Effective 1 September 2026 · India DPDP Act 2023
DPDP Act 2023 compliance position
Redcubical Systems Private Limited is a Data Fiduciary for its own website, marketing, recruitment and supplier data, and a Data Processor for personal data inside client platforms we build or operate. This page explains the roles the Digital Personal Data Protection Act 2023 creates, the grounds we rely on, your rights as a Data Principal, and how to exercise them.
- Written in plain terms rather than as a statutory restatement
- Data Principal requests: nitesh@redcubical.com, acknowledged in 48 hours
- Includes a DPDP against GDPR comparison on the points that matter
- Grievance route and onward escalation to the Data Protection Board
Section 1
The Act, the roles it creates, and where we sit
What is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 is India’s general data protection law, enacted in August 2023. It applies to digital personal data processed in India, and to processing outside India where it relates to offering goods or services to people in India. It is consent-centred, materially shorter than the GDPR, and enforced by the Data Protection Board of India.
The Act does not cover personal data made publicly available by the person themselves or under a legal obligation, nor processing for purely personal or domestic purposes. It does not distinguish a special category of sensitive data, which surprises anyone arriving from the GDPR, and it places duties on Data Principals as well as on organisations.
Our engagement with it is practical rather than theoretical. We built HealHub, a clinical system holding Indian patient records, before the Act was passed, and we have had to bring a live product into line rather than design against the Act on a whiteboard. That experience is what informs the guidance below.
The Act at a glance
- Statute
- Digital Personal Data Protection Act, 2023 (Act 22 of 2023)
- Enacted
- August 2023
- Regulator
- Data Protection Board of India
- Appeals
- Telecom Disputes Settlement and Appellate Tribunal
- Rules status
- [Company to confirm before publication]
- This page effective
- 1 September 2026, version 1.0
- Our role, own data
- Data Fiduciary
- Our role, client data
- Data Processor
- SDF status
- Not notified as a Significant Data Fiduciary
- Requests
- nitesh@redcubical.com
- Grievance officer
- Contact and escalation
| Role | What the Act means by it | Where we sit |
|---|---|---|
| Data Principal | The individual the personal data relates to. For a child, the parent or lawful guardian; for a person with disability, a lawful guardian | You, if you enquire, apply for a role, supply us, or use a client system we operate |
| Data Fiduciary | The person who alone or with others determines the purpose and means of processing. Carries the primary obligations of notice, consent, security, breach reporting and grievance redressal | Us, for our website, marketing, recruitment, supplier and internal data |
| Data Processor | A person who processes personal data on behalf of a Data Fiduciary, only under a valid contract with it | Us, for personal data inside a client platform. The client instructs; we do not decide the purpose |
| Consent Manager | A platform registered with the Board through which a Data Principal can give, manage, review and withdraw consent, accountable to the Data Principal | Not applicable. We do not act as a Consent Manager, and we do not currently integrate with one |
| Significant Data Fiduciary | A Data Fiduciary or class notified by the Central Government by reference to volume and sensitivity of data, risk to Data Principal rights, State security and public order. Must appoint an India-based Data Protection Officer, an independent data auditor, and run periodic impact assessments and audits | Not applicable. We have not been notified. If notified, the additional duties would be published here |
The distinction matters when you make a request. If your data sits inside a client platform, we are the Processor and we cannot decide the outcome. We will identify the Data Fiduciary, pass the request on within two business days, and support their response. If your data is ours, we answer it directly.
Section 2
Principles, lawful grounds and the notice we must give
The principles the Act works from
- Lawfulness. Personal data may be processed only for a lawful purpose, with consent or under a specified legitimate use.
- Purpose limitation. Use is confined to the purpose for which the data was given.
- Data minimisation. Only the personal data necessary for that purpose.
- Accuracy. Reasonable effort to keep data correct and complete, particularly where a decision affecting the person depends on it.
- Storage limitation. Erase once the purpose is served and retention is no longer required by law.
- Security. Reasonable security safeguards to prevent breach, and this duty sits with both Fiduciary and Processor in practice through contract.
- Accountability. The Data Fiduciary remains responsible for compliance even where a Processor does the work.
Lawful grounds
There are two routes, and no equivalent of the GDPR legitimate-interests basis.
Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the stated purpose. It must be itemised rather than bundled, and requests must be available in English and the languages listed in the Eighth Schedule to the Constitution.
Certain legitimate uses permit processing without consent, including where the Data Principal voluntarily provided the data for that purpose, for employment purposes and safeguarding the employer from loss, for compliance with law or a court order, for a medical emergency or epidemic, and for specified State functions. The list is closed. We rely on the voluntary-provision and employment limbs, and nothing beyond them.
Section 3
Your rights as a Data Principal, and how to use them
Four rights, plus duties the Act places on you. The table gives the statutory basis, how to exercise each one here, and the time we take to respond.
How do I exercise a DPDP right?
Email nitesh@redcubical.com with "DPDP request" in the subject line, state which right you are exercising, and give us enough detail to find your records. We acknowledge within 48 hours and respond substantively within 30 days. There is no charge. Where we hold the data as a Processor for a client, we identify them and pass the request on within two business days.
| Right | What you get | How to exercise it | Our response time |
|---|---|---|---|
| Access to information (Section 11) | A summary of the personal data we hold about you, the processing activities, and the identities of any other Data Fiduciaries and Processors it has been shared with | Email nitesh@redcubical.com, subject "DPDP request: access" | Acknowledged in 48 hours, answered within 30 days |
| Correction and completion (Section 12) | Correction of inaccurate or misleading data, completion of incomplete data, and updating | Same address, subject "DPDP request: correction", telling us the correct value | Usually within 7 days, 30 days at the outside |
| Erasure (Section 12) | Deletion where the purpose is served or you withdraw consent, unless retention is required by law | Same address, subject "DPDP request: erasure" | Within 30 days, with confirmation in writing |
| Grievance redressal (Section 13) | A readily available means of raising a grievance with us, before approaching the Board | Our grievance officer, via the grievance officer page | 15 days for IT Rules grievances, 30 days for DPDP matters |
| Nomination (Section 14) | Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity | Same address, subject "DPDP nomination", naming the person and their contact details | Recorded and confirmed within 30 days |
| Withdraw consent (Section 6(4)) | Withdrawal as easy as giving consent, with no detriment and no explanation required | Unsubscribe link, or one email to the same address | Processing stops within 3 business days |
| Your duties (Section 15) | Not to impersonate another person, suppress material information, file a frivolous complaint, or furnish false particulars. The Board may impose a penalty of up to INR 10,000 for breach of these duties | Not applicable, but worth knowing before filing | Not applicable |
Where we cannot act on a request we tell you why and what your options are, including going to the Board. Identity verification is requested only where we genuinely cannot be confident who you are, because a verification step is also a data collection step. Requests made through a Consent Manager, once that ecosystem is operating, will be handled the same way.
Section 4
Safeguards, breach reporting and cross-border transfer
Reasonable security safeguards
Section 8(5) requires reasonable security safeguards to prevent a personal data breach. Our summary set:
- AES-256 at rest, TLS 1.2 or better in transit, with keys held in a managed key service.
- Named individual accounts, least privilege, hardware-backed multi-factor authentication on administrative access.
- Time-bounded, approval-based, logged access to client production systems, granted per task rather than standing.
- Background verification, individual confidentiality undertakings and annual security training for all staff.
- Mandatory code review, dependency and secret scanning in the pipeline, centralised audit logging.
- Backups with tested restores, and a documented incident response plan with a named owner.
The honest limit: we hold no ISO/IEC 27001 or SOC 2 certification and do not claim one. Controls are mapped to ISO 27001 Annex A. The penalty for failing to take reasonable safeguards runs to INR 250 crore, which concentrates attention rather better than a certificate does.
Section 5
DPDP Act against the GDPR, on the points that change your compliance work
Most of our clients already run a GDPR programme and want to know what is different rather than what is the same. This is that list.
| Point | DPDP Act 2023 | UK and EU GDPR |
|---|---|---|
| Scope | Digital personal data only. Paper records outside scope unless later digitised | Personal data by any means, including structured paper filing systems |
| Sensitive data | No special category. All personal data treated alike | Article 9 special categories with additional conditions |
| Lawful bases | Consent, or a closed list of specified legitimate uses. No legitimate-interests ground | Six bases including legitimate interests and vital interests |
| Terminology | Data Principal, Data Fiduciary, Data Processor, Consent Manager | Data subject, controller, processor. No consent-manager concept |
| Rights | Access, correction, erasure, grievance redressal, nomination | Access, rectification, erasure, restriction, portability, objection, and rights around automated decisions |
| Portability and objection | No portability right and no general right to object | Both available, subject to conditions |
| Duties on the individual | Yes. Section 15 duties, with a penalty up to INR 10,000 for a frivolous complaint | None. The GDPR imposes no duties on data subjects |
| Cross-border transfer | Permitted except to countries restricted by government notification. Sectoral localisation rules still apply | Restricted unless adequacy, safeguards such as SCCs, or a derogation applies |
| DPO requirement | Only for Significant Data Fiduciaries, and the DPO must be based in India | Where Article 37 criteria are met, and the DPO may be located anywhere |
| Impact assessments and audits | Only for Significant Data Fiduciaries, plus independent data audits | DPIA required wherever processing is high risk |
| Breach notification | Notify the Board and every affected Data Principal, in the prescribed form, without the GDPR risk threshold | Notify the authority within 72 hours where there is a risk, and individuals where the risk is high |
| Consent standard | Free, specific, informed, unconditional, unambiguous, itemised, and available in the Eighth Schedule languages | Freely given, specific, informed, unambiguous. No language schedule |
| Children | Verifiable parental consent under 18. Tracking and targeted advertising to children prohibited outright | Digital-services consent age between 13 and 16 by member state, with a best-interests assessment |
| Regulator and appeals | Data Protection Board of India, appeal to the TDSAT | The ICO or an EU or EEA supervisory authority, appeal through national courts |
| Maximum penalties | Up to INR 250 crore for security failures, INR 200 crore for breach-reporting or children’s data failures | The higher of 4 percent of worldwide annual turnover or 20 million euros, or 17.5 million pounds in the UK |
The practical consequence for a GDPR-compliant organisation entering India is usually narrower than expected: your security, retention and breach machinery largely transfers, but your consent capture and your notice need rework, and any reliance on legitimate interests needs a new justification because that ground does not exist under the Act.
Answers
DPDP Act questions
Is Redcubical Systems a Data Fiduciary or a Data Processor under the DPDP Act?
Both, depending on the data. For our own website, marketing, recruitment and supplier data we are the Data Fiduciary and we determine the purpose. For personal data inside a client platform we build or operate, the client is the Data Fiduciary and we are the Data Processor acting only on their documented instructions under a written contract.
What rights do I have as a Data Principal?
Access to a summary of your personal data and our processing, correction and erasure, grievance redressal, and the ability to nominate someone to exercise your rights if you die or become incapacitated. Email nitesh@redcubical.com to use any of them. We acknowledge within 48 hours and respond within 30 days.
How does the DPDP Act differ from the GDPR?
The DPDP Act is shorter and consent-centred. It has no special category of sensitive data, no legitimate-interests ground, no data portability right, no general right to object, and no mandatory DPIA except for Significant Data Fiduciaries. It adds a nomination right and duties on Data Principals. Cross-border transfer is permitted by default except to countries the government restricts.
Do you transfer Indian personal data outside India?
Rarely, and only where the client instructs it. Section 16 of the Act permits transfer to any country other than those the Central Government restricts by notification, which is the reverse of the GDPR adequacy approach. Where a client hosts in London, Frankfurt, Bahrain or Mumbai, we follow the region their contract specifies and document it in the data processing agreement.
Are you a Significant Data Fiduciary?
No. Significant Data Fiduciary status applies only where the Central Government notifies a class of Data Fiduciary based on data volume, sensitivity, risk to electoral democracy, State security and similar factors. We have not been notified. If we were, we would appoint a Data Protection Officer based in India, commission an independent data auditor and run periodic impact assessments.
How do I escalate if I am not satisfied with your response?
Use our grievance officer first, described on the grievance officer page, because the Act generally requires you to exhaust the Data Fiduciary’s grievance mechanism before approaching the regulator. If that does not resolve it, you may complain to the Data Protection Board of India, whose decisions are appealable to the Telecom Disputes Settlement and Appellate Tribunal.
A DPDP request, or a compliance question from a client
Both go to nitesh@redcubical.com. Requests are acknowledged within 48 hours. Client compliance questions get an engineer’s answer rather than a policy extract, usually within three business days.