Understanding the Law

The DPDP Act, 2023 & the DPDP Rules, 2025

Key dates, applicability and the penalty schedule under India's data protection law.

Overview

A staggered commencement, with a hard deadline

The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)), bringing the DPDP Act, 2023 into force in stages. The Data Protection Board of India is constituted and operational.

Substantive obligations — notice and consent, security safeguards, breach reporting, retention and erasure, and Data Principal rights — take effect on 13 May 2027, with no grace period thereafter. A complete compliance programme typically requires nine to eighteen months. The Act applies to any entity processing digital personal data in India, and to entities outside India offering goods or services to Data Principals in India.

Who Must Comply

  • Data Fiduciaries — any person who determines the purpose and means of processing digital personal data.
  • Data Processors — Section 8(2) retains liability with the Fiduciary regardless of contractual terms.
  • Foreign entities offering goods or services to Data Principals in India (Section 3).
  • Significant Data Fiduciaries, once notified under Section 10, carry additional obligations under Rule 13.
Key Dates

The Compliance Timeline

13 Nov 2025
DPDP Rules notified (G.S.R. 846(E)). Data Protection Board of India operational.
13 Nov 2026
Consent Manager registration opens.
13 May 2027
Full compliance required — consent, security safeguards, breach reporting, retention limits and Data Principal rights. No grace period.
₹250 Cr
Maximum penalty per contravention. Exposure is cumulative across multiple heads.
In Detail

The Act, Section by Section

Five groups of obligations, from initial diagnostic to Significant Data Fiduciary requirements.

Readiness & Gap Assessment

Ten workstreams establishing compliance status ahead of 13 May 2027

A diagnostic review covering applicability, data mapping, notice and consent, security safeguards and cross-border transfer, resulting in a risk-rated gap assessment and remediation roadmap.

  • Applicability & scoping assessment
  • Data discovery, inventory & mapping
  • Notice & consent architecture
  • Security safeguards & breach readiness
View More

Implementation & Documentation

The evidence trail required by an auditor or the Board

The complete set of policies, notices, registers and contracts that make a DPDP programme demonstrable, not just documented.

  • Privacy Policy & standalone notices
  • Record of Processing Activities (RoPA)
  • Data Processing Agreements & vendor addenda
  • DPIA framework and templates
View More

Significant Data Fiduciary Obligations

Additional requirements under Rule 13 once notified under Section 10

Entities notified as Significant Data Fiduciaries carry an elevated compliance architecture, including annual assessment and independent audit.

  • Annual Data Protection Impact Assessment
  • Independent annual data audit
  • Data Protection Officer appointment
  • Algorithmic due diligence
View More

Ongoing Compliance

Sustaining compliance as processing, vendors and products change

DPDP compliance is not a one-time project. This covers the recurring obligations that keep a programme current year on year.

  • Periodic compliance management
  • Rights & grievance desk
  • Breach response support
  • Regulatory watch & Board reporting
View More

Specialised Advisory

Sectoral overlays, transactions and specialised risk review

Situations where DPDP intersects with sectoral regulation, M&A activity, and global privacy programmes.

  • Sector-specific DPDP overlays
  • Privacy due diligence in M&A
  • GDPR-to-DPDP bridge assessments
  • Independent Data Auditor engagement
View More
The Cost of Getting It Wrong

Penalties Under the Schedule to the Act

Penalties are assessed per contravention. A single incident may attract more than one head.

Maximum PenaltyContravention
₹250 croreFailure to take reasonable security safeguards to prevent a personal data breach
₹200 croreFailure to notify the Board or affected Data Principals of a personal data breach
₹200 croreNon-compliance with the additional obligations relating to children
₹150 croreFailure of a Significant Data Fiduciary to meet its additional obligations
₹50 croreAny other breach of the provisions of the Act or the Rules

The Board considers the nature and gravity of the breach, the type of personal data affected, its repetitive character, gain realised or loss avoided, and remedial action taken in determining quantum. A documented compliance programme is a mitigating factor.

Speak With Our Data Protection & Privacy Team