Table of Contents
The DPDP Act 2023 requires every organisation that processes personal data of Indian individuals to: obtain valid consent, publish a DPDP notice, minimise data collection, maintain accuracy, limit storage, implement security safeguards, provide grievance redressal, and notify breaches. The compliance deadline is May 13, 2027. Penalties reach ₹250 crore per violation.
What is the DPDP Act 2023?
The Digital Personal Data Protection (DPDP) Act 2023 is India's first comprehensive data privacy law. It was passed by Parliament and signed into law on August 11, 2023. The Rules under the Act were notified in January 2025, starting the compliance clock for all organisations processing personal data of Indian individuals.
Before the DPDP Act, India had no unified data protection legislation. Organisations were governed only by the Information Technology Act 2000 and its rules — a patchwork framework with weak enforcement and no individual rights. The DPDP Act changes this fundamentally, creating enforceable rights for individuals and hard financial penalties for organisations that mishandle personal data.
The Act draws from global data protection frameworks — particularly the EU's General Data Protection Regulation (GDPR) — but is specifically designed for India's digital economy and regulatory context. It uses Indian-specific terminology (Data Fiduciary, Data Principal) and creates an India-specific enforcement body, the Data Protection Board of India.
May 13, 2027 — the deadline for full DPDP Act compliance. The Rules were notified in January 2025. All organisations processing personal data of Indian individuals must be compliant by this date or face penalties assessed by the Data Protection Board of India.
Who does the DPDP Act apply to?
The DPDP Act applies to any entity that processes digital personal data of individuals in India (called Data Principals). This includes Indian businesses of all sizes, foreign companies with Indian users, and non-profit organisations. There is no minimum turnover threshold or employee-count exemption.
What is a Data Fiduciary?
A Data Fiduciary is any person, company, government body, or other entity that alone or jointly with others determines the purpose and means of processing personal data. If your organisation decides what data to collect and why — you are a Data Fiduciary and must comply with all DPDP obligations.
Common examples of Data Fiduciaries in India: e-commerce platforms, fintech apps, NBFC lenders, hospitals, schools, HR software vendors, SaaS companies, marketing agencies, and any startup that collects user sign-up data.
What is a Data Processor?
A Data Processor is any entity that processes personal data on behalf of a Data Fiduciary. Data Processors are not directly regulated by the DPDP Act in the same way — but Data Fiduciaries are responsible for ensuring their Data Processors also protect data adequately through contractual safeguards.
Exemptions from DPDP Act
The following are exempt from DPDP Act obligations:
- Personal or domestic purposes — individuals processing data for purely personal use
- Publicly available data — data that the Data Principal themselves has made public
- Research, archiving, and statistical purposes — subject to standards prescribed by the government
- Certain government functions — national security, public order, and prevention of offences
- Journalistic activity — processing for journalistic or editorial purposes, subject to the Press Council of India Act
Key definitions under the DPDP Act
Understanding the DPDP Act requires clarity on its specific terminology, which differs from both common usage and GDPR.
| DPDP Term | Meaning | GDPR Equivalent |
|---|---|---|
| Data Principal | The individual whose personal data is being processed | Data Subject |
| Data Fiduciary | The entity that determines the purpose and means of processing | Data Controller |
| Data Processor | An entity that processes data on behalf of a Data Fiduciary | Data Processor |
| Significant Data Fiduciary (SDF) | A Data Fiduciary designated by the government due to the sensitivity or volume of data processed | No direct equivalent |
| Personal Data | Any data about an identifiable individual | Personal Data |
| Digital Personal Data | Personal data in digital form, or non-digital personal data that is digitised | Broader under GDPR |
| Consent Manager | A registered entity through which Data Principals manage their consent | No direct equivalent |
| Data Protection Board | The statutory body that adjudicates complaints and imposes penalties | Supervisory Authority (e.g. ICO, CNIL) |
The 8 core obligations of a Data Fiduciary
Every Data Fiduciary must fulfil the following 8 obligations. These are not optional — failure to comply with any of them exposes the organisation to penalties from the Data Protection Board.
-
1Obtain valid consent
Consent must be free, specific, informed, unconditional, and unambiguous. It must be obtained through a clear affirmative action — a pre-ticked checkbox does not constitute consent. Consent must be as easy to withdraw as it is to give. Where a legitimate use (Legitimate Interest equivalent under DPDP) applies, consent may not be required — but the list of legitimate uses is narrower than GDPR Article 6.
-
2Provide a DPDP notice
Before or at the time of requesting consent, Data Fiduciaries must provide a clear notice in plain language explaining: what personal data will be collected, the purpose for which it will be processed, how Data Principals can exercise their rights, and how to contact the grievance officer. The notice must be available in all 22 scheduled languages of India upon request.
-
3Data minimisation
Collect only the personal data that is necessary for the stated purpose. If your checkout flow collects date of birth but you have no legitimate reason to require it, you must stop collecting it. This principle applies to every data field — it is a constraint on collection design, not just a policy commitment.
-
4Data accuracy
Personal data must be accurate and complete. Where inaccurate or incomplete data could result in adverse action against a Data Principal — such as a credit decision or employment outcome — Data Fiduciaries must take reasonable steps to ensure accuracy before acting on the data.
-
5Storage limitation
Personal data must not be retained for longer than is necessary for the purpose for which it was collected. Once the purpose is served and there is no legal obligation to retain, the data must be deleted. Data Fiduciaries must establish and implement retention schedules and automated deletion processes.
-
6Security safeguards
Reasonable technical and organisational security measures must be implemented to protect personal data from breaches. The Act does not prescribe specific technical controls — the standard is "reasonable" based on the nature and sensitivity of the data, the volume processed, and the state of technology. ISO 27001 certification is one widely accepted framework for demonstrating reasonable security.
-
7Grievance redressal
Every Data Fiduciary must provide an accessible grievance mechanism for Data Principals. This includes appointing a Grievance Officer (name and contact details must be published), establishing a process for receiving and resolving complaints, and responding within timeframes specified in the Rules. Data Principals can escalate unresolved grievances to the Data Protection Board.
-
8Breach notification
In the event of a personal data breach, Data Fiduciaries must notify both the Data Protection Board and each affected Data Principal without undue delay. The notification must describe the nature of the breach, the categories and volume of data affected, likely consequences, and measures taken or proposed. There is no specific 72-hour window as in GDPR, but "without undue delay" will be interpreted strictly by the Board.
42-item interactive checklist across 8 categories — consent, notice, rights, security, breach, and more.
The 8 rights of Data Principals
Individuals (Data Principals) whose data is processed have the following enforceable rights under the DPDP Act. Data Fiduciaries must build processes to fulfil these rights within the timeframes prescribed in the Rules.
The right to obtain a summary of what personal data the Data Fiduciary holds and how it is being processed.
The right to correct inaccurate personal data or complete incomplete data held by the Data Fiduciary.
The right to have personal data erased when it is no longer necessary for the purpose or when consent is withdrawn.
The right to file a complaint with the Data Fiduciary's Grievance Officer and to escalate to the Data Protection Board if unresolved.
The right to nominate another individual to exercise data protection rights on their behalf in the event of death or incapacity — unique to the DPDP Act.
The right to withdraw consent at any time. Withdrawal must be as easy as giving consent. Processing must cease once consent is withdrawn, subject to any lawful basis for continued processing.
The right to receive a summary of the personal data processed, identities of all Data Processors the data has been shared with, and any other information prescribed by the Rules.
If a grievance is not resolved by the Data Fiduciary, the Data Principal can file a complaint directly with the Data Protection Board of India for adjudication.
Significant Data Fiduciaries — additional obligations
The Government of India may designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on the volume or sensitivity of data they process, or their potential impact on national security or electoral processes. SDFs face additional obligations beyond the standard 8.
Large social media platforms, large e-commerce marketplaces, critical information infrastructure operators, companies processing health or financial data at scale, and any entity whose data processing poses significant risk to Data Principals' rights. The government has not yet published the final SDF list.
Additional SDF obligations
- Data Protection Officer (DPO): Must appoint a DPO who is based in India, represents the SDF, and is the point of contact for the Data Protection Board. Unlike GDPR, the DPO does not need to be independent — but must be a senior official.
- Data Protection Impact Assessment (DPIA): Must conduct DPIAs before undertaking any new processing activity that may pose high risk to Data Principals.
- Independent data audit: Must appoint an independent data auditor to assess the SDF's compliance with the Act and prescribed standards.
- Additional standards: The government may prescribe additional processing standards, data retention limits, or security requirements specific to SDFs.
Cross-border data transfers under the DPDP Act
The DPDP Act permits cross-border transfers of personal data to countries or territories notified by the Government of India. This is a positive whitelist approach — unlike GDPR's adequacy decisions, India will publish a list of permitted destination countries. Transfers to countries not on the whitelist will be restricted.
The government has not yet published the final whitelist. Until it does, organisations should continue current practices while preparing their data flow mapping to understand which cross-border transfers they rely on. Transfers to countries for state security or diplomatic reasons may be restricted even if otherwise on the whitelist.
Key implication for Indian businesses: SaaS companies using US-based cloud infrastructure (AWS, Azure, GCP) should assess whether their US data processing arrangements will be permitted under the final rules. Most major cloud providers are expected to be on the whitelist, but data residency requirements may apply to certain categories of sensitive data.
DPDP Act penalties — the full schedule
The Data Protection Board of India assesses penalties for violations of the DPDP Act. Penalties are per violation and can accumulate across multiple breaches. The Board considers the nature, gravity, and duration of the violation when determining the penalty amount.
| Violation | Maximum Penalty |
|---|---|
| Failure to implement adequate security safeguards resulting in a personal data breach | ₹250 crore |
| Failure to notify the Data Protection Board and affected Data Principals of a breach | ₹200 crore |
| Failure to fulfil obligations in relation to children's data and Significant Data Fiduciaries' additional obligations | ₹200 crore |
| Non-fulfilment of Data Principal rights | ₹50 crore |
| Non-compliance with any other provision of the Act or Rules | ₹50 crore |
| Non-compliance with a direction of the Data Protection Board | ₹150 crore |
The Data Protection Board considers the nature, gravity, and duration of the violation; whether it was intentional or negligent; whether the organisation cooperated with the Board; the number of Data Principals affected; and the organisation's prior compliance history. Unlike GDPR, there is no explicit turnover-based cap — a ₹250 crore penalty falls equally on a Series A startup and a large enterprise.
DPDP Act vs GDPR — side-by-side comparison
Many Indian businesses also serve EU customers and must comply with both the DPDP Act and GDPR. Here is how the two frameworks compare:
| Dimension | DPDP Act 2023 | GDPR |
|---|---|---|
| Scope of data | Digital personal data only | All personal data (digital and non-digital) |
| Territorial scope | Data of Indian individuals processed in India or abroad | Data of EU individuals processed anywhere in the world |
| Legal bases for processing | Consent + narrow list of Legitimate Uses | 6 lawful bases including Legitimate Interests |
| DPO requirement | Only for Significant Data Fiduciaries | Based on type of processing (Article 37) |
| DPIA requirement | Only for Significant Data Fiduciaries | Required for high-risk processing (Article 35) |
| Maximum penalty | ₹250 crore per violation | €20 million or 4% of global annual turnover |
| Breach notification window | "Without undue delay" (no fixed window) | 72 hours to supervisory authority |
| Right to portability | Not explicitly included | Yes (Article 20) |
| Right to nominate | Yes — unique to DPDP Act | No direct equivalent |
| Cross-border transfers | Whitelist approach (permitted countries) | Adequacy decisions + SCCs + BCRs |
| Enforcement body | Data Protection Board of India | National supervisory authorities (ICO, CNIL, etc.) |
DPDP Act compliance checklist — key items
Full DPDP compliance requires action across 8 categories. Below are the highest-priority items. For the complete 42-item interactive checklist, see our DPDP Act Compliance Checklist.
- Conduct a data mapping exercise — document all personal data collected, its purpose, storage location, and data flows to third parties
- Audit existing consent mechanisms — are they specific, informed, and as easy to withdraw as to give?
- Draft and publish a DPDP-compliant privacy notice in plain language (with multilingual support mechanism)
- Appoint a Grievance Officer and publish their name and contact details on your website
- Build workflows to fulfil Data Principal rights requests (access, correction, erasure, withdrawal)
- Implement a breach detection and notification process — define who notifies the Board, who notifies affected individuals, and the internal escalation path
- Review vendor and partner contracts — ensure Data Processors have adequate security obligations and data processing agreements in place
- Implement data retention schedules and automated deletion for personal data no longer needed for its purpose
How long does DPDP compliance take?
For most Indian businesses, achieving full DPDP Act compliance takes 4–9 months depending on the complexity of your data ecosystem, current security maturity, and how quickly your technical teams can implement consent and rights-management workflows.
| Compliance Activity | Typical Duration | Who Does It |
|---|---|---|
| Data mapping and inventory | 4–6 weeks | Privacy/legal + engineering |
| Gap assessment against DPDP obligations | 2–3 weeks | Privacy/legal + DPO |
| Consent mechanism design and implementation | 4–8 weeks | Product + engineering |
| Privacy notice drafting and multilingual review | 2–4 weeks | Legal + communications |
| Data Principal rights workflow implementation | 4–6 weeks | Engineering + legal |
| Security controls and DLP implementation | 6–12 weeks | Security team / CISO |
| Breach notification procedure and runbook | 2–3 weeks | Security + legal |
| Staff training programme | 2–4 weeks | HR + privacy team |
| Vendor contract review and DPA execution | 4–8 weeks | Legal + procurement |
Given the May 13, 2027 deadline, organisations that have not yet begun should start immediately. Data mapping alone typically uncovers unexpected data flows and third-party sharing that require additional remediation time. Starting in late 2026 leaves minimal margin for setbacks.
Data mapping, consent implementation, privacy notice, rights workflows, breach procedures, and DPO advisory. One team, one programme, one deadline.
Frequently asked questions about the DPDP Act
-
The DPDP Act 2023 was enacted on August 11, 2023. The Rules were notified in January 2025. Most provisions of the Act are now in force, with the compliance deadline set at May 13, 2027. The Data Protection Board of India is being constituted and is expected to begin accepting complaints before the compliance deadline. Organisations should treat compliance as active and urgent — not a future obligation.
-
Yes. The DPDP Act applies to the processing of any personal data of Indian individuals — including employee data, vendor contact data, and customer contact data at B2B companies. If your HR system holds employee records, your CRM holds contact names and emails of business contacts, or your support platform holds names and phone numbers — you are processing personal data and the Act applies. B2B companies must comply with consent obligations, storage limitation, security safeguards, and breach notification at minimum.
-
Yes. There is no turnover or employee-count threshold in the DPDP Act. Any organisation that processes digital personal data of Indian individuals must comply, regardless of size. However, the government may prescribe different compliance timelines or reduced obligations for certain categories of Data Fiduciaries — this has not been announced yet. Until such carve-outs are notified, all organisations should plan for full compliance.
-
Existing privacy policies are unlikely to be fully DPDP-compliant without revision. The DPDP Act requires a specific DPDP Notice that is separate from (or clearly incorporated into) your privacy policy. The notice must be in plain language, must clearly state the purpose of processing, and must explain how Data Principals can exercise their rights. Most legacy privacy policies drafted under the IT Act framework will need to be substantially rewritten. Consent mechanisms embedded in existing terms of service (checkbox at registration) also need to be reviewed for DPDP compliance.
-
The DPDP Act defines a child as anyone under 18 years of age. Processing the personal data of a child requires verifiable parental consent. Data Fiduciaries must not undertake processing that adversely affects children's wellbeing, track or behaviorally target children, or process data in a manner that causes harm. Platforms likely to be accessed by children must implement age-verification mechanisms. Violation of children's data obligations attracts a penalty of up to ₹200 crore.
-
The Data Protection Board of India (DPBI) is the statutory body created under the DPDP Act to adjudicate complaints and enforce penalties. Data Principals whose grievances are not resolved by a Data Fiduciary's grievance officer can file complaints with the Board. The Board investigates, issues show-cause notices, conducts hearings, and can impose financial penalties up to ₹250 crore. The Board is not yet fully constituted but is expected to be operational before the May 2027 compliance deadline.
-
The DPDP Act itself does not mandate data localisation (keeping data within India). However, cross-border transfers are only permitted to countries on the government's whitelist of permitted destinations. The government can also restrict transfers to specific countries or restrict transfers of specific categories of data. Sector-specific regulations (RBI, IRDAI, SEBI) may impose additional localisation requirements independently of the DPDP Act — these remain in force.