DPDP compliant email: what the law asks of your mailboxes, and what it does not
Every business email system processes personal data: customers, employees, vendors. That makes your organisation a Data Fiduciary under the Digital Personal Data Protection Act. Here is what that actually requires, in plain terms, with the one myth cleared up first.
What DPDP means for business email
India's Digital Personal Data Protection Act 2023, with the DPDP Rules notified in November 2025, requires any organisation that processes personal data, which includes running business email, to process it for a lawful purpose with notice and consent, protect it with reasonable security safeguards, report a personal data breach to the Data Protection Board within 72 hours and to affected individuals without delay, and erase it once its purpose is served. Penalties run up to ₹250 crore for failing to maintain security safeguards and up to ₹200 crore for failing to notify a breach. The Act does not require personal data to be stored in India: transfers are permitted except to countries the government specifically restricts. Sector regulators (RBI for payment data, CERT-In for security logs, SEBI and IRDAI for their intermediaries) are where localisation and log-retention duties come from. Most DPDP obligations take effect over the 18-month phase-in that began with the Rules, which puts the deadline in the first half of 2027.
Guidance, not legal advice. Checked against the Act and the Rules on 6 September 2026; confirm specifics with your counsel.
What the Act requires of a Data Fiduciary that runs email
Six duties matter for email. The Act is technology-neutral, so none of them name "email", but all of them land on it.
1. Notice and consent
Personal data may be processed only for a lawful purpose, with a clear notice and the individual's consent, or under a listed legitimate use such as employment. Marketing email to a list you did not get consent for is the most common way businesses fall foul of this.
2. Reasonable security safeguards
The Fiduciary must protect personal data in its possession or under its control, including data held by a processor on its behalf. For email that means encryption, access control, protection against phishing and account takeover, and logs that show who accessed what.
3. Breach notification
A personal data breach must be reported to the Data Protection Board within 72 hours of becoming aware of it, with details of its nature, extent and remediation, and to every affected individual without delay. A compromised mailbox full of customer data is a breach.
4. Erasure when the purpose is served
Personal data must be erased once the purpose for which it was collected is no longer served, unless retention is required by law. Mail archives that keep everything forever by default need a retention policy.
5. Accountability for processors
You may use a processor (an email host is one) only under a valid contract, and you remain responsible for what happens to the data. Who your provider is, where they run, and what they can see becomes your compliance question.
6. Rights, grievances, and Significant Data Fiduciaries
Individuals can ask what you hold, have it corrected or erased, and complain; you need a grievance contact. Organisations the government designates as Significant Data Fiduciaries add a Data Protection Officer based in India, periodic audits and impact assessments.
DPDP does not say your email must be hosted in India
It is the most repeated claim in vendor marketing, and it is wrong. Here is what actually governs where your mail lives.
What DPDP says about location
The Act permits transfer of personal data outside India except to countries the central government notifies as restricted. There is no general requirement to keep a copy in India and no requirement that your mail server sits here. What DPDP does demand is that you remain accountable wherever the data goes, which is harder to evidence when a foreign provider holds it under foreign law.
Where localisation duties actually come from
- RBI: payment system data must be stored only in India (2018 directive), which reaches any email that carries it.
- CERT-In: 2022 directions require ICT logs to be kept for 180 days within India and incidents reported within six hours.
- SEBI and IRDAI: cyber-security frameworks for market intermediaries and insurers that set their own data and audit expectations.
- Your customers' due diligence: enterprise and government buyers increasingly ask where email is hosted before they sign.
So the honest case for Indian-hosted or on-premise email is accountability and sector rules, not a DPDP mandate. See the on-premise page for how that is done, and the RBI checklist if you are a bank or NBFC.
A 10-point DPDP email readiness checklist
What a compliance owner should be able to answer yes to before the phase-in deadline. Print it, tick it, and take the gaps to your provider.
- 1. Inventory. You know which mailboxes and shared folders hold customer, employee or vendor personal data.
- 2. Marketing consent. Every bulk email list has a recorded consent or a legitimate-use basis, and every message carries an unsubscribe that works.
- 3. Access control. Multi-factor authentication on every account, role-based admin rights, and a leaver process that closes access the same day.
- 4. Encryption. TLS in transit everywhere; S/MIME or equivalent for mail that carries sensitive personal data.
- 5. Leak prevention. DLP rules that stop Aadhaar, PAN, card and account numbers leaving by mail unless they should.
- 6. Logging. Login, access and admin actions are logged, kept for the period your sector requires (180 days for CERT-In), and reviewable.
- 7. Breach playbook. A written procedure that gets you from "mailbox compromised" to a Board notification inside 72 hours, with named owners.
- 8. Retention and erasure. Archive and deletion rules that match the purpose of the data, and a way to erase an individual's data on request.
- 9. Processor contract. A data processing agreement with your email provider that states what they do with the data, where, and how they support your obligations.
- 10. Grievance contact. A published way for individuals to ask what you hold and have it corrected or erased, and someone who answers.
Get the checklist as a PDF, with the provision behind every line
Six pages: the ten controls with the section of the Act or the Rules each one satisfies and the evidence to keep, the RBI, CERT-In, SEBI and IRDAI overlap table, the penalty schedule, the phase-in timeline, and every source cited. Powered by XgenPlus, not legal advice.
Your checklist is ready
A copy is on its way to your inbox as well. The link is valid for 7 days.
Thanks, our team will send you the checklist shortly.
Want the gaps closed rather than just listed? Tell us about your setup.
The checklist items your email platform can carry for you
Compliance is your organisation's, not a product's. These are the items an Indian-built, Indian-hosted or on-premise email platform takes off the list.
Safeguards, built in
Multi-factor authentication, role-based administration, TLS everywhere, S/MIME with a built-in certificate authority, and DLP rules for Indian identifiers. Items 3, 4 and 5.
Logs and evidence
Login, access and admin audit trails you can review and export, retained to your policy. Backup and archive controls that let you set retention rather than keep everything by default. Items 6 and 8.
Accountability you can show
Hosted in India by an Indian company, or installed on your own infrastructure so the data never leaves your control. Ask us for our data processing terms for item 9. Deployed inside BSNL, BPCL, BEML, PDCC Bank and MECON.
Discuss your DPDP gaps → See the security controls On-premise option
DPDP and business email, answered
Does the DPDP Act apply to my company's email?
Yes, if your mailboxes hold personal data about identifiable people in India, which for any business with customers or employees they do. The Act applies to digital personal data processed in India regardless of the size of the organisation, with lighter duties for some small entities the government may notify.
Does DPDP require my email to be hosted in India?
No. DPDP permits cross-border transfer except to countries the government restricts. Localisation duties come from sector regulators: RBI for payment data, CERT-In for security logs (180 days, in India), and SEBI or IRDAI frameworks for their intermediaries. Indian hosting or on-premise deployment makes DPDP accountability easier to evidence, but the Act itself does not mandate it.
How fast must an email breach be reported?
Under the DPDP Rules, to the Data Protection Board within 72 hours of becoming aware of the breach, with its nature, extent, timing and the remedial steps taken, and to each affected individual without delay. CERT-In's separate direction requires cyber incidents to be reported to it within six hours.
What are the penalties?
Up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach, up to ₹200 crore for failing to notify the Board or affected individuals, up to ₹200 crore for breaching the duties around children's data, up to ₹150 crore for a Significant Data Fiduciary's additional obligations, and up to ₹50 crore for any other breach of the Act or the Rules. Penalties are per instance and set by the Board on the facts.
When do the obligations take effect?
The DPDP Rules were notified in November 2025 with a phased schedule: the Data Protection Board and related provisions immediately, consent-manager registration within 12 months, and most obligations on Data Fiduciaries, including notice, security safeguards, breach reporting and erasure, within 18 months, which lands in the first half of 2027.
Is a marketing email list a DPDP problem?
It is the most common one. Sending marketing email to people who did not give consent for that purpose, or keeping their data after they withdraw it, breaches the consent and erasure duties. Keep a record of how each address was obtained, honour unsubscribes immediately, and separate marketing lists from transactional mail.
Bring your email in line with DPDP before the deadline
Tell us your mailbox count, where your mail is hosted today and which sector rules also apply. We reply within one business day with the gaps we can close and how.
Trusted by our clients
Government bodies, public-sector undertakings and enterprises run mission-critical email on XgenPlus.
XgenPlus has successfully completed the installation and completed the project. The performance and total solution of XgenPlus is exceptional, along with excellent support from the team.
XgenPlus Technologies went above and beyond our expectations by delivering our EAI/IDN-compliant hosted email service promptly and in accordance with our purchase order. We wholeheartedly endorse their exceptional corporate mailing solution.
The installation and project completion by XgenPlus have been a resounding success. The exceptional performance and comprehensive solution, coupled with their outstanding team support, have exceeded our expectations.
XgenPlus customized and installed the solution at the Rajasthan State Data Center, taking on onsite management, tuning, monitoring and reporting. The service has been operational and running smoothly since August 2017.
On behalf of Air India Express, I appreciate your team for delivering the product so efficiently and in a very pleasing manner.
XgenPlus is ideal for organizations that require a mail server which is easy to implement, manage and is cost effective — secure, and ready for collaboration.