Summary: In the digital era, data has become one of the most valuable assets of an organisation, while digital platforms, cloud systems, artificial intelligence, electronic communication and data-driven business models have increased the importance of privacy, security, accountability and responsible use of personal data. With the notification of the Digital Personal Data Protection Rules, 2025 on 14 November 2025, organisations are required to strengthen their data-protection compliance framework. Although the DPDP Act does not specifically assign responsibility to the Company Secretary, the CS can play an important governance and oversight role by advising the Board, coordinating with relevant functions, monitoring compliance, maintaining records, and facilitating review of privacy notices, consent, grievance redressal, data breaches, retention and deletion practices. The statutory responsibilities remain with the Data Fiduciary, Data Protection Officer, Data Processor and other designated persons as prescribed under the DPDP Act, Rules and applicable laws, and the Act does not specifically designate the CS as the Data Protection Officer. For listed entities, the DPDP framework also needs to be considered alongside the disclosure and governance architecture under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, including assessment of whether a cybersecurity incident, personal-data breach or other privacy-related event is material under the applicable LODR framework. The Company Secretary can serve as an important link between the Board, management and functional teams in coordinating such assessments, escalation, reporting, remediation and documentation. The framework therefore provides Company Secretaries an opportunity to strengthen governance, accountability, transparency, responsible data stewardship and stakeholder trust.
Company Secretary’s Role in the DPDP Ecosystem
In the digital era, data has become one of the most valuable assets of an organisation. The growing use of digital platforms, cloud systems, artificial intelligence, electronic communication and data-driven business models has changed the way personal data is collected, processed, stored and shared. While these technologies improve innovation and business efficiency, they also create challenges relating to privacy, security, accountability and responsible use of personal data.
With the notification of the Digital Personal Data Protection Rules, 2025 on 14 November 2025, organisations are required to strengthen their data-protection compliance framework.
Although the DPDP Act does not specifically assign responsibility to the Company Secretary (CS), the CS can play an important governance and oversight role by advising the Board, coordinating with relevant functions, monitoring compliance, maintaining records, and facilitating review of privacy notices, consent, grievance redressal, data breaches, retention and deletion practices.
The Company Secretary’s role under the DPDP framework is primarily one of governance, coordination and compliance oversight. The statutory responsibilities, however, remain with the Data Fiduciary, Data Protection Officer, Data Processor and other designated persons as prescribed under the DPDP Act, Rules and applicable laws. The Act does not specifically designate the CS as the Data Protection Officer.
The DPDP framework also provides an opportunity for Company Secretaries to build expertise in this emerging area of regulatory governance, particularly as organisations increasingly adopt AI, cloud computing, digital platforms and other data-driven technologies.
Thus, the Company Secretary can serve as an important link between the Board, management and various functional teams, helping the organisation establish a structured and effective data-protection governance framework.
DPDP Framework, SEBI LODR and Listed Entities
“For listed entities, the DPDP framework needs to be viewed in conjunction with the disclosure and governance architecture prescribed under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015. While the DPDP Act does not create an automatic requirement for every personal-data breach to be disclosed to the stock exchanges, a listed entity should independently assess whether a data breach, cybersecurity incident or other privacy-related event is material under the applicable LODR framework. The Company Secretary assumes an important coordinating role in facilitating such assessment, ensuring appropriate escalation to the Board and coordinating with legal, information-security, compliance and investor-relations functions for timely and accurate regulatory disclosures.”
The role of the Company Secretary in the DPDP ecosystem should, therefore, not be viewed merely through the narrow lens of statutory compliance. Rather, it represents an opportunity to reinforce the Company’s commitment to accountability, transparency, responsible data stewardship and stakeholder trust.
SEBI’s LODR FAQ page lists the “FAQs on LODR Regulations 2015” dated 23 April 2025.
The important distinction is:
- Cyber security incident / breach: An event affecting the confidentiality, integrity or availability of information systems/data, including unauthorized access, disruption, compromise, etc.
- Loss of data/documents: Loss or compromise of company data or documents can also trigger the relevant disclosure/compliance requirements.
- Materiality: A cyber incident may become a material event/information under Regulation 30, depending on its nature, impact and the applicable materiality framework.
- SEBI has also recognised that cyber incidents can affect the operations/performance of a listed entity and are relevant to investors.
In the event of a cybersecurity incident involving personal data, a listed entity should adopt a coordinated approach so that its obligations under the DPDP framework, SEBI LODR and other applicable laws are assessed independently and within the prescribed timelines.
Cybersecurity or Personal-Data Incident Response Framework
| Stage | Suggested Timeline | Key Action | Role of Company Secretary |
|---|---|---|---|
| 1. Incident Detection | Immediately / T+0 | Identify and record the cybersecurity or personal-data incident. | Ensure appropriate escalation to senior management and relevant functions. |
| 2. Preliminary Assessment | Immediately | Determine the nature, scope and potential impact of the incident. | Coordinate with IT, Information Security, Legal, Compliance and Risk teams. |
| 3. Personal Data Assessment | T+0 to T+1 | Determine whether the incident involves personal data and whether it constitutes a personal-data breach under the DPDP framework. | Facilitate documentation of the assessment and ensure appropriate governance escalation. |
| 4. LODR Materiality Assessment | At the earliest opportunity | Assess whether the incident constitutes a material event or information under Regulation 30 of SEBI LODR. | Coordinate the materiality assessment in consultation with Legal, Compliance, Risk and senior management. |
| 5. Board / Committee Escalation | As soon as practicable | Escalate material or significant incidents in accordance with the company’s incident-response and governance framework. | Place the matter before the Board / relevant Committee, where appropriate, and maintain proper records. |
| 6. DPDP Reporting | Within the applicable statutory timeline | Where the incident constitutes a personal-data breach, undertake the notifications required under the DPDP Act and Rules. | Coordinate with the designated compliance/legal function and maintain evidence of reporting. |
| 7. Stock Exchange Disclosure | As prescribed under Regulation 30 | Where the incident is material or otherwise reportable, make the requisite disclosure to the stock exchanges within the applicable timeline. | Coordinate preparation, approval and submission of the disclosure and ensure consistency and accuracy of information. |
| 8. Regulatory / Sectoral Reporting | As applicable | Assess requirements under CERT-In, RBI, IRDAI, TRAI or other sector-specific regulations, as applicable. | Ensure that applicable regulatory reporting obligations are identified, monitored and tracked. |
| 9. Remediation | Post-incident | Contain the incident, rectify vulnerabilities and implement corrective measures. | Monitor governance-level action points and report significant remediation measures to the Board. |
| 10. Closure & Documentation | Post-incident | Prepare the incident report, document lessons learned and complete the compliance record. | Maintain records of decisions, approvals, disclosures, correspondence, remedial measures and closure of the incident. |
A single cybersecurity or personal-data incident may trigger multiple regulatory obligations. The Company Secretary should ensure that each applicable framework—DPDP, SEBI LODR, CERT-In and sector-specific regulations—is independently assessed and that the respective reporting and disclosure timelines are complied with.
Frequently Asked Questions (FAQs)
Digital Personal Data Protection Act, 2023 – A Company Secretary’s Perspective
Q1. Is the Company Secretary statutorily responsible for compliance under the DPDP Act, 2023?
Answer:
The DPDP Act does not specifically designate the Company Secretary as the officer responsible for overall compliance under the Act. The statutory obligations are primarily imposed on the relevant Data Fiduciary and, where applicable, other designated persons or entities. However, considering the governance and compliance implications of the DPDP framework, the Company Secretary can play an important role in facilitating compliance, coordinating with relevant functions and advising the Board on material data-protection matters.
Q2. If a listed company suffers a personal-data breach, is it required to disclose it to SEBI/stock exchanges?
Answer:
A personal-data breach should not be treated as automatically requiring disclosure under SEBI LODR solely because it constitutes a breach under the DPDP framework. The listed entity should undertake a separate assessment under the applicable SEBI LODR requirements, including the materiality framework applicable to Regulation 30. Where the event is material or otherwise falls within a prescribed disclosure requirement, the listed entity should make the requisite disclosure within the applicable timeline. At the same time, the company must separately evaluate its obligations under the DPDP framework and any sector-specific regulatory requirements.
Q3. Is a company required to include a separate DPDP compliance report in its Annual Report?
Answer:
The Digital Personal Data Protection Act, 2023 does not prescribe a general requirement for every company to include a separate or standalone “DPDP Compliance Report” in its Annual Report. However, companies should evaluate whether material matters relating to data protection need to be disclosed under other applicable corporate, securities, accounting or sector-specific regulatory requirements.
Q4. Why is DPDP compliance relevant to the Company Secretary?
Answer:
The DPDP framework has implications for corporate governance, regulatory compliance, risk management, internal controls, stakeholder protection and Board oversight. The Company Secretary, as a governance professional and adviser to the Board, is well positioned to facilitate the integration of data-protection requirements into the company’s broader governance and compliance framework.
Q5. Should DPDP compliance be placed before the Board of Directors?
Answer:
Where appropriate, DPDP compliance may be placed before the Board or the relevant Board Committee, particularly where the company processes significant volumes of personal data or faces material privacy and data-security risks. Matters such as DPDP readiness, material data-protection risks, significant data breaches, compliance gaps and major remediation measures may warrant Board-level attention.
Q6. Does every company need to appoint a Data Protection Officer (DPO)?
Answer:
No. The requirement to appoint a Data Protection Officer is not applicable in the same manner to every Data Fiduciary. Additional requirements, including those relating to a DPO, apply to a Significant Data Fiduciary as prescribed under the DPDP framework. Companies should assess their status and applicable requirements rather than assuming that every company must appoint a DPO.
Q7. Can the Company Secretary also act as the Data Protection Officer?
Answer:
The Company Secretary is not automatically the DPO merely by virtue of holding the office of Company Secretary. If a company proposes to appoint its Company Secretary as DPO, the appointment should be evaluated separately with reference to the statutory requirements applicable to the DPO, including independence and other prescribed conditions, wherever applicable.
Q8. What should the Company Secretary review on the company’s website?
Answer:
The Company Secretary may coordinate with the relevant functions to review the company’s privacy-related disclosures and ensure that appropriate notices and mechanisms are available wherever personal data is collected. Particular attention should be given to the requirements concerning the contents and manner of providing notice under the DPDP Rules, 2025.
The review may cover:
- Privacy Notice;
- information regarding personal data collected;
- purpose of processing;
- consent mechanisms;
- withdrawal of consent;
- Data Principal rights;
- grievance mechanism; and
- relevant contact or communication mechanisms.
Q9. Is Board approval mandatory for a DPDP Policy?
Answer:
The requirement for Board approval should be determined based on the company’s governance framework, Articles of Association, applicable laws, internal delegation of authority and the nature of the policy. Even where specific Board approval is not legally mandated, material data-protection policies may appropriately be brought to the attention of the Board or relevant Committee as part of effective governance.
Q10. What DPDP-related matters may be relevant for Board-level reporting?
Answer:
Depending on the nature and scale of the company’s activities, the following matters may be considered for Board-level reporting:
- status of DPDP implementation;
- material data-protection risks;
- significant privacy or security incidents;
- material personal-data breaches;
- status of remediation measures;
- appointment of relevant personnel, where applicable;
- Significant Data Fiduciary status, where relevant;
- Data Protection Impact Assessments, where applicable;
- data-protection audits;
- material regulatory communications;
- significant Data Processor/vendor risks;
- major changes to privacy and data-governance policies; and
- material litigation or regulatory proceedings relating to personal data.
Q11. What is a cyber security incident?
A cyber security incident is an event that adversely affects or has the potential to affect the confidentiality, integrity or availability of information systems, networks or data.
Under SEBI’s framework, the relevant cyber incidents are linked to the applicable CERT-In definitions/directions and SEBI’s CSCRF requirements.
Q12. What are examples of cyber incidents?
Examples can include:
- Ransomware attack
- Malware infection
- Phishing leading to compromise
- Unauthorised access to systems
- Data breach/data leak
- Website or application compromise
- Denial-of-service/distributed denial-of-service attack
- Compromise of critical systems
- Theft or unauthorised disclosure of sensitive information
The CSCRF FAQs contain a specific section on “Classification and Handling of Cybersecurity Incidents.”
Q13. Can a cyber incident affect quarterly corporate governance reporting?
Yes. SEBI’s framework has historically contemplated disclosure of cyber security incidents/breaches and loss of data/documents in the corporate governance reporting framework, including reporting of corrective actions/outstanding incidents.
Q14. Is ransomware required to be reported to SEBI?
Yes, where it falls within the incidents requiring reporting under the CSCRF. SEBI’s cybersecurity framework treats serious incidents such as ransomware/intrusion among the incidents requiring regulatory attention and reporting.
The applicable reporting timeline under the CSCRF can be within 6 hours for specified reportable incidents.
Key Takeaway
The DPDP framework provides an opportunity for Company Secretaries to strengthen their role as governance professionals, compliance advisers and strategic partners to the Board. While the Company Secretary is not automatically the statutory Data Protection Officer, the profession can play a pivotal role in creating a culture of accountability, transparency and responsible data governance within organisations.




