Last updated: 27 July 2026
Quick Answer: The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's data protection law governing how organisations process the digital personal data of individuals in India. The DPDP Rules, 2025 were published in the Official Gazette on 14 November 2025 and take effect in phases up to 14 May 2027. Non-compliance can attract penalties of up to ₹250 crore per breach.
Every Indian company that collects customer, employee or vendor personal data is now a "Data Fiduciary" with statutory obligations under the DPDP Act. The Data Protection Board of India, established under the Act, enforces these duties, and the DPDP Rules, 2025 fix the operational detail and the timeline. This guide covers the obligations, the penalty schedule, and what to look for in DPDP and data protection compliance software.
DPDP Compliance Obligations at a Glance
The table below summarises the core duties a Data Fiduciary must operationalise. Each obligation is set out in the DPDP Act, 2023 or the DPDP Rules, 2025.
| Obligation | What it requires | Source |
|---|---|---|
| Lawful basis | Process personal data only on consent or a specified legitimate use | Section 4(1)(a)/(b); Section 7 |
| Consent notice | Give a clear, itemised, standalone notice in English or an Eighth Schedule language | Section 5(3); Rule 3(a),(b)(i) |
| Security safeguards | Implement reasonable technical and organisational safeguards | Section 8(5); Rule 6 |
| Breach notification | Inform the Board and affected individuals (Data Principal) of every personal-data breach | Section 8(6); Rule 7 |
| Data-principal rights | Enable access, correction, erasure, grievance redressal and nomination | Sections 11 to 14 |
| Retention limits | Erase personal data once the purpose is served | Section 8(7); Rule 8 |
| SDF duties | Appoint a DPO, run a DPIA and an annual audit if designated significant, and observe algorithmic-risk and cross-border processing restrictions | Section 10(2); Rule 13 |
What Is the DPDP Act 2023 and Who Must Comply?
The DPDP Act is India's first independent data protection law and it was approved by the President on 11 August 2023. This Act regulates the processing of "digital personal data," which is defined as personal data (information about an identifiable individual) that exists in digital form.
Who becomes a Data Fiduciary?
Compliance is not only a concern for businesses that handle technology in their operations. Each entity plays their part in the equation of personal data, since any organisation that determines how and why personal data is processed becomes a Data Fiduciary; e.g., banks, hospitals, manufacturers, retailers, and employers.
Does the DPDP Act apply to companies outside India?
In certain situations, yes. Under Section 3 of the Digital Personal Data Protection Act, 2023, the law applies to the processing of personal data within the territory of India. It also applies to data processed outside India, if that processing is connected to offering goods or services to individuals in India. As a result, any foreign-based organisation offering any services to people in India would fall within the scope of this law.
When Does the DPDP Act Come Into Force?
The obligations commence in phases. The Ministry of Electronics and Information Technology (MeitY) published the DPDP Rules, 2025 in the Official Gazette on 14 November 2025, with a staggered timeline.
| Phase | Effective date | What commences |
|---|---|---|
| Phase I | 14 November 2025 | Data Protection Board setup (Rules 1, 2 and 17 to 21) |
| Phase II | November 2026 | Consent Manager registration and obligations (Rule 4) |
| Phase III | 14 May 2027 | Substantive Data Fiduciary duties: consent notice, security safeguards, breach reporting, retention limits, children's/disability consent (Rules 3, 6 to 12); SDF obligations and data-principal rights (Rules 13 to 14); cross-border transfer conditions and research/archival exemption (Rules 15 to 16); State processing for subsidies/benefits (Rule 5); and appeals and government information requests (Rules 22 to 23) |
Why should you start DPDP compliance now?
There is a mechanism through which the law will be enforced, and rules will start being followed from 14 May 2027. So, it is crucial to start working on compliance strategies and plans now and get ready for that.
What Are the Penalties for DPDP Act Non-Compliance?
The schedule included in the DPDP Act outlines the penalties applicable by the Data Protection Board after the inquiry has been conducted. The penalty involves fines only, and no imprisonment is involved. However, the amount of penalty can be different for every violation, and the penalties will depend on factors set out in the Act - the nature, gravity and duration of the breach, whether it is a repeat violation, whether the company gained or avoided a loss from it, and how quickly and effectively it responded.
| Breach | Section | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards | Section 8(5) | ₹250 crore |
| Failure to notify a personal-data breach | Section 8(6) | ₹200 crore |
| Breach of children's-data obligations | Section 9 | ₹200 crore |
| Breach of Significant Data Fiduciary duties | Section 10 | ₹150 crore |
| Breach of a Data Principal's duties | Section 15 | ₹10,000 |
| Any other provision of the Act or Rules | Catch-all | ₹50 crore |
Can one incident trigger more than one penalty?
Because the Board can penalise breaches of different provisions separately, a single incident can trigger obligations under more than one provision - for example, a safeguards failure that is also not reported to the Board in time can expose a company to penalties under more than one section. This is why evidencing each obligation - not merely performing it - matters.
What Are Your Core Obligations as a Data Fiduciary?
Four obligations carry the most implementation burden: obtaining valid consent, notifying the Board and affected individuals of a breach, honouring the rights of Data Principals, and a set of additional duties for larger or high-risk organisations designated as Significant Data Fiduciaries.
How must consent and notice be handled?
Consent should not only be expressed willingly but also be based on individual understanding of the information provided, be clear and precise concerning its purpose - and, importantly, be given through a clear affirmative action, not assumed or pre-ticked. Rule 3 sets the requirement that consent notices must be a separate, standalone communication about the specific personal data being collected, its purpose, and the goods or services it enables. Moreover, people should also have options of withdrawing their consent as easily as they gave it.
What is the 72-hour breach-notification rule?
Rule 7 has made it mandatory to establish two types of notifications even if the incident involves a very small breach. This essentially means the appropriate Data Principal has to be notified without delay besides informing the Board regarding the breach situation including issues like nature, extent and timing of the breach as well as probable implications of the breach. The complete report has to be submitted to the Board in 72 hours unless the Board has permitted a longer period on a written request. Thus, the deadline can only be met if the process of detection and escalation is already in place before the breach, which is where enterprise risk and incident-response tooling earns its place.
What rights can data principals exercise?
From Sections 11 to 14, an individual is given the right to obtain a summary of his information, its processing, and who else it has been shared with, and to ask for a correction, updating or erasure of data. The individual may also appoint someone else to exercise those rights in the event of his death or incapacity. The Data Fiduciaries must separately give the contact detail of a person who is able to explain all the matters related to the processing.
What extra duties apply to a Significant Data Fiduciary?
In accordance with several characteristics such as the volume and sensitivity of data processed, the Central Government may designate the company as a Significant Data Fiduciary (SDF). In compliance with Section 10 and Rule 13, the SDF should appoint a Data Protection Officer in India. This officer should be accountable to the board of directors or similar governing body, conduct a Data Protection Impact Assessment (DPIA) and an independent audit once every twelve (12) months, and ensure that the algorithmic operations do not infringe basic rights of individuals.
How Does the DPDP Act Compare With the GDPR?
Simply following the GDPR regime is insufficient to consider any Indian firm compliant with the DPDP Act. Numerous Indian businesses already have the GDPR regime in place and are worried about their compliance with the Indian law. However, these laws differ in terms of scope, legal foundations, and application.
| Dimension | GDPR (EU) | DPDP Act (India) |
|---|---|---|
| Material scope | Personal data in any form | Digital personal data only |
| Sensitive-data category | Yes, special categories | No separate category |
| Legal bases | Six lawful bases | Consent and specified legitimate uses |
| Breach reporting | 72 hours to the authority | Without delay to Data Principal and Board; detailed report to the Board within 72 hours |
| Maximum penalty | Twenty million euro or 4% of global turnover | Up to ₹250 crore, depending on the provision breached |
| Regulator | National data-protection authorities | Data Protection Board of India |
| Cross-border data | Restricted transfers outside the EEA | Permitted except to countries the Government restricts |
What must a GDPR-ready firm still add for DPDP?
The GDPR stipulates solid principles of security and rights, but the requirements for obtaining consent, breach notification mechanisms and the obligations of the SDF will need to be revised to align with Indian legislation. This mapping is based on the entire text of the Digital Personal Data Protection Act, 2023 on India Code and the Digital Personal Data Protection Rules, 2025.
What Are the Most Common DPDP Compliance Mistakes?
The downfall of the DPDP Act's implementation is often caused mostly by issues with processes rather than by technology. Here is a list of the five aspects that Indian companies have been working on ahead of the deadline of 14 May 2027:
- Treating a GDPR programme as sufficient and never re-mapping consent notices, breach mechanics and SDF duties to the Indian text.
- Bundling the consent notice into terms and conditions instead of the standalone, itemised notice Rule 3 requires.
- Having no breach-response workflow, so the without-delay intimation and 72-hour Board report cannot be met in practice.
- Ignoring employee and vendor data, forgetting that payroll, HR and supplier records are personal data within scope.
- Keeping data indefinitely, missing the erasure duty the Act imposes and the retention limits the Rules impose once the purpose is served.
What Should You Look For in DPDP and Data-Privacy Compliance Software?
When large companies want to find the best DPDP Act compliance software or GDPR and data protection compliance software more broadly in India, they often default to brand reputation. But the reality is that compliance software must be able to perform the tasks, not just carry a recognisable name. The right compliance software must convert the compliance needs mentioned above into active tasks with evidence a company can produce if the Board ever inquires. Prioritise these capabilities:
- A mapped obligation register covering the DPDP Act, the DPDP Rules and adjacent laws, updated as the phased dates arrive.
- Consent and notice records that store the notice version, language and timestamp against each Data Principal.
- Breach-response workflows that trigger the without-delay intimation and the 72-hour Board report with a full evidence log.
- Data-principal request handling for access, correction, erasure and grievance, with response-time tracking.
- Retention controls that flag the erasure timelines the Rules require, including the three-year rule under the Third Schedule for e-commerce and social-media intermediaries with 2 crore+ registered users, and online gaming intermediaries with 50 lakh+ registered users.
- Audit-ready evidence - versioned policies, DPIAs and audit reports mapped to each SDF duty.
How does a GRC platform consolidate DPDP compliance?
A GRC platform such as LexComply's compliance management system treats DPDP as one regulated domain within a wider library of 1,300+ Central and State Acts. Data protection tasks therefore sit alongside secretarial, tax and HR and labour-law compliance in a single, allocated and monitored compliance calendar. That consolidation matters because employee, payroll and vendor records are personal data too, and the DPDP Act applies across every function that holds them.
Legal Disclaimer
This article provides general information about Indian data-protection law as of the date it is published and is not legal advice. Organisations should confirm their specific obligations and timelines with a qualified professional before acting.
Frequently Asked Questions
Is the DPDP Act in force in 2026?
The Act is enacted and its enforcement machinery is live: the DPDP Rules were published on 14 November 2025, and the Data Protection Board has been established. The substantive processing obligations, however, become binding from 14 May 2027 under the phased schedule.
Does the DPDP Act apply to small businesses and startups?
Yes. There is no turnover or headcount exemption from being a Data Fiduciary, so a two-person startup and a large bank carry the same core duties. Under Section 17(3), the Central Government may exempt startups from the notice (Section 5), retention (Sections 8(3) and 8(7)) and Sections 10 and 11 obligations. Until then, every business must comply.
What is a Consent Manager under the DPDP Rules?
A Consent Manager is a registered, interoperable platform through which individuals give, manage, review and withdraw consent. To register, an entity must, among other conditions under Part A of the First Schedule, be incorporated in India, maintain a minimum net worth of ₹2 crore, and have its platform independently certified against the Board's data-protection standards.
Do I need a Data Protection Officer under the DPDP Act?
A dedicated DPO is mandatory only for a Significant Data Fiduciary, and that DPO must reside in India and report to the board of directors or similar governing body. Other Data Fiduciaries must still publish the contact details of a person who can answer processing questions.
Does GDPR compliance make my company DPDP Act compliant?
No. A GDPR programme provides a strong base for security controls and data-subject rights (referred to as "Data Principal" under the DPDP Act), but it does not close the gap. The DPDP Act consent notice, the dual breach-reporting mechanics, the retention rules and the SDF duties each follow the Indian text and must be mapped and evidenced separately.
How quickly must a data breach be reported?
Every personal-data breach, whatever its scale, must be intimated to each affected individual and the Data Protection Board without delay, covering its nature, extent, timing and likely impact. A detailed report on the facts, cause, mitigation taken and confirmation of intimation is then due to the Board within 72 hours of awareness, unless it grants a longer period on written request.
Can DPDP Act penalties really reach ₹250 crore?
Yes. The Schedule to the DPDP Act sets a maximum of ₹250 crore for failing to take reasonable security safeguards. The Data Protection Board fixes the actual amount after an inquiry, weighing the gravity, duration and repetition of the breach, and since different provisions carry separate penalties, a single incident touching more than one obligation can result in more than one penalty.