DPDP Act Compliance

The Digital Personal Data Protection Act, 2023 governs how businesses collect and use the personal data of people in India. It requires a clear notice and valid consent (or another lawful ground), reasonable security safeguards, prompt reporting of personal data breaches, and a way for people to exercise their rights.

The Digital Personal Data Protection Rules, 2025 bring the Act into force in stages. Most of the duties on businesses apply from 13 May 2027, and the registration of Consent Managers begins on 13 November 2026. The Act also applies to businesses outside India that offer goods or services to people in India.

When you need it

  • Before the May 2027 deadline

    The core duties apply from 13 May 2027. Notices, consent flows, vendor contracts and breach procedures take time to put right, so the work usually starts well before.

  • When launching a product or app

    A new website, app or service that collects personal data is the easiest point to build the notice, consent and retention rules in, rather than retrofitting them.

  • Before investment or an acquisition

    Investors and acquirers increasingly ask how a business handles personal data. Gaps found in due diligence can hold up or reprice a deal.

  • When customers send data questionnaires

    Larger clients now ask their vendors how they comply with the DPDP Act, and expect the answers to be backed by documents.

  • After a personal data breach

    A breach has to be reported to the Data Protection Board and to each affected person. The steps and timelines are set by the Rules.

How the process works

Six stages, from mapping the data to training the people who handle it. Timings are typical, not promised.

  1. 1

    Data mapping

    Commonly two to four weeks, depending on size

    Work out what personal data the business collects, where it comes from, why it is used, where it is stored, who it is shared with and how long it is kept. Everything else rests on this map.

    Documents

    • A list of the websites, apps, forms and systems that collect personal data
    • The current privacy policy, consent wording and sign-up forms
    • A list of vendors and service providers that receive personal data
  2. 2

    Gap assessment

    One to two weeks after the data map

    Compare the map with the Act and the Rules: the grounds for each use of data, the notices given, children’s data, security safeguards, retention and the handling of requests from individuals. The result is a written list of gaps in order of priority.

  3. 3

    Notices and consent

    Alongside the gap assessment

    Rewrite the privacy notice so that it meets the Rules: a clear, itemised description of the data and the purpose, how consent can be withdrawn, how rights can be exercised and how to complain to the Data Protection Board. Consent must be free, specific, informed, unconditional and unambiguous, and as easy to withdraw as to give.

  4. 4

    Contracts with processors

    Depends on the number of vendors

    A business remains responsible for personal data handed to a vendor for processing. Contracts with processors (cloud hosting, payroll, CRM and marketing tools) need terms on security, breach reporting, deletion and sub-processors.

    Documents

    • Existing agreements with vendors that process personal data
  5. 5

    Internal procedures

    Two to four weeks

    Put in place the procedures the Act assumes: breach response and reporting, a retention and deletion schedule, handling of access, correction and erasure requests, and a published contact for data protection questions.

  6. 6

    Training and review

    Before 13 May 2027, then at least once a year

    Train the teams that handle personal data, especially HR, marketing, sales and technology, and set a date to review the position as the Board issues further guidance.

Common questions

In stages. The DPDP Rules, 2025 were notified on 13 November 2025, and the provisions setting up the Data Protection Board applied at once. Registration of Consent Managers begins on 13 November 2026, and most of the duties on businesses apply from 13 May 2027.

To discuss the DPDP Act, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 29 September 2026.