Delta Filings
Governance Intelligence
Get Started
Compliance 10 min read · 2026-05-24

The DPDP Act for the Company Secretary: What the New Data Privacy Regime Means for Your Compliance Calendar

By Delta Filings · The Governance Desk

Data privacy and personal information protection

The Digital Personal Data Protection Act, 2023 is now the operating data privacy law for India, with rules notified through 2025 and the enforcement framework activated in stages. The most-common reaction in CS teams has been to mark it as “an IT problem” and move on. That is a category error. The Act's compliance architecture — Data Protection Officer appointment, consent management, breach notification, board reporting, vendor data processing agreements — sits squarely on the CS desk in any company without a dedicated chief privacy officer. This article is the CS-led playbook for 2026.

The Act in one paragraph

The DPDP Act applies to processing of digital personal data within India and to processing outside India where the entity offers goods or services to data principals in India. Data Fiduciaries (the entities) must obtain consent for processing, provide notices, honour rights of data principals (correction, erasure, grievance redressal), implement reasonable security safeguards, notify breaches to the Data Protection Board, and appoint a DPO if classified as a Significant Data Fiduciary. The Board has been constituted and is moving toward enforcement.

Where the CS fits

The CS is not the engineer building the consent platform. The CS is the architect of the corporate-governance overlay on top of the engineering. Specifically:

  • Board awareness and reporting. Quarterly or half-yearly board review of privacy posture — incidents, audits, regulatory engagements.
  • DPO appointment (for SDFs) — the CS often becomes the DPO or oversees the appointment.
  • Vendor management. Every data processor needs a Data Processing Agreement. The CS owns the standard template and the population.
  • Breach notification SOP. The Act prescribes notification to the Data Protection Board and (where applicable) to affected data principals. The breach SOP must be CS-owned, not buried in IT.
  • Disclosure layer. Privacy posture is becoming part of investor materials, ESG ratings, and BRSR Core. CS + IR coordination.

What changed when the 2025 rules dropped

  • Notice and consent architecture — specific format requirements, multilingual obligations.
  • Breach notification timelines — operationally defined.
  • SDF classification criteria — turnover, volume of personal data processed, sensitivity, risk to data principals.
  • Consent Manager registration and operations — the consent management framework moved from concept to operational.
  • Children's data — verifiable parental consent regime.
  • Cross-border transfer — negative list approach. Specific jurisdictions blocked; others permitted unless restricted.

The CS playbook for 2026

Quarter 1 — Diagnose

  1. Data mapping. What personal data does the company hold, where, for how long, on what legal basis.
  2. Vendor map. Who processes data on the company's behalf? Each one needs a DPA.
  3. Consent inventory. Where consent is being relied on, is it valid under the Act (free, specific, informed, unambiguous, demonstrable withdrawal)?
  4. SDF assessment. Is the company likely to be designated? Plan for it.

Quarter 2 — Architect

  1. Privacy policy refresh — DPDP-compliant notice format.
  2. Consent management platform — internal build or third-party.
  3. Grievance officer designation and process.
  4. DPA template approved by board / general counsel.
  5. Breach response SOP, with simulations.

Quarter 3 — Operate

  1. DPO appointment if classified as SDF.
  2. Vendor DPA rollouts — start with the top 20 by data volume.
  3. Employee training programs.
  4. First board-level privacy report.

Quarter 4 — Refine

  1. Annual privacy audit — internal or external.
  2. Periodic DPIA (Data Protection Impact Assessment) — at least for high-risk processing.
  3. Board's report disclosure preparation — privacy posture summary.

The penalties — and why they get the CFO's attention

  • Up to ₹250 crore for non-implementation of reasonable security safeguards leading to a breach.
  • Up to ₹200 crore for non-notification of breach.
  • Up to ₹150 crore for not complying with children-related obligations.
  • Up to ₹50 crore for non-compliance with notice requirements.

These are per-instance penalties. Aggregate exposure for a major breach can dwarf SEBI penalties.

The DPDP / Reg 30 overlap

A major cyber security breach is a Schedule III Part A event for listed entities — separate Reg 30 disclosure obligation, separate timeline. The 30-minute / 12-hour Reg 30 clock and the DPDP Board notification timeline run in parallel, not sequentially. Build them into the same SOP.

How Delta Filings supports DPDP compliance

The Delta Filings privacy module ships a DPDP compliance calendar, a vendor DPA tracker with version control, a breach simulation playbook, and the board-report template for privacy posture. For a CS supporting a company classified or likely to be classified as a Significant Data Fiduciary, the centralised view of vendor coverage and DPA currency is one of the higher-leverage artefacts in your toolkit.

The closing note

The DPDP Act has shifted India from GDPR-curious to GDPR-adjacent in twelve months. The first wave of Data Protection Board enforcement actions will set the operating culture for the next decade. The companies whose CS treated this as a governance build now will set the floor. The companies whose CS waited for an enforcement action will set the cautionary tales. Pick which one.

Track filings without the manual work

Delta Filings ingests NSE & BSE corporate filings, drafts SEBI letters with AI, tracks insider trading windows, and runs your compliance calendar — all in one place.

Get Started for ₹4,999/year

Related articles