Digital Personal Data Protection Act, 2023

DPDP Compliance Advisory

Full compliance is mandatory from 13 May 2027, with no grace period. Mehta & Mehta advises organisations on notice, consent, security safeguards and Data Principal rights under the DPDP Act and Rules.

13 Nov 2025DPDP Rules notified, Board operational
13 Nov 2026Consent Manager registration opens
13 May 2027Full compliance — no grace period
₹250 CrMaximum penalty per contravention
Overview

A governance obligation, not a technology project

A complete DPDP programme typically requires nine to eighteen months across discovery, remediation and implementation. The Act applies to any entity processing digital personal data in India, and to entities outside India that offer goods or services to Data Principals in India.

Responsibility for compliance rests with the Board. Mehta & Mehta advises accordingly.

Understand the Act & Penalties

Who Must Comply

  • Data Fiduciaries — any person who determines the purpose and means of processing digital personal data.
  • Data Processors — Section 8(2) retains liability with the Fiduciary regardless of contractual terms.
  • Foreign entities offering goods or services to Data Principals in India (Section 3).
  • Significant Data Fiduciaries, once notified under Section 10, carry additional obligations under Rule 13.
How We Engage

Four Complementary Mandates

Engagements may cover a single mandate or the full compliance lifecycle.

01

Readiness & Gap Assessment

Diagnostic review against the Act and the Rules.

02

Implementation & Documentation

Policies, notices, consent architecture and the supporting evidence trail.

03

Significant Data Fiduciary Advisory

Rule 13 obligations, including the annual DPIA and independent audit.

04

Ongoing Compliance Retainership

Sustained compliance, breach readiness and Board reporting.

View the Full Breakdown
Why Mehta & Mehta

Four Pillars That Set Us Apart

Governance DNA

DPDP compliance is treated as a governance obligation, consistent with our practice as Company Secretaries and Chartered Accountants.

Regulatory Overlay

DPDP obligations are mapped against existing RBI, SEBI and IRDAI requirements to avoid conflict.

Audit-Ready Output

Every deliverable is prepared to withstand review by an Independent Data Auditor or the Board.

Single Point of Contact

A Senior Partner leads each engagement, supported by a team of 150-plus professionals.

Trusted Corporate & Legal Advisors Since 1990  ·  ICSI Registered  ·  Pan-India Presence

Speak With Our Data Protection & Privacy Team