[Home](/)/[Resources](/resources)/India DPDP Act for Hardware

IndiaPrivacy

# India Digital Personal Data Protection Act — Hardware Obligations

The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first comprehensive data protection law, establishing consent-based requirements for personal data processing that directly affect connected hardware products collecting data from Indian users. For IoT, consumer electronics, and connected device manufacturers, the DPDP Act creates privacy-by-design obligations, consent architecture requirements, and data localisation considerations that must be built into product design before market entry.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Findia-dpdp-act-hardware)

At a glance

Legislation

DPDP Act 2023

Regulator

Data Protection Board

Breach notification

72 hours

Scope

Extra-territorial

Children's age threshold

Under 18

## When the DPDP Act applies to hardware products

The DPDP Act applies to the processing of "digital personal data" — personal data in digital form. For hardware manufacturers, the triggering question is whether the product collects, stores, or transmits personal data from Indian users. The Act's extra-territorial scope means the manufacturer's location is irrelevant; if your product processes data of Indian data principals, you are a data fiduciary under the Act.

### Product collects personal data from Indian citizens

**Details:** Biometrics, health metrics, location data, and usage patterns collected by any sensor or interface on a connected device constitute personal data under the DPDP Act. The Act applies to the data fiduciary — typically the manufacturer or platform operator — regardless of where the company is incorporated.

### Cloud platform processes Indian user data

**Details:** If a hardware product's companion platform stores, analyses, or transfers personal data of Indian users — even on overseas servers — the DPDP Act's obligations apply. Extra-territorial scope is explicit: processing of Indian users' data outside India falls within the Act.

### App or firmware transmits data to servers

**Details:** Any firmware or mobile application that sends personal data from a device to a server — whether in India or abroad — triggers DPDP compliance. This includes over-the-air telemetry, crash reports, usage analytics, and health data sync.

### B2B hardware processing employee personal data

**Details:** Enterprise hardware — access control systems, fleet trackers, workplace wearables — processes employee personal data. The DPDP Act does not exclude B2B scenarios; the employer acting as data fiduciary must ensure lawful processing, notice, and consent even for workforce data.

## Key obligations for data fiduciaries (manufacturers and operators)

As a data fiduciary, a hardware manufacturer or platform operator bears the primary compliance obligations under the DPDP Act. These obligations attach from the point of data collection and persist through the full data lifecycle — including deletion when the purpose is fulfilled.

01

Obtain free, specific, informed, unconditional, and unambiguous consent before processing any personal data — a single bundled consent for all purposes is not valid under the DPDP Act.

02

Provide clear and plain-language notice at the time of consent detailing: what personal data is being collected, the purpose of processing, and the identity and contact details of the data fiduciary.

03

Enable withdrawal of consent as easily as it was given — withdrawal must be technically feasible and must result in cessation of processing for the original purpose.

04

Appoint a Data Protection Officer (DPO) accessible to data principals if the entity is designated a Significant Data Fiduciary, with the DPO's contact details published.

05

Implement appropriate technical and organisational security safeguards proportionate to the sensitivity and volume of personal data processed — encryption, access controls, and secure data transfer are baseline expectations.

06

Report personal data breaches to the Data Protection Board of India within 72 hours of becoming aware — hardware manufacturers must build breach detection and escalation processes into product operations.

07

Erase personal data when the purpose for which it was collected has been fulfilled, or when consent is withdrawn — data retention schedules must be defined and enforced at a technical level in firmware and cloud platforms.

08

For children's data (users under 18): no behavioural monitoring, targeted advertising, or tracking is permitted. Verifiable parental consent is mandatory before any personal data of a child is processed.

## Significant Data Fiduciary (SDF) designation

The DPDP Act creates a tiered compliance framework. Entities processing large volumes of sensitive data — or data posing national security or public order risks — may be designated Significant Data Fiduciaries, attracting a higher set of obligations. Hardware manufacturers in health, critical infrastructure, and high-volume consumer categories should assess SDF exposure early.

### Criteria for Significant Data Fiduciary designation

**Details:** The Central Government designates SDFs based on: volume of personal data processed, sensitivity of data (biometric, health, financial), risk to national security or public order, and potential impact on sovereignty or electoral integrity. Sector-specific SDF designations are expected for health tech, fintech, and critical infrastructure.

### Additional SDF obligations

**Details:** SDFs must conduct periodic Data Protection Impact Assessments (DPIAs), appoint an independent Data Auditor to audit compliance, maintain records of processing activities, and cannot transfer personal data to countries notified as restricted by the Central Government.

### Cross-border data transfer restrictions

**Details:** The DPDP Act restricts transfer of personal data to countries on a government-notified restricted list. SDFs face stricter transfer controls. All data fiduciaries must ensure overseas transfer recipients provide comparable protections — standard contractual clauses or adequacy assessments are anticipated in Rules.

### Indian government's role in SDF designation

**Details:** The Ministry of Electronics and Information Technology (MEITY) and Data Protection Board will publish sector-specific SDF designations. Hardware manufacturers in health, defence, and critical infrastructure should anticipate SDF designation and begin building compliant data architectures proactively.

## Hardware product design implications

DPDP compliance is not a legal afterthought — it requires architectural decisions at the firmware, connectivity, and cloud platform layer. Products designed with privacy-by-design principles from the outset are significantly easier to certify and operate in compliance with the Act.

01

Data minimisation in sensor design: collect only the personal data that is strictly necessary for the stated product purpose. Sensors that capture data beyond the disclosed purpose create consent and compliance risk.

02

Consent architecture in firmware and companion app: consent flows must be granular (purpose-specific), revocable, and logged with timestamps. Implicit or pre-ticked consent is non-compliant.

03

Local processing vs. cloud architecture: processing data on-device rather than transmitting to cloud servers reduces the scope of DPDP obligations. Edge AI and on-device inference can be a privacy-by-design strategy for health and biometric wearables.

04

Data retention policy enforcement: firmware and cloud platforms must technically enforce retention limits — automatic deletion or anonymisation when the retention period expires, not just a policy commitment.

05

Biometric data handling: health wearables processing SpO2, ECG, or fingerprint data handle sensitive personal data. Encryption at rest and in transit, strict purpose limitation, and documented consent are non-negotiable.

06

Children's IoT product consent: products marketed to or likely used by under-18 users must implement verifiable parental consent mechanisms before collecting any personal data — age gates without verification are insufficient.

## Frequently asked questions

### Does the DPDP Act apply to hardware manufacturers based outside India?

Yes. The DPDP Act has explicit extra-territorial scope: it applies to the processing of personal data of Indian data principals regardless of where the data fiduciary (manufacturer or platform operator) is located. A European or US hardware company whose product is sold in India and collects Indian users' data must comply with the Act's consent, notice, and security obligations.

### What is the consent mechanism for IoT devices with no screen or interface?

For screenless IoT devices (smart plugs, sensors, industrial monitors), consent must be obtained through an alternative interface — typically the companion mobile app or web portal during device setup. The DPDP Rules are expected to clarify consent mechanisms for constrained devices, but the current practice is to capture granular, purpose-specific consent during app onboarding before the device begins processing.

### What qualifies as a 'data breach' requiring DPDP notification for hardware products?

Any unauthorised access, disclosure, alteration, or destruction of personal data that may harm data principals qualifies as a personal data breach under the DPDP Act. For hardware products, this includes: firmware vulnerabilities exploited to exfiltrate user data, cloud platform breaches exposing device telemetry, and physical theft of devices containing unencrypted personal data. Notification to the Data Protection Board is required within 72 hours.

### How does the DPDP Act affect wearables and health monitoring devices?

Wearables collecting health data (heart rate, SpO2, ECG, blood glucose) process sensitive personal data, which attracts heightened obligations. Manufacturers must: obtain explicit consent for health data specifically, implement strong encryption, define clear retention periods, and ensure health data is not used for purposes beyond those disclosed (e.g., insurance profiling without separate consent). Devices targeting children face additional restrictions on behavioural monitoring.

**Disclaimer:** This page is an educational resource only and does not constitute legal advice. The DPDP Act 2023 Rules are pending finalisation; requirements may change. Consult qualified legal counsel for compliance decisions specific to your products and markets.

🇮🇳 India roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇮🇳 India compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/33-india-dpdpa-compliance-hardware-devices)[Prefer to read? Get the book — $24.99](/books/33-india-dpdpa-compliance-hardware-devices)

Related guides

*   [UK GDPR for Connected ProductsUK GDPR applies to any connected hardware product collecting or transmitting personal data about UK users.](/guides/uk-gdpr-connected-products)
*   [India Telecom Security TestingGuide to India's DoT mandatory security testing for telecom equipment — NCCS testing process, Trusted Telecom Portal, TEC MTCTE…](/guides/india-telecom-security-testing)
*   [India Smart Meter ComplianceComplete guide to smart meter compliance in India — BIS mandatory certification under IS 16444 and IS 15959, EESL technical spe…](/guides/india-smart-meter-compliance)
*   [US NIST IoT CybersecurityGuide to NIST SP 800-213 and SP 800-213A — the six IoT device cybersecurity capability baseline areas, non-technical documentat…](/guides/us-nist-iot-cybersecurity)