Apple devices and the DPDP Act: what compliance means for your fleet
The DPDP Act 2023 expects reasonable security safeguards for personal data. For a fleet of Apple devices, that expectation translates into specific, checkable controls.

The Digital Personal Data Protection Act, 2023 makes Indian businesses that determine how personal data is processed, Data Fiduciaries in the Act's language, responsible for protecting it with reasonable security safeguards, and answerable when a breach happens. Much of the commentary on the Act concerns consent notices and websites. Less discussed is where personal data physically lives day to day: on the laptops and phones your employees carry. If those include Macs, iPhones and iPads, this guide translates the Act's expectations into the concrete device controls that meet them. It is a practitioner's view, not legal advice, and it pairs best with counsel on the policy side.
The uncomfortable starting question
Ask it plainly: if a laptop belonging to your sales head was stolen today, could you state, with evidence, that the customer data on it was encrypted and that access to your systems from it was revoked within the hour? For a managed Apple fleet the answer is a report and two clicks. For an unmanaged fleet the honest answer is usually "we believe so", which is not an answer a Data Protection Board enquiry, or a large customer's procurement team, will find persuasive.
Safeguard one: encryption you can prove
Every Mac should have FileVault enforced by MDM with recovery keys escrowed centrally; iPhones and iPads encrypt by hardware once a passcode exists, so the enforceable control is a passcode policy. The operative word in both cases is enforced. A policy document saying devices must be encrypted protects nobody; an MDM report showing every device compliant, with named exceptions being chased, is a reasonable safeguard in the working sense of the phrase. Our macOS hardening service covers the Mac side of this in depth.
Safeguard two: access that ends when it should
Personal data protection fails most often at the edges of employment. The Act's principles imply data should not remain accessible to people with no continuing purpose, which at device level means: remote lock and wipe capability on every company device, work-partition removal on every BYOD phone, and Activation Lock under company control so a leaver cannot hold a device hostage. All three exist only if devices were enrolled in management before the exit, which is why enrolment coverage, not tooling sophistication, is the first compliance metric worth tracking.
Safeguard three: patching as an obligation, not a habit
A known, unpatched vulnerability on a device holding personal data is difficult to describe as a reasonable safeguard once something goes wrong through it. Apple ships security fixes frequently; declarative device management lets you enforce installation deadlines rather than request them. An update policy with deadlines, plus a report showing fleet patch levels, converts patching from an intention into evidence. This is the core of managed patching for macOS.
Safeguard four: breach readiness
The Act requires notifying the Data Protection Board and affected individuals when a personal data breach occurs, and CERT-In's reporting directions run in parallel for cyber incidents, on short timelines. Device management contributes the part most businesses cannot improvise during an incident: knowing what was on the device, whether it was encrypted, when it last checked in, and being able to lock it now. The difference between "a laptop was stolen" and "an encrypted, managed laptop was stolen, was locked within the hour, and held no local copies of the customer database" is the difference between a notification and a crisis.
The employee side: BYOD without surveillance
Employees are data principals too, and their personal iPhones are full of their own personal data. Full device management of personal phones sits badly with the Act's spirit and with common sense. Apple's account-driven user enrolment resolves the tension: the business controls a separated work partition and technically cannot see personal content. Adopting it is simultaneously a security control and a data-minimisation position, which is a rare combination. The mechanics are on our user enrolment page, and the account layer on Managed Apple Accounts.
Working with counsel and your DPO
Device controls are one strand of DPDP compliance, and they work best when the technical and policy strands reference each other. Give whoever owns your privacy programme three artefacts from the device side: the enrolment coverage report, the encryption and patch compliance report, and the written exit procedure with its revocation timings. In return, take from them the data inventory, because knowing which roles handle which personal data is what turns a flat device policy into a tiered one, stricter controls where the data justifies it, lighter touch elsewhere. That exchange, repeated quarterly, is what a defensible posture looks like in practice: neither side improvising, both sides holding documents the other produced. Small firms without a formal DPO should still assign the role of privacy owner to someone; the exchange works at any size.
If a breach does happen, the same relationship carries the response: the device console supplies the facts (what device, what data exposure, what containment, at what time), and counsel shapes the notifications. Rehearse that handoff once, on a tabletop scenario, before you need it at speed. The rehearsal usually exposes one gap, most often that nobody is sure who can authorise a remote wipe out of hours, and fixing that gap on a quiet Tuesday costs nothing.
A device-level compliance checklist
- Every company Apple device enrolled in MDM, with an owner recorded
- Encryption enforced and reported: FileVault on Macs, passcode policy on iOS and iPadOS
- Update deadlines enforced on every platform
- Remote lock and wipe tested, not merely available
- Activation Lock under organisational control on company devices
- BYOD access through user enrolment and conditional access only
- Exit process that revokes device access the same day, every time
- Reports for all of the above, producible on request
Frequently asked questions
Does the DPDP Act specifically require MDM?
No. The Act requires reasonable security safeguards and is deliberately not prescriptive about tools. But for a fleet of laptops and phones holding personal data, it is hard to construct a credible safeguards story without centralised enforcement and evidence, which is precisely what device management provides. MDM is not named; it is implied by the standard of proof you will want to meet.
We are a small company. Does this apply to us?
The Act applies to businesses processing digital personal data broadly, with obligations scaling up for significant data fiduciaries. A twenty-person firm holding customer personal data still carries the core duties, including safeguards and breach notification. The good news is that at twenty devices, the controls in this guide are days of work, not months.
Are Apple's built-in protections enough on their own?
They are excellent raw material and insufficient evidence. Hardware encryption, Gatekeeper and sandboxing protect the device; they do not prove fleet-wide compliance, enforce your policies, or revoke a leaver's access. Compliance lives in the management layer on top of the platform, which is what our Apple device management service exists to provide.
What should we do first, this week?
Inventory. List every device that touches company data, company-owned and personal, and mark which are under management. The gap in that list is your real exposure, and it usually surprises people. Everything else in this guide is ordered work once the list exists.
Further reading

DPDP Act: What Your IT Has to Change
The Digital Personal Data Protection Act changes how Indian businesses must handle personal data. Here is what it means for your systems, in the order it is worth doing.
Read post
Jamf vs Intune for Apple Devices in India: Honest Guide
We deploy both platforms, so we have no reason to flatter either. Here is how Jamf and Intune actually compare for managing Apple devices in an Indian business.
Read post
Apple Device Security for Hyderabad Businesses (2026)
A practical guide to apple device security for Indian businesses, built-in protections, MDM baselines, conditional access and a hardening checklist.
Read postHave a question about this topic?
If you would like help applying any of this to your environment, send us the specifics and an engineer will reply.