Digital Personal Data Protection Act, 2023 · DPDP Rules, 2025

Know your DPDP exposure before the Board does.

We assess how India's new data protection law affects your business — data, systems, contracts and people — and give you a prioritised, costed path to compliance.

Key enforcement date

13 May 2027

Notice, consent, security safeguards, breach reporting, children's data, data-principal rights and Significant Data Fiduciary duties all become enforceable.

₹250 cr

max penalty per instance for failing to keep reasonable security safeguards

72 hrs

to file a detailed breach report with the Data Protection Board

The timeline

The clock started on 13 November 2025.

MeitY notified the DPDP Rules, 2025 with an 18-month phased rollout. The old IT Act SPDI regime continues until the substantive obligations commence.

Phase 1 · 13 Nov 2025

In force now

Definitions, the Data Protection Board of India (four members, digital-first) and its procedures.

Phase 2 · 13 Nov 2026

Consent Managers

Registration of Consent Managers with the Board — India-incorporated platforms that let people give, review and withdraw consent.

Phase 3 · 13 May 2027

Full compliance

All core Data Fiduciary obligations, penalties and SDF duties become enforceable.

Watch this space: in January 2026 MeitY consulted industry on compressing the timeline to 12 months for Significant Data Fiduciaries. As of October 2026 this has not been notified in the Gazette — large data processors should plan as if it could be.

What businesses must do

If you collect personal data in digital form, you're a Data Fiduciary.

Notice & consent

A standalone, plain-language notice itemising the data and each purpose. Withdrawing consent must be as easy as giving it.

Security safeguards

Encryption or masking, access control, logging and monitoring, backups, and safeguards written into processor contracts.

Breach reporting

Intimate the Board without delay, a detailed report within 72 hours, and tell affected individuals in plain language.

Data-principal rights

Access, correction, update, erasure, grievance and nomination — with requests answered within 90 days.

Retention & erasure

Delete data once its purpose is served; specified large platforms must erase after prescribed inactivity, with advance notice.

Children & guardians

Verifiable parental consent for under-18s, no tracking or targeted ads to children, guardian consent for persons with disabilities.

Accountability

Publish a contact for privacy queries (a designated officer or DPO) and run a working grievance process.

Significant Data Fiduciaries

A DPO based in India, annual DPIA and independent audit, algorithmic due diligence, and possible localisation of specified data.

The cost of inaction

Penalties are set per instance, not per year.

Maximum amounts from the Schedule to the DPDP Act. The Board weighs gravity, duration, repetition and mitigation when setting the final figure. Fines are only part of the cost — add remediation under pressure, lost contracts and reputational damage.

Maximum penalties under the DPDP Act, 2023
ViolationProvisionUp to
Failure to take reasonable security safeguards to prevent a breachs. 8(5)₹250 crore
Failure to notify the Board or affected individuals of a breachs. 8(6)₹200 crore
Breach of obligations relating to childrens. 9₹200 crore
Breach of additional obligations of a Significant Data Fiduciarys. 10₹150 crore
Any other breach of the Act or RulesResidual₹50 crore

Our approach

From discovery to a governed, audit-ready implementation.

We sit between your company and the technology vendors courting it: an independent assessment and costed roadmap first, then a vendor chosen and negotiated on your behalf, and governance until the build is done.

01

Discover

AI-accelerated

Data inventory, purpose register and sensitivity map.

02

Assess

Record of Processing and a clause-by-clause compliance scorecard.

03

Quantify & draft

DPIA and risk register; DPDP-aligned policies.

04

Plan & select

Costed roadmap; vendor-neutral partner selection and negotiation.

05

Govern

Oversight of the partner’s build through to audit-ready go-live.

Built for medium-size Indian companies without an in-house DPO or privacy team.

See the full approach →

How ready is your business?

Ten questions on the obligations with the largest penalties. Get a readiness score and your top gaps in three minutes.

Start the readiness check

Insights

Plain-English DPDP guidance

All insights →
TIMELINESDPDP timeline explained: what's due, and whenThree phases, one deadline that matters, and a proposal that could pull it forward.
BREACHESThe 72-hour rule vs CERT-In's 6 hours: running two clocksHow to build one incident process that satisfies both regulators.Coming soon
CONSENTIs your cookie banner a DPDP consent notice? Probably not.What an itemised, standalone notice actually looks like.Coming soon
SDFWill you be a Significant Data Fiduciary? A self-checkThe factors the government weighs, and what designation adds to your workload.Coming soon

Contact

Find out where you stand.

A free 30-minute scoping call: we'll tell you whether you're likely in scope as a Data Fiduciary, processor or Significant Data Fiduciary, and what a full assessment would cover.

Prefer email? Write to dpdpimpact@gmail.com.