What Is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023 and was published in the Gazette of India the same day. The DPDP Rules 2025 were notified on 13 November 2025, converting the earlier draft rules into binding law and activating the enforcement framework.
The Act establishes a rights-based framework where individuals (called Data Principals) have defined rights over their personal data, and organisations processing that data (called Data Fiduciaries) have specific obligations to meet.
Unlike the GDPR, the DPDP Act does not recognise "legitimate interest" as a lawful basis for processing. Consent is the primary legal basis — and it must be free, specific, informed, unconditional, and unambiguous. The only exceptions are a limited set of "certain legitimate uses" defined under Section 7 of the Act.
The law applies to all organisations processing digital personal data in India, regardless of size or sector. It also applies to organisations outside India if they process personal data in connection with offering goods or services to individuals in India.
Who Needs to Comply with the DPDP Act?
The DPDP Act applies to every entity that determines the purpose and means of processing personal data — the law calls this entity a Data Fiduciary. In practical terms, if your organisation does any of the following, you are a Data Fiduciary:
- Collects customer data through a website, app, or form
- Processes employee data for HR, payroll, or benefits
- Stores user data in databases, cloud services, or third-party tools
- Shares personal data with vendors, payment processors, or analytics platforms
- Runs marketing campaigns using personal data (email, SMS, push notifications)
There is no size exemption. The Act applies to startups, SMBs, large enterprises, government bodies, and multinational corporations operating in India equally.
Significant Data Fiduciaries (SDF)
Organisations processing large volumes of personal data, operating in sensitive sectors, or posing systemic risk may be designated as Significant Data Fiduciaries by the Central Government. SDFs face additional obligations:
- Appointing an India-resident Data Protection Officer (DPO)
- Conducting annual Data Protection Impact Assessments (DPIAs)
- Engaging an independent external Data Auditor for annual compliance reviews
- Algorithmic transparency obligations for AI and automated decision-making systems
Sectors most likely to be classified include BFSI, healthcare, telecom, large technology platforms, and government data processing entities.
Not Sure If Your Data Flows Fulfill DPDPA Obligations?
If your organization processes digital personal data of Indian customers or employees, get instant gap validation and a personalized readiness score from our certified privacy team.
DPDPA Enforcement Timeline — Three Phases
The DPDP Act is not a future obligation. It is being enforced in phases. Understanding where you stand in this timeline determines what you need to do — and how fast.
13 November 2025
Rules 1, 2, and 17-21 took effect immediately. The Data Protection Board of India (DPBI) was formally constituted. Definitions and procedural frameworks are live. Complaints can already be filed against organisations.
The enforcement infrastructure exists. A Data Principal can lodge a complaint with the Board today. The absence of a full compliance deadline does not mean the absence of a regulator.
13 November 2026
The Consent Manager registration framework opens. Rule 4 comes into force. The Board gains full power to inquire into violations and levy penalties. Enforcement and penalty machinery becomes operative.
From this date, the Board can investigate and penalise non-compliance — six months before the full deadline. Organisations waiting until May 2027 to start compliance work will find themselves under scrutiny while still in implementation.
13 May 2027
Rules 3, 5-16, 22, and 23 take full effect. This is when all substantive obligations become enforceable: Notice notice & consent; DSR rights; Security safeguards; Breach notifications; Data retention; Children's rules; Cross-border rules; Vendor contracts.
There is no grace period expected. The Board is already operational and has been receiving complaints since early 2026.
DPDPA Penalty Structure — What Non-Compliance Costs
The DPDP Act prescribes penalties per violation. A single data breach incident can trigger multiple penalty categories simultaneously.
| Violation | Maximum Penalty |
|---|---|
| Failure to implement reasonable security safeguards | ₹250 Crore |
| Failure to notify the Board and affected Data Principals of a breach | ₹200 Crore |
| Violations involving children's data (Section 9) | ₹200 Crore |
| Failure to meet Significant Data Fiduciary obligations | ₹150 Crore |
| General non-compliance with Act provisions | ₹50 Crore |
These are not theoretical numbers. The Data Protection Board has the authority to impose these penalties, and the enforcement mechanism is already in place. For context, the ₹250 crore ceiling is higher in absolute terms than the GDPR’s maximum penalty for most organisations. Beyond financial penalties, non-compliance carries reputational risk, loss of enterprise client trust, and potential disqualification from government contracts and regulated-sector partnerships.
Key DPDPA Obligations for Data Fiduciaries
Data Fiduciaries must comply with 8 fundamental obligations under the Act and Rules. Below is a detailed breakdown of each obligation.
Notice and Consent
Before collecting personal data, you must provide a clear, standalone privacy notice that specifies what data is being collected, the purpose of processing, and the Data Principal's right to withdraw consent. Consent must be purpose-specific — you cannot bundle multiple purposes into a single consent request. Consent records must be maintained with timestamps, version history, and proof of what was shown and what was agreed to. The burden of proof lies on the Data Fiduciary.
How PrivacyOS helps: Our Consent & Cookie Management module provides geo-aware consent banners, purpose-linked consent capture, multilingual notice delivery in all 22 scheduled Indian languages, and immutable consent audit logs.
Explore module capabilitiesData Principal Rights
The DPDP Act grants individuals five categories of rights: Right to Access (Section 11) — Request a summary of personal data being processed and the processing activities; Right to Correction and Erasure (Section 12) — Request correction of inaccurate data or erasure of data no longer necessary; Right to Grievance Redressal (Section 13) — File grievances with the Data Fiduciary before approaching the Board; Right to Nominate (Section 14) — Nominate another individual to exercise rights in case of death or incapacity. Data Fiduciaries must respond to rights requests within the timelines specified in the Rules. Failure to respond is itself a violation.
How PrivacyOS helps: Our DSR Automation module provides a branded self-service portal with identity verification, smart routing, SLA tracking, automated data purging, and signed proof-of-completion for audit trails.
Explore module capabilitiesData Security and Protection
Section 8(4) requires Data Fiduciaries to implement 'reasonable security safeguards' to prevent data breaches. While the Act does not prescribe specific technical measures, the industry standard includes encryption, access controls, audit logging, and regular vulnerability assessments.
How PrivacyOS helps: Our Data Discovery & Classification module identifies where personal data resides across your systems, and our Security & Compliance Services cover ISO 27001 readiness, SOC 2 preparation, and VAPT — so your security posture matches your compliance claims.
Explore module capabilitiesBreach Notification
Section 8(6) and Rule 7 require Data Fiduciaries to notify the Data Protection Board and affected Data Principals of any personal data breach 'without delay.' The DPDP Rules require detailed reporting within 72 hours. Additionally, CERT-In's existing mandate requires intimation of cybersecurity incidents within 6 hours. A single breach triggers two parallel clocks — CERT-In 6-hour and DPDPA 72-hour — with different notification requirements and different authorities.
How PrivacyOS helps: Our Breach Response & Incident Management module provides dual-clock tracking, automated escalation based on severity, notification templates for the Board and Data Principals, and a secure evidence vault for complete incident documentation.
Explore module capabilitiesChildren's Data (Section 9)
Processing personal data of children (individuals under 18) requires verifiable parental or guardian consent before any processing begins. The Act also restricts tracking, behavioural monitoring, and targeted advertising directed at children. This obligation applies to any organisation whose products or services may be accessed by minors — including EdTech platforms, gaming companies, social media apps, and e-commerce sites.
How PrivacyOS helps: Our Children's Data Protection module provides age verification gates, OTP-verified parental consent workflows, guardian consent for children with disabilities (Rule 11), and default restrictions on ad targeting and profiling.
Explore module capabilitiesVendor and Processor Management
Section 8(2) requires Data Fiduciaries to ensure that any Data Processor processing personal data on their behalf does so under a valid contract with appropriate data protection obligations. You are responsible for the compliance of your vendors. Every payment gateway, cloud provider, analytics tool, CRM, and marketing platform that touches personal data needs a Data Processing Agreement (DPA) and ongoing compliance monitoring.
How PrivacyOS helps: Our Vendor & Third-Party Risk Management module provides vendor risk questionnaires, DPA tracking, ongoing compliance monitoring, risk scoring, and a centralised vendor compliance dashboard.
Explore module capabilitiesData Retention and Deletion
Personal data must be retained only for as long as necessary to fulfil the purpose for which it was collected. Once the purpose is served or consent is withdrawn, the data must be deleted — unless retention is required by law. The DPDP Rules 2025 also introduce a mandatory 1-year retention period for security logs and traffic data, overriding shorter retention policies for these specific data categories.
Cross-Border Data Transfers
The DPDP Act permits cross-border data transfers to all countries except those specifically restricted by the Central Government. As of mid-2026, no countries have been notified as restricted — but the framework allows future restrictions. Organisations must maintain data flow inventories that track which countries their data is transferred to.
DPDPA vs GDPR — Key Differences
If your organisation already complies with GDPR, you have a head start — but DPDPA is not GDPR. Key differences include:
| Area | DPDPA | GDPR |
|---|---|---|
| Lawful basis for processing | Consent is primary. No "legitimate interest" basis. | Six lawful bases including legitimate interest. |
| Sensitive data categories | No separate category — all personal data treated equally. Additional obligations only for SDFs. | Special categories (health, biometric, political, etc.) with stricter rules. |
| Consent Manager | Regulated entity registered with the Board — a government-licensed intermediary, not just software. | No equivalent concept. |
| Data Protection Officer | Mandatory only for Significant Data Fiduciaries. | Mandatory for public authorities and large-scale processing. |
| Cross-border transfers | Permitted unless specifically restricted by government notification. | Requires adequacy decisions, SCCs, or BCRs. |
| Penalties | Up to ₹250 crore (~€27M) per violation. | Up to €20M or 4% of global turnover. |
| Scope | Digital personal data of individuals in India. | Personal data of EU residents globally. |
For a detailed comparison, read our guide on DPDPA vs GDPR.
How PrivacyOS Helps You Achieve DPDPA Compliance
PrivacyOS is an all-in-one privacy, security, and compliance platform built specifically for Indian businesses. Unlike global platforms that were designed for GDPR and retrofitted for India, PrivacyOS is purpose-built for the DPDP Act 2023 and DPDP Rules 2025.
Assess Your Current State
We start with a comprehensive review of your data processing activities, consent mechanisms, vendor relationships, and existing security controls. You receive a clear gap assessment showing exactly where you stand against each DPDPA obligation — and what needs to change.
Implement Compliance Controls
Based on the assessment, we deploy the PrivacyOS modules your organisation needs: Consent & Cookie Management — collect and prove valid consent; DSR Automation — handle rights requests within regulatory timelines; Data Discovery & Classification — find and map all personal data; DPIA — conduct and document privacy impact assessments; Breach Response — set up incident management with dual-clock tracking; Vendor Risk Management — assess and monitor third-party compliance; Compliance Dashboards — real-time visibility into compliance posture.
Monitor, Report, and Maintain
Compliance is not a one-time project. PrivacyOS provides ongoing monitoring, real-time compliance dashboards, periodic assessments, and expert advisory through our DPO-as-a-Service offering — keeping your programme current as regulations evolve and your business grows.
What Makes PrivacyOS Different
All-in-one platform
Consent, DSR, data discovery, DPIA, breach response, vendor risk, dashboards, and training in one system
Built for India
DPDP Act-aligned workflows, India-specific PII detection (Aadhaar, PAN), 22-language support
Platform + advisory
Technology combined with certified privacy consultants and DPO-as-a-Service
Privacy + security
Also supports ISO 27001, SOC 2, and VAPT — no need for a separate security vendor
Works at every scale
From 10-person startups to enterprise organisations with complex data flows
DPDPA Compliance Checklist — Quick Reference
Use this interactive checklist as a starting point to evaluate your readiness. Tick the completed items below to trace your compliance program metrics.
Consent & Notice
Data Principal Rights
Data Security
Breach Response
Vendor Management
Children's Data
Organisational
For a detailed checklist version, download our DPDPA Compliance Checklist.
Frequently Asked Questions About DPDPA Compliance
Start Your DPDPA Compliance Journey
The Data Protection Board is operational. Complaints are being filed. The May 2027 deadline is less than a year away. Every month you delay is a month of unmanaged risk and potential regulatory exposure.
PrivacyOS helps organisations of all sizes — from startups to enterprises — build compliance programmes that are audit-ready, operationally sustainable, and aligned to the DPDP Act 2023.
Talk to our privacy experts for a free compliance assessment. We will review your current data processing activities, identify gaps, and show you exactly what needs to happen before May 2027.
