State · West Bengal

DPDPA Compliance in West Bengal

West Bengal firms that process digital personal data must meet remaining DPDPA duties from 13 May 2027: a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. Tea-garden rolls and Howrah contractor packs will not wait for a Kolkata-only banner.

Last reviewed: 23 September 2026

Why DPDPA compliance matters in West Bengal specifically

West Bengal's exposure is riverine and hill. Howrah and Durgapur-Asansol plants hold worker and contractor IDs. North Bengal tea gardens keep seasonal labour Aadhaar. Jute units hold piece-rate rolls. Kolkata BFSI and trading firms keep client KYC. Bangla Sahayata Kendra and municipal vendors process citizen applications as Data Processors; those copies stay personal data and need a Section 8(2) contract.

What West Bengal businesses should prepare first

  • Map Kolkata plus Howrah, Durgapur and tea-garden files on one sheet — system, purpose, processor, owner.
  • Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
  • Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
  • Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — plant IT, garden payroll, Sahayata vendor, LOS.

Frequently asked questions

We run a tea garden or a Howrah workshop, not a Salt Lake IT firm. Does DPDPA apply?

Yes. If you decide the purpose and means for digital personal data — labour IDs, contractor KYC, trading files — you are a Data Fiduciary. There is no district carve-out. Section 8(5) security failures sit under the ₹250 crore Schedule slab.

If a Sahayata Kendra or garden payroll vendor leaks, who do we tell and by when?

Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.

Does every Kolkata NBFC need a Rule 13 audit before May 2027?

No. Rule 13 annual DPIA and independent audit start only after a Section 10 Significant Data Fiduciary notice. Most still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Software is not your Section 10(2)(b) auditor.

Official sources

Get a DPDPA readiness walkthrough for your West Bengal business

Book 30 minutes to map Howrah, tea-garden and Kolkata BFSI files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.