India’s enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) marks a decisive shift toward a modern data protection regime anchored in accountability, consent, and enforcement. While the statute is primarily directed at “data fiduciaries,” its implications extend well beyond operational compliance. At the boardroom level, the Act has triggered a reassessment of governance responsibilities, risk allocation, and critically Directors and Officers (“D&O”) insurance.