Data has quietly become one of the most valuable assets of almost every organisation. A hospital stores patient records and diagnostic reports, a university maintains years of student and applicant information, an NBFC processes KYC and financial information, while even a small business may have employee records, customer details, CCTV footage and thousands of contacts stored across its ERP, CRM, emails and Excel sheets.
The Digital Personal Data Protection Act 2023, commonly referred to as the DPDP Act 2023, brings a new level of accountability to the way organisations collect, use, store, share and eventually erase digital personal data.
For organisations operating in Delhi, Gurugram, Noida, Faridabad, Ghaziabad and the wider NCR, this is particularly relevant. Delhi NCR has a very high concentration of schools, universities, hospitals, financial institutions, IT companies, manufacturing businesses and service organisations. Delhi alone reported 5,556 recognised schools with around 44.91 lakh students in 2024-25. The Economic Survey of Delhi 2025-26 also reports 1,181 private hospitals and nursing homes as of December 2025. Add the education and healthcare ecosystems of Noida, Gurugram, Faridabad and Ghaziabad, and the volume of personal data being processed across NCR becomes enormous.
This is why DPDP Act compliance in Delhi NCR deserves management attention today, rather than being treated as something that can be addressed when a problem arises.
What is the DPDP Act 2023 and Why Does It Matter?
The Digital Personal Data Protection Act provides India’s legal framework for processing digital personal data. At its heart, the idea is fairly straightforward: organisations may legitimately need personal data to conduct business and provide services, but the individuals to whom that data relates also have a right to protection of their personal data.
Think about an ordinary company. It may have employee names, addresses, photographs, PAN information, salary details and bank accounts. Its sales team may have thousands of customer names, email addresses and mobile numbers. HR may have CVs of people who applied for jobs several years ago. CCTV systems may contain employee and visitor footage. Marketing teams may maintain old databases of prospects, while information may also exist with payroll providers, cloud platforms, CRM vendors and other service providers.
The important question under the DPDP Act for businesses is therefore not simply whether the company has a privacy policy. The bigger question is whether the organisation actually understands its personal data.
What are you collecting, why are you collecting it, where is it stored, who can access it, whom are you sharing it with, how are you protecting it, how long do you need it and what happens when you no longer need it? These questions form the foundation of a practical DPDP compliance framework.
Why Delhi NCR Organisations Should Start Early
It would not be correct to claim that the Government has officially announced that Delhi NCR will be the first region targeted for DPDP audits. There is no need to make such a claim either. The scale of personal-data processing in the region provides enough reason for organisations to prepare.
Delhi NCR combines a large population with a dense concentration of educational institutions, healthcare facilities, corporate offices, financial-services companies, technology businesses and manufacturing units. Many of these organisations have also been operating for decades, which means the challenge is not restricted to the data being collected today. There can be years of historical personal data sitting across old applications, servers, backup systems, emails, laptops, spreadsheets and third-party platforms.
The longer an organisation waits, the larger this data estate can become. DPDP Act compliance is therefore easier to approach as a planned exercise than as an emergency project initiated after a complaint, security incident or regulatory requirement. Education and healthcare illustrate this particularly well.
Education: A Simple Example That Explains the DPDP Challenge
Consider a university in Delhi NCR receiving 25,000 applications for 3,000 available seats. During the admission process, applicants may provide their name, photograph, date of birth, mobile number, email address, residential address, parents’ information, marksheets, identification documents, entrance examination information and payment details.
The university eventually admits 3,000 students. The obvious question is: what happens to the personal data of the remaining 22,000 applicants?
Some of it may remain in the admission portal. An Excel export may have been downloaded by the admission team. Documents may exist in employee email accounts. A cloud backup may contain another copy, and the technology provider operating the admission system may also hold data. Three years later, if someone asks why the university still possesses their documents, will the institution know exactly where that person’s information exists and why it is still being retained?
This is where DPDP moves from being a legal subject to a management issue.
For students who actually join the university, the situation becomes even more complex. Their information moves through admissions, academics, accounts, examinations, hostel administration, library systems, transport, learning-management systems, internship programmes and placement departments. After graduation, some information may move into alumni databases. A relationship that started with one admission form can create a trail of personal data across multiple departments and applications for many years.
Schools have another important consideration because they routinely process children’s personal data. The DPDP framework contains specific provisions concerning children’s personal data, including requirements relating to verifiable parental consent, subject to the applicable provisions, Rules and exemptions.
For schools, colleges and universities, delaying DPDP Act implementation can therefore make the eventual exercise harder. Every new academic session adds another batch of applicants, students, parents, documents, photographs, results, backups and digital records. The institution is not reducing its compliance problem by waiting; in many cases, it is increasing the volume of data that will eventually need to be understood and governed.
A sensible starting point for an educational institution is a DPDP readiness assessment. Start with admissions, identify what information is collected and then follow that information through the organisation. The exercise often reveals data in places that senior management did not even know existed.
Healthcare: Consider a 100-Bed Hospital
Now consider a 100-bed multi-speciality hospital in Delhi NCR. Suppose, purely for illustration, that it handles around 250 OPD visits per day. That could mean more than 90,000 patient visits in a year before considering emergency cases, hospital admissions and other interactions.
A patient’s journey can involve registration, consultation, diagnostics, radiology, pharmacy, admission, insurance or TPA processing, billing, discharge and follow-up. During this journey, the hospital may process the patient’s name, address, contact information, date of birth, identification details, medical history, prescriptions, laboratory reports, radiology records, billing information, insurance information and emergency contacts.
Now ask the hospital management a very simple question: where is one patient’s complete data? The answer may be surprisingly difficult.
Registration information may be stored in the Hospital Management System, diagnostic reports in a laboratory system and radiology images in another application. Insurance documents may have been emailed to a TPA. Reports could have been shared through messaging applications. An outsourced laboratory may have another copy. Backups contain historical information, while the hospital’s software provider may have privileged technical access to the system for support.
The hospital may have perfectly legitimate reasons for retaining many medical records, including requirements arising from other applicable laws and regulations. DPDP does not mean that every old patient record should simply be deleted. It does mean that the organisation should understand what it holds, why it retains it, who can access it, how it is protected and where information is being shared.
The seriousness becomes clearer when we consider a data incident. Imagine that an employee accidentally exports 20,000 patient records and the file reaches an unauthorised person. Management now has to establish what information was affected, which patients were involved, which system the information came from, who had access to it, what safeguards existed and what actions are required.
Trying to answer these questions after an incident is far more difficult than maintaining this visibility beforehand. For hospitals, diagnostic centres and other healthcare organisations, this is one of the strongest reasons to start DPDP Act compliance early.
NBFCs and Financial Services: Personal Data Travels Further Than You Think
NBFCs and other financial-services organisations present another interesting example because their business naturally requires considerable personal and financial information.
A customer applying for a loan may provide PAN and KYC information, bank statements, income documents, employment details, contact information and other information required for credit assessment. In a digital lending environment, information may also flow between the regulated entity, technology platforms and Lending Service Providers.
Suppose an NBFC receives 10,000 loan applications but approves only 2,000. What happens to the information belonging to the remaining 8,000 applicants? Some information may have to be retained because of applicable legal or regulatory requirements, while other information may no longer need to remain indefinitely. The organisation has to know the difference.
There is also the issue of third parties. If a customer submitted information through an application operated by a service provider, the NBFC needs visibility over how that information is processed across the ecosystem. DPDP therefore cannot be handled only by the IT department. Compliance, operations, information security, legal teams and management all have roles to play.
DPDP Compliance is Not Just About Consent
One of the easiest mistakes organisations can make is reducing DPDP to a consent checkbox.
Consent is important where consent is the applicable basis for processing, but a complete DPDP compliance framework goes much further. An organisation needs to understand its data inventory, purposes of processing, notices, applicable legal bases, access controls, vendor relationships, security safeguards, retention requirements, individual request processes and breach-response mechanisms.
For example, installing a consent checkbox on a university admission form does not solve the problem if copies of applicants’ documents remain uncontrolled across multiple systems for years. Similarly, obtaining consent at hospital registration does not solve the problem if hundreds of employees have unnecessary access to patient information. Real compliance is about data governance, not simply documentation.
What Happens if an Organisation Does Not Comply?
The DPDP Act provides for substantial monetary penalties for specified contraventions. Depending on the nature of the contravention, the Schedule to the Act provides for penalties reaching up to Rs. 250 crore in certain cases, including failure to take reasonable security safeguards to prevent a personal-data breach.
However, DPDP Act penalties for non compliance should not be the only reason businesses take this seriously.
For a hospital, loss of patient trust can be extremely damaging. For a university, an incident involving student information can create concern among students and parents. For an NBFC, misuse or exposure of financial information can have regulatory, commercial and reputational consequences. Businesses can also face management distraction, investigation costs, technology remediation, contractual issues and disruption to normal operations. Privacy compliance should therefore be viewed as risk management rather than simply another statutory expense.
What Should Delhi NCR Businesses Do Now?
A common mistake is to begin by buying data privacy management software. Technology can certainly help, particularly when an organisation has large volumes of data, but software should follow understanding rather than replace it.
The first exercise should be data discovery. Select one business process and follow the data. A university can start with admissions, a hospital with patient registration, an NBFC with loan applications and a normal enterprise with employees or customers.
Identify what personal data is being collected, why it is required, where it is stored, who has access, which external parties receive it and how long it needs to be retained. Then move to the next department.
This gradually creates a data inventory and data-flow map. Once the organisation understands its current position, gaps in notices, consent mechanisms, security, access controls, vendor contracts, retention policies and incident management become much easier to identify. A structured DPDP readiness assessment can help management convert these findings into priorities rather than attempting to solve everything simultaneously.
What Does a Practical DPDP Readiness Exercise Look Like?
A good readiness programme does not need to start as a massive transformation project. It can be phased.
The organisation can begin by identifying personal-data processing activities and mapping data flows. The next stage can review notices, consent mechanisms and other applicable processing grounds, followed by access controls and information-security safeguards. Vendors and other data processors should then be reviewed, along with contractual arrangements and their access to organisational data.
Retention deserves special attention because many organisations have historically followed an informal policy of keeping everything indefinitely. Different categories of information can have different statutory, regulatory, contractual and business retention requirements. The objective should not be indiscriminate deletion but a documented understanding of why information is retained.
Employee training is equally important. Even a technically secure application can be undermined if someone downloads thousands of personal records into an unsecured Excel sheet and shares it casually. These activities together form the foundation for meaningful DPDP compliance services and, where appropriate, subsequent DPDP audit services.
The Government’s Intent is Bigger Than Penalties
It is easy to discuss DPDP primarily in terms of penalties, but that can obscure the larger purpose of the legislation.
The Digital Personal Data Protection Act seeks to balance two legitimate interests: an individual’s right to protect personal data and the need of organisations to process such data for lawful purposes.
A university obviously needs student information to provide education. A hospital needs patient information to provide healthcare. An NBFC needs customer information to assess and service loans. A company needs employee information to manage employment.
The objective is not to prevent these organisations from functioning. It is to make them more accountable for the personal information entrusted to them.
For management, the principle is reasonably straightforward: understand what personal data you collect, have a legitimate reason for processing it, be transparent about its use where required, protect it appropriately, control access, understand third-party sharing, retain it where legitimately required and erase it when it no longer needs to be retained.
Why Waiting Until the Last Moment Can Cost More
The DPDP Act 2023 and the subsequent DPDP Rules are being brought into operation according to the Government’s notified commencement framework. Organisations should treat the available transition period as preparation time rather than waiting time.
A company cannot discover ten years of personal data overnight. A university cannot instantly identify every copy of student and applicant information stored across departments. A 100-bed hospital cannot suddenly map every patient-data flow between its HMS, laboratory, radiology, pharmacy, insurance and external vendors.
The larger and older the organisation, the more time this exercise can require.
This is particularly relevant for Delhi NCR because of the region’s concentration of schools, universities, hospitals, financial institutions, technology companies, manufacturing businesses and service organisations. There is no official basis to claim that Delhi NCR will necessarily be the first region selected for government DPDP audits, but organisations processing personal data at this scale have sufficient reason to prepare without waiting for regulatory scrutiny.
Start With One Question
For any CEO, hospital administrator, school director, university management team or business owner, a useful starting point is surprisingly simple: if someone asks us today what personal data we hold about them, where it exists, why we have it, who has access to it and whom we have shared it with, how confidently can we answer?
If the answer requires several departments, spreadsheets, emails and phone calls just to understand where the data is, the organisation has already identified its first DPDP challenge.
A DPDP readiness assessment can provide that visibility and help create a phased roadmap covering people, processes, policies, contracts, security and technology.
For businesses and institutions across Delhi, Noida, Gurugram, Faridabad and Ghaziabad, the sensible approach is not to wait for a complaint, breach or compliance deadline before looking at personal data. The better approach is to understand it now, while there is still time to fix the gaps systematically.
That is where meaningful DPDP Act compliance in Delhi NCR begins.

