Compliance

DPDP Act 2023. How India's Data Protection Law Affects Exporters

Key provisions, consent requirements, cross-border transfers, DPDP vs GDPR comparison, penalties up to Rs 250 crore, and compliance checklist for exporters.

By Aaryan Kakani · · 11 min read

What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) was enacted by the Indian Parliament on 11 August 2023 and received Presidential assent the same month. It is India's first comprehensive data protection legislation, replacing the patchwork of rules under the Information Technology Act, 2000 and the IT (Reasonable Security Practices) Rules, 2011.

The Act applies to the processing of digital personal data within India, whether collected online or collected offline and subsequently digitized. It also has extraterritorial reach. It applies to processing of personal data outside India if such processing is in connection with offering goods or services to individuals in India.

The implementing rules have been notified in phases through 2025 and 2026. The Data Protection Board of India (DPBI) has been constituted and is operational. While full enforcement is being rolled out progressively, the core obligations around consent, purpose limitation, and security safeguards are already in effect.

Key Terminology

Data Principal

The individual whose data is being processed (your buyer, employee, vendor contact)

Data Fiduciary

The entity that determines purpose and means of processing (your company)

Data Processor

Entity processing data on behalf of the Fiduciary (your CRM vendor, cloud provider)

Significant Data Fiduciary (SDF)

Entities notified by the government based on data volume, sensitivity, and risk to sovereignty

Why Exporters Should Care

If you are an Indian exporter, you almost certainly process personal data that falls under the DPDP Act. The law is not limited to tech companies or e-commerce giants. Any business that collects, stores, or uses personal information about identifiable individuals is covered.

Here is the personal data most export businesses handle daily:

Data CategoryExamplesDPDP Covered?
Buyer contactsNames, emails, phone numbers of international buyersYes
CRM recordsPurchase history, communication logs, meeting notesYes
Trade fair leadsBusiness cards scanned, LinkedIn contacts, follow-up listsYes
Employee dataHR records, payroll, PAN/Aadhaar, bank detailsYes
Payment infoBank account details, SWIFT codes, remittance recordsYes
Vendor contactsSupplier/freight forwarder/CHA contact personsYes
Marketing listsEmail lists, WhatsApp broadcast lists, newsletter subscribersYes

Key Provisions That Matter for Exporters

Consent is the primary lawful basis for processing personal data under the DPDP Act. The Act requires consent to be free, specific, informed, unconditional, and unambiguous , given through a clear affirmative action. Key requirements include:

  • Purpose limitation. Data can only be processed for the specific purpose for which consent was obtained. You cannot collect buyer emails for order confirmations and then use them for marketing without separate consent.
  • Informed consent. Before collecting data, you must provide a clear notice describing what data you are collecting, why, and how the individual can exercise their rights. This notice must be in English or any language in the Eighth Schedule of the Constitution.
  • Withdrawal rights. Data Principals can withdraw consent at any time, and it must be as easy to withdraw consent as it was to give it. Once withdrawn, you must stop processing and delete the data within a reasonable period.

Data Principal Rights

The Act grants individuals (Data Principals) several rights that exporters must be prepared to fulfil:

  • Right to access. Individuals can request a summary of their personal data being processed and the processing activities.
  • Right to correction and erasure. Individuals can request correction of inaccurate data or complete erasure of data that is no longer necessary.
  • Right to grievance redressal. Every Data Fiduciary must provide a grievance redressal mechanism. If unresolved, the Data Principal can approach the Data Protection Board.
  • Right to nominate. Individuals can nominate another person to exercise their rights in case of death or incapacity.

Cross-Border Data Transfer

This is where the DPDP Act takes a fundamentally different approach from GDPR. Instead of requiring an adequacy assessment or standard contractual clauses for each destination country, the DPDP Act uses a blacklist model :

Data transfers are permitted to all countries by default. The Central Government can restrict transfers to specific countries by issuing a notification. Until such a restriction is notified, your data can flow freely to any jurisdiction.

For exporters, this is relatively favorable. You can continue using international CRM systems, cloud providers, and email services hosted abroad without needing country-specific transfer mechanisms. However, you should monitor government notifications, as restrictions can be imposed at any time based on national security or sovereignty concerns.

Data Protection Board of India

The DPBI is the adjudicatory body under the Act. It is not a regulator in the traditional sense. It does not issue licenses or prior approvals. Instead, it handles complaints from Data Principals, investigates data breaches, and imposes penalties. The Board functions as a digital-first body, with proceedings conducted virtually by default.

Significant Data Fiduciary Obligations

Entities notified as Significant Data Fiduciaries face additional requirements:

  • Data Protection Officer. Must appoint a DPO based in India who reports to the Board of Directors.
  • Data Protection Impact Assessment. Must conduct periodic DPIAs for high-risk processing activities.
  • Periodic audit. Must engage an independent data auditor to evaluate compliance.

Impact on Different Types of Export Businesses

E-Commerce Export Sellers

If you sell on Amazon Global Selling, Shopify, or similar platforms, you collect significant personal data: customer names, shipping addresses, email addresses, phone numbers, purchase history, abandoned cart data, and return/refund records.

Under the DPDP Act, you need consent for marketing emails and retargeting based on purchase history. Order fulfillment data is covered under the "performance of contract" legitimate use, but any secondary use (analytics, cross-selling, sharing with third-party marketing tools) requires separate consent. Abandoned cart emails (a standard e-commerce practice) may need a consent mechanism depending on how the data was collected.

B2B Exporters

Traditional B2B exporters maintain buyer contact databases built over years from trade fairs, LinkedIn outreach, industry directories, and referrals. These databases contain personal data. The contact person's name, designation, email, phone number, and sometimes personal mobile numbers.

The DPDP Act does not grandfather legacy databases. If your existing data was collected without DPDP-compliant consent, you may need to obtain fresh consent or establish that the processing falls under a legitimate use exception. For active business relationships where you are fulfilling orders, the contract performance exemption likely applies. For dormant leads or cold outreach lists, the consent requirement is harder to satisfy.

Payment and Financial Data

Exporters handle significant financial personal data: buyer bank details for remittances, FEMA-related transaction records, EDPMS entries, FIRC/BRC documents that contain individual names and account numbers, and employee payroll data.

Processing financial data for regulatory compliance (RBI, FEMA, customs) falls under the legal compliance exemption. However, if you store this data beyond the regulatory retention period, or use it for purposes beyond compliance (credit assessment of buyers, for example), consent obligations apply.

Employee and HR Data

Employee data processing for employment purposes is covered under the legitimate use exemption. You do not need separate consent for maintaining employee records, processing payroll, or providing statutory benefits. However, using employee data for purposes beyond employment (sharing with third parties for background checks beyond what employment law requires, employee monitoring beyond reasonable scope) may trigger consent requirements.

DPDP Act vs GDPR. Side-by-Side Comparison

If you export to the EU, you likely already deal with GDPR. Here is how the two laws compare on provisions that matter most to exporters:

ProvisionDPDP Act (India)GDPR (EU)
ScopeDigital personal data onlyAll personal data (digital and physical)
Lawful basesConsent + limited legitimate usesSix lawful bases including legitimate interest
Consent standardFree, specific, informed, unambiguousFreely given, specific, informed, unambiguous
DPO requirementOnly for Significant Data FiduciariesRequired for public bodies and large-scale processors
Cross-border transfersBlacklist model. All allowed unless restrictedWhitelist model. Adequacy decision or SCCs required
Data portabilityNot explicitly providedExplicit right to data portability
Breach notificationNotify Data Protection Board (timeline in rules)Notify supervisory authority within 72 hours
Maximum penaltyRs 250 crore (~USD 30M) per instance4% of global annual turnover or EUR 20M
Right to be forgottenRight to erasure (when purpose fulfilled or consent withdrawn)Comprehensive right to erasure with listed grounds

DPDP Act vs Other Global Data Protection Laws

Indian exporters ship to diverse markets, each with its own data protection regime. Here is how the DPDP Act compares to laws in key export destinations:

AspectUK GDPRSingapore PDPAUAE Federal Decree-Law No. 45Japan APPI
Consent approachMultiple lawful basesConsent + exceptionsConsent-centricConsent + legitimate interest
Cross-border mechanismAdequacy + IDTAsComparable protection standardAdequate level of protectionConsent or equivalent measures
Breach notification72 hours to ICO3 days to PDPCPrescribed timelinePromptly to PPC
Maximum penaltyGBP 17.5M or 4% turnoverSGD 1M or 10% turnoverAED 2MJPY 100M + criminal

The practical takeaway for exporters is that data protection is now a global norm. If you export to the UK, Singapore, UAE, or Japan, you face overlapping obligations. The DPDP Act's blacklist approach to cross-border transfers is more permissive than most of these frameworks, which is a relative advantage for Indian exporters. However, you still need to comply with the destination country's law when handling their residents' data.

Penalties for Non-Compliance

The DPDP Act prescribes significant penalties, with amounts specified in the Schedule to the Act. Unlike GDPR's turnover-based formula, the DPDP Act sets fixed caps for different categories of violations:

ViolationMaximum Penalty
Failure to take reasonable security safeguards leading to a data breachRs 250 crore (~USD 30M)
Non-compliance with provisions relating to children's dataRs 200 crore (~USD 24M)
Failure to notify the Board and affected individuals of a data breachRs 200 crore (~USD 24M)
Non-compliance with additional obligations of Significant Data FiduciaryRs 150 crore (~USD 18M)
Non-compliance with any other provision of the ActRs 50 crore (~USD 6M)
Non-compliance by Data Principal (providing false information, filing frivolous complaints)Rs 10,000

The Data Protection Board determines the penalty amount based on several factors: the nature, gravity, and duration of the breach; the type and nature of personal data affected; whether the fiduciary took remedial action; whether the breach was repeated; and the likely impact on the data principal. For SME exporters, the Board is expected to consider the entity's size and financial capacity, though this is not guaranteed to result in lower penalties.

DPDP Act Compliance Checklist for Exporters

Here is a practical checklist tailored for Indian export businesses. Not every item applies to every exporter. Prioritize based on your data processing activities and scale.

Priority 1. Do Now

  • Data mapping. Inventory all personal data you collect, where it is stored, who has access, and why you process it. Cover CRM, email, accounting software, HR systems, and any spreadsheets with contact information.
  • Privacy policy. Create or update your privacy policy with DPDP-compliant disclosures. Must cover: identity of the Data Fiduciary, purpose of processing, rights of Data Principals, and grievance redressal mechanism.
  • Consent mechanism. Implement opt-in consent for marketing emails, newsletters, and any data use beyond order fulfillment. A simple checkbox at the point of data collection is a starting point.
  • Grievance redressal. Designate a contact person or email address for data protection queries. Publish this in your privacy policy and on your website.

Priority 2. Do Within 3 Months

  • Vendor agreements. Review contracts with cloud providers, CRM vendors, email service providers, and any Data Processors. Ensure they include data processing clauses that align with DPDP Act requirements.
  • Data retention policy. Define how long you retain different categories of personal data. Delete data when the purpose is fulfilled or consent is withdrawn, unless a regulatory retention period applies.
  • Security measures. Implement reasonable security safeguards. At minimum: access controls, encryption for sensitive data at rest and in transit, regular backups, and employee training on data handling.
  • Breach response plan. Document a basic incident response process: how you detect breaches, who is responsible for assessment, how you notify the Board and affected individuals, and how you contain and remediate.

Priority 3. Ongoing

  • Consent management. Build a system to track consent status, handle withdrawal requests, and maintain audit trails of when and how consent was obtained.
  • Employee training. Train export team, sales team, and marketing staff on DPDP obligations, particularly around handling buyer data and responding to data principal requests.
  • Monitor government notifications. Track notifications for cross-border transfer restrictions, Significant Data Fiduciary designations, and any amendments to the implementing rules.

Where DPDP Intersects with Export Compliance

Export businesses already operate under a dense regulatory framework. FEMA, customs law, DGFT regulations, RBI circulars, GST. The DPDP Act adds a new layer that intersects with existing obligations in several ways:

EDPMS Data

Export Data Processing and Monitoring System entries contain personal data. Exporter names, authorized signatories, bank account details. Processing this data for RBI compliance is exempt from consent requirements under the DPDP Act's legal compliance provision. However, the security safeguard obligations still apply. An EDPMS data breach would trigger both DPDP notification requirements and potential RBI scrutiny.

Customs and Shipping Bill Data

Shipping bills, bills of entry, and ICEGATE submissions contain personal data of authorized signatories, CHA details, and sometimes buyer information. These are processed under legal obligation and exempt from consent. However, if you extract this data for secondary purposes (analytics, marketing), the exemption no longer applies.

Buyer Verification and KYC

Exporters performing buyer due diligence (denied party screening, credit checks, end-use verification for SCOMET items) collect personal data about buyer personnel. This processing is typically covered under legal compliance or contract performance exemptions, but the scope must be proportionate. Collecting more data than necessary for verification may fall outside the exemption.

FEMA and Banking Data

FIRCs, BRCs, forex remittance records, and AD bank correspondence contain personal financial data. Processing for FEMA compliance and RBI reporting is exempt, but retention beyond the statutory period or use for credit scoring of buyers requires a lawful basis under DPDP.

Practical Steps. What to Do Now vs What Can Wait

DPDP Act compliance is not an overnight project, and the government has recognized this by rolling out rules in phases. Here is a realistic prioritization for SME exporters working with limited budgets and teams:

Do This Week

  • Add a basic privacy policy to your website with DPDP-required disclosures
  • Add an unsubscribe link to all marketing emails
  • Publish a grievance redressal email address
  • Stop collecting data you do not actually use

Do This Month

  • Map all personal data across CRM, email, HR, and accounting systems
  • Add consent checkboxes to web forms and inquiry forms
  • Review CRM vendor agreements for data processing terms
  • Enable encryption for stored sensitive data

Do This Quarter

  • Implement a data retention and deletion schedule
  • Create a basic data breach response plan
  • Train your export and sales teams on data handling
  • Audit third-party tools (analytics, marketing, cloud) for compliance

Can Wait (But Monitor)

  • Full consent management platform (unless processing at scale)
  • Data Protection Impact Assessment (only if notified as SDF)
  • Formal DPO appointment (only if notified as SDF)
  • Cross-border transfer restrictions (none notified yet)

The cost of basic compliance is modest for most SME exporters. A privacy policy can be drafted for Rs 10,000. 25,000 by a consultant. Consent mechanisms are built into most modern CRM and email tools. Data mapping is primarily an internal exercise. The big-ticket items (formal DPIAs, independent audits, DPO appointments) only apply to Significant Data Fiduciaries, which most export SMEs will not be.

Related Reading

Denied Party Screening for Indian Exporters

How to screen buyers against restricted entity lists while staying DPDP-compliant.

EDPMS Common Errors and Solutions

Fix EDPMS entries and understand the data that flows between your bank and RBI.

E-Commerce Export Compliance in India

Compliance requirements for Amazon, Shopify, and marketplace sellers exporting from India.

Export Compliance Audit Checklist

Complete audit checklist covering FEMA, customs, DGFT, and now DPDP Act requirements.

Update history

  • First published.