One Law. Six Penalty Tiers. One Platform To Cover Them.

The Digital Personal Data Protection Act, 2023 is India's first comprehensive law governing digital personal data. It comes into force in three phases, ending with full compliance required by 13 May 2027. It applies to any organisation processing the personal data of individuals in India, including organisations headquartered outside the country if that processing relates to offering goods or services to individuals within India. 

The obligations themselves aren't unusual: consent, notice, retention, security safeguards, breach response, children's data protection. What's new is the enforcement. Non-compliance carries penalties of up to Rs 250 crore, and penalties apply per violation, not as an annual cap, so a single incident that touches multiple obligations can trigger multiple, cumulative penalties. 

TeamSync isn't a dedicated DPDP compliance tool. But the underlying requirements- knowing where personal data lives, controlling who can access it, proving that access with an audit trail, deleting it on schedule, detecting and logging a breach- are the same things the platform is already built to do.

What The DPDP Act Requires

Requirement

What it actually says

Applicability

Covers digital personal data of individuals in India, including processing by entities located outside India

Consent

Free, specific, informed, unconditional, and unambiguous; withdrawal must be as easy as giving it

Notice

Clear notice at or before collection, itemising purpose and data categories

Purpose limitation

Data used only for the consented purpose, or a legally permitted exemption

Data Principal rights

Access, correction, erasure, grievance redressal, nomination of another person to act on their behalf

Security safeguards

"Reasonable security safeguards" against unauthorised access, use, or breach

Breach notification

Notification to the Data Protection Board and affected Data Principals in the event of a personal data breach 

Children's data

Verifiable parental consent required before processing a child's personal data 

Retention

Data erased once its purpose is served, unless another law requires it to be kept

Significant Data Fiduciary (SDF)

India-based Data Protection Officer, annual DPIA, annual independent audit, and algorithmic fairness assessment 

Cross-border transfer

Permitted by default; government retains power to restrict transfers to specified countries

Consent Manager

A registered third party through which a Data Principal gives, manages, and withdraws consent 

The Penalty Schedule

Penalties sit across six tiers, and the Board has discretion on the actual quantum based on the nature, gravity, duration, and repetition of the violation, along with mitigating steps taken.

Violation

Maximum penalty

Failure to implement reasonable security safeguards

Rs 250 crore 

Failure to notify the Board or affected Data Principals of a breach

Rs 200 crore 

Non-compliance with children's data provisions

Rs 200 crore 

Failure to fulfil additional SDF obligations

Rs 150 crore 

Breach of a voluntary undertaking accepted by the Board

Equal to the penalty for the original underlying breach 

Breach of a Data Principal's own duties

Rs 10,000 

Flag for legal: these are structured per violation type, not per inquiry, so a single investigation that surfaces both a security-safeguard failure and a breach-notification failure can result in both maximums applying together. Worth confirming with your compliance reviewer how directly to state that on a public page.

Three Phases, One Deadline

Phase

What it covers

Phase 1 — 13 Nov 2025

Data Protection Board established; core definitions in force 

Phase 2 — 13 Nov 2026

Enforcement powers, penalty framework, and Consent Manager registration active 

Phase 3 — 13 May 2027

Full compliance required, consent, notice, all obligations and rights. No grace period after this date 

What Else Runs On The Same Platform

Capability

What it does inside the DPDP perimeter

Intelligent Repository

Central store for personal data with retention rules applied at the platform level

RBAC

Access control layer that supports the "reasonable security safeguards" requirement

Compliance Audit Trail

Cryptographic audit chain of who accessed or changed personal data, and when

DocuTalk

Permission-aware AI search, never surfaces data a user isn't already entitled to see

Semantic Search / Discovery Graph

Locate personal data across unstructured files for data-mapping and DPIA work

Smart Expiry

Automated deletion once a retention period or purpose lapses

Risk Radar

Flags documents containing personal data categories that need closer handling

Security and Deployment

Air-gapped, on-premise, and quantum-secure encryption options for the storage layer

What A Board Inquiry Looks Like

Inquiry

What you'd need to produce

"Show us the personal data you hold on this individual"

Data export mapped to that Data Principal

"Show us your security safeguards for this data"

Access control and encryption configuration, with audit trail

"Show us when this breach was detected and who was notified"

Timestamped incident log, cryptographic chain of events

"Show us evidence of parental consent for this account"

Consent record retrieval

"Show us your DPIA and audit documentation" (SDFs only)

Generated compliance package

What Changes For Privacy And Compliance Teams

Activity

Before

With TeamSync

Data mapping for DPIA

Multi-week manual survey

Semantic Search across the estate

Breach evidence assembly

Ad hoc reconstruction

Generated artifact from the audit chain

Retention and deletion

Manual tracking, spreadsheets

Automated, rule-based

Access control evidence

Policy documents

Live RBAC configuration + audit trail

SDF audit prep

Multi-quarter project

Architectural answer

How TeamSync Compares

When evaluating platforms for DPDP readiness, TeamSync is typically weighed against:

  • OneTrust / TrustArc: Strong consent and privacy-workflow tooling, but a lighter native document repository, personal data sitting inside unstructured files still needs to be found and secured elsewhere

  • Seclore: Strong rights-managed document security, narrower on the broader repository, workflow, and AI layer

  • Securiti: Strong data discovery and classification, but the storage and access-control layer for the documents themselves sits outside its scope

  • In-house DPO tooling + spreadsheets: Most flexible on paper, but data mapping, retention automation, and breach audit trail are left entirely to the team