FAQ

Frequently Asked Questions

Common questions on DPDP Act applicability, penalties and how engagements with Mehta & Mehta work.

Does the DPDP Act apply to us if we're not based in India? +

Yes. Section 3 extends the Act to any entity outside India that offers goods or services to Data Principals in India, or that profiles individuals in India in connection with such offerings.

We already comply with GDPR — are we covered? +

Not automatically. DPDP shares some GDPR concepts but differs materially on consent mechanics, breach reporting (no materiality threshold), children's data, and cross-border transfer rules. A GDPR programme is a strong starting point, not a substitute — our GDPR-to-DPDP bridge assessment identifies the gaps.

What happens if we miss the 13 May 2027 deadline? +

There is no grace period. Non-compliance exposes the organisation to penalties of up to ₹250 crore per contravention, assessed cumulatively across multiple heads where more than one obligation is breached.

Do we need a Data Protection Officer? +

Only Significant Data Fiduciaries, once notified under Section 10, are required to appoint a DPO under Rule 13. Other entities should still designate an accountable individual as a matter of good governance.

Can we engage you for just one part of this, not the full programme? +

Yes. Engagements may cover a single mandate — for example, only the readiness and gap assessment — or the full compliance lifecycle through to and beyond the 2027 deadline.

Speak With Our Data Protection & Privacy Team