Advisory · Virtual DPO DPDP Act, 2023 · Rules, 2025 · GDPR Art. 37(6)

Virtual Data Protection Officer

India's DPDP Act, 2023 — switched on by the Rules notified in November 2025 — expects your organization to be able to point to a person: a published contact for data principals' questions, a grievance owner on a clock and, once you are designated a Significant Data Fiduciary, a Data Protection Officer who is an individual, based in India, answerable to your board. That person is scarce to hire, expensive to keep and rarely a full-time seat. We provide the function on a service basis: a named, India-based privacy professional with Intect's privacy practice behind them, owning your programme from the data map to the breach drill — and covering the GDPR where your users are in Europe.

A designated privacy professional — and the office behind them. CIPP/E-certified. Delhi-based.

DPDP Act, 2023 DPDP Rules, 2025 Data Protection Board of India GDPR Art. 37(6) CIPP/E-certified professionals
Regime
DPDP Act, 2023 + DPDP Rules, 2025
Mandate
SDF DPO · Sec 10(2)(a)
Clock
Rules notified Nov 2025 · core duties mid-2027
Also covers
GDPR Arts. 37–39
02

India's law names a role. Filling it is the hard part.

India's data-protection regime arrives in two instruments: the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025 that operationalize it — notified in November 2025 with a phased compliance clock.

(If you have seen the regime called "DPDPA 2025", that shorthand bundles the two together.) Read them side by side and they keep pointing at a person. Every Data Fiduciary must publish the business contact of a Data Protection Officer or of someone able to answer data principals' questions — prominently, and in every response to a rights request (Sec 8(9); Rule 9) — and must run an effective grievance mechanism that answers within a published window the Rules cap at ninety days (Sec 8(10); Rule 14(3)). Once the government designates you a Significant Data Fiduciary, the officer stops being optional and becomes an individual, based in India, responsible to your Board of Directors and fronting your grievance redressal (Sec 10(2)(a)).

The role is genuinely hard to staff. It needs law, operations and security in one head; enough seniority to face a board and the Data Protection Board of India; and enough distance to disagree with the people paying for it. Outside the largest organizations it is rarely a full-time seat, which makes the hire harder still — too senior to be cheap, too part-time to justify the salary. Notice, though, what the Act asks of every fiduciary below the significant tier: "a person who is able to answer" — a function to be owned, not necessarily a payroll entry. That is the office we provide: the named professional, and the machinery behind them.

"The law doesn't ask whether privacy is somebody's job. It asks who — by name, published on your website, answerable to your board."
03

Who must do what, and by when

The DPDP regime is a ladder: every Data Fiduciary carries the base obligations, Significant Data Fiduciaries carry the officer mandate on top, and the Rules set the clock for both. This is the current legal position — find your rung.

Rung 1 — Every Data Fiduciary DPDP Act, 2023 + Rules, 2025
Published contact person · Sec 8(9) · Rule 9Grievance mechanism · Sec 8(10)≤ 90-day response · Rule 14(3)Breach: principals informed without delay · Rule 7Detailed Board report ≤ 72 hours · Rule 7Reasonable security safeguards · Rule 6
A published contact

The business contact information of your Data Protection Officer "if applicable" — or of a person able to answer data principals' questions about their data — displayed prominently on your website or app and included in every response to a rights request (Sec 8(9); Rule 9).

A working grievance mechanism

An effective grievance-redressal mechanism (Sec 8(10)) that responds within your published window, which the Rules cap at ninety days (Rule 14(3)) — and which data principals must exhaust before they can complain to the Data Protection Board, so a grievance handled well is usually the end of the matter.

Breach clocks

On a personal data breach: intimation to every affected data principal without delay, a first description to the Data Protection Board without delay, and the detailed report to the Board within seventy-two hours (Rule 7).

Reasonable security safeguards

The Rule 6 minimums behind all of it — encryption or masking, access control, logs and monitoring, backups — the obligation the breach clocks assume you have already met.

Rung 2 — Significant Data Fiduciary Designated by Central Govt · Sec 10(1)
DPO mandatory · Sec 10(2)(a)IndividualBased in IndiaResponsible to the BoardGrievance contact point+ independent data auditor · Sec 10(2)(b)+ DPIA & audit every 12 months · Rule 13+ algorithmic due diligence · Rule 13
Designation

Notified as an SDF by the Central Government, on factors including the volume and sensitivity of the data you process and the risk to data principals (Sec 10(1)).

The DPO mandate

A Data Protection Officer who is an individual, is based in India, is responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal (Sec 10(2)(a)).

The assurance duties

An independent data auditor (Sec 10(2)(b)), plus a Data Protection Impact Assessment and audit once in every twelve months with significant observations reported to the Data Protection Board (Sec 10(2)(c); Rule 13) — alongside Rule 13's algorithmic due-diligence and data-localization duties.

November 2025

The DPDP Rules, 2025 notified; the Data Protection Board and the regime's procedural machinery take effect.

The eighteen-month window

The runway the Rules grant for the core obligations — for building the contact-person, grievance, breach and DPO functions, not for deferring them.

Mid-2027

The core Data Fiduciary obligations — including the contact-person, grievance, breach-reporting and SDF duties — become enforceable.

FIG. 01The DPDP obligations ladder — every Data Fiduciary, the SDF DPO mandate on top, and the enforcement clock for both

Whichever rung you stand on, the obligations converge on one practical answer: a named person, a grievance queue that answers in time and a breach process that can hit a seventy-two-hour clock. That is the office we provide. For the full readiness programme behind the law — data mapping, notice, consent, rights — see our DPDP Act page.

04

What the office owns

A DPO is not a mailbox. These are the nine standing responsibilities the function carries — continuously, not as a one-off project.

Privacy programme governance 01

A charter, a policy suite and an annual privacy plan with a board calendar — the mandate of the office, exercised on a defensible cadence.

Data mapping & records of processing 02

What personal data you hold, where it flows, why and on what basis — the processing records everything under the DPDP regime depends on, and the RoPA (GDPR Art. 30) where Europe reaches you.

DPIAs & privacy by design 03

Data protection impact assessments on the cadence the law prescribes — every twelve months for SDFs (Sec 10(2)(c); Rule 13), and for high-risk processing under the GDPR (Art. 35) — with early advice so new products ship privacy-sound instead of being retrofitted.

Consent & notice architecture 04

Notices in clear, plain language; consent that is specific, informed and as easy to withdraw as it was to give; verifiable parental consent where children's data is in play.

Rights & grievance handling 05

Access, correction, erasure and grievance workflows that answer within the clock — your published window, at most ninety days, under the DPDP Rules, and one month under the GDPR where it applies.

Breach notification readiness 06

Playbooks for the 72-hour clocks — the detailed report to the Data Protection Board (Rule 7) and, where Europe applies, the supervisory-authority notice (Art. 33) — rehearsed before they are needed.

Vendor & processor management 07

Processor contracts and DPAs, due diligence on the parties that touch your data, and lawful mechanisms for the transfers your operations rely on.

Regulator & authority liaison 08

The prepared, cooperative contact point when the Data Protection Board of India calls — or an EU supervisory authority (Art. 39(1)(d)–(e)) — with the records already in order.

Training & board reporting 09

A workforce that knows its obligations and a board that hears about privacy on schedule — with the attendance and reporting records to prove both.

One office · one named contact · continuous, not project-based
05

One function, three ways to hold it

The right structure depends on your rung of the ladder — Data Fiduciary or Significant Data Fiduciary — and what your counsel is comfortable putting on the record.

Data Fiduciary

Named external DPO

For Data Fiduciaries below the significant tier, the appointment is straightforward: our named, India-based privacy professional serves as the published contact person and grievance owner the DPDP regime requires (Sec 8(9); Rule 9), with Intect's practice behind them. Where the GDPR also reaches you, the same professional serves as your designated DPO under a service contract — the model Article 37(6) expressly provides for, structured the way the EDPB's DPO guidelines describe: a team that carries the tasks together, under one lead contact in charge of your account.

Significant Data Fiduciary

DPO office behind your appointee

the conservative structure for SDFs

You appoint the DPO — an executive who satisfies the statute, including the DPDP requirement that an SDF's officer be an individual based in India, responsible to the board. We run the office behind them: the data maps, DPIAs, registers, rights queues, breach playbooks and board packs that make the appointment real rather than nominal. The title stays in-house; the workload and the expertise don't have to. This is the conservative structure for Significant Data Fiduciaries while external appointments remain unsettled ground.

Interim · handover

Interim & first DPO

A resignation to cover, a customer or regulator question that can't wait, or a first privacy programme to stand up before the Rules' obligations bite: we hold the function while it matters, build the machinery, and hand over cleanly to the permanent hire — including helping you find and brief that hire. Nothing we build leaves with us.

06

Independence isn't a courtesy. It's a design constraint.

Both laws assume the DPO can tell the organization things it doesn't want to hear — and keep their job afterwards.

The DPDP Act builds independence in through the reporting line: a Significant Data Fiduciary's officer answers not to a function head but to the Board of Directors itself (Sec 10(2)(a)) — the statute's way of saying the role must be able to disagree and survive. The GDPR writes the same protection out in full: the DPO "does not receive any instructions" in the exercise of the tasks, "shall not be dismissed or penalised" for performing them, and reports directly to the highest management level (Art. 38(3)) — whether or not they are an employee (Recital 97). Article 38(6) then draws the boundary that disqualifies most convenient candidates: the DPO may hold other duties only if they create no conflict of interest, and the EDPB-endorsed guidelines translate that into a rule of thumb — anyone who determines the purposes and means of processing cannot mark their own homework, which typically rules out the CEO, COO, CFO, head of marketing, head of HR and head of IT. We run every engagement to that standard, whichever law reaches you.

This is where an external DPO is often structurally stronger, not weaker: no second hat, no career stake in the product roadmap, and an engagement that survives internal politics.

But independence without access is just distance — the office must be involved early and resourced properly, a duty the GDPR makes explicit (Art. 38(1)–(2)) and any board-responsible officer needs in practice. So we set the operating model up front: standing invitations to the forums where processing decisions are made, defined information flows, an escalation path to the board, and dissent recorded in writing when advice is not followed.

07

Also serving people in the EU

One office can front both regimes — and the EU regime is where the service model has its oldest legal footing.

The GDPR has required a data protection officer for a wide class of organizations since 2018 — mandatory when you are a public authority, when your core activities involve large-scale regular and systematic monitoring of data subjects, or when they involve large-scale processing of special-category or criminal-convictions data (Art. 37(1)). The tests apply to controllers and processors alike, so an Indian SaaS or IT-services firm can be caught in its own right. And the GDPR is explicit about the model on this page: the DPO "may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract" (Art. 37(6)) — the clause that gives DPO-as-a-service its legal pedigree — with the EDPB-endorsed DPO guidelines describing exactly our structure: a service-provider team carrying the function together, under a single named lead in charge of each client. If you serve both markets, we run one privacy office to the stricter standard: one data map, one rights machinery, both clocks. For the EU regime end to end, see our GDPR page.

A GDPR DPO is mandatory when Art. 37(1)
Public authority or bodyLarge-scale regular & systematic monitoringLarge-scale special-category or criminal-convictions dataControllers and processors alike
External is explicit Art. 37(6)

"…or fulfil the tasks on the basis of a service contract."

The express legal basis for an external DPO.

08

Breach-readiness, written by people who test defences

Most DPO services come from law practices. Yours would come from an offensive-security firm — and on one subject, that changes the work.

The legal view of a breach

Notification as paperwork

On paper, a personal data breach is a reporting exercise: assess, notify the Data Protection Board — or the supervisory authority — within the 72-hour window, inform the people affected, document everything. A DPO drafted from precedent can write that playbook. What the playbook assumes — that the intrusion will be detected promptly, contained cleanly and understood well enough to describe — is exactly the part legal drafting cannot supply.

The tested view

Notification as the last step

Intect is a CERT-In empaneled security firm; the people behind your DPO test systems for a living. So the safeguards the DPDP Rules set as mandatory minimums (Rule 6) and GDPR Article 32 expects — encryption, access control, logging, monitoring, the ability to detect and investigate unauthorized access — are treated as things to validate, not recite, with our assessment teams cross-linked where testing is wanted. The 72-hour drill is rehearsed against realistic intrusion scenarios, and if the real day comes, your report to the Data Protection Board is written by someone who understands what happened — not just what must be filed.

Notification is the last step of breach-readiness. Detection, containment and evidence are the first — and they are testable.

CERT-IN EMPANELED
09

What you receive

The office produces the artefacts a working privacy programme runs on — and the named person who stands behind them.

01

A named privacy professional

Your designated officer or contact person, published on your website and notices as the law requires (Rule 9; Art. 37(7) where the GDPR applies), reachable by data principals, regulators and — where Europe applies — data subjects.

02

Privacy programme charter & annual plan

The mandate, the policy suite and the board calendar that give the function authority and rhythm.

03

Data map & records of processing

The DPDP processing records and the RoPA, kept current as systems and vendors change.

04

DPIA register & assessments

A repeatable impact-assessment method, applied on the cadence the law prescribes and maintained as a register.

05

Consent & notice architecture

Notices, consent and withdrawal flows, and children's-data handling designed against the actual legal texts.

06

Rights & grievance machinery

Request workflows with response-time tracking against the DPDP clock — your published window, at most ninety days — and the GDPR's one month where it applies, plus the grievance mechanism the Act requires.

07

Breach playbook, rehearsed

Detection-to-notification runbooks built to the Rule 7 clock — and Art. 33 where it applies — exercised with your team before they are needed.

08

Vendor & processor governance

DPA templates and reviews, processor due diligence and a transfer-mechanism register.

09

Board reporting & training records

Regular reporting to your governing body and workforce training with the evidence trail kept.

DPDP Act, 2023 DPDP Rules, 2025 Data Protection Board of India GDPR Arts. 37–39 CIPP/E-certified team CERT-In Empaneled
10

Why teams choose Intect for the DPO function

CIPP/E-certified CERT-In Empaneled Delhi-based Independent by structure

India-based, as the Act expects — A Delhi-based team for a law that wants its officers in India: grievance clocks handled in your time zone, and the Rules tracked as they phase in through 2027.

Privacy-credentialed, in-house — CIPP/E-certified privacy professionals on staff — people who work the law and the practice, not a template kit with a logo on it.

Independent by structure — External, conflict-free and board-facing — the position the DPDP's board-responsibility design assumes and GDPR Articles 37–39 protect.

Security-literate — Your DPO sits beside researchers who test controls for a living, so "reasonable security safeguards" is a judgement made from evidence, not from a vendor questionnaire.

11

Frequently asked questions

Do we actually need a DPO under the DPDP Act?

Only Significant Data Fiduciaries must appoint a Data Protection Officer — an individual, based in India, responsible to the board (Sec 10(2)(a)). But every Data Fiduciary carries most of a DPO's public-facing job under another name: a published contact person able to answer data principals' questions (Sec 8(9); Rule 9) and a grievance mechanism that responds within a published window of at most ninety days (Rule 14(3)) — enforceable from mid-2027 under the Rules' phased timeline, which is a window for building the function, not deferring it. One point in your favour: data principals must exhaust your grievance mechanism before they can complain to the Data Protection Board, so a grievance handled well is usually the end of the matter. We assess your actual processing and tell you which rung of the ladder you stand on — including when the answer is "you don't need us for this."

Can an external provider legally be our DPO under the DPDP Act?

It depends on your tier, and we tell you plainly rather than paper over it. If you are not a Significant Data Fiduciary, no DPO is mandated at all, and your published contact person and grievance owner can plainly be an outsourced professional — the Act asks for "a person who is able to answer," not an employee. If you are an SDF, the Act requires your DPO to be an individual, based in India, responsible to your board — it does not say "employee," but it has no GDPR-style service-contract clause either, and no official guidance yet settles whether an external individual qualifies. So we structure the engagement to hold either way: our named, India-based professional formally appointed where your counsel is comfortable, or your internal appointee with our office doing the work behind them — the conservative structure while the question remains open.

We also serve people in the EU — does the GDPR change the answer?

It adds a second, better-settled one. The GDPR makes a DPO mandatory for public authorities and for organizations whose core activities involve large-scale regular and systematic monitoring or large-scale special-category processing (Art. 37(1)) — and it catches processors too. It is also explicit that the officer may be external: Article 37(6) allows the DPO to "fulfil the tasks on the basis of a service contract," with the EDPB-endorsed guidelines describing a service-provider team under a single named lead — exactly our model. Two nuances we raise ourselves: the guidelines recommend a GDPR DPO be located in the EU, while accepting that an organization with no EU establishment may be served effectively by one outside it — we assess which side of that line your footprint falls on before you appoint us. And if you designate a DPO voluntarily, the full requirements of Articles 37–39 attach as if the designation were mandatory — so don't hand out the title casually.

How is a virtual DPO different from a privacy consultant?

A consultant advises and leaves. A DPO is designated: named on your website, tasked by statute with informing, advising and monitoring, protected in their independence, and on the record as your contact point for individuals and regulators — with the continuity those duties imply. The guidelines are strict about the difference: an advisor who doesn't meet the DPO requirements shouldn't carry the title. Both are legitimate instruments — if what you need is a one-time readiness programme rather than a standing officer, our DPDP Act and GDPR readiness services are the better fit, and we will say so.

Can the same person be our DPO and our CISO?

They shouldn't be. The DPDP Act makes the point structurally — the SDF's officer answers to the Board of Directors, not to a function head — and the GDPR makes it explicit: Article 38(6) permits a DPO to hold other duties only where they create no conflict of interest, and the guidelines' rule of thumb is that anyone who determines the purposes and means of processing is conflicted, naming the head of IT among the usual examples. A CISO decides how personal data is secured; a DPO monitors whether those decisions comply. One person doing both is marking their own homework. The roles pair well — they should just be different people. We offer both as services, staffed separately with separate mandates: see our Virtual CISO page.

Does appointing a DPO make us compliant — and who carries the liability?

No, and it stays with you — any provider who implies otherwise is misdescribing the law. The DPDP Act places its obligations on the Data Fiduciary; appointing an officer discharges one of them, not all of them. The GDPR reasons identically — compliance is expressly the controller's responsibility, and the DPO guidelines state it directly: data protection compliance is a corporate responsibility of the data controller, not of the DPO. What a DPO — internal or virtual — actually does is inform, advise, monitor and front the programme, which is what turns compliance from an assertion into something you can demonstrate. And since both regimes are laws rather than certification schemes, there is no "DPDP certificate" or "GDPR certificate" to obtain from us or anyone else.

12

The office connects to the programme

A DPO runs the machinery; these services build and prove the parts.

Scope a DPO engagement

Give privacy a name.

Tell us what you process — we'll tell you honestly which rung of the DPDP ladder you stand on, what mid-2027 requires of you, and scope the DPO function that fits.