in Dehradun & Bengaluru · Delivering across 10 countries

nitesh@redcubical.com +91 90687 14658

REDCUBICALSYSTEMS

Effective 1 September 2026 · India DPDP Act 2023

DPDP Act 2023 compliance position

Redcubical Systems Private Limited is a Data Fiduciary for its own website, marketing, recruitment and supplier data, and a Data Processor for personal data inside client platforms we build or operate. This page explains the roles the Digital Personal Data Protection Act 2023 creates, the grounds we rely on, your rights as a Data Principal, and how to exercise them.

  • Written in plain terms rather than as a statutory restatement
  • Data Principal requests: nitesh@redcubical.com, acknowledged in 48 hours
  • Includes a DPDP against GDPR comparison on the points that matter
  • Grievance route and onward escalation to the Data Protection Board

Section 1

The Act, the roles it creates, and where we sit

What is the DPDP Act 2023?

The Digital Personal Data Protection Act 2023 is India’s general data protection law, enacted in August 2023. It applies to digital personal data processed in India, and to processing outside India where it relates to offering goods or services to people in India. It is consent-centred, materially shorter than the GDPR, and enforced by the Data Protection Board of India.

The Act does not cover personal data made publicly available by the person themselves or under a legal obligation, nor processing for purely personal or domestic purposes. It does not distinguish a special category of sensitive data, which surprises anyone arriving from the GDPR, and it places duties on Data Principals as well as on organisations.

Our engagement with it is practical rather than theoretical. We built HealHub, a clinical system holding Indian patient records, before the Act was passed, and we have had to bring a live product into line rather than design against the Act on a whiteboard. That experience is what informs the guidance below.

The Act at a glance

Statute
Digital Personal Data Protection Act, 2023 (Act 22 of 2023)
Enacted
August 2023
Regulator
Data Protection Board of India
Appeals
Telecom Disputes Settlement and Appellate Tribunal
Rules status
[Company to confirm before publication]
This page effective
1 September 2026, version 1.0
Our role, own data
Data Fiduciary
Our role, client data
Data Processor
SDF status
Not notified as a Significant Data Fiduciary
Grievance officer
Contact and escalation
Roles under the Act, and how they map to us
RoleWhat the Act means by itWhere we sit
Data PrincipalThe individual the personal data relates to. For a child, the parent or lawful guardian; for a person with disability, a lawful guardianYou, if you enquire, apply for a role, supply us, or use a client system we operate
Data FiduciaryThe person who alone or with others determines the purpose and means of processing. Carries the primary obligations of notice, consent, security, breach reporting and grievance redressalUs, for our website, marketing, recruitment, supplier and internal data
Data ProcessorA person who processes personal data on behalf of a Data Fiduciary, only under a valid contract with itUs, for personal data inside a client platform. The client instructs; we do not decide the purpose
Consent ManagerA platform registered with the Board through which a Data Principal can give, manage, review and withdraw consent, accountable to the Data PrincipalNot applicable. We do not act as a Consent Manager, and we do not currently integrate with one
Significant Data FiduciaryA Data Fiduciary or class notified by the Central Government by reference to volume and sensitivity of data, risk to Data Principal rights, State security and public order. Must appoint an India-based Data Protection Officer, an independent data auditor, and run periodic impact assessments and auditsNot applicable. We have not been notified. If notified, the additional duties would be published here

The distinction matters when you make a request. If your data sits inside a client platform, we are the Processor and we cannot decide the outcome. We will identify the Data Fiduciary, pass the request on within two business days, and support their response. If your data is ours, we answer it directly.

Section 2

Principles, lawful grounds and the notice we must give

The principles the Act works from

  • Lawfulness. Personal data may be processed only for a lawful purpose, with consent or under a specified legitimate use.
  • Purpose limitation. Use is confined to the purpose for which the data was given.
  • Data minimisation. Only the personal data necessary for that purpose.
  • Accuracy. Reasonable effort to keep data correct and complete, particularly where a decision affecting the person depends on it.
  • Storage limitation. Erase once the purpose is served and retention is no longer required by law.
  • Security. Reasonable security safeguards to prevent breach, and this duty sits with both Fiduciary and Processor in practice through contract.
  • Accountability. The Data Fiduciary remains responsible for compliance even where a Processor does the work.

Lawful grounds

There are two routes, and no equivalent of the GDPR legitimate-interests basis.

Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the stated purpose. It must be itemised rather than bundled, and requests must be available in English and the languages listed in the Eighth Schedule to the Constitution.

Certain legitimate uses permit processing without consent, including where the Data Principal voluntarily provided the data for that purpose, for employment purposes and safeguarding the employer from loss, for compliance with law or a court order, for a medical emergency or epidemic, and for specified State functions. The list is closed. We rely on the voluntary-provision and employment limbs, and nothing beyond them.

Section 3

Your rights as a Data Principal, and how to use them

Four rights, plus duties the Act places on you. The table gives the statutory basis, how to exercise each one here, and the time we take to respond.

How do I exercise a DPDP right?

Email nitesh@redcubical.com with "DPDP request" in the subject line, state which right you are exercising, and give us enough detail to find your records. We acknowledge within 48 hours and respond substantively within 30 days. There is no charge. Where we hold the data as a Processor for a client, we identify them and pass the request on within two business days.

Data Principal rights, mechanism and our response times
RightWhat you getHow to exercise itOur response time
Access to information (Section 11)A summary of the personal data we hold about you, the processing activities, and the identities of any other Data Fiduciaries and Processors it has been shared withEmail nitesh@redcubical.com, subject "DPDP request: access"Acknowledged in 48 hours, answered within 30 days
Correction and completion (Section 12)Correction of inaccurate or misleading data, completion of incomplete data, and updatingSame address, subject "DPDP request: correction", telling us the correct valueUsually within 7 days, 30 days at the outside
Erasure (Section 12)Deletion where the purpose is served or you withdraw consent, unless retention is required by lawSame address, subject "DPDP request: erasure"Within 30 days, with confirmation in writing
Grievance redressal (Section 13)A readily available means of raising a grievance with us, before approaching the BoardOur grievance officer, via the grievance officer page15 days for IT Rules grievances, 30 days for DPDP matters
Nomination (Section 14)Nominate another individual to exercise your rights on your behalf in the event of your death or incapacitySame address, subject "DPDP nomination", naming the person and their contact detailsRecorded and confirmed within 30 days
Withdraw consent (Section 6(4))Withdrawal as easy as giving consent, with no detriment and no explanation requiredUnsubscribe link, or one email to the same addressProcessing stops within 3 business days
Your duties (Section 15)Not to impersonate another person, suppress material information, file a frivolous complaint, or furnish false particulars. The Board may impose a penalty of up to INR 10,000 for breach of these dutiesNot applicable, but worth knowing before filingNot applicable

Where we cannot act on a request we tell you why and what your options are, including going to the Board. Identity verification is requested only where we genuinely cannot be confident who you are, because a verification step is also a data collection step. Requests made through a Consent Manager, once that ecosystem is operating, will be handled the same way.

Section 4

Safeguards, breach reporting and cross-border transfer

Reasonable security safeguards

Section 8(5) requires reasonable security safeguards to prevent a personal data breach. Our summary set:

  • AES-256 at rest, TLS 1.2 or better in transit, with keys held in a managed key service.
  • Named individual accounts, least privilege, hardware-backed multi-factor authentication on administrative access.
  • Time-bounded, approval-based, logged access to client production systems, granted per task rather than standing.
  • Background verification, individual confidentiality undertakings and annual security training for all staff.
  • Mandatory code review, dependency and secret scanning in the pipeline, centralised audit logging.
  • Backups with tested restores, and a documented incident response plan with a named owner.

The honest limit: we hold no ISO/IEC 27001 or SOC 2 certification and do not claim one. Controls are mapped to ISO 27001 Annex A. The penalty for failing to take reasonable safeguards runs to INR 250 crore, which concentrates attention rather better than a certificate does.

Section 5

DPDP Act against the GDPR, on the points that change your compliance work

Most of our clients already run a GDPR programme and want to know what is different rather than what is the same. This is that list.

DPDP Act 2023 compared with the UK and EU GDPR
PointDPDP Act 2023UK and EU GDPR
ScopeDigital personal data only. Paper records outside scope unless later digitisedPersonal data by any means, including structured paper filing systems
Sensitive dataNo special category. All personal data treated alikeArticle 9 special categories with additional conditions
Lawful basesConsent, or a closed list of specified legitimate uses. No legitimate-interests groundSix bases including legitimate interests and vital interests
TerminologyData Principal, Data Fiduciary, Data Processor, Consent ManagerData subject, controller, processor. No consent-manager concept
RightsAccess, correction, erasure, grievance redressal, nominationAccess, rectification, erasure, restriction, portability, objection, and rights around automated decisions
Portability and objectionNo portability right and no general right to objectBoth available, subject to conditions
Duties on the individualYes. Section 15 duties, with a penalty up to INR 10,000 for a frivolous complaintNone. The GDPR imposes no duties on data subjects
Cross-border transferPermitted except to countries restricted by government notification. Sectoral localisation rules still applyRestricted unless adequacy, safeguards such as SCCs, or a derogation applies
DPO requirementOnly for Significant Data Fiduciaries, and the DPO must be based in IndiaWhere Article 37 criteria are met, and the DPO may be located anywhere
Impact assessments and auditsOnly for Significant Data Fiduciaries, plus independent data auditsDPIA required wherever processing is high risk
Breach notificationNotify the Board and every affected Data Principal, in the prescribed form, without the GDPR risk thresholdNotify the authority within 72 hours where there is a risk, and individuals where the risk is high
Consent standardFree, specific, informed, unconditional, unambiguous, itemised, and available in the Eighth Schedule languagesFreely given, specific, informed, unambiguous. No language schedule
ChildrenVerifiable parental consent under 18. Tracking and targeted advertising to children prohibited outrightDigital-services consent age between 13 and 16 by member state, with a best-interests assessment
Regulator and appealsData Protection Board of India, appeal to the TDSATThe ICO or an EU or EEA supervisory authority, appeal through national courts
Maximum penaltiesUp to INR 250 crore for security failures, INR 200 crore for breach-reporting or children’s data failuresThe higher of 4 percent of worldwide annual turnover or 20 million euros, or 17.5 million pounds in the UK

The practical consequence for a GDPR-compliant organisation entering India is usually narrower than expected: your security, retention and breach machinery largely transfers, but your consent capture and your notice need rework, and any reliance on legitimate interests needs a new justification because that ground does not exist under the Act.

Answers

DPDP Act questions

Is Redcubical Systems a Data Fiduciary or a Data Processor under the DPDP Act?

Both, depending on the data. For our own website, marketing, recruitment and supplier data we are the Data Fiduciary and we determine the purpose. For personal data inside a client platform we build or operate, the client is the Data Fiduciary and we are the Data Processor acting only on their documented instructions under a written contract.

What rights do I have as a Data Principal?

Access to a summary of your personal data and our processing, correction and erasure, grievance redressal, and the ability to nominate someone to exercise your rights if you die or become incapacitated. Email nitesh@redcubical.com to use any of them. We acknowledge within 48 hours and respond within 30 days.

How does the DPDP Act differ from the GDPR?

The DPDP Act is shorter and consent-centred. It has no special category of sensitive data, no legitimate-interests ground, no data portability right, no general right to object, and no mandatory DPIA except for Significant Data Fiduciaries. It adds a nomination right and duties on Data Principals. Cross-border transfer is permitted by default except to countries the government restricts.

Do you transfer Indian personal data outside India?

Rarely, and only where the client instructs it. Section 16 of the Act permits transfer to any country other than those the Central Government restricts by notification, which is the reverse of the GDPR adequacy approach. Where a client hosts in London, Frankfurt, Bahrain or Mumbai, we follow the region their contract specifies and document it in the data processing agreement.

Are you a Significant Data Fiduciary?

No. Significant Data Fiduciary status applies only where the Central Government notifies a class of Data Fiduciary based on data volume, sensitivity, risk to electoral democracy, State security and similar factors. We have not been notified. If we were, we would appoint a Data Protection Officer based in India, commission an independent data auditor and run periodic impact assessments.

How do I escalate if I am not satisfied with your response?

Use our grievance officer first, described on the grievance officer page, because the Act generally requires you to exhaust the Data Fiduciary’s grievance mechanism before approaching the regulator. If that does not resolve it, you may complain to the Data Protection Board of India, whose decisions are appealable to the Telecom Disputes Settlement and Appellate Tribunal.

A DPDP request, or a compliance question from a client

Both go to nitesh@redcubical.com. Requests are acknowledged within 48 hours. Client compliance questions get an engineer’s answer rather than a policy extract, usually within three business days.