Digital Personal Data Protection Act, 2023 · DPDP Rules, 2025
Know your DPDP exposure before the Board does.
We assess how India's new data protection law affects your business — data, systems, contracts and people — and give you a prioritised, costed path to compliance.
Key enforcement date
13 May 2027
Notice, consent, security safeguards, breach reporting, children's data, data-principal rights and Significant Data Fiduciary duties all become enforceable.
₹250 cr
max penalty per instance for failing to keep reasonable security safeguards
72 hrs
to file a detailed breach report with the Data Protection Board
The timeline
The clock started on 13 November 2025.
MeitY notified the DPDP Rules, 2025 with an 18-month phased rollout. The old IT Act SPDI regime continues until the substantive obligations commence.
Phase 1 · 13 Nov 2025
In force now
Definitions, the Data Protection Board of India (four members, digital-first) and its procedures.
Phase 2 · 13 Nov 2026
Consent Managers
Registration of Consent Managers with the Board — India-incorporated platforms that let people give, review and withdraw consent.
Phase 3 · 13 May 2027
Full compliance
All core Data Fiduciary obligations, penalties and SDF duties become enforceable.
Watch this space: in January 2026 MeitY consulted industry on compressing the timeline to 12 months for Significant Data Fiduciaries. As of October 2026 this has not been notified in the Gazette — large data processors should plan as if it could be.
What businesses must do
If you collect personal data in digital form, you're a Data Fiduciary.
Notice & consent
A standalone, plain-language notice itemising the data and each purpose. Withdrawing consent must be as easy as giving it.
Security safeguards
Encryption or masking, access control, logging and monitoring, backups, and safeguards written into processor contracts.
Breach reporting
Intimate the Board without delay, a detailed report within 72 hours, and tell affected individuals in plain language.
Data-principal rights
Access, correction, update, erasure, grievance and nomination — with requests answered within 90 days.
Retention & erasure
Delete data once its purpose is served; specified large platforms must erase after prescribed inactivity, with advance notice.
Children & guardians
Verifiable parental consent for under-18s, no tracking or targeted ads to children, guardian consent for persons with disabilities.
Accountability
Publish a contact for privacy queries (a designated officer or DPO) and run a working grievance process.
Significant Data Fiduciaries
A DPO based in India, annual DPIA and independent audit, algorithmic due diligence, and possible localisation of specified data.
The cost of inaction
Penalties are set per instance, not per year.
Maximum amounts from the Schedule to the DPDP Act. The Board weighs gravity, duration, repetition and mitigation when setting the final figure. Fines are only part of the cost — add remediation under pressure, lost contracts and reputational damage.
| Violation | Provision | Up to |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a breach | s. 8(5) | ₹250 crore |
| Failure to notify the Board or affected individuals of a breach | s. 8(6) | ₹200 crore |
| Breach of obligations relating to children | s. 9 | ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | s. 10 | ₹150 crore |
| Any other breach of the Act or Rules | Residual | ₹50 crore |
Our approach
From discovery to a governed, audit-ready implementation.
We sit between your company and the technology vendors courting it: an independent assessment and costed roadmap first, then a vendor chosen and negotiated on your behalf, and governance until the build is done.
01
Discover
AI-acceleratedData inventory, purpose register and sensitivity map.
02
Assess
Record of Processing and a clause-by-clause compliance scorecard.
03
Quantify & draft
DPIA and risk register; DPDP-aligned policies.
04
Plan & select
Costed roadmap; vendor-neutral partner selection and negotiation.
05
Govern
Oversight of the partner’s build through to audit-ready go-live.
Built for medium-size Indian companies without an in-house DPO or privacy team.
See the full approach →How ready is your business?
Ten questions on the obligations with the largest penalties. Get a readiness score and your top gaps in three minutes.
Insights
Plain-English DPDP guidance
Contact
Find out where you stand.
A free 30-minute scoping call: we'll tell you whether you're likely in scope as a Data Fiduciary, processor or Significant Data Fiduciary, and what a full assessment would cover.
Prefer email? Write to dpdpimpact@gmail.com.