The Digital Personal Data Protection Act, 2023 makes almost any organisation processing personal data in India a Data Fiduciary. Most of the commentary on it is written for a legal audience. This is the version for the people who have to build it.
What genuinely changes in your systems
- Consent has to be recorded, not assumed — the notice text shown, and when it was agreed to. If you cannot reproduce what a person actually saw, you cannot evidence consent.
- Withdrawal has to be as easy as giving consent, which means it needs a real path in the product rather than an email address that someone reads eventually.
- Retention has to end. Data kept beyond its purpose is a breach of the Act, so deletion needs to be a scheduled job, not an intention.
- Access, correction and erasure requests need somewhere to land and a process behind them.
- You must be able to notify the Data Protection Board and affected people if there is a breach — which presumes you would detect one.
What is mostly paperwork
Grievance redressal, the nomination right, and much of the notice content are policy work. They matter, and an auditor will ask for them, but they do not require engineering.
Where testing fits
The Act expects reasonable security safeguards without enumerating them. In practice, an assessment that demonstrates you have tested for unauthorised access to personal data — and fixed what it found — is the most direct evidence you can hold that the standard was met.
Significant Data Fiduciaries carry more: independent data audits and data protection impact assessments. If you are likely to be designated one, that obligation is worth planning for now rather than discovering later.