Your data register is now a legal register.
Every company, LLP, society, trust and professional practice that touches an Indian's personal data is a Data Fiduciary under the DPDP Act — whether it meant to be or not. S & S Associates build the notices, consent architecture, registers, policies and SOPs that turn that exposure into a documented, defensible compliance file.
In short
The Digital Personal Data Protection Act, 2023 makes any entity that decides the purpose and means of processing personal data a Data Fiduciary — with duties to give notice, obtain consent, keep data secure, and report a breach to the Data Protection Board within 72 hours. Penalties reach ₹250 crore. S & S Associates map your data flows and build the full compliance file — registers, notices, consent, policies, vendor DPAs and SOPs.
Mandatory instruments in a complete DPDP compliance file
Hours to file the detailed breach report with the Board
Maximum penalty the Data Protection Board can impose
Compliance layers the 44 instruments are organised into
The Act does not ask what kind of entity you are
It asks whether you determine the purpose and means of processing personal data. Under Section 2, a "person" includes companies, societies, trusts, LLPs, sole proprietors and associations alike — for-profit or not. If any of this sits in your systems, you are already a Data Fiduciary.
Employee & HR records
Payroll, PF/ESI, appraisals and contact data of staff and consultants — the notice duty applies to every Data Principal, including employees.
Members, donors & investors
Governing-body, shareholder, donor and funder contact details — a society or not-for-profit structure gives no exemption.
Website, app & event data
Visitors, newsletter subscribers, webinar and training participants — every intake channel is a processing activity.
Vendor & client contacts
Any personal data shared with, or received from, processors and sub-processors under a service contract.
If any of the above is in your systems today, you are already a Data Fiduciary under Chapter II of the Act — the only open question is how much of your compliance file exists in writing.
44 instruments, organised into 7 layers
Resolutions, registers, notices, consent forms, policies, agreements and SOPs — every "shall"-type obligation in the Act mapped to a specific deliverable.
Layer 1Governance & Resolutions
Board resolutions and role allocation that place accountability for data protection on record.
Layer 2Registers & Data Mapping
Data mapping, processing inventory, consent logs and breach registers — the factual backbone.
Layer 3Statutory Notices
The itemised notices owed to every Data Principal describing what is collected, why and their rights.
Layer 4Consent Architecture
Consent forms, withdrawal mechanisms and Consent Manager workflows built to be auditable.
Layer 5Policies
Master privacy policy, plus retention and breach policies that set the rules your teams follow.
Layer 6Agreements
Vendor data processing agreements (DPAs) that make third-party processing enforceable.
Layer 7Standard Operating Procedures
Step-by-step SOPs that keep every breach, grievance and rights-request clock auditable.
Two clocks start the moment you become aware
Under Section 8(6) and Rule 7 of the DPDP Rules, 2025, the timeline runs continuously — weekends and holidays included.
Intimate the Board
Alert the Data Protection Board with the nature, extent, timing and likely impact of the breach.
Notify Data Principals
Tell every affected individual in plain language what happened, what to do, and who to contact.
File the detailed report
Submit the full report — facts, causes, mitigation and steps to prevent recurrence — to the Board.
Non-compliance is priced in crores
Under the Schedule to the Act, the Data Protection Board of India can impose these amounts directly.
Failure to take reasonable security safeguards to prevent a breach.
Failure to notify the Board and affected Data Principals of a breach.
Non-compliance with obligations relating to children's personal data.
Non-compliance with any other duty under the Act or the rules.
Penalty bands can apply cumulatively for the same incident — an inadequate safeguard and a missed breach notice are two separate exposures.
Your compliance file, built to be defensible
As Company Secretaries, we produce the documents a regulator would ask for — mapped to the Act, ready to show.
Data mapping & registers
A processing inventory that records what personal data you hold, why, where it flows and who touches it.
Notices & consent forms
The statutory notices to every Data Principal and consent forms with clean, logged withdrawal mechanisms.
Policies
A master privacy policy plus retention and breach policies that set out exactly how your teams must act.
Vendor DPAs
Data processing agreements that bind your processors and sub-processors to the standard the Act expects.
Breach & SOPs
Step-by-step SOPs that keep the without-delay and 72-hour clocks auditable when an incident hits.
Free diagnostic
A short call that maps your data flows against the DPDP checklist and shows exactly where your gaps are.
The questions people actually ask
Who is a Data Fiduciary under the DPDP Act, 2023?
Any person — including a company, LLP, society, trust or sole proprietor — that determines the purpose and means of processing digital personal data in India is a Data Fiduciary under Section 2(i), whether it is for-profit or not-for-profit. There is no small-entity exemption.
What is the deadline to notify a personal data breach?
On becoming aware of a breach, a Data Fiduciary must intimate the Data Protection Board of India without delay and notify every affected Data Principal, then submit a detailed report to the Board within 72 hours (extendable only if the Board permits on written request). The clock runs continuously, including weekends and holidays.
What is the maximum penalty under the DPDP Act?
The Board can impose up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to notify a breach and for breaching children's-data obligations, and up to ₹50 crore for other contraventions. Bands can apply cumulatively for the same incident.
When does the DPDP Act become enforceable?
The DPDP Rules, 2025 were notified on 13 November 2025, starting a phased rollout. Key obligations such as security safeguards and breach notification are expected to be fully enforceable by around May 2027 — a defined window to build your compliance file before the clock matters.
What documents does a company need for DPDP compliance?
A defensible file typically includes a data mapping register, consent notices and logs, a master privacy policy, retention and breach policies, vendor DPAs, and SOPs for breach, grievance and rights-request handling. We organise these as 44 instruments across 7 layers.
How does S & S Associates help?
We run a diagnostic of your data flows, then build the registers, notices, consent architecture, policies, vendor DPAs and SOPs the Act requires — turning your exposure into a documented, defensible compliance file, with ongoing support as the rules evolve.
Find out which of the 44 instruments you're missing
A short diagnostic call maps your data flows against the DPDP checklist and tells you precisely where your exposure sits — before we quote a single rupee of fee.
Book Free DiagnosticThis page is for general information only and does not constitute legal advice. Obligations, timelines and penalties under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are governed by the Act, the rules and directions of the Data Protection Board of India in force from time to time, and are being implemented in phases. Please seek formal advice for your specific circumstances.