Compliance Guide

The DPDP Act: what actually applies, and when

Most DPDP content on the internet gets the timeline wrong. This guide sets out what is genuinely in force today, what lands in May 2027, and what an Indian organisation should be doing in the meantime — in the Act’s own vocabulary.

Reviewed July 2026 Covers DPDP Act 2023 & DPDP Rules 2025 Reading time about 12 minutes
Start here: DPDP is not enforceable yet

The Digital Personal Data Protection Act received assent on 11 August 2023, but sat dormant for over two years because it carried no commencement date. The DPDP Rules were notified on 13 November 2025 and brought only the Data Protection Board provisions into force. Every substantive obligation — notice, consent, data principal rights, children’s data, breach reporting — and the entire penalty regime commence after an eighteen-month transition, around May 2027.

Until then the Information Technology Act 2000 and the SPDI Rules 2011 remain the operative data protection law in India. Any vendor telling you DPDP fines are being levied today is wrong.

The timeline that matters

11 August 2023 Act receives presidential assent

Act No. 22 of 2023 is passed with no commencement date, leaving the Central Government to appoint dates for different provisions.

13 November 2025 DPDP Rules notified — Phase 1 in force

Published in the Gazette via G.S.R. 846(E). Only definitions and the Data Protection Board provisions (Rules 1, 2, 17–21) commence immediately. MeitY announced this publicly on 14 November, but the 13th is the operative date from which all transition periods run.

Around May 2027 The real deadline — everything else commences

Rules 3 and 5–16 and the corresponding sections of the Act take effect together: notice, consent, security safeguards, retention, children’s data, Significant Data Fiduciary duties, data principal rights, breach reporting — and the penalty regime. There is no further staggering by company size, sector or revenue.

On the exact dates

Advisers compute the anniversaries differently depending on whether the counting is inclusive — you will see both 12 and 13 November 2026, and both 12 and 13 May 2027, in print. Plan to the month, not the day, and confirm the precise date with your counsel before it drives a contractual commitment.

Who the Act applies to

DPDP covers digital personal data only — data collected in digital form, or collected on paper and subsequently digitised. Paper records that are never scanned fall entirely outside the Act. There is no separate category of sensitive personal data: health information and a shipping address carry the same statutory treatment, which is a deliberate departure from both GDPR and India’s own SPDI Rules.

The vocabulary you will be held to

  • Data Principal — the individual the data is about. GDPR calls this the data subject. Where the individual is a child, it includes the parent or lawful guardian.
  • Data Fiduciary — whoever determines the purpose and means of processing. Functionally the GDPR controller, but the word is deliberate: it imports a trust-based framing, and the Data Fiduciary remains liable regardless of any contrary contract with a processor.
  • Data Processor — processes on behalf of a Data Fiduciary. Notably, the Act imposes almost no direct statutory obligations on processors; they are reached only through the mandatory contract. An Indian IT or BPO vendor’s DPDP posture is contractual, not statutory.
  • Significant Data Fiduciary — a Data Fiduciary notified as such by the Central Government, having regard to volume and sensitivity of data, risk to Data Principals, sovereignty, electoral democracy, State security and public order.
  • Consent Manager — a Board-registered single point of contact through which a Data Principal can give, manage, review and withdraw consent. Uniquely, the Consent Manager is accountable to the Data Principal.
A very common error worth avoiding

Significant Data Fiduciary status is not self-assessed and not automatic on crossing a threshold — it requires a government notification, and none has been issued yet. There is no user-count or revenue threshold for SDF status anywhere in the Act or Rules.

The 2 crore and 50 lakh user figures circulating in DPDP content come from the Third Schedule and relate to retention and erasure for e-commerce, social media and online gaming intermediaries. They have nothing to do with SDF designation.

What every Data Fiduciary has to do

The obligations below commence around May 2027. The work behind them — particularly the data inventory — takes considerably longer than the drafting.

  • Notice that is standalone and independently understandable, itemising the data collected and each purpose, in plain language, with links to withdraw consent, exercise rights and complain to the Board. It must be offered in English and the Eighth Schedule languages.
  • A lawful ground for every activity. There are only two: consent, or one of the enumerated legitimate uses. There is no legitimate-interest balancing test, which is the single biggest re-papering exercise for anyone running a GDPR-shaped programme.
  • Consent that is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, limited to the data necessary for the stated purpose — and withdrawal that is as easy as giving it, propagated to processors and downstream systems.
  • Security safeguards including encryption, obfuscation, masking or tokenisation, access control, logging and monitoring sufficient to detect and investigate unauthorised access, backups, and one-year log retention.
  • Retention and erasure against a “purpose no longer served” test, with erasure propagating into backups, warehouses, logs and vendors.
  • A grievance redressal mechanism and published contact details for the person able to answer questions about processing.
  • Contracts with every processor — the only route by which the Act reaches them.
The obligation people miss

The Act puts the burden of proving valid notice and valid consent on the Data Fiduciary. There is no GDPR Article 30 records-of-processing requirement in DPDP — but that burden of proof makes a consent audit trail mandatory in substance. You need evidence of what notice was shown, in which language, when, and exactly what was consented to.

Data Principal rights

Four rights: access to a summary of the personal data processed and the identities of everyone it has been shared with; correction, completion, updating and erasure; grievance redressal; and nomination — appointing someone to exercise rights on death or incapacity, which has no GDPR equivalent.

Note what is absent. DPDP has no right to data portability, no right to object, no right to restriction of processing, and no right against solely automated decision-making. Rights also attach only to consent-based processing and to data voluntarily provided — not to every lawful basis.

The 90-day figure is widely misreported

The Rules attach the ninety-day cap to the grievance redressal mechanism, and require you to publish the response period you commit to. They do not set a statutory deadline for access or erasure requests, although the Government’s own press release blurred this and most vendor blogs have repeated it.

The safe operating posture: publish your stated response period, and treat ninety days as the practical outer limit for rights requests generally.

Breach reporting — stricter than GDPR in two ways

A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability. Critically, there is no harm threshold and no materiality threshold: every breach is reportable, to both the Board and every affected Data Principal.

  • To affected Data Principals — without delay. Through their user account or a registered channel, in concise plain language, covering the nature, extent and timing of the breach; the consequences relevant to them; what you have done to mitigate it; what they should do to protect themselves; and a business contact who can respond.
  • To the Data Protection Board — without delay, describing the nature, extent, timing and location of the breach and its likely impact.
  • To the Board again — within 72 hours of becoming aware, with updated detail, the broad facts and circumstances, mitigation measures, findings on who caused it, remedial steps to prevent recurrence, and a report on the intimations given to Data Principals. This deadline is extendable on written request to the Board.
CERT-In has not gone away

The CERT-In Directions of April 2022 require reporting of specified cyber incidents within six hours of noticing them. That obligation is live today and is entirely unaffected by DPDP. From May 2027 an Indian organisation will run parallel six-hour CERT-In and DPDP breach workflows off the same incident. Build one runbook that satisfies both, rather than two that compete during an incident.

Penalties

Penalties are civil monetary penalties imposed by the Data Protection Board after inquiry. The Act creates no criminal offences, and there is no turnover-linked penalty anywhere in the regime. These are ceilings, not fixed fines — the Board must weigh the nature, gravity and duration of the breach, whether you gained from it, and whether you mitigated promptly.

FailureMaximum penalty
Failure to take reasonable security safeguards to prevent a breach₹250 crore
Failure to notify a personal data breach to the Board or affected Data Principals₹200 crore
Breach of the additional obligations relating to children₹200 crore
Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Breach of any other provision of the Act or Rules₹50 crore
Breach of the duties of a Data Principal (false or frivolous complaints)₹10,000

Two features have no GDPR analogue: DPDP penalises the Data Principal for frivolous complaints or false information, and the Board may accept a voluntary undertaking at any stage, which bars further proceedings on that breach. Appeals lie to the TDSAT within sixty days.

Children’s data

India sets the child threshold at under 18 — the highest of any major regime, with no sectoral or state-level variation, against 16 (reducible to 13) under GDPR and 13 under COPPA. Processing a child’s data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising to children are prohibited outright. For most consumer businesses this is a direct adtech, analytics and recommender-system change rather than a policy exercise.

How DPDP differs from GDPR

If you are extending an existing GDPR programme, these are the gaps that will actually bite.

Under DPDP
Under GDPR
ScopeDigital personal data only — paper records never digitised are out of scope.
ScopeAutomated processing and structured manual filing systems.
Lawful groundsTwo: consent, or an enumerated legitimate use. No legitimate-interest test.
Lawful groundsSix, including contractual necessity and legitimate interests.
Sensitive dataNo special category at all.
Sensitive dataArticle 9 heightened regime for health, biometrics, beliefs and more.
TransfersBlacklist model, with no country currently restricted. No transfer mechanism required.
TransfersAdequacy, SCCs, BCRs or a derogation needed for every export.
RightsAccess, correction and erasure, grievance, nomination.
RightsAdds portability, objection, restriction and rights over automated decisions.
DPO and DPIARequired only of designated Significant Data Fiduciaries — but the DPO must be based in India and answer to the board.
DPO and DPIARisk-based, and can apply to organisations of any size.
BreachEvery breach reportable, no risk filter; Board and individuals notified without delay; 72-hour detailed Board report, extendable.
Breach72 hours to the authority unless unlikely to cause risk; individuals only on high risk.
PenaltiesFixed rupee ceilings per breach. No turnover link, no criminal liability.
PenaltiesUp to €20m or 4% of worldwide turnover, whichever is higher.
Claims circulating that are simply wrong

That DPDP operates a country whitelist (it is a blacklist, currently empty); that it mandates data localisation (the only localisation hook applies to Significant Data Fiduciaries and is dormant until the Government specifies categories); that DPIAs are required for all high-risk processing (SDF-only); that it carries a plain GDPR-style 72-hour rule; and that it captures mere monitoring of behaviour from outside India (extraterritorial reach is limited to offering goods or services to Data Principals in India).

A readiness checklist

Roughly in dependency order. Items 1 and 2 have the longest lead time and everything else depends on them.

1
Confirm your roleData Fiduciary, Processor, or both — per processing activity. Test extraterritorial reach if you are outside India.
2
Build the data inventorySystems, data elements, purposes, grounds, sources, recipients, retention. The longest-lead item by far.
3
Re-ground every activityConsent or a specific legitimate use. Re-paper anything currently running on legitimate-interest logic.
4
Rebuild noticesStandalone, itemised, plain language, with withdrawal and rights links — in English and the Eighth Schedule languages.
5
Re-engineer consent captureGranular, unbundled, affirmative action, no pre-ticked boxes, minimised to the stated purpose.
6
Build withdrawal parityAs easy to withdraw as to give, propagating to processors and downstream systems.
7
Stand up consent recordsYou carry the burden of proof. Retain what notice was shown, in which language, when, and what was agreed.
8
Deploy security safeguardsEncryption or masking, access control, monitoring, backups, one-year log retention.
9
Write the breach runbookWithout-delay intimations, 72-hour Board report, extension procedure — integrated with CERT-In’s six-hour rule.
10
Remediate vendor contractsEvery processor under a valid contract with security, breach flow-up, sub-processor control and erasure terms.
11
Implement retention and erasurePer-purpose schedules, plus the Third Schedule clock if you are a large e-commerce, social or gaming intermediary.
12
Build the rights workflowPublished intake channels and identifiers, identity verification, access summaries, erasure, nomination.
13
Publish grievance contactsAn effective mechanism within your published period, capped at ninety days, with contacts on the site and app.
14
Assess SDF exposureIf designation is plausible, plan for an India-based DPO reporting to the board, annual DPIA and independent audit.
15
Handle children’s dataAge assurance, verifiable parental consent, and suppression of tracking and targeted ads for under-18s.
16
Map sectoral overlaysRBI, SEBI, IRDAI, telecom and CERT-In obligations survive DPDP and are already in force.

What to do between now and May 2027

The transition period is not idle time. The inventory, the lawful-ground remapping and the vendor contract remediation are each multi-quarter exercises in a mid-sized organisation, and they are sequential — you cannot rebuild notices until you know what you collect and why. Organisations that treat May 2027 as the start of the work rather than the end of it will be re-papering consent under enforcement pressure.

The one genuinely soft obligation worth planning for early: where consent was obtained before commencement, you must give the Data Principal fresh notice as soon as reasonably practicable. Legacy consent refresh across an existing customer base is a project, not a task.

DPSuite operationalises all of this

Consent and preference management, data principal request workflows, RoPA and data mapping, DPIAs, breach reporting and grievance redressal — running well before the deadline.

About this guide. Prepared by ProbityGRC and reviewed in July 2026 against the DPDP Act 2023 and the DPDP Rules 2025 as notified on 13 November 2025. The DPDP regime is still being operationalised: the Data Protection Board was in the process of being constituted at the time of writing, no Significant Data Fiduciaries had been designated, no countries had been restricted for transfers, and no localisation categories had been specified. This guide is general information about the law as we understand it, not legal advice, and it is no substitute for advice from qualified counsel on your specific circumstances. Confirm any date or figure that will drive a contractual or regulatory commitment.