Compliance
DPDP Act 2023. How India's Data Protection Law Affects Exporters
Key provisions, consent requirements, cross-border transfers, DPDP vs GDPR comparison, penalties up to Rs 250 crore, and compliance checklist for exporters.
By Aaryan Kakani · · 11 min read
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) was enacted by the Indian Parliament on 11 August 2023 and received Presidential assent the same month. It is India's first comprehensive data protection legislation, replacing the patchwork of rules under the Information Technology Act, 2000 and the IT (Reasonable Security Practices) Rules, 2011.
The Act applies to the processing of digital personal data within India, whether collected online or collected offline and subsequently digitized. It also has extraterritorial reach. It applies to processing of personal data outside India if such processing is in connection with offering goods or services to individuals in India.
The implementing rules have been notified in phases through 2025 and 2026. The Data Protection Board of India (DPBI) has been constituted and is operational. While full enforcement is being rolled out progressively, the core obligations around consent, purpose limitation, and security safeguards are already in effect.
Key Terminology
Data Principal
The individual whose data is being processed (your buyer, employee, vendor contact)
Data Fiduciary
The entity that determines purpose and means of processing (your company)
Data Processor
Entity processing data on behalf of the Fiduciary (your CRM vendor, cloud provider)
Significant Data Fiduciary (SDF)
Entities notified by the government based on data volume, sensitivity, and risk to sovereignty
Why Exporters Should Care
If you are an Indian exporter, you almost certainly process personal data that falls under the DPDP Act. The law is not limited to tech companies or e-commerce giants. Any business that collects, stores, or uses personal information about identifiable individuals is covered.
Here is the personal data most export businesses handle daily:
| Data Category | Examples | DPDP Covered? |
|---|---|---|
| Buyer contacts | Names, emails, phone numbers of international buyers | Yes |
| CRM records | Purchase history, communication logs, meeting notes | Yes |
| Trade fair leads | Business cards scanned, LinkedIn contacts, follow-up lists | Yes |
| Employee data | HR records, payroll, PAN/Aadhaar, bank details | Yes |
| Payment info | Bank account details, SWIFT codes, remittance records | Yes |
| Vendor contacts | Supplier/freight forwarder/CHA contact persons | Yes |
| Marketing lists | Email lists, WhatsApp broadcast lists, newsletter subscribers | Yes |
Key Provisions That Matter for Exporters
Consent Requirements
Consent is the primary lawful basis for processing personal data under the DPDP Act. The Act requires consent to be free, specific, informed, unconditional, and unambiguous , given through a clear affirmative action. Key requirements include:
- Purpose limitation. Data can only be processed for the specific purpose for which consent was obtained. You cannot collect buyer emails for order confirmations and then use them for marketing without separate consent.
- Informed consent. Before collecting data, you must provide a clear notice describing what data you are collecting, why, and how the individual can exercise their rights. This notice must be in English or any language in the Eighth Schedule of the Constitution.
- Withdrawal rights. Data Principals can withdraw consent at any time, and it must be as easy to withdraw consent as it was to give it. Once withdrawn, you must stop processing and delete the data within a reasonable period.
Data Principal Rights
The Act grants individuals (Data Principals) several rights that exporters must be prepared to fulfil:
- Right to access. Individuals can request a summary of their personal data being processed and the processing activities.
- Right to correction and erasure. Individuals can request correction of inaccurate data or complete erasure of data that is no longer necessary.
- Right to grievance redressal. Every Data Fiduciary must provide a grievance redressal mechanism. If unresolved, the Data Principal can approach the Data Protection Board.
- Right to nominate. Individuals can nominate another person to exercise their rights in case of death or incapacity.
Cross-Border Data Transfer
This is where the DPDP Act takes a fundamentally different approach from GDPR. Instead of requiring an adequacy assessment or standard contractual clauses for each destination country, the DPDP Act uses a blacklist model :
Data transfers are permitted to all countries by default. The Central Government can restrict transfers to specific countries by issuing a notification. Until such a restriction is notified, your data can flow freely to any jurisdiction.
For exporters, this is relatively favorable. You can continue using international CRM systems, cloud providers, and email services hosted abroad without needing country-specific transfer mechanisms. However, you should monitor government notifications, as restrictions can be imposed at any time based on national security or sovereignty concerns.
Data Protection Board of India
The DPBI is the adjudicatory body under the Act. It is not a regulator in the traditional sense. It does not issue licenses or prior approvals. Instead, it handles complaints from Data Principals, investigates data breaches, and imposes penalties. The Board functions as a digital-first body, with proceedings conducted virtually by default.
Significant Data Fiduciary Obligations
Entities notified as Significant Data Fiduciaries face additional requirements:
- Data Protection Officer. Must appoint a DPO based in India who reports to the Board of Directors.
- Data Protection Impact Assessment. Must conduct periodic DPIAs for high-risk processing activities.
- Periodic audit. Must engage an independent data auditor to evaluate compliance.
Impact on Different Types of Export Businesses
E-Commerce Export Sellers
If you sell on Amazon Global Selling, Shopify, or similar platforms, you collect significant personal data: customer names, shipping addresses, email addresses, phone numbers, purchase history, abandoned cart data, and return/refund records.
Under the DPDP Act, you need consent for marketing emails and retargeting based on purchase history. Order fulfillment data is covered under the "performance of contract" legitimate use, but any secondary use (analytics, cross-selling, sharing with third-party marketing tools) requires separate consent. Abandoned cart emails (a standard e-commerce practice) may need a consent mechanism depending on how the data was collected.
B2B Exporters
Traditional B2B exporters maintain buyer contact databases built over years from trade fairs, LinkedIn outreach, industry directories, and referrals. These databases contain personal data. The contact person's name, designation, email, phone number, and sometimes personal mobile numbers.
The DPDP Act does not grandfather legacy databases. If your existing data was collected without DPDP-compliant consent, you may need to obtain fresh consent or establish that the processing falls under a legitimate use exception. For active business relationships where you are fulfilling orders, the contract performance exemption likely applies. For dormant leads or cold outreach lists, the consent requirement is harder to satisfy.
Payment and Financial Data
Exporters handle significant financial personal data: buyer bank details for remittances, FEMA-related transaction records, EDPMS entries, FIRC/BRC documents that contain individual names and account numbers, and employee payroll data.
Processing financial data for regulatory compliance (RBI, FEMA, customs) falls under the legal compliance exemption. However, if you store this data beyond the regulatory retention period, or use it for purposes beyond compliance (credit assessment of buyers, for example), consent obligations apply.
Employee and HR Data
Employee data processing for employment purposes is covered under the legitimate use exemption. You do not need separate consent for maintaining employee records, processing payroll, or providing statutory benefits. However, using employee data for purposes beyond employment (sharing with third parties for background checks beyond what employment law requires, employee monitoring beyond reasonable scope) may trigger consent requirements.
DPDP Act vs GDPR. Side-by-Side Comparison
If you export to the EU, you likely already deal with GDPR. Here is how the two laws compare on provisions that matter most to exporters:
| Provision | DPDP Act (India) | GDPR (EU) |
|---|---|---|
| Scope | Digital personal data only | All personal data (digital and physical) |
| Lawful bases | Consent + limited legitimate uses | Six lawful bases including legitimate interest |
| Consent standard | Free, specific, informed, unambiguous | Freely given, specific, informed, unambiguous |
| DPO requirement | Only for Significant Data Fiduciaries | Required for public bodies and large-scale processors |
| Cross-border transfers | Blacklist model. All allowed unless restricted | Whitelist model. Adequacy decision or SCCs required |
| Data portability | Not explicitly provided | Explicit right to data portability |
| Breach notification | Notify Data Protection Board (timeline in rules) | Notify supervisory authority within 72 hours |
| Maximum penalty | Rs 250 crore (~USD 30M) per instance | 4% of global annual turnover or EUR 20M |
| Right to be forgotten | Right to erasure (when purpose fulfilled or consent withdrawn) | Comprehensive right to erasure with listed grounds |
DPDP Act vs Other Global Data Protection Laws
Indian exporters ship to diverse markets, each with its own data protection regime. Here is how the DPDP Act compares to laws in key export destinations:
| Aspect | UK GDPR | Singapore PDPA | UAE Federal Decree-Law No. 45 | Japan APPI |
|---|---|---|---|---|
| Consent approach | Multiple lawful bases | Consent + exceptions | Consent-centric | Consent + legitimate interest |
| Cross-border mechanism | Adequacy + IDTAs | Comparable protection standard | Adequate level of protection | Consent or equivalent measures |
| Breach notification | 72 hours to ICO | 3 days to PDPC | Prescribed timeline | Promptly to PPC |
| Maximum penalty | GBP 17.5M or 4% turnover | SGD 1M or 10% turnover | AED 2M | JPY 100M + criminal |
The practical takeaway for exporters is that data protection is now a global norm. If you export to the UK, Singapore, UAE, or Japan, you face overlapping obligations. The DPDP Act's blacklist approach to cross-border transfers is more permissive than most of these frameworks, which is a relative advantage for Indian exporters. However, you still need to comply with the destination country's law when handling their residents' data.
Penalties for Non-Compliance
The DPDP Act prescribes significant penalties, with amounts specified in the Schedule to the Act. Unlike GDPR's turnover-based formula, the DPDP Act sets fixed caps for different categories of violations:
| Violation | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards leading to a data breach | Rs 250 crore (~USD 30M) |
| Non-compliance with provisions relating to children's data | Rs 200 crore (~USD 24M) |
| Failure to notify the Board and affected individuals of a data breach | Rs 200 crore (~USD 24M) |
| Non-compliance with additional obligations of Significant Data Fiduciary | Rs 150 crore (~USD 18M) |
| Non-compliance with any other provision of the Act | Rs 50 crore (~USD 6M) |
| Non-compliance by Data Principal (providing false information, filing frivolous complaints) | Rs 10,000 |
The Data Protection Board determines the penalty amount based on several factors: the nature, gravity, and duration of the breach; the type and nature of personal data affected; whether the fiduciary took remedial action; whether the breach was repeated; and the likely impact on the data principal. For SME exporters, the Board is expected to consider the entity's size and financial capacity, though this is not guaranteed to result in lower penalties.
DPDP Act Compliance Checklist for Exporters
Here is a practical checklist tailored for Indian export businesses. Not every item applies to every exporter. Prioritize based on your data processing activities and scale.
Priority 1. Do Now
- Data mapping. Inventory all personal data you collect, where it is stored, who has access, and why you process it. Cover CRM, email, accounting software, HR systems, and any spreadsheets with contact information.
- Privacy policy. Create or update your privacy policy with DPDP-compliant disclosures. Must cover: identity of the Data Fiduciary, purpose of processing, rights of Data Principals, and grievance redressal mechanism.
- Consent mechanism. Implement opt-in consent for marketing emails, newsletters, and any data use beyond order fulfillment. A simple checkbox at the point of data collection is a starting point.
- Grievance redressal. Designate a contact person or email address for data protection queries. Publish this in your privacy policy and on your website.
Priority 2. Do Within 3 Months
- Vendor agreements. Review contracts with cloud providers, CRM vendors, email service providers, and any Data Processors. Ensure they include data processing clauses that align with DPDP Act requirements.
- Data retention policy. Define how long you retain different categories of personal data. Delete data when the purpose is fulfilled or consent is withdrawn, unless a regulatory retention period applies.
- Security measures. Implement reasonable security safeguards. At minimum: access controls, encryption for sensitive data at rest and in transit, regular backups, and employee training on data handling.
- Breach response plan. Document a basic incident response process: how you detect breaches, who is responsible for assessment, how you notify the Board and affected individuals, and how you contain and remediate.
Priority 3. Ongoing
- Consent management. Build a system to track consent status, handle withdrawal requests, and maintain audit trails of when and how consent was obtained.
- Employee training. Train export team, sales team, and marketing staff on DPDP obligations, particularly around handling buyer data and responding to data principal requests.
- Monitor government notifications. Track notifications for cross-border transfer restrictions, Significant Data Fiduciary designations, and any amendments to the implementing rules.
Where DPDP Intersects with Export Compliance
Export businesses already operate under a dense regulatory framework. FEMA, customs law, DGFT regulations, RBI circulars, GST. The DPDP Act adds a new layer that intersects with existing obligations in several ways:
EDPMS Data
Export Data Processing and Monitoring System entries contain personal data. Exporter names, authorized signatories, bank account details. Processing this data for RBI compliance is exempt from consent requirements under the DPDP Act's legal compliance provision. However, the security safeguard obligations still apply. An EDPMS data breach would trigger both DPDP notification requirements and potential RBI scrutiny.
Customs and Shipping Bill Data
Shipping bills, bills of entry, and ICEGATE submissions contain personal data of authorized signatories, CHA details, and sometimes buyer information. These are processed under legal obligation and exempt from consent. However, if you extract this data for secondary purposes (analytics, marketing), the exemption no longer applies.
Buyer Verification and KYC
Exporters performing buyer due diligence (denied party screening, credit checks, end-use verification for SCOMET items) collect personal data about buyer personnel. This processing is typically covered under legal compliance or contract performance exemptions, but the scope must be proportionate. Collecting more data than necessary for verification may fall outside the exemption.
FEMA and Banking Data
FIRCs, BRCs, forex remittance records, and AD bank correspondence contain personal financial data. Processing for FEMA compliance and RBI reporting is exempt, but retention beyond the statutory period or use for credit scoring of buyers requires a lawful basis under DPDP.
Practical Steps. What to Do Now vs What Can Wait
DPDP Act compliance is not an overnight project, and the government has recognized this by rolling out rules in phases. Here is a realistic prioritization for SME exporters working with limited budgets and teams:
Do This Week
- Add a basic privacy policy to your website with DPDP-required disclosures
- Add an unsubscribe link to all marketing emails
- Publish a grievance redressal email address
- Stop collecting data you do not actually use
Do This Month
- Map all personal data across CRM, email, HR, and accounting systems
- Add consent checkboxes to web forms and inquiry forms
- Review CRM vendor agreements for data processing terms
- Enable encryption for stored sensitive data
Do This Quarter
- Implement a data retention and deletion schedule
- Create a basic data breach response plan
- Train your export and sales teams on data handling
- Audit third-party tools (analytics, marketing, cloud) for compliance
Can Wait (But Monitor)
- Full consent management platform (unless processing at scale)
- Data Protection Impact Assessment (only if notified as SDF)
- Formal DPO appointment (only if notified as SDF)
- Cross-border transfer restrictions (none notified yet)
The cost of basic compliance is modest for most SME exporters. A privacy policy can be drafted for Rs 10,000. 25,000 by a consultant. Consent mechanisms are built into most modern CRM and email tools. Data mapping is primarily an internal exercise. The big-ticket items (formal DPIAs, independent audits, DPO appointments) only apply to Significant Data Fiduciaries, which most export SMEs will not be.
Related Reading
Denied Party Screening for Indian Exporters
How to screen buyers against restricted entity lists while staying DPDP-compliant.
EDPMS Common Errors and Solutions
Fix EDPMS entries and understand the data that flows between your bank and RBI.
E-Commerce Export Compliance in India
Compliance requirements for Amazon, Shopify, and marketplace sellers exporting from India.
Export Compliance Audit Checklist
Complete audit checklist covering FEMA, customs, DGFT, and now DPDP Act requirements.
Update history
- First published.