Companies Act 2013 and DPDP Act 2023: The Compliance Intersection CS Teams Must Navigate
By LegalInk Editorial ·
Companies Act 2013 and DPDP Act 2023: The Compliance Intersection CS Teams Must Navigate
The Digital Personal Data Protection Act, 2023 has been treated, in most corporate circles, as a problem for the IT or information security team. For company secretaries, that framing misses something important. Several obligations under the DPDP Act — consent architecture, grievance redressal, data fiduciary accountability, and breach notification — map directly onto governance structures that already exist under the Companies Act, 2013: board oversight, audit committee jurisdiction, secretarial audit scope, and related-party transaction disclosure. The intersection is not theoretical. It creates practical gaps in compliance frameworks when the two statutes are administered in silos. This post maps those overlaps precisely, with a focus on what CS teams need to own, flag, and document before the DPDP Rules are notified and enforcement begins.
The Governance Overlap: Where Both Statutes Touch the Board
Board Responsibility Under DPDP Act 2023
The DPDP Act does not use the phrase "board of directors" explicitly, but the accountability structure it establishes sits squarely at the level of the Data Fiduciary — which, for a company, means the entity itself and the natural persons who control its decision-making. Section 8 of the DPDP Act places comprehensive obligations on Data Fiduciaries: ensuring the accuracy of personal data, implementing reasonable security safeguards, engaging Data Processors only under contract, and notifying the Data Protection Board and affected Data Principals in the event of a personal data breach.
These are not IT-level obligations. A breach notification requirement that runs to a statutory authority is a board-level disclosure event, particularly for listed companies that simultaneously operate under SEBI's Listing Obligations and Disclosure Requirements Regulations, 2015. The CS is the natural coordinator of that disclosure pipeline because the same individual typically owns Regulation 30 disclosures, stock exchange intimations, and board minute-keeping.
Section 134 and the Directors' Responsibility Statement
Section 134 of the Companies Act, 2013 requires the board's report to include a Directors' Responsibility Statement covering, among other things, the adequacy of internal financial controls and compliance with applicable laws. Once the DPDP Rules are notified and the Act becomes fully operational, DPDP compliance will constitute a "compliance with applicable laws" obligation falling within Section 134(5)(f). The intersection at this point becomes formal: the directors' report will need to address the company's data protection compliance posture, and the auditor's report under Section 143(3)(i) on internal financial controls will inevitably be read alongside it.
Company secretaries drafting or coordinating the annual board report should begin building a DPDP compliance checklist into the Section 134 workflow now — before enforcement begins — so the disclosure architecture is in place rather than retrofitted in the first reporting cycle after notification.
Audit Committee Jurisdiction and the DPDP Compliance Layer
Current Scope Under Section 177
Section 177 of the Companies Act, 2013 mandates audit committees for prescribed classes of companies and assigns them oversight over financial statements, internal controls, related-party transactions, and risk management. The DPDP Act introduces a category of risk — data breach liability, regulatory penalty, and reputational exposure — that audit committees are not currently constituted to assess but are arguably already obligated to consider under their existing risk mandate.
The audit committee's jurisdiction over "evaluation of internal financial controls and risk management systems" under Section 177(4)(vii) is broad enough to encompass data protection risk, particularly where a breach could generate regulatory penalties or material litigation exposure. This is not a stretch of statutory interpretation; it follows directly from the ordinary meaning of "risk management systems."
What the Audit Committee Should Be Asking
The audit committee's engagement with DPDP compliance should cover, at minimum, the following questions:
- Whether the company has mapped its personal data processing activities and identified its status as Data Fiduciary or Data Processor under Section 2 of the DPDP Act for each processing stream.
- Whether consent frameworks under Section 6 for employee, customer, and vendor data are documented, auditable, and capable of withdrawal as required.
- Whether the company has a tested breach notification protocol that satisfies Section 8(6) and can interface with SEBI disclosure requirements for listed entities.
- Whether Data Processor contracts under Section 8(2) have been reviewed and updated to allocate liability appropriately, including for sub-processors.
- Whether children's data and Significant Data Fiduciary obligations under Sections 9 and 10 have been assessed for applicability.
The CS's role is to ensure these questions appear on the audit committee's agenda, that responses are minuted, and that any deficiencies identified are tracked to resolution. This is where DPDP oversight becomes a secretarial function, not purely a legal or IT one. A standing quarterly item — "Data protection compliance update" — in the audit committee agenda is a simple but effective mechanism.
Related-Party Transactions and Data Flows
Why Related-Party Structures Create DPDP Exposure
Related-party transactions under Section 188 of the Companies Act, 2013 and the associated Rules require board and, in some cases, shareholder approval. What the existing framework does not address — but the DPDP Act now makes relevant — is the data dimension of those transactions.
Consider the standard corporate group structure: a holding company shares employee records, customer data, or vendor databases with subsidiaries, associates, or joint ventures. These are related parties under Section 2(76) of the Companies Act. Under the DPDP Act, sharing personal data with a third party — including a related entity — constitutes processing or transfer that requires either valid consent under Section 6 or a legitimate use basis under Section 7. Critically, the Data Fiduciary remains accountable for how that data is handled downstream by the recipient.
The intersection is particularly sharp here. Related-party data flows that have never been scrutinised from a consent or data-sharing agreement perspective may now carry regulatory risk. A group-level intranet platform shared across subsidiaries, a consolidated HR system administered by the parent for its operating companies, or a centralised customer database shared between a parent and its subsidiary — each of these may involve personal data transfers that need to be assessed under Section 8(2) and documented in an intra-group data sharing agreement.
A concrete example illustrates the issue. A parent company centralises payroll processing for its three operating subsidiaries. Employee personal data — bank details, PAN, salary information, dependents' information — flows from each subsidiary to the parent. Under the Companies Act, this is a Section 188 transaction requiring disclosure. Under the DPDP Act, each subsidiary is a Data Fiduciary in relation to its own employees, and the parent is a Data Processor for that processing stream. A written contract under Section 8(2) is required. The consent or legitimate use basis must be established at the subsidiary level, not assumed by virtue of group affiliation.
Practical Steps for CS Teams
The CS team is not expected to conduct the DPDP legal analysis, but it is well-positioned to flag the gap. When preparing the related-party transaction register or the disclosures required under Section 188 and Schedule V, the CS should include a standing inquiry: does this transaction involve the sharing or processing of personal data? If yes, has the company documented a legal basis for that transfer under the DPDP Act, and is there an executed data processing or sharing agreement on file?
This does not require a comprehensive privacy audit at every RPT review cycle. It requires a documented question and a responsible owner — typically the Data Protection Officer, where appointed, or General Counsel — who signs off that the data dimension has been assessed. The CS records the sign-off in the RPT file and flags exceptions to the audit committee.
For companies managing complex group structures, the LegalInk compliance framework for technology provides a structured way to map these obligations across entities and maintain audit-ready documentation.
Secretarial Audit Scope and DPDP Corporate Compliance
Section 204 and the Expanding Compliance Universe
Section 204 of the Companies Act, 2013 requires prescribed companies to obtain a secretarial audit report from a practising company secretary, covering compliance with applicable laws. The DPDP Act, once fully operational, will be an applicable law for virtually every company that processes personal data — which is to say, virtually every company that has employees, customers, or vendors who are natural persons.
The Form MR-3 secretarial audit report currently covers the Companies Act, SEBI Regulations, Depositories Act, FEMA, and sector-specific laws identified by the auditor as material to the company's operations. DPDP compliance will need to be incorporated into this scope. Practising company secretaries conducting secretarial audits should begin developing verification procedures: consent record sampling, data principal rights request logs, breach register maintenance, Data Processor contract documentation, and evidence of board or committee-level oversight.
For the company being audited, this means that gaps in DPDP compliance infrastructure will surface in the secretarial audit report — a board-level document filed with the Registrar of Companies and visible to shareholders. That is an additional incentive for management to treat DPDP as a corporate governance matter, not solely an IT or legal one. A qualification in the MR-3 report on data protection compliance is the kind of disclosure that institutional investors and proxy advisory firms will increasingly factor into voting recommendations.
SOP Requirements and Documentation Standards
The DPDP Act does not prescribe detailed SOPs in the manner of, say, ISO 27001, but the accountability principle embedded in Section 8 implies that Data Fiduciaries must be able to demonstrate compliance — which in practice requires documented processes. From a secretarial practice standpoint, companies will need SOPs covering:
- Consent collection and withdrawal mechanisms, with audit trails capturing the version of the notice presented, the timestamp of consent, and the channel.
- Data Principal grievance redressal under Section 13, including response timelines and escalation paths to the Data Protection Board.
- Breach identification, internal escalation, and external notification to the Data Protection Board and affected Data Principals under Section 8(6).
- Periodic review of Data Processor agreements and sub-processor registers.
- Retention and deletion schedules aligned with Section 8(7), including specific deletion triggers for inactive customer accounts and exited employees.
These SOPs should be approved at an appropriate governance level — ideally the board or a board-delegated committee — and the approval should be minuted. The CS ensures that approval is properly documented and that the SOPs are reviewed at least annually as part of the compliance calendar, alongside review of the code of conduct, whistleblower policy, and other governance documents.
The LegalInk compliance framework for technology includes template documentation structures that CS teams can adapt for this purpose, reducing the time spent building SOP architecture from scratch.
The Penalty Exposure That Boards Need to Understand
DPDP Penalties and Corporate Governance Implications
Section 33 of the DPDP Act, 2023 read with the Schedule prescribes penalties up to Rs. 250 crore for failure to implement reasonable security safeguards resulting in a personal data breach, and up to Rs. 200 crore for failure to notify the Data Protection Board and affected Data Principals of a breach. Lesser failures — including failures relating to children's data and obligations of Significant Data Fiduciaries — carry their own penalty bands. These are not trivial exposures for mid-sized and large companies.
For the CS, the governance implication is direct. Penalty orders from the Data Protection Board, once that body becomes operational, are likely to constitute material events for listed companies, triggering disclosure obligations under Regulation 30 of the LODR Regulations read with Schedule III. The CS is typically the officer responsible for LODR disclosures. The compliance chain — breach occurs, internal escalation, DPB notification, LODR disclosure to stock exchanges, board intimation, communication to auditors — needs to be mapped and owned before a breach happens, not assembled in the 24 hours after one is detected.
A useful exercise for the CS is to run a tabletop simulation: assume a breach is detected at 9 PM on a Friday. Who is notified internally? Who decides whether it meets the threshold for DPB notification? Who drafts the Data Principal communication? Who clears the LODR disclosure? Who briefs the chair of the audit committee? If those questions do not have named owners with documented timelines, the compliance framework is not yet operational, regardless of what the policy document says.
Directors' and Officers' Exposure
The DPDP Act does not yet contain explicit provisions for personal liability of directors or officers in the manner of, say, Section 447 of the Companies Act. However, where a penalty is imposed on a company and the board has failed to exercise adequate oversight — particularly after the secretarial audit framework begins capturing DPDP compliance — questions of directorial duty under Section 166 of the Companies Act become relevant. Section 166(3) requires a director to exercise duties with due and reasonable care, skill and diligence. A director who cannot demonstrate that they took reasonable steps to ensure DPDP compliance may face scrutiny in any subsequent derivative action, shareholder challenge, or regulatory inquiry.
This is not speculative risk amplification. It is the natural consequence of the intersection: once data protection becomes a mainstream corporate compliance obligation, the governance standards that already apply to directors under the Companies Act extend to cover it. Boards that have historically treated information security as a line item in the technology budget will need to elevate it to a recurring board agenda item, with documented decisions and clear ownership.
Practical Takeaway
The DPDP Act is not yet fully in force — the Rules remain pending at the time of writing — but the compliance architecture needs to be built now, not after notification. For company secretaries, the practical implication is clear: DPDP compliance is not a parallel workstream to be managed separately by the IT or legal function. It runs through governance structures that the CS already owns — board reports under Section 134, audit committee minutes under Section 177, related-party disclosures under Section 188, and secretarial audit scope under Section 204. Existing secretarial workflows need a data protection layer added to them, and the CS is the natural person to own that integration.
The work to do in the next two quarters is concrete: build a DPDP question into the Section 188 RPT review, add a standing agenda item to the audit committee, draft SOPs for consent and breach notification with documented board approval, and map the breach disclosure chain end-to-end. Teams looking to build audit-ready DPDP compliance documentation alongside their existing Companies Act obligations can explore structured frameworks at legalink.co.in.
Related posts
- IT Act Section 72A: What Counts as Unlawful Disclosure of Personal Information
- SEBI AIF Compliance: A Fund Manager's Regulatory Primer
- IT Act Section 79 Safe Harbour: What Intermediaries Must Do to Keep Immunity
- GST Section 16 CGST: Conditions You Must Meet to Claim ITC
- DPDP Act Section 8: What Data Fiduciary Obligations Actually Require