Your Salesforce Org Has Three DPDP Act Exposure Points
maximum penalty under India's Digital Personal Data Protection Act
Your Salesforce org faces penalties up to ₹250 crore (~$30M USD) under DPDP Act 2023 for significant violations. Your Indian customer, lead, and employee records are in scope. The Act creates GDPR-equivalent rights: consent requirements, deletion rights, data minimization obligations. If your org processes Indian citizen data, you are already subject to these rules.
timeframe for honoring data erasure requests from Indian data principals
Your team must fulfill deletion requests from Indian data principals promptly. For your Salesforce org with Indian customer records, this means cascade deletion across all related objects, field history, and sandbox copies. Your team is likely doing this manually today: SOQL queries per object, CSV exports, legal review. Manual compliance at scale is not feasible.
data principals covered by India's DPDP Act. The world's largest data subject population
Your org is covered regardless of where your company is headquartered. If your Contacts, Leads, or Accounts include Indian citizens, DPDP Act applies to your Salesforce data. Your Sales Cloud, Service Cloud, and marketing records containing Indian customer data are all in scope. The Act's extraterritorial reach mirrors GDPR.
Three Obligations Every India-Touching Salesforce Org Must Meet
India's Digital Personal Data Protection Act (DPDP 2023) applies to any organization processing digital personal data of Indian citizens. Three rights create specific Salesforce obligations:
DPDP Act 2023
Data Erasure Rights
Data principals (Indian citizens) have the right to erasure. Organizations must fulfill deletion requests promptly. For Salesforce organizations with Indian customer records, this means cascade deletion across all related objects, field history, and sandbox copies.
Privacy Rights AutomationDPDP Act 2023
Data Minimization Governance
DPDP Act requires organizations to retain personal data only as long as necessary for its stated purpose. When the purpose expires, the personal data must be automatically scheduled for deletion with audit documentation.
Data Retention ManagerDPDP Act 2023
Sandbox Data Protection
DPDP Act's data minimization principle applies to non-production environments. Developer and QA sandboxes should not contain real Indian customer data. Masking sensitive PII in sandbox environments is a core compliance control.
DataMaskerThe Schedule to the Act
DPDP Act 2023 penalty schedule
Section 33 of the Digital Personal Data Protection Act, 2023 lets the Data Protection Board of India impose these monetary penalties after an inquiry. Each cap applies per breach — they are not an annual ceiling.
| Breach | Section | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | Section 8(5) | ₹250 crore |
| Failure to notify the Board and affected Data Principals of a personal data breach | Section 8(6) | ₹200 crore |
| Breach of the additional obligations for children's personal data | Section 9 | ₹200 crore |
| Breach of the additional obligations of a Significant Data Fiduciary | Section 10 | ₹150 crore |
| Breach of any other provision of the Act or its rules | — | ₹50 crore |
| Breach of a voluntary undertaking accepted by the Board | Section 32 | Up to the cap for the original breach |
| Breach of the duties of a Data Principal (e.g. a false complaint) | Section 15 | ₹10,000 |
Source: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), Section 33 and the Schedule. Figures last checked . ₹1 crore is ₹10 million; ₹250 crore is roughly US$30 million at recent exchange rates.
Three Products. Three DPDP Requirements. One Platform.
Data Erasure Rights
Privacy Rights AutomationAutomate Data Erasure for Indian Data Principals
Privacy Rights Automation handles DPDP Act deletion requests end-to-end. When an Indian data principal exercises their right to erasure, CC identifies all personal data across Salesforce records, related objects, field history, and non-production environments and executes a compliant deletion with full audit trail. Same automation layer handles GDPR for EU customers simultaneously.
Data Minimization Governance
Data Retention ManagerEnforce Data Minimization and Retention Limits
DPDP Act requires organizations to retain personal data only as long as necessary for its stated purpose. Data Retention Manager implements purpose-based retention policies. When the purpose expires, the personal data is automatically scheduled for deletion. Supports multi-jurisdiction scheduling: different retention periods for Indian, EU, and US customer records in the same Salesforce org.
Sandbox Data Protection
DataMaskerMask Indian Customer Data in Sandbox Environments
DataMasker ensures Indian customer PII (names, aadhaar references, phone numbers, addresses) is masked in all sandbox environments. DPDP Act's data minimization principle applies to non-production environments: developer and QA sandboxes should not contain real Indian customer data. DataMasker eliminates this exposure on every sandbox refresh.
Key Takeaways
DPDP Act consent requirements automated: purpose-based consent records stored natively in Salesforce
Right to correction and erasure fulfilled in one click, Section 12 and 13 obligations automated
30-day data principal access request window met without manual SOQL queries or CSV exports
Significant data fiduciary obligations: sandbox masking and PII discovery support enhanced requirements
Data minimization enforced with automated retention policies, storage limitation by design
Operates 100% within Salesforce: no outbound data transfers, no DPDP cross-border transfer obligation
Frequently Asked Questions
The Digital Personal Data Protection Act (DPDP Act 2023) is India's national data protection law, signed into law in August 2023. It applies to any organization that processes digital personal data of Indian citizens, regardless of where the organization is located. Implementation rules (expected 2026) will specify enforcement timelines. Organizations with Indian customer, lead, or employee data in Salesforce should be preparing now.
DPDP Act shares GDPR's core concepts (consent requirements, data principal rights, data minimization) but has key differences: no data localization requirement (data can leave India), no mandatory DPO for most organizations, and penalties up to ₹250 crore vs GDPR's €20M or 4% global revenue. For Salesforce teams, the practical compliance automation is very similar: deletion request automation, retention governance, and sandbox data protection.
Yes. This is one of CC's most common deployment patterns. Privacy Rights Automation uses configurable rules to identify requests by jurisdiction. A deletion request from an EU data subject follows GDPR rules; an Indian data principal's request follows DPDP Act rules. Both are handled by the same automation layer with jurisdiction-specific audit documentation.
DPDP Act covers 'digital personal data'. Any data about an identifiable individual that is collected or processed digitally. In Salesforce, this includes Contact and Lead records, Account records with individual contact information, Service Cloud case records with personal details, and any custom objects containing Indian citizen data. Sandbox copies of all these are also in scope.
The DPDP Act was signed into law in August 2023. As of February 2026, the Central Government has not yet published the implementation rules (expected via gazette notification). However, the Data Protection Board of India is expected to begin enforcement shortly after rules are finalized. Organizations processing Indian personal data should begin compliance work now. Implementation typically takes 6-12 weeks with CC.
India DPDP Act Section 8(6) requires data fiduciaries to notify the Data Protection Board and affected data principals of personal data breaches. Cloud Compliance addresses the preparedness dimension: sandbox masking reduces the attack surface for non-production breaches, and Personal Data Discovery creates an accurate inventory of where personal data sits in your org. When a breach occurs, knowing exactly what data was exposed, which fields, which records, is critical for the notification obligation. An audit trail from Cloud Compliance provides the technical record regulators and data principals need.
Related Compliance Solutions
GDPR Compliance for Salesforce
EU/UK privacy regulation automation for Salesforce.
Privacy Rights Automation
1-click deletion request fulfillment with audit trails.
Data Retention Manager
Automated retention schedules per jurisdiction.
For Data Privacy Officers
How Cloud Compliance helps Privacy Officers meet multi-jurisdiction mandates.

