The regulatory landscape, translated into operations

India's Digital Personal Data Protection Act, 2023 changes what 'disposed of' has to mean. This page summarizes the law, the principles, the penalties — and how each maps to what we actually deliver.

What the law is, and why devices are in scope

The DPDP Act is India's comprehensive personal data protection law. It applies to any organization — or platform — that processes personal data, and its erasure obligations follow the data wherever it lives, including on retired laptops, phones, servers, and drives. Any entity that accepts a used device, whether through internal IT retirement or a consumer trade-in program, inherits fiduciary responsibility for the data on it.

11 Aug 2023
DPDP Act receives Presidential assent
13 Nov 2025
DPDP Rules notified
13 May 2027
Full enforcement expected
Lawful & Transparent Processing
Personal data is processed only with a lawful basis and clear notice to the data principal.
Purpose Limitation
Data collected for one purpose cannot be silently repurposed — including data on retired devices.
Data Minimisation
Hold only what is needed; excess data on old hardware is unmanaged liability.
Storage Limitation
When the purpose ends, retention must end — verifiably.
Reasonable Security Safeguards
Fiduciaries must protect data throughout its lifecycle, including at disposal.
Accountability
The fiduciary must be able to demonstrate compliance — assertions are not evidence.
Erasure Obligations
Erasure on purpose completion or consent withdrawal must be executed and provable.
  • Consent management with auditable withdrawal handling
  • Clear, itemized privacy notices to data principals
  • Personal data breach reporting to the Data Protection Board and affected principals
  • Erasure and retention rules tied to purpose completion
  • Significant Data Fiduciary obligations: DPO, independent audits, DPIAs
  • Data-principal rights: access, correction, erasure, grievance redressal
  • Conditions governing cross-border transfer of personal data
Maximum penalty per instance₹250 crore
Failure to implement reasonable security safeguardsup to ₹200 crore
Failure to notify a personal data breachup to ₹200 crore
Violations involving children's dataup to ₹200 crore
General non-complianceup to ₹50 crore
NIST SP 800-88 Rev.1DoD 5220.22-MISO 27001GDPRSOC 2HIPAAPCI DSSCPCB E-Waste RulesRBI Guidance (Regulated Financial Entities)

What we actually deliver

Device-level, cryptographically signed certificates (SHA-256 + RSA-2048)

Full chain-of-custody documentation — geo-tagged, time-stamped, digitally signed

Audit-ready reporting mapped to DPDP, RBI guidance, and CPCB requirements

"Every question answered with evidence, not assurance."

Ready to make device retirement your most documented process?

Talk to our compliance team. Every question answered with evidence, not assurance.