TheDPDPAct.com -
Official WhatsApp Channel
Stay updated with the latest DPDP Act news, compliance insights, updates, and resources.
Join Our WhatsApp Channel →The Digital Personal Data Protection Act applies to every organisation processing digital personal data of individuals in India, and that universality is important — it means no sector can treat this as someone else's regulatory challenge. But "universal" and "identical" are not the same thing. The practical compliance experience for a Central Ministry looks very different from that of a fintech startup, a hospital network, or a manufacturing plant, even though all four share the same legal framework and the same 13 May 2027 deadline.
The difference isn't in the obligations — those are the same for all Data Fiduciaries. It's in the data being held, the legacy frameworks each sector already operates under, the risk profiles regulators are most likely to examine, and the specific compliance challenges each sector has spent the least time preparing for. This piece maps those differences, sector by sector.
The government's own August 2025 statement — "compliance with the DPDP Act is not optional, it is a regulatory requirement for all government bodies, businesses and organisations handling personal data" — was addressed first to ministries and states. That sequencing matters: the government has made clear it expects the public sector to lead from the front, not wait for the private sector compliance conversation to mature first.
Government bodies, Central Ministries, State Governments, and public bodies sit in an unusual position under the Act. They are simultaneously subject to the DPDP framework as Data Fiduciaries — processing citizen data at an enormous scale across welfare, identity, revenue, and service delivery functions — and accountable to a political expectation of compliance that sits above any single regulatory enforcement action. A Central Ministry that appears non-compliant with a law the government itself enacted carries a reputational and accountability dimension that goes beyond the INR 250 crore penalty.
The specific challenge for government: data minimisation and purpose limitation at scale. Government databases — Aadhaar-linked records, tax filings, welfare beneficiary data, health registries — were built to accumulate. The DPDP Act's requirement that personal data be held only for the period necessary for the purpose it was collected introduces an erasure and retention discipline that most government data architectures have never been designed to enforce. Mapping purpose to retention, across systems that have often grown without formal documentation of why specific data was collected, is a substantial exercise before consent architecture or security safeguards can even be meaningfully addressed.
For private-sector enterprises — companies handling customer, employee, or partner data — the most important framing is that DPDP compliance is not a new discipline. It's a new statutory layer on top of existing data governance practices, and the quality of those practices determines how much additional work the DPDP framework actually requires.
An enterprise that already runs ISO 27001-aligned security controls, has a functioning vendor management program, and maintains documented consent records for marketing activity is not starting from scratch. It's mapping existing controls to a new statutory framework, identifying the gaps, and closing them. An enterprise that has grown quickly on a cloud platform, accumulated user data under terms of service that don't clearly separate processing purposes, and never formally documented its data flows is genuinely starting from scratch — and eight months is a tight timeline for that starting point.
The sector-specific complication that applies most broadly to enterprises is the employee data dimension. The DPDP Act's obligations extend to employee personal data — HR records, payroll information, performance data, health information collected for insurance purposes. The "certain legitimate uses" provisions in the Act allow some processing without explicit consent in employment contexts, but the boundaries are specific and require careful mapping against what an organisation actually does with employee data, not a general assumption that employment relationships permit everything.
For enterprises operating in financial services, the regulatory complexity compounds specifically. BFSI entities — banks, NBFCs, payment aggregators, fintech platforms, digital lenders — operate under RBI's existing data governance framework alongside the DPDP Act rather than instead of it. The RBI Cyber Security Framework, Master Directions on Digital Payment Security, and 2022 Digital Lending Guidelines all remain in force. The DPDP Act adds a parallel layer of consent, notice, and security obligations — including, critically, that RBI's breach reporting window (as short as two to six hours for certain incident types) is meaningfully tighter than DPDP's 72-hour notification requirement, creating a dual notification obligation that needs a single, coherent incident response workflow to satisfy both.
Educational institutions, healthcare providers, financial services bodies, and research organisations share a characteristic that makes DPDP compliance particularly consequential: they hold data about populations with heightened vulnerability or sensitivity, and they do so in operational contexts where the data's existence has often been taken as self-justifying.
Healthcare is where the stakes are clearest. Hospitals, clinics, diagnostic centres, and health platforms process some of the most sensitive personal data in existence — diagnostic histories, treatment records, prescription information, disability and mental health data. This data has historically been held in environments with relatively weak access controls and informal data sharing practices — patient reports shared by WhatsApp with treating physicians, lab results stored on unrestricted shared drives, health app data shared with advertisers without disclosure. The DPDP Act treats health-related data as personal data attracting full fiduciary duties, and a breach in this context carries reputational consequences that significantly exceed the regulatory penalty.
Healthcare also faces a specific challenge around the right to erasure. The Act allows individuals to request deletion of personal data once the purpose for which it was collected is served. Medical records, however, often have ongoing clinical and legal value well beyond the immediate treatment purpose. Building a retention framework that balances DPDP erasure obligations against the legitimate clinical and regulatory reasons to retain medical records requires healthcare organisations to do work that most haven't yet started.
For educational institutions, Section 9 of the Act sits above everything else. Every student below 18 is a child under the DPDPA — which means every processing activity involving student data requires verifiable parental or guardian consent. The Act prohibits tracking, behavioural monitoring, and targeted advertising directed at children outright, regardless of what consent mechanisms exist. Edtech platforms built on behavioural analytics models and contextual advertising have a fundamental redesign obligation under the Act, not a consent form drafting exercise.
Industrial and commercial sectors face a compliance challenge defined more by breadth than depth. A manufacturing plant processing payroll data for 2,000 employees, a telecom operator processing call records and location data for millions of subscribers, and a retail chain processing customer purchase histories are all Data Fiduciaries, but with enormously different risk profiles, data volumes, and specific compliance priorities.
Telecom is among the highest-risk industrial sectors for DPDP purposes. Operators hold call records, SMS metadata, location histories, payment information, and device identifiers at the subscriber scale — and they hold them continuously, across years of service relationships. Most large telecom operators are strong candidates for Significant Data Fiduciary designation, which adds the DPO, DPIA, and mandatory independent audit requirements on top of the baseline obligations. The consent architecture challenge for telecom is compounded by the legacy of implicit consent embedded in service agreements that predate the DPDPA by years or decades.
IT/ITeS presents a different compliance shape. Indian IT and BPO companies frequently act as Data Processors — handling personal data on behalf of clients, under contractual terms, rather than determining the processing purposes themselves. Under the DPDPA, the Data Fiduciary remains accountable for the processor's security practices, which means Indian IT service providers are operating in a compliance environment where their own DPDP status (processor) must be distinguished from their clients' status (fiduciary) — and where the contractual terms governing their engagements need to reflect both dimensions.
For retail, the consent architecture around customer data is the central challenge. Loyalty programs, purchase history analytics, targeted marketing, and third-party data sharing are all common retail data practices that the DPDPA requires to be supported by specific, purpose-limited, withdrawable consent — and most retail businesses have never built the consent management infrastructure to manage this at scale.
Beneath the sector-specific differences, the compliance gap that applies most consistently across all four categories is the same one: the gap between what an organisation's data governance documentation claims about its data practices, and what those practices actually look like when someone maps the data flows in full.
Every DPDP compliance program starts at the same place regardless of sector: understanding what data is actually collected, where it actually lives, who actually has access to it, and what it's actually being used for. That discovery exercise rarely produces a picture that matches the existing privacy policy. The work required to close the gap between the two is what the next eight months before May 2027 are for.
At ILLUME, we work with organisations across all four of these sectors — bringing both the regulatory understanding and the technical security assessment capability that DPDP compliance requires. Whether the specific challenge is mapping data flows across a complex enterprise environment, demonstrating the reasonable security safeguards that Section 8(5) requires, or preparing for Significant Data Fiduciary obligations, reach out to Illume to scope what the right program looks like for your sector and your situation.