Discuss this page with an LLM

What This Means In Practice

Use this table to brief your legal, product and marketing teams.

Question DPDP Direction DPDP vs Pre-DPDP: Key Privacy Changes Direction Practical Impact
Can we process by default? Often consent-first Often depends on a different legal model India flows may need earlier consent design.
Is a global privacy model enough? No Not always Global privacy work does not map one-to-one to DPDP.
Are children protected differently? Under 18 Check local age thresholds Indian child-user products need stricter review.
Is breach risk enough to trigger work? Yes Yes Security, response and evidence matter in both systems.

Three Questions To Ask Internally

  1. Are we copying a non-India privacy model into an Indian product?
  2. Do our consent flows work for Indian users?
  3. Which global privacy controls can be reused, and which must be redesigned for DPDP?

If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

The Shift from SPDI to All Personal Data

Before this law, Indian regulations only focused on Sensitive Personal Data or Information (SPDI). This included narrow categories like passwords or medical records. The DPDP Act covers every piece of digital information that can identify a person. Businesses can no longer ignore basic identifiers like IP addresses or device IDs in their privacy frameworks.

Enforcement and Accountability Changes

In the previous unregulated state, data breaches often went unreported because there was no mandatory notification law. DPDP creates a legal obligation to inform the Data Protection Board and the affected individuals. The burden of proof has shifted. Businesses must now demonstrate they have valid consent for every data point they process and store.

Comparison Table

FeaturePre-DPDP Status QuoDPDP Act 2023
Data ScopeOnly “Sensitive” data (SPDI)All digital personal data
Breach AlertsNot mandatory for mostMandatory for all breaches
ConsentOften implied or buriedMust be free, specific, and informed
User RightsLimited or non-existentRights to access, correct, and erase
ChildrenNo specific protectionRestricted processing for under 18s
Board OversightNo dedicated regulatorData Protection Board of India
StorageNo specific limitsMust delete data once purpose is met

This week

Identify all datasets that were previously classified as “non-sensitive” under the IT Act, such as marketing lead lists. Map these to the new DPDP requirements to ensure they are covered by your future consent management system.

FAQ

Q: Are physical paper files covered by the new law? A: No. DPDP only applies to data in digital form or physical records that are digitized later. Purely manual paper filing systems remain outside this specific law’s scope.

Q: Can we still use “opt-out” consent for marketing? A: No. DPDP requires affirmative action. You cannot rely on pre-ticked boxes or silence as a form of consent for processing personal data.

Q: What is the biggest change for small businesses? A: The biggest change is accountability. Small firms must now track why they collected data and delete it once the specific task is finished, rather than keeping it indefinitely.

Confused by the differences?

Dual compliance is tricky. Our experts can help you navigate both DPDP vs Pre-DPDP: Key Privacy Changes and DPDP requirements.

Book Strategy Call
Book clarity call