
India data protection DPDP Act lawyer
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s comprehensive data protection statute, enacted as Act No. 22 of 2023 and receiving presidential assent on August 11, 2023. The legislation establishes a consent-based framework governing the processing of digital personal data within India and, in certain circumstances, data processed outside India that relates to offering goods or services to individuals in India. For US-based companies with India operations, subsidiaries, or customer bases, the DPDP Act introduces compliance obligations that intersect with existing US data governance practices. The Act creates the Data Protection Board of India as its enforcement authority and provides for significant financial penalties for non-compliance. Understanding how the DPDP Act applies to cross-border data flows, what obligations it imposes on data fiduciaries, and how it interacts with US-sectoral privacy frameworks is a threshold question for businesses operating across the US-India corridor. Law Offices of SRIS, P.C. is a US law firm founded in 1997, practicing since that year, with a cross-border practice that includes data protection matters involving India.
The Digital Personal Data Protection Act, 2023 establishes India’s first comprehensive data privacy framework, replacing the earlier patchwork of judicial precedent and sector-specific rules. What the DPDP Act Covers
The DPDP Act applies to the processing of digital personal data within India, and to processing outside India when the data relates to offering goods or services to data principals located in India. The Act defines a data fiduciary as any person who determines the purpose and means of processing personal data, and a data principal as the individual to whom the personal data relates. Processing is permitted on several grounds, with consent serving as the primary lawful basis. The Act also recognizes certain legitimate uses where consent is not required, including employment-related processing, compliance with legal obligations, and specified public-interest purposes. The legislation introduces the concept of a consent manager, a registered entity that facilitates the management of consent on behalf of data principals through an accessible and interoperable platform.
The DPDP Act imposes obligations on data fiduciaries that include providing notice to data principals about the personal data being collected and the purposes of processing, implementing reasonable security safeguards, and reporting data breaches to the Data Protection Board. Significant data fiduciaries, a class to be designated by the central government based on factors such as the volume and sensitivity of data processed, are subject to additional obligations including the appointment of a data protection officer and independent data audits. The Act also addresses cross-border data transfers: the central government may, by notification, restrict the transfer of personal data to countries or territories outside India. As of 2026, the government has not issued a comprehensive list of restricted jurisdictions, and the default position permits cross-border transfers except to countries specifically blacklisted. The penalty framework is substantial, with the Data Protection Board empowered to impose financial penalties of up to INR 250 crore for certain violations, measured against the nature, gravity, and duration of the non-compliance.
Cross-border data protection matters involving India require coordination between US-admitted counsel and India-admitted counsel, each handling the law of their respective jurisdiction. How Cross-Border Data Protection Matters Are Handled
When a US-based company seeks to assess its DPDP Act obligations, the matter typically involves both US-law and India-law dimensions. The US-law side may include reviewing existing data processing agreements, privacy policies drafted for US-sectoral compliance, and contractual provisions governing data flows between the US parent entity and its India subsidiary or service providers. The India-law side requires analysis of the DPDP Act’s consent requirements, legitimate-use grounds, data fiduciary obligations, and any sector-specific rules issued by Indian regulatory authorities. Law Offices of SRIS, P.C. handles the US-law aspects of these matters through its US-admitted attorneys. For the India-law side, the firm collaborates with Sowmya R, Of Counsel, enrolled with the State Bar Council of Madhya Pradesh (Enrollment No. MP2285/2014). She is not admitted in any US state bar. Her role is limited to India-law matters in collaboration with the US-admitted attorneys of the firm.
The division of work reflects the jurisdictional limits of each attorney’s licensure. Mr. Sris, admitted in Virginia, Maryland, the District of Columbia, New Jersey, and New York, addresses the US-law dimensions of a cross-border data protection matter: reviewing US privacy policies for consistency with DPDP Act requirements, advising on contractual frameworks between US and India entities, and addressing US-sectoral compliance considerations that may run parallel to DPDP Act obligations. Sowmya R addresses the India-law dimensions: analyzing whether the company’s data processing activities fall within the DPDP Act’s territorial scope, assessing consent mechanisms against the Act’s requirements, evaluating applicable legitimate-use grounds, and advising on engagement with the Data Protection Board of India. The two sides collaborate as needed while maintaining strict jurisdictional separation. No attorney practices law in a jurisdiction where they are not admitted.
Mr. Sris founded Law Offices of SRIS, P.C. in 1997 and is admitted in five US jurisdictions; Sowmya R serves as Of Counsel for India-law matters. About Mr. Sris and the India Of Counsel
Mr. Sris, former prosecutor, is the founder of Law Offices of SRIS, P.C., which he established in 1997. He is admitted to practice law in Virginia, Maryland, the District of Columbia, New Jersey, and New York. Mr. Sris testified before the Virginia House Courts of Justice Committee in support of 2019 HB 635 (chief patron Del. David Bulova), the bill that became the 2019 revision to Va. Code § 20-107.3(g). His practice includes cross-border matters where US law intersects with foreign legal frameworks, including data protection compliance for businesses with India operations.
For India-law matters, the firm works with Sowmya R, Of Counsel, enrolled with the State Bar Council of Madhya Pradesh (Enrollment No. MP2285/2014). She is not admitted in any US state bar. Her practice with Law Offices of SRIS, P.C. is limited to matters of India law and to serving as a liaison for clients with US-licensed attorneys at the firm. All US-law aspects of a cross-border data protection matter are handled by Mr. Sris and the US-admitted attorneys of the firm. The firm holds its principal location in Virginia, by appointment only, and does not maintain a location in India.
Frequently Asked Questions
What is the Digital Personal Data Protection Act, 2023 and who must comply?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s comprehensive data protection law that governs the processing of digital personal data within India and, in certain cases, outside India. The Act applies to data fiduciaries — entities that determine the purpose and means of processing personal data — when they process data within Indian territory. It also applies extraterritorially to processing outside India when the data relates to offering goods or services to data principals located in India. The Act covers personal data collected in digital form or digitized after collection. Certain categories of data processing are exempt, including processing for personal or domestic purposes, and processing by government agencies for specified sovereign functions. The Act does not apply to data processed outside India by entities that have no connection to offering goods or services in India.
How does the DPDP Act affect US companies with India subsidiaries or customers?
A US company with an India subsidiary that processes personal data in India, or a US company that offers goods or services to individuals in India and processes their personal data, may fall within the DPDP Act’s scope. The India subsidiary, as a data fiduciary operating within India, is directly subject to the Act’s obligations including consent requirements, notice obligations, and breach reporting duties. The US parent company may have indirect exposure through its subsidiary’s compliance obligations, and may have direct exposure if it independently determines the purpose and means of processing personal data of data principals in India. Cross-border data flows between the US parent and the India subsidiary raise additional considerations under the Act’s transfer provisions. The central government may restrict transfers to certain countries, and as of 2026, the regulatory framework for such restrictions continues to develop.
What penalties can the Data Protection Board of India impose under the DPDP Act?
The Data Protection Board of India is empowered to impose financial penalties of up to INR 250 crore for certain violations of the DPDP Act. The penalty amount is determined by reference to factors set out in the Act, including the nature, gravity, and duration of the non-compliance, the type and nature of the personal data affected, and whether the violation was intentional or resulted from negligence. The Board may also direct a data fiduciary to take remedial measures, including ceasing processing activities, and may accept voluntary undertakings from data fiduciaries. The penalty framework is structured to be proportionate, and the Act provides for an appellate mechanism through the Telecom Disputes Settlement and Appellate Tribunal. The Board’s enforcement powers represent a significant shift from India’s prior data protection landscape, which lacked a dedicated enforcement authority with penalty powers of this magnitude.
How do cross-border data transfers work under the DPDP Act?
The DPDP Act permits cross-border transfer of personal data except to countries or territories that the central government has specifically restricted by notification. This represents a departure from the earlier proposed data localization requirements that would have mandated storage of certain categories of personal data within India. Under the enacted framework, data fiduciaries may transfer personal data outside India unless the destination country has been blacklisted. As of 2026, the central government has not issued a comprehensive list of restricted jurisdictions. However, sector-specific regulations issued by other Indian regulatory authorities — such as the Reserve Bank of India’s data localization requirements for payment systems — may impose additional restrictions that operate alongside the DPDP Act. Companies transferring data from India should monitor both the DPDP Act’s notification framework and any sector-specific rules applicable to their industry.
What is the role of the Data Protection Board of India under the DPDP Act?
The Data Protection Board of India is the enforcement authority established under the DPDP Act, responsible for adjudicating complaints, imposing penalties, and directing remedial measures. The Board functions as a digital office, conducting proceedings online and exercising powers that include summoning persons, examining them under oath, and receiving evidence. Data principals may file complaints with the Board alleging non-compliance by a data fiduciary. The Board may inquire into such complaints and, where it finds a violation, issue orders directing the data fiduciary to take specified remedial action or imposing financial penalties. The Board also has the power to accept voluntary undertakings from data fiduciaries, which may include commitments to implement specific compliance measures. The Board’s establishment marks a significant institutional development in India’s data governance framework, providing a dedicated forum for data protection enforcement.
How does the DPDP Act compare to the GDPR and US privacy frameworks?
The DPDP Act shares structural similarities with the European Union’s General Data Protection Regulation (GDPR) — including consent-based processing, data principal rights, and an independent enforcement authority — but differs in scope, exemptions, and cross-border transfer rules. Unlike the GDPR, the DPDP Act does not create a right to data portability or a right to object to automated decision-making in the same form. The Act’s government-exemption provisions are broader than those under the GDPR, permitting the central government to exempt certain government agencies from the Act’s application. Compared to US privacy frameworks, which are primarily sectoral — such as the Health Insurance Portability and Accountability Act for health data and the Gramm-Leach-Bliley Act for financial data — the DPDP Act is a comprehensive, cross-sectoral statute. US companies accustomed to sectoral compliance may need to adjust to the DPDP Act’s omnibus approach when their activities fall within its territorial scope.