DPDP Act 2023 Compliance Guide for Law Firms in India | CourtMesh
    Skip to main content
    All articles

    DPDP Act 2023: What Law Firms Must Do Now to Stay Compliant (Without Getting Overwhelmed)

    8 May 202620 min readCourtMesh Team
    DPDP Act 2023 Compliance Guide for Law Firms in India

    The Digital Personal Data Protection Act, 2023 did not simply add another subject to the syllabus. It changed the shape of the work. An advisory question gets answered once and the file closes. A statutory obligation has to keep being satisfied, and has to be capable of being demonstrated afterwards. For the firms absorbing that shift, the hard part was never reading the Act. It is carrying what the Act creates.

    Ask a room of Indian advocates whether they understand the DPDP Act 2023 and you will get a slightly impatient yes. That is fair. Reading a statute closely is the job, and the vocabulary of data fiduciary, data principal, consent and notice is learnable in an afternoon. Nobody in that room is worried about the analysis.

    Now ask the same room how they are tracking the continuing obligations they have taken on for forty clients, each with its own review cycles, vendor contracts, notices to refresh and requests to answer. The answer changes. Someone mentions a spreadsheet. Someone mentions a partner who keeps most of it in her head. Someone says, honestly, that they will deal with it when a client asks. That gap between understanding the law and carrying the work is where the real exposure sits.

    From an Advisory Question to a Continuing Condition

    For two decades, personal data in India was governed by an assortment of things rather than one thing: rules made under information technology legislation, sectoral regulation for banking, telecom and insurance, contractual undertakings driven mostly by foreign counterparties, and the constitutional recognition of privacy as a fundamental right. Work arrived episodically in that world. A client had a question, you advised, the file closed. It was legal work of the shape firms are built for: a discrete question, a considered answer, an invoice.

    A dedicated statute does something different. It names roles. An organisation that determines the purpose and means of processing personal data is a data fiduciary, the individual whose data it is is a data principal, and an entity processing on the fiduciary's behalf is a data processor. That naming looks like terminology and is in fact the whole change, because once roles are defined in a statute, obligations attach to a status rather than to a transaction. Nobody stops being a data fiduciary in the months between projects.

    An opinion is delivered once. A status is occupied continuously, and has to hold up on any day somebody asks.

    The second structural change is demonstrability. A regime of this kind does not only ask whether an organisation behaved reasonably. It asks whether it can show what it did, which means records, versions, dates, and a trail of who decided what and when. A client that did everything right and wrote none of it down is in a worse position than one that did the same things and kept the paper. That requirement alone converts a great deal of advisory work into record-keeping, and record-keeping is continuous by nature.

    The status point in one line

    A client can stop having a data project. A client cannot stop being a data fiduciary while it continues to handle personal data. Advice attaches to a project. Obligations attach to a status. Nearly every operational consequence in this article follows from that one difference.

    What the DPDP Act 2023 means for law firms
    The work does not arrive as one large brief. It arrives as many small commitments that keep coming back.

    The New Work It Creates for Firms Advising Clients

    The workstreams are usually described as a list of documents to produce, and that description misleads. In each case the document is the small part. What follows the document is the part that fills a firm's year.

    Consent and notice design

    Drafting a notice and designing a consent flow is contained work. Keeping them accurate is not. Organisations change what they do with personal data constantly: a feature ships, an analytics tool is swapped, a business line starts collecting something new. Each change can quietly falsify a notice that was correct when written. Withdrawal of consent also has to keep working downstream, which is as much an engineering question as a legal one. Every consent flow is a deliverable plus a standing commitment to look at it again.

    Data processing agreements and vendor terms

    A data fiduciary that engages processors has to push obligations down a contractual chain, and the chain is longer than clients expect. Not just the cloud provider: the payroll bureau, the CRM, the email platform, the support tool, the transcription service, the marketing agency, and whoever the agency subcontracted to. The work is not producing a template, it is managing a portfolio. Vendors are onboarded, contracts renew, sub-processors change, and large suppliers revise their terms unilaterally. This is the workstream most reliably missed, because renewals are silent.

    Breach response readiness

    Nobody is ready for an incident at the moment it occurs, which is why readiness is built well beforehand. The useful deliverable is not a policy document but a rehearsed sequence: who is called, who decides, what is recorded, what is preserved, and who speaks to whom. Where notification obligations apply, their scope, timing and content have to be confirmed against the position actually in force when the incident happens, not against a note written when the Act was passed. There is now a text to rehearse against: Rule 7 of the 2025 Rules requires intimation to each affected data principal and to the Board without delay, followed by a detailed report to the Board within seventy-two hours of becoming aware, and it commences with the substantive tranche in May 2027. Note that the CERT-In directions under the information technology legislation are in force now and run on their own trigger and their own clock. For the firm, incident support is a standing commitment that has to work on a bad Friday evening.

    Data principal rights requests

    The Act gives individuals rights they can exercise against a data fiduciary. For the client that means a queue: requests have to be recognised as requests, verified as genuine, answered and recorded. For the firm it means design work, an intake route, an identity check, an escalation path, and then the hard ones themselves. A request touching litigation material, a former employee, or data about someone who is not the client's customer comes back to the firm as an urgent question with no notice. That is small, unschedulable, high-attention work, which is what a matter-centric practice handles worst.

    Retention and deletion

    Retention is where policy meets plumbing. A schedule is straightforward to draft and genuinely difficult to implement, because data copies itself in the ordinary course of business. The record in the primary system has a shadow in the warehouse, an export in a spreadsheet, an attachment in three inboxes, and a copy in a backup taken before anyone thought about any of this. Deleting the first is easy. Knowing about the other four is the work, and verifying that deletion actually happened is a recurring task rather than a sign-off.

    Monitoring as the rules and practice develop

    This is the workstream firms most often forget to price. A framework of this kind does not arrive complete. Rules are made, guidance emerges, a regulator develops working practice, and the market settles on what counts as reasonable. The Indian framework has now moved past the stage where a firm can be vague about it: the Digital Personal Data Protection Rules, 2025 were notified in November 2025, and their commencement is staged. The rules constituting and governing the Data Protection Board took effect on notification, the consent manager registration rule follows twelve months later in November 2026, and the substantive tranche, which carries the notice, consent, security safeguard, breach intimation and data principal rights obligations, commences eighteen months after notification, which falls in May 2027.

    That staging has an awkward consequence a firm should be explicit about with clients rather than smoothing over. For most of a client's substantive obligations there is a published standard to build to and a date that has not yet arrived, which means nobody is in breach of them yet and nobody can be said to be compliant with them yet either. What exists is a state of preparation, measured against a text you can now actually read. Advising on that honestly is different work from advising on a live regime, and it is worth saying which of the two you are doing. Confirm what is in force on the day you act rather than taking it from any earlier note, including this article. A firm advising on the Act has effectively undertaken to notice when something moves and tell the clients it affects.

    The table below sets each workstream against the thing that actually matters about it: not the document, but the reason the document is never the end of it.

    WorkstreamThe one-off deliverableWhat makes it a continuing obligation
    Consent and noticeA drafted notice and a consent flow for each purpose.Purposes change as the business changes, withdrawal has to keep working downstream, and a notice accurate at launch goes out of date silently, with nothing to announce the drift.
    Vendor and processor termsA negotiated data processing agreement or agreed clauses.Vendors are onboarded, contracts renew, sub-processors change, supplier terms are revised. Each renewal is a point at which the data terms should be re-checked, and renewals arrive without asking.
    Breach readinessAn incident plan with a named escalation chain.People leave and systems change, so a plan nobody rehearses is a document rather than a capability. What must be notified, and how quickly, has to be confirmed against the position then in force.
    Data principal rightsA documented process for receiving and answering requests.Requests arrive unpredictably and cannot be scheduled. Routine ones consume the client's time; awkward ones come back to the firm with urgency attached.
    Retention and deletionA retention schedule mapped to categories of data.Copies proliferate faster than policies. Confirming deletion actually happened across systems, exports and backups is periodic verification, not a single sign-off.
    Records and demonstrabilityA compliance register and a first set of records.A register has value only while it is current. One that has quietly stopped being updated is worse than none, because it still looks authoritative to whoever relies on it.
    Monitoring the frameworkA note on the position as it stands today.Rules, guidance and practice develop. Somebody has to notice the change, assess it, and work out which clients it touches.

    The Firm Is a Data Fiduciary Too

    Here is the part that gets least attention and deserves the most. Firms have largely read the DPDP Act 2023 as a subject to advise on. It is also a statute the firm is subject to. Very few professional service businesses in India hold as much personal data, about as many people, in as sensitive a form, with as little internal structure, as a busy law firm. Consider what is sitting in your systems right now.

    • Client identity documents, bank details and billing records collected at onboarding
    • The personal circumstances that are the substance of a family or employment brief
    • Medical records and income proof of claimants and their families in a compensation matter
    • Financial records of a judgment debtor gathered for an execution petition
    • Allegations about individuals in a criminal brief, many of whom have been convicted of nothing
    • Recruitment records, payroll and identity documents for your own advocates, clerks and staff
    • Diligence material on directors and shareholders from a transaction that may never have closed

    Notice how much of that was never collected from the person it concerns. A large share of what a law firm holds is personal data about people who did not choose to deal with the firm, do not know the firm holds it, and would be surprised how long it has been sitting there.

    Client data, held for years

    Engagement records, onboarding documents, billing details, and the personal circumstances that make the matter what it is. It stays long after the matter ends, because a closed file is not a deleted file and nobody decided when it should become one.

    Data about people who never engaged you

    Opposing parties, witnesses, family members, employees of a counterparty, individuals named in a report. They did not choose your firm, and the duty you owe your client says nothing about what you owe them.

    The firm's own employment records

    Advocates, interns, clerks and support staff generate recruitment files, payroll data and performance material. On this data the firm is simply an employer, with obligations that look much like any other employer's.

    Copies in places you do not control

    The working copy on a personal laptop, the brief forwarded over a consumer messaging app, the PDF in four inboxes, the scan on a junior's phone. The real data map is wider than the document system suggests.

    Confidentiality is not the same question

    The instinctive response is that firms already handle this, because confidentiality and privilege have governed the profession for as long as it has existed. That response is sincere and it is not sufficient, because confidentiality answers a narrower question. It tells you not to disclose. A data protection framework asks a wider set: on what basis are you processing this at all, what were people told, how long are you keeping it, who else inside the firm can reach it, and what happens when it leaks. A firm can be scrupulously confidential for thirty years and never once have asked any of those.

    There are also genuinely hard questions where this framework meets the conduct of litigation. How obligations apply to material already on the court record, what the position is for data received in the course of a brief rather than collected directly, and how processing necessary for legal proceedings or required under another law is treated: these turn on the provisions as they stand and on the facts of the particular processing, and they need working through on advice rather than settling by assumption in either direction. What is not seriously arguable is that the questions do not arise for law firms at all.

    Before reading the list below, do the exercise honestly. How many of these are true of your firm this morning?

    Client identity documents retained indefinitely, because nobody ever decided when they should go
    Case files on personal laptops and personal cloud accounts, outside anything the firm controls or can inventory
    Matter material circulated over consumer messaging apps, where the firm cannot say who still holds a copy
    Interns and departing associates who keep access to matter folders long after their involvement ended
    Vendors touching firm data, from transcription to IT support and cloud storage, engaged on no written data terms
    No prepared answer for the day a former client, an employee, or an opposing party asks what you hold about them
    No incident plan, so the first hour after something goes wrong is spent working out who is in charge
    No record of what the firm holds, where it sits, or who inside the firm can reach it

    A firm advising clients on the DPDP Act 2023 while carrying most of that list is in an awkward position, and the awkwardness is better confronted internally than externally. Part of it is credibility: it is hard to run a data mapping exercise for a client knowing your own firm has never attempted one. The larger part is that the obligation applies to the firm on its own account, and the exposure does not wait for a client to notice.

    A firm that cannot say what personal data it holds is not well placed to tell a client to know what it holds.

    Why This Load Defeats a Diary and a Spreadsheet

    Why continuing compliance obligations overwhelm manual tracking in a law firm
    Litigation is a few heavy things that announce themselves. Compliance is many light things that do not.

    Litigation practice is organised around a small number of large objects. Each matter is heavy, distinct and memorable, with a name, a client who calls, and dates that arrive with an institution behind them. Ten live matters occupy the mind, and the mind holds them tolerably well, which is why the diary survived as long as it did. Continuing compliance work has the opposite shape, and four features of it defeat manual tracking regardless of how careful anyone is.

    Many small items, not a few large ones

    A hearing announces itself. A periodic notice review does not. The failure mode is not that any instance is difficult, it is that no single instance feels important enough to interrupt anything else, so it slips by a week, repeatedly, for a year.

    Spread across clients, not concentrated

    Fifty clients with four continuing commitments each is two hundred live obligations, most dormant most of the time. No individual holds that map, and no single conversation surfaces more than a fragment of it.

    Triggered by events you never see

    A client adds a vendor, launches a feature, changes a data flow, or has an incident. The obligation starts running before your firm hears about it, which is the failure pattern litigators know from clocks that begin elsewhere.

    Nothing goes wrong visibly

    Miss a hearing and there is a consequence that week. Miss a review cycle and there is none until something else goes wrong, at which point the omission gets examined closely. Silence looks exactly like compliance until it does not.

    The tooling mismatch follows directly. A diary works when items are few, heavy and self-announcing. This work is many, light and silent. The spreadsheet then fails in the way every firm has watched it fail: somebody sets it up carefully, it is accurate for a quarter, then a busy month arrives. Because nobody owns it, nobody notices it has stopped being true. It stays open on a screen, still looking authoritative, describing a world that expired weeks ago.

    One compounding factor makes all of this worse. Nobody is doing DPDP work instead of litigation. The recurring obligations land in the same week as the hearings, the drafting and the client calls, and they lose that competition every time, because a hearing has a court behind it and a review cycle has only a note.

    What a Firm Should Actually Do

    The answer is unglamorous, which is a point in its favour. There is no clever structural fix for many small recurring obligations. There is standardising what you produce, keeping one honest record of what is owed and when, giving every line an owner, and arranging things so that what is due presents itself rather than waiting to be remembered.

    1

    Standardise the deliverables

    Decide once what a notice review, a vendor data schedule, a rights request process, a retention schedule and an incident plan look like when your firm produces them. A standard deliverable is faster to produce, easier to delegate, easier to review, and far easier to update across every affected client at once when the position moves.

    2

    Keep one register of client obligations and dates

    One record, for the whole firm, of every continuing obligation it has taken on: what it is, which client, what triggers it, when it next falls due, and where the current deliverable lives. This register is the single most useful artefact in the exercise, and its value collapses the moment it goes stale, which is why it belongs where the firm already works.

    3

    Assign an owner to every line

    Each recurring item belongs to a named person, not to a team and not to the firm in general. Ownerless items are the ones that quietly stop happening, because everybody assumes somebody. When an owner leaves or changes seat, reassignment should be a deliberate act with a record.

    4

    Make what is due surface rather than be remembered

    The weekly question should not be what have we forgotten, which depends on somebody's memory on a busy morning. It should be here is what is due, produced without anyone going looking. That reversal is the entire reason for using a system rather than a document.

    5

    Run the whole exercise on the firm itself

    Do for your own firm what you would do for a client. Work out what personal data you hold and where it actually lives, including copies outside the document system. Decide retention for matter files and identity documents. Put written data terms in place with vendors who touch firm data. Tighten who can open which matter, and write down what happens in an incident.

    6

    Re-check when the position changes

    As rules, guidance or accepted practice develop, the register answers the otherwise unanswerable question: which clients are affected, and which deliverables need revisiting. Without it, a firm chooses between writing to everyone about everything and writing to nobody, and it usually chooses the second.

    If a firm does only two of these, make them the register and the ownership. Standardisation saves time and careful reading avoids error, but an obligation that is written down and owned by a named person is the one that survives a busy quarter.

    The Honest Limits

    Everything above is meant to be operationally useful, which makes it important to be precise about what it is not. An article about compliance is a poor place to be loose with claims, and the most dangerous outcome of building a better system is a firm that starts trusting it further than it can carry.

    Not legal advice, and no tool makes a firm compliant

    This article is general commentary for practitioners. It is not legal advice and it is not a statement of what the law requires of you or your clients. Compliance obligations under the DPDP Act 2023 depend on the specific facts of an organisation, on the role it occupies in a given processing activity, and on the state of the Act, the rules made under it, and the practice around them as they stand when you act. All of that must be checked against the current position, not taken from any article, including this one. Equally: no software makes a firm or its clients compliant. A system can hold obligations you have already identified and surface dates you have already entered. It cannot identify an obligation nobody thought of, it cannot decide what the Act requires of a particular client, and its silence is not confirmation that nothing is due. The analysis, the judgement and the responsibility stay with the advocates.

    The corollary matters too, because it is where a well-run firm slips. A register is only as complete as the analysis that populated it. It records the decisions you have made and says nothing about the ones you have not made yet. Treat it as a memory aid for work already thought through, never as assurance that the thinking is finished.

    Where CourtMesh Fits

    Within that boundary, it is worth being exact about what a platform contributes. CourtMesh does not advise on the DPDP Act 2023, does not assess anyone's compliance, and cannot tell you what a client's obligations are. What it addresses is the second half of this article: keeping the work in one place, and making what is due visible instead of remembered.

    Obligations and dates in one place

    CourtMesh My Cases holds matters with task and deadline tracking, and deadlines carry urgency states such as Overdue, Urgent and Due Soon. A review due this week looks different from one months away, which is the reversal described above applied to work that would otherwise live in a diary.

    One vault instead of many drives

    Notices, policies, schedules and successive versions of each deliverable sit in a shared document vault rather than on individual laptops, with team collaboration under access controls. Who can open a matter becomes a decision rather than an accident.

    Vendor terms tracked as contracts

    CourtMesh CLM handles contract intake, approvals, and obligation and renewal tracking. That is the right shape for processor and vendor data terms, because those are contracts with dates attached, and they are the workstream most reliably missed at renewal.

    One login across the practice

    Research, My Cases and CLM sit on one platform, so the record of what is due is not in a different tool from the matters and documents it refers to. The register you never open is the register that goes stale.

    On the firm's own position as a data fiduciary, the honest statement is narrow, and it is narrower than the sentence vendors in this market usually reach for. We do not claim that CourtMesh is DPDP Act compliant, and you should be sceptical of any vendor who does. There is no certification scheme under the Act, no regulator has assessed us, and the substantive obligations do not commence until May 2027, so the claim would have nothing behind it. It would also sit badly next to the point made further up this article, which is that no software makes anybody compliant.

    What we will state, because these are facts about our own arrangements rather than conclusions about the law, is that the platform is hosted in AWS Mumbai and that customer data is not used to train AI models. Those two facts stand on their own, they are verifiable in the ordinary way you would verify any vendor commitment, and they are fair questions to ask of anybody you hand client material to. They tell you where your data sits while it is with us. They tell you nothing about the rest of your firm, which remains yours to work out.

    Make the recurring work visible

    The DPDP Act 2023 turned a category of legal work from something you finish into something you carry. The firms that struggle will not be the ones that misread the statute. They will be the ones that took on two hundred small continuing commitments across fifty clients and tried to hold them in a diary, a spreadsheet and a partner's memory, while being a data fiduciary in their own right and never quite getting to that part. Keep one register of what is owed and when, give every line an owner, and let the system tell you what is due. CourtMesh brings matters, deadlines, documents and contract obligations into one place behind one login, with the access controls a growing firm needs. It will not make you or your clients compliant, and nothing honest would claim to. It will stop the work being invisible until it is late.

    Explore CourtMesh
    DPDP ActData ProtectionLaw FirmsComplianceIndia
    X LinkedIn