Pillar Guide · DPDPA Compliance

DPDPA Compliance: What Indian Businesses Need to Know and Do Before May 2027

The Digital Personal Data Protection Act, 2023 (DPDPA) is India’s first comprehensive data protection law. It governs how organisations collect, process, store, and protect the personal data of individuals in India. The DPDP Rules were notified on 13 November 2025, and full compliance is required by 13 May 2027 — with no grace period expected.

If your organisation processes digital personal data of individuals in India — whether you are a startup, an enterprise, a hospital, a bank, or an e-commerce platform — the DPDP Act applies to you.

This page covers everything you need to understand and act on: what the law requires, who it applies to, the enforcement timeline, the penalty structure, and how PrivacyOS helps you build a compliance programme that holds up under regulatory scrutiny.

· DPDPA Compliance · Trust Assured
FAST TRACK APPLICATION

Apply for DPDPA Assessment

Fill the details to get started with our corporate panel.

Representative PortraitRepresentative PortraitRepresentative PortraitRepresentative Portrait
4.9/5

Trusted by 1,000+ compliance teams

What Is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023 and was published in the Gazette of India the same day. The DPDP Rules 2025 were notified on 13 November 2025, converting the earlier draft rules into binding law and activating the enforcement framework.

The Act establishes a rights-based framework where individuals (called Data Principals) have defined rights over their personal data, and organisations processing that data (called Data Fiduciaries) have specific obligations to meet.

Unlike the GDPR, the DPDP Act does not recognise "legitimate interest" as a lawful basis for processing. Consent is the primary legal basis — and it must be free, specific, informed, unconditional, and unambiguous. The only exceptions are a limited set of "certain legitimate uses" defined under Section 7 of the Act.

The law applies to all organisations processing digital personal data in India, regardless of size or sector. It also applies to organisations outside India if they process personal data in connection with offering goods or services to individuals in India.

Who Needs to Comply with the DPDP Act?

The DPDP Act applies to every entity that determines the purpose and means of processing personal data — the law calls this entity a Data Fiduciary. In practical terms, if your organisation does any of the following, you are a Data Fiduciary:

  • Collects customer data through a website, app, or form
  • Processes employee data for HR, payroll, or benefits
  • Stores user data in databases, cloud services, or third-party tools
  • Shares personal data with vendors, payment processors, or analytics platforms
  • Runs marketing campaigns using personal data (email, SMS, push notifications)

There is no size exemption. The Act applies to startups, SMBs, large enterprises, government bodies, and multinational corporations operating in India equally.

Significant Data Fiduciaries (SDF)

Organisations processing large volumes of personal data, operating in sensitive sectors, or posing systemic risk may be designated as Significant Data Fiduciaries by the Central Government. SDFs face additional obligations:

  • Appointing an India-resident Data Protection Officer (DPO)
  • Conducting annual Data Protection Impact Assessments (DPIAs)
  • Engaging an independent external Data Auditor for annual compliance reviews
  • Algorithmic transparency obligations for AI and automated decision-making systems

Sectors most likely to be classified include BFSI, healthcare, telecom, large technology platforms, and government data processing entities.

DPDPA ADVISORY & GAP ANALYSIS

Not Sure If Your Data Flows Fulfill DPDPA Obligations?

If your organization processes digital personal data of Indian customers or employees, get instant gap validation and a personalized readiness score from our certified privacy team.

DPDPA Enforcement Timeline — Three Phases

The DPDP Act is not a future obligation. It is being enforced in phases. Understanding where you stand in this timeline determines what you need to do — and how fast.

Phase 1Already Active

13 November 2025

Rules 1, 2, and 17-21 took effect immediately. The Data Protection Board of India (DPBI) was formally constituted. Definitions and procedural frameworks are live. Complaints can already be filed against organisations.

Business Impact:

The enforcement infrastructure exists. A Data Principal can lodge a complaint with the Board today. The absence of a full compliance deadline does not mean the absence of a regulator.

Phase 21 Year In

13 November 2026

The Consent Manager registration framework opens. Rule 4 comes into force. The Board gains full power to inquire into violations and levy penalties. Enforcement and penalty machinery becomes operative.

Business Impact:

From this date, the Board can investigate and penalise non-compliance — six months before the full deadline. Organisations waiting until May 2027 to start compliance work will find themselves under scrutiny while still in implementation.

Phase 3Hard Deadline

13 May 2027

Rules 3, 5-16, 22, and 23 take full effect. This is when all substantive obligations become enforceable: Notice notice & consent; DSR rights; Security safeguards; Breach notifications; Data retention; Children's rules; Cross-border rules; Vendor contracts.

Business Impact:

There is no grace period expected. The Board is already operational and has been receiving complaints since early 2026.

DPDPA Penalty Structure — What Non-Compliance Costs

The DPDP Act prescribes penalties per violation. A single data breach incident can trigger multiple penalty categories simultaneously.

ViolationMaximum Penalty
Failure to implement reasonable security safeguards₹250 Crore
Failure to notify the Board and affected Data Principals of a breach₹200 Crore
Violations involving children's data (Section 9)₹200 Crore
Failure to meet Significant Data Fiduciary obligations₹150 Crore
General non-compliance with Act provisions₹50 Crore

These are not theoretical numbers. The Data Protection Board has the authority to impose these penalties, and the enforcement mechanism is already in place. For context, the ₹250 crore ceiling is higher in absolute terms than the GDPR’s maximum penalty for most organisations. Beyond financial penalties, non-compliance carries reputational risk, loss of enterprise client trust, and potential disqualification from government contracts and regulated-sector partnerships.

Key DPDPA Obligations for Data Fiduciaries

Data Fiduciaries must comply with 8 fundamental obligations under the Act and Rules. Below is a detailed breakdown of each obligation.

Obligation 01

Notice and Consent

Before collecting personal data, you must provide a clear, standalone privacy notice that specifies what data is being collected, the purpose of processing, and the Data Principal's right to withdraw consent. Consent must be purpose-specific — you cannot bundle multiple purposes into a single consent request. Consent records must be maintained with timestamps, version history, and proof of what was shown and what was agreed to. The burden of proof lies on the Data Fiduciary.

How PrivacyOS helps: Our Consent & Cookie Management module provides geo-aware consent banners, purpose-linked consent capture, multilingual notice delivery in all 22 scheduled Indian languages, and immutable consent audit logs.

Explore module capabilities
Obligation 02

Data Principal Rights

The DPDP Act grants individuals five categories of rights: Right to Access (Section 11) — Request a summary of personal data being processed and the processing activities; Right to Correction and Erasure (Section 12) — Request correction of inaccurate data or erasure of data no longer necessary; Right to Grievance Redressal (Section 13) — File grievances with the Data Fiduciary before approaching the Board; Right to Nominate (Section 14) — Nominate another individual to exercise rights in case of death or incapacity. Data Fiduciaries must respond to rights requests within the timelines specified in the Rules. Failure to respond is itself a violation.

How PrivacyOS helps: Our DSR Automation module provides a branded self-service portal with identity verification, smart routing, SLA tracking, automated data purging, and signed proof-of-completion for audit trails.

Explore module capabilities
Obligation 03

Data Security and Protection

Section 8(4) requires Data Fiduciaries to implement 'reasonable security safeguards' to prevent data breaches. While the Act does not prescribe specific technical measures, the industry standard includes encryption, access controls, audit logging, and regular vulnerability assessments.

How PrivacyOS helps: Our Data Discovery & Classification module identifies where personal data resides across your systems, and our Security & Compliance Services cover ISO 27001 readiness, SOC 2 preparation, and VAPT — so your security posture matches your compliance claims.

Explore module capabilities
Obligation 04

Breach Notification

Section 8(6) and Rule 7 require Data Fiduciaries to notify the Data Protection Board and affected Data Principals of any personal data breach 'without delay.' The DPDP Rules require detailed reporting within 72 hours. Additionally, CERT-In's existing mandate requires intimation of cybersecurity incidents within 6 hours. A single breach triggers two parallel clocks — CERT-In 6-hour and DPDPA 72-hour — with different notification requirements and different authorities.

How PrivacyOS helps: Our Breach Response & Incident Management module provides dual-clock tracking, automated escalation based on severity, notification templates for the Board and Data Principals, and a secure evidence vault for complete incident documentation.

Explore module capabilities
Obligation 05

Children's Data (Section 9)

Processing personal data of children (individuals under 18) requires verifiable parental or guardian consent before any processing begins. The Act also restricts tracking, behavioural monitoring, and targeted advertising directed at children. This obligation applies to any organisation whose products or services may be accessed by minors — including EdTech platforms, gaming companies, social media apps, and e-commerce sites.

How PrivacyOS helps: Our Children's Data Protection module provides age verification gates, OTP-verified parental consent workflows, guardian consent for children with disabilities (Rule 11), and default restrictions on ad targeting and profiling.

Explore module capabilities
Obligation 06

Vendor and Processor Management

Section 8(2) requires Data Fiduciaries to ensure that any Data Processor processing personal data on their behalf does so under a valid contract with appropriate data protection obligations. You are responsible for the compliance of your vendors. Every payment gateway, cloud provider, analytics tool, CRM, and marketing platform that touches personal data needs a Data Processing Agreement (DPA) and ongoing compliance monitoring.

How PrivacyOS helps: Our Vendor & Third-Party Risk Management module provides vendor risk questionnaires, DPA tracking, ongoing compliance monitoring, risk scoring, and a centralised vendor compliance dashboard.

Explore module capabilities
Obligation 07

Data Retention and Deletion

Personal data must be retained only for as long as necessary to fulfil the purpose for which it was collected. Once the purpose is served or consent is withdrawn, the data must be deleted — unless retention is required by law. The DPDP Rules 2025 also introduce a mandatory 1-year retention period for security logs and traffic data, overriding shorter retention policies for these specific data categories.

Obligation 08

Cross-Border Data Transfers

The DPDP Act permits cross-border data transfers to all countries except those specifically restricted by the Central Government. As of mid-2026, no countries have been notified as restricted — but the framework allows future restrictions. Organisations must maintain data flow inventories that track which countries their data is transferred to.

DPDPA vs GDPR — Key Differences

If your organisation already complies with GDPR, you have a head start — but DPDPA is not GDPR. Key differences include:

AreaDPDPAGDPR
Lawful basis for processingConsent is primary. No "legitimate interest" basis.Six lawful bases including legitimate interest.
Sensitive data categoriesNo separate category — all personal data treated equally. Additional obligations only for SDFs.Special categories (health, biometric, political, etc.) with stricter rules.
Consent ManagerRegulated entity registered with the Board — a government-licensed intermediary, not just software.No equivalent concept.
Data Protection OfficerMandatory only for Significant Data Fiduciaries.Mandatory for public authorities and large-scale processing.
Cross-border transfersPermitted unless specifically restricted by government notification.Requires adequacy decisions, SCCs, or BCRs.
PenaltiesUp to ₹250 crore (~€27M) per violation.Up to €20M or 4% of global turnover.
ScopeDigital personal data of individuals in India.Personal data of EU residents globally.

For a detailed comparison, read our guide on DPDPA vs GDPR.

How PrivacyOS Helps You Achieve DPDPA Compliance

PrivacyOS is an all-in-one privacy, security, and compliance platform built specifically for Indian businesses. Unlike global platforms that were designed for GDPR and retrofitted for India, PrivacyOS is purpose-built for the DPDP Act 2023 and DPDP Rules 2025.

Step 1

Assess Your Current State

We start with a comprehensive review of your data processing activities, consent mechanisms, vendor relationships, and existing security controls. You receive a clear gap assessment showing exactly where you stand against each DPDPA obligation — and what needs to change.

Step 2

Implement Compliance Controls

Based on the assessment, we deploy the PrivacyOS modules your organisation needs: Consent & Cookie Management — collect and prove valid consent; DSR Automation — handle rights requests within regulatory timelines; Data Discovery & Classification — find and map all personal data; DPIA — conduct and document privacy impact assessments; Breach Response — set up incident management with dual-clock tracking; Vendor Risk Management — assess and monitor third-party compliance; Compliance Dashboards — real-time visibility into compliance posture.

Step 3

Monitor, Report, and Maintain

Compliance is not a one-time project. PrivacyOS provides ongoing monitoring, real-time compliance dashboards, periodic assessments, and expert advisory through our DPO-as-a-Service offering — keeping your programme current as regulations evolve and your business grows.

What Makes PrivacyOS Different

All-in-one platform

Consent, DSR, data discovery, DPIA, breach response, vendor risk, dashboards, and training in one system

Built for India

DPDP Act-aligned workflows, India-specific PII detection (Aadhaar, PAN), 22-language support

Platform + advisory

Technology combined with certified privacy consultants and DPO-as-a-Service

Privacy + security

Also supports ISO 27001, SOC 2, and VAPT — no need for a separate security vendor

Works at every scale

From 10-person startups to enterprise organisations with complex data flows

DPDPA Compliance Checklist — Quick Reference

Use this interactive checklist as a starting point to evaluate your readiness. Tick the completed items below to trace your compliance program metrics.

Your Readiness Progress0% (0/31 items)

Consent & Notice

Privacy notices are clear, standalone, and purpose-specific
Consent is collected before processing begins
Consent records are timestamped and stored with version history
Consent withdrawal mechanism is accessible and functional
Multilingual notices are available for your user base

Data Principal Rights

Self-service portal or mechanism exists for rights requests
Identity verification is performed before processing requests
SLA tracking is in place for response timelines
Proof of resolution is generated and stored
Grievance redressal process is documented and operational

Data Security

Personal data inventory exists and is current
Encryption is applied to data at rest and in transit
Access controls are role-based and regularly reviewed
Vulnerability assessments and penetration tests are conducted periodically
Security incident response plan exists and is tested

Breach Response

Breach detection and classification process is defined
CERT-In 6-hour and DPDPA 72-hour notification workflows are in place
Notification templates for the Board and Data Principals are prepared
Evidence collection and storage procedures are documented
Post-incident review process is defined

Vendor Management

Inventory of all Data Processors is maintained
Data Processing Agreements (DPAs) are signed with every processor
Vendor risk assessments are conducted periodically
Vendor compliance is monitored on an ongoing basis

Children's Data

Age verification mechanisms are in place where applicable
Parental/guardian consent workflows are functional
Tracking, profiling, and targeted advertising restrictions are enforced for minors

Organisational

Data Protection Officer is appointed (if SDF or by choice)
Employee training on DPDPA obligations is conducted
Compliance documentation is maintained and audit-ready
DPIA process is established (mandatory for SDFs)

For a detailed checklist version, download our DPDPA Compliance Checklist.

Frequently Asked Questions About DPDPA Compliance

Start Your DPDPA Compliance Journey

The Data Protection Board is operational. Complaints are being filed. The May 2027 deadline is less than a year away. Every month you delay is a month of unmanaged risk and potential regulatory exposure.

PrivacyOS helps organisations of all sizes — from startups to enterprises — build compliance programmes that are audit-ready, operationally sustainable, and aligned to the DPDP Act 2023.

Talk to our privacy experts for a free compliance assessment. We will review your current data processing activities, identify gaps, and show you exactly what needs to happen before May 2027.

Call Us: +91 8887946496