DPDP Act Compliance
The Digital Personal Data Protection Act, 2023 governs how businesses collect and use the personal data of people in India. It requires a clear notice and valid consent (or another lawful ground), reasonable security safeguards, prompt reporting of personal data breaches, and a way for people to exercise their rights.
The Digital Personal Data Protection Rules, 2025 bring the Act into force in stages. Most of the duties on businesses apply from 13 May 2027, and the registration of Consent Managers begins on 13 November 2026. The Act also applies to businesses outside India that offer goods or services to people in India.
When you need it
Before the May 2027 deadline
The core duties apply from 13 May 2027. Notices, consent flows, vendor contracts and breach procedures take time to put right, so the work usually starts well before.
When launching a product or app
A new website, app or service that collects personal data is the easiest point to build the notice, consent and retention rules in, rather than retrofitting them.
Before investment or an acquisition
Investors and acquirers increasingly ask how a business handles personal data. Gaps found in due diligence can hold up or reprice a deal.
When customers send data questionnaires
Larger clients now ask their vendors how they comply with the DPDP Act, and expect the answers to be backed by documents.
After a personal data breach
A breach has to be reported to the Data Protection Board and to each affected person. The steps and timelines are set by the Rules.
How the process works
Six stages, from mapping the data to training the people who handle it. Timings are typical, not promised.
- 1
Data mapping
Commonly two to four weeks, depending on sizeWork out what personal data the business collects, where it comes from, why it is used, where it is stored, who it is shared with and how long it is kept. Everything else rests on this map.
Documents
- A list of the websites, apps, forms and systems that collect personal data
- The current privacy policy, consent wording and sign-up forms
- A list of vendors and service providers that receive personal data
- 2
Gap assessment
One to two weeks after the data mapCompare the map with the Act and the Rules: the grounds for each use of data, the notices given, children’s data, security safeguards, retention and the handling of requests from individuals. The result is a written list of gaps in order of priority.
- 3
Notices and consent
Alongside the gap assessmentRewrite the privacy notice so that it meets the Rules: a clear, itemised description of the data and the purpose, how consent can be withdrawn, how rights can be exercised and how to complain to the Data Protection Board. Consent must be free, specific, informed, unconditional and unambiguous, and as easy to withdraw as to give.
- 4
Contracts with processors
Depends on the number of vendorsA business remains responsible for personal data handed to a vendor for processing. Contracts with processors (cloud hosting, payroll, CRM and marketing tools) need terms on security, breach reporting, deletion and sub-processors.
Documents
- Existing agreements with vendors that process personal data
- 5
Internal procedures
Two to four weeksPut in place the procedures the Act assumes: breach response and reporting, a retention and deletion schedule, handling of access, correction and erasure requests, and a published contact for data protection questions.
- 6
Training and review
Before 13 May 2027, then at least once a yearTrain the teams that handle personal data, especially HR, marketing, sales and technology, and set a date to review the position as the Board issues further guidance.
Common questions
In stages. The DPDP Rules, 2025 were notified on 13 November 2025, and the provisions setting up the Data Protection Board applied at once. Registration of Consent Managers begins on 13 November 2026, and most of the duties on businesses apply from 13 May 2027.
Yes. The Act applies to any business that processes digital personal data, whatever its size. The Central Government has the power to exempt certain classes of businesses, such as startups, from some provisions, so it is worth checking the notifications that apply to your sector.
Not for employment purposes. Section 7 of the Act treats processing for the purposes of employment as a legitimate use, so consent is not needed for it. The other duties still apply, including security safeguards, accuracy and deletion when the data is no longer needed.
It can. The Act applies to processing outside India if it is connected with offering goods or services to people in India, so a foreign company with Indian customers or users should check how it applies.
The Data Protection Board can impose penalties set out in the Schedule to the Act. The highest, up to ₹250 crore, is for failing to take reasonable security safeguards to prevent a personal data breach. Failing to report a breach, or breaching the duties on children’s data, can each attract up to ₹200 crore.
Only if the business is notified as a Significant Data Fiduciary. Every other business must publish the contact details of a person who can answer questions about how it processes personal data.
No. The principles are similar, but the Act has its own grounds for processing: there is no general "legitimate interest" basis as there is under the GDPR, and consent does much more of the work. A business that complies with the GDPR still needs to check its notices, consent and contracts against the Indian law.
Related
To discuss the DPDP Act, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 29 September 2026.

