Indian Company Master Data Made Simple

Search:
MCA
GSTIN
LEI
Udyam
Directors
36+ lakh companies in our registry
Legal & Regulatory

DPDP Act 2023 and DPDP Rules 2025: Complete Compliance Guide for Indian Businesses

The Digital Personal Data Protection (DPDP) Act 2023 received Presidential assent on 11 August 2023, and its long-awaited rulebook — the DPDP Rules 2025 — was notified by MeitY on 13 November 2025. The framework now has firm timelines: the Data Protection Board is being stood up immediately, Consent Manager registration opens from 13 November 2026, and the substantive obligations (consent, security, breach notification, retention and Data Principal rights) become enforceable on 13 May 2027. This guide explains what the law requires, who it applies to, the corrected penalty schedule, and how to build a compliance programme before the deadline.

12 min read 2240 words Updated 27 Jun 2026

Key Points

Applies to any entity processing digital personal data of people in India — including companies headquartered outside India that offer goods or services here
The final DPDP Rules 2025 were notified on 13 November 2025 (G.S.R. 846(E)); most substantive obligations become enforceable on 13 May 2027
Data Fiduciaries must obtain free, specific, informed, unconditional and unambiguous consent before processing personal data
Significant Data Fiduciaries face extra duties: a resident DPO, an independent annual audit, a DPIA, and partial data localisation under Rule 13
Penalties reach up to Rs 250 crore for a security-safeguards breach and up to Rs 200 crore for failing to report a breach or for children's-data violations
Children's data (persons under 18) requires verifiable parental consent — verified via identity details or government virtual tokens such as DigiLocker; no tracking or targeted advertising
The Data Protection Board of India is being constituted under the notified Rules and will adjudicate complaints and impose penalties

What is the DPDP Act 2023?

The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first standalone legislation dedicated to the protection of personal data. It was passed by both Houses of Parliament in August 2023 and received Presidential assent on 11 August 2023. The Ministry of Electronics and Information Technology (MeitY) is the nodal ministry responsible for its implementation.

The Act sat on the statute book without an operating framework until 13 November 2025, when MeitY notified the final Digital Personal Data Protection Rules 2025 (Gazette notification G.S.R. 846(E)). The Rules give the Act practical teeth — they set out how consent, breach reporting, children's data verification, Significant Data Fiduciary duties and the Data Protection Board will actually work. The compliance countdown is now live, with most obligations becoming enforceable on 13 May 2027.

Before the DPDP Act, India had no dedicated data privacy statute — businesses relied on a patchwork of provisions under the Information Technology Act 2000, the IT (Reasonable Security Practices) Rules 2011, and sector-specific guidelines from regulators such as RBI and SEBI. The DPDP Act 2023 replaces this fragmented framework with a principles-based, rights-oriented law modelled on global best practices, while retaining India-specific carve-outs.

The Act introduces clear concepts: a Data Principal (the individual whose data is collected), a Data Fiduciary (the entity that determines the purpose and means of processing), and a Data Processor (a third party that processes data on behalf of the fiduciary). Understanding which role your business plays is the starting point for any compliance programme.

Who Does the DPDP Act Apply To?

The Act has a broad territorial reach. It applies to:

  • Processing of digital personal data within India, where such data is collected online or is digitised after offline collection.
  • Processing of personal data outside India if it relates to the offering of goods or services to individuals within India.

In plain terms, any Indian company — from a bootstrapped startup in Bengaluru to a large NBFC in Mumbai — that collects a customer's name, phone number, email, or Aadhaar-linked details is a Data Fiduciary and falls squarely under the Act. Similarly, a foreign e-commerce platform serving Indian consumers must comply even if it has no physical presence in India.

Exemptions are limited. Processing for national security, prevention of crime, or research, archiving and statistical purposes may be exempt by Central Government notification. Certain notice and erasure obligations are relaxed for specified classes such as startups (as notified) and for processing of employee data for limited purposes — but the core duties of lawful processing and security still apply.

Key Definitions Every Business Must Know

Term What It Means in Practice
Personal Data Any data about an identifiable individual — name, mobile number, PAN, the GSTIN of a sole proprietor, IP address, location data, biometrics.
Data Fiduciary Your company — any entity that decides why and how personal data is processed. You bear the primary compliance burden, including for processing done on your behalf by a processor.
Data Principal Your customer, employee, or website visitor — the natural person whose data you process. They hold statutory rights.
Consent Manager A registered intermediary through which Data Principals can give, manage, review, and withdraw consent across fiduciaries. Registration with the Board opens from 13 November 2026.
Significant Data Fiduciary (SDF) Entities notified by the Central Government based on volume of data processed, sensitivity, national security risk, or systemic impact. Higher compliance obligations apply.
Data Protection Board The adjudicatory body established under the Act and the 2025 Rules to receive complaints, investigate breaches, and impose penalties.

Core Obligations for All Data Fiduciaries

Every business that qualifies as a Data Fiduciary under the DPDP Act must fulfil the following baseline obligations. These become enforceable on 13 May 2027, but the build-out should start now.

1. Notice and Consent

Before collecting any personal data, you must provide a clear, plain-language notice to the Data Principal specifying what data is being collected, the purpose of processing, the rights of the individual, and how to lodge a complaint with the Board. The notice must be made available in English or any of the 22 languages listed in the Eighth Schedule to the Constitution.

Consent must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action. Pre-ticked boxes, bundled consents, and consent buried in dense terms-and-conditions clauses will not satisfy this standard. Consent can be withdrawn at any time, and the withdrawal must be as easy as giving it.

2. Purpose Limitation

You may process personal data only for the specific purpose for which consent was obtained or for a purpose explicitly permitted by law (a "legitimate use"). Processing for a new, incompatible purpose requires fresh consent. This has direct implications for businesses that repurpose customer data for marketing or share data with third parties.

3. Data Minimisation and Accuracy

Collect only the personal data that is necessary for the specified purpose. Data held must be kept accurate and updated, especially where it is used to make a decision affecting the Data Principal or is shared with another fiduciary.

4. Storage Limitation and Erasure

Personal data must not be retained beyond the period necessary to fulfil its purpose. Once the purpose is served — or when consent is withdrawn — you must erase the data and instruct your processors to do the same, unless retention is required by law. The Rules also fix a hard retention limit for notified large fiduciaries: e-commerce platforms with 2 crore or more registered users, online gaming intermediaries with 50 lakh or more, and social media intermediaries with 2 crore or more must erase a user's personal data three years after the user last approached them, after giving the user at least 48 hours' advance notice of the erasure.

5. Security Safeguards

Data Fiduciaries must implement reasonable technical and organisational security safeguards to prevent personal data breaches. The Rules spell these out to include encryption, masking or tokenisation, access controls, logging and monitoring, data backups, and contractual security obligations on processors. A failure here carries the single largest penalty under the Act.

6. Breach Notification

On becoming aware of a personal data breach, you must intimate each affected Data Principal without delay, describing the breach, its likely consequences and your remedial measures. You must also notify the Data Protection Board without delay, and then submit a detailed report to the Board within 72 hours (or a longer period the Board allows) covering the broad facts, the events leading to the breach, the mitigation taken and the notifications sent to Data Principals.

7. Grievance Redressal

Every Data Fiduciary must publish the contact details of a person who can answer questions about its processing, and must operate a grievance-redressal mechanism. Complaints from Data Principals must be resolved within the period the fiduciary publishes, subject to a statutory cap of 90 days. Unresolved complaints can be escalated to the Data Protection Board.

Significant Data Fiduciaries — Enhanced Compliance

The Central Government will designate certain entities as Significant Data Fiduciaries based on factors including the volume and sensitivity of personal data processed, risk to electoral democracy, the security of the State, and potential impact on public order. Large tech platforms, major e-commerce companies, digital lenders, and health-tech firms are most likely to be designated.

Under Rule 13 of the DPDP Rules 2025, SDFs carry additional obligations beyond the baseline:

  • Data Protection Officer (DPO): Must appoint a DPO based in India, who reports to the board of directors and is the point of contact for grievance redressal.
  • Annual DPIA and audit: Must, once every twelve months, undertake a Data Protection Impact Assessment and an independent audit, and furnish a report of significant observations to the Data Protection Board.
  • Algorithmic diligence: Must verify that algorithmic software used for processing is not likely to harm Data Principals.
  • Restricted localisation: Must ensure that personal data and traffic data specified by a Central Government committee is not transferred outside India. All other personal data continues to follow the general cross-border rules.

Even if your business is not an SDF today, building DPO-level accountability into your governance structure is good practice — the list of SDFs may expand over time as the Board gains experience.

Children's Data — Special Obligations

The DPDP Act treats data of persons below 18 years of age as a special category requiring heightened protection, and the 2025 Rules retained this threshold without lowering it. If your platform, app, or service is likely to be accessed by children, you must:

  • Obtain verifiable parental consent before processing any personal data of the child. Verification relies on identity and age details already held by the fiduciary, or on a virtual token mapped to such details issued by an authorised entity, such as a DigiLocker service provider.
  • Refrain from processing that is likely to cause any detrimental effect on the well-being of the child.
  • Not carry out tracking, behavioural monitoring, or targeted advertising directed at children.

Certain classes — such as healthcare providers, schools and child-welfare bodies — get limited exemptions for specified processing. Businesses in ed-tech, gaming, and social media should watch this area closely, as failure to comply with children's-data obligations can attract penalties of up to ₹200 crore.

Rights of Data Principals

The Act grants every individual (Data Principal) the following rights against businesses that hold their data:

  • Right to Information: Know what personal data the fiduciary holds and the identities of any other fiduciaries or processors with whom it has been shared.
  • Right to Correction and Erasure: Require the fiduciary to correct inaccurate data, complete incomplete data, or erase data no longer needed for the original purpose.
  • Right to Grievance Redressal: Lodge complaints with the fiduciary's grievance mechanism, and escalate unresolved complaints to the Data Protection Board.
  • Right to Nominate: Nominate another individual to exercise rights on their behalf in the event of death or incapacity.

Businesses should build a Data Subject Rights (DSR) request workflow — ideally a self-service portal — that allows individuals to raise requests and receive timely responses. Manual handling of rights requests at scale is operationally risky and costly.

Cross-Border Data Transfers

Unlike earlier drafts of the Personal Data Protection Bill that proposed strict data localisation for sensitive categories, the enacted DPDP Act 2023 takes a more permissive approach. Cross-border transfer of personal data is permitted, except to countries the Central Government restricts by notification — a negative list rather than a positive whitelist. The 2025 Rules add that a fiduciary must meet any conditions the Government specifies for making personal data available to a foreign State or its agencies.

The one firm restriction is for Significant Data Fiduciaries under Rule 13: categories of personal and traffic data specified by a Government-appointed committee must stay within India. Businesses that rely on cloud infrastructure hosted outside India (AWS, Azure, GCP), use global HR platforms, or share customer data with foreign group entities should document their data flows, keep contractual safeguards in place, and track the Government's notifications.

Penalties for Non-Compliance

The DPDP Act's penalty framework is among the most significant in India's regulatory history. The Schedule to the Act lists the maximum financial penalties the Data Protection Board may impose after an inquiry:

Violation Maximum Penalty
Failure to take reasonable security safeguards to prevent a breach (Section 8(5)) Up to ₹250 crore
Failure to notify the Board and affected Data Principals of a breach (Section 8(6)) Up to ₹200 crore
Breach of additional obligations relating to children (Section 9) Up to ₹200 crore
Breach of additional obligations of a Significant Data Fiduciary (Section 10) Up to ₹150 crore
Breach of duties by a Data Principal (e.g., false particulars, impersonation) Up to ₹10,000
Breach of a term of a voluntary undertaking accepted by the Board Up to the penalty applicable to the underlying breach
Any other non-compliance with the Act or the Rules Up to ₹50 crore

Note that the Act imposes no separate penalty directly on a Data Processor — the Data Fiduciary remains liable for processing carried out on its behalf, so you cannot outsource the risk to a vendor. These are per-instance ceilings, not annual caps; where a single inquiry reveals several distinct violations, the Board can impose separate penalties for each. The Board may also direct remedial action, including deletion of illegally held data.

Building Your DPDP Compliance Programme

Compliance with the DPDP Act is not a one-time filing — it is an ongoing governance programme. The steps below apply to businesses of all sizes, with the depth of implementation scaling to your data footprint, and should be substantially complete before the 13 May 2027 deadline.

Step 1: Conduct a Data Audit

Map every category of personal data your organisation collects — customer KYC, employee records, lead forms, CRM entries, website cookies, payment details. For each data stream, document what is collected, why, where it is stored, who has access, and with which third parties it is shared. This data inventory is the foundation of every other compliance activity.

Step 2: Identify Your Role

Determine whether your organisation is a Data Fiduciary, a Data Processor (processing data on behalf of another fiduciary), or both (common in SaaS and BPO businesses). Your obligations differ significantly. If you are a processor, ensure your contracts with fiduciaries include standard data processing and security clauses.

Step 3: Update Your Privacy Notice

Your existing privacy policy almost certainly does not meet the DPDP Act's notice requirements. Rewrite it in plain language, specify each processing purpose clearly, explain rights and how to exercise them, give a contact for queries and complaints, and publish it prominently. Offer it in the scheduled languages your users request.

Step 4: Rebuild Your Consent Flows

Audit every touchpoint where you collect personal data — signup forms, checkout flows, contact forms, cookie banners, third-party API integrations. Each must present a clear notice and a genuine consent choice before data is collected. Remove pre-checked boxes and bundled consents, and provide a withdrawal mechanism as accessible as the original consent.

Step 5: Appoint a Grievance / Contact Person

Publish the contact details of the person who handles data-protection queries and grievances, and document the resolution process within the 90-day cap. SDFs must additionally appoint a resident DPO who reports to the board of directors.

Step 6: Set Up a Breach Response Protocol

Draft a written incident response plan covering detection and containment, internal escalation, breach assessment, intimation to affected Data Principals without delay, notification to the Board, and the detailed 72-hour report to the Board. Run a tabletop exercise so your team knows the playbook.

Step 7: Review Third-Party Vendor Contracts

Any vendor that processes personal data on your behalf (cloud hosting, payroll software, analytics platform, CRM vendor) is a Data Processor. Your contract must bind them to equivalent security standards and prohibit sub-processing without your authorisation. Review and update all Data Processing Agreements accordingly — remember the liability stays with you.

Step 8: Address Children's Data if Applicable

If your platform may be used by persons under 18 — especially in ed-tech, gaming, social media, or health — implement age assurance, verifiable parental consent (using identity details or a DigiLocker-issued virtual token), and disable behavioural profiling or targeted advertising for this cohort.

Current Regulatory Status (2026)

The DPDP Act 2023 is enacted law, and its operating framework — the DPDP Rules 2025 — was notified on 13 November 2025. The Rules come into force in phases:

  • 13 November 2025: Provisions establishing and operating the Data Protection Board of India took effect; the Board is being constituted.
  • 13 November 2026: Registration and obligations of Consent Managers come into force.
  • 13 May 2027: The substantive obligations — notice and consent, security safeguards, breach notification, retention and erasure, Data Principal rights, and SDF duties — become enforceable.

Businesses should treat the period to May 2027 as a compliance build-out window, not a free pass. Penalty powers attach once the substantive rules bite, and a credible programme cannot be assembled overnight. Starting now avoids the scramble — and legal exposure — of a last-minute rush.

For businesses that also need to verify corporate identity, director details, or company filings as part of their customer onboarding or KYC workflows, WeeDoo's free company search gives instant access to data on over 27 lakh MCA-registered entities — a practical complement to your data protection due-diligence process.

Registration Process

1

Conduct a Data Audit

1-2 weeks

Map every category of personal data collected across all touchpoints — website, CRM, HR systems, payment flows, and third-party integrations. Document what is collected, why, where stored, and with whom shared.

2

Identify Your Role

1-2 days

Determine whether your organisation is a Data Fiduciary, a Data Processor, or both. Your obligations under the Act differ materially depending on this classification, and the fiduciary stays liable for its processors.

3

Update Privacy Notice

1 week

Rewrite your privacy policy in plain language specifying each processing purpose, individual rights, a contact for queries and complaints, and the consent-withdrawal mechanism. Offer scheduled-language versions on request.

4

Rebuild Consent Flows

2-4 weeks

Audit every data-collection touchpoint — forms, cookie banners, checkout flows. Replace bundled or pre-ticked consents with specific, granular consent and implement an easy withdrawal path.

5

Appoint Grievance / Contact Person

1-2 weeks

Publish the contact details of the person handling data-protection queries and grievances, and document a resolution process within the 90-day statutory cap. SDFs must additionally appoint a resident DPO reporting to the board.

6

Establish Breach Response Protocol

1-2 weeks

Draft a written incident response plan covering detection, containment, intimation to affected Data Principals without delay, Board notification, and the detailed 72-hour report to the Board. Conduct a tabletop drill.

7

Review Vendor Contracts

2-4 weeks

Update contracts with all third-party vendors that process personal data on your behalf. Ensure Data Processing Agreements bind them to equivalent security standards and restrict unauthorised sub-processing.

8

Implement Children's Data Safeguards

2-4 weeks (if applicable)

If your platform may be accessed by persons under 18, implement age assurance, verifiable parental consent (identity details or a DigiLocker virtual token), and disable behavioural profiling or targeted advertising for this cohort.

Documents Required

  • Data inventory / processing register (internal working document)
  • Updated Privacy Notice (English + scheduled languages as requested)
  • Consent management records — logs of when and how consent was obtained
  • Data Processing Agreements with all third-party vendors
  • Grievance / contact-person appointment and published contact details
  • Breach response / incident response plan (SOP)
  • Data Protection Impact Assessment and audit reports (mandatory annually for SDFs)
  • Records of Data Principal rights requests and resolutions

Cost Breakdown

Privacy policy drafting / legal review₹10,000 - ₹50,000 (one-time)
Data audit by external consultant₹25,000 - ₹2,00,000 (varies by organisation size)
Consent management platform (SaaS tool)₹20,000 - ₹2,00,000 per year
Data Processing Agreement review / redrafting₹15,000 - ₹75,000 (legal fees)
DPO appointment (external / fractional)₹1,00,000 - ₹5,00,000 per year (SDF obligation)
Staff awareness training₹10,000 - ₹50,000 per programme
Independent data audit (SDFs only)₹2,00,000 - ₹10,00,000+ annually

Compliance Requirements

Task / FormDue DatePenalty
Breach intimation to Data Protection Board + detailed reportAffected Data Principals and Board notified without delay; detailed report to the Board within 72 hours (extendable). Enforceable from 13 May 2027Up to ₹200 crore
Grievance resolution for Data PrincipalsWithin the period published by the fiduciary, capped at 90 daysUp to ₹50 crore (any other non-compliance)
Data erasure / 3-year retention limit (notified large fiduciaries)Erase 3 years after user's last contact, with at least 48 hours' prior noticeUp to ₹50 crore (₹250 crore if a security-safeguards breach)
Consent Manager registration (intermediaries only)Provisions in force from 13 November 2026As directed by the Board
Annual DPIA + independent audit, report to Board (Significant Data Fiduciaries)Once every 12 months from designation as SDFUp to ₹150 crore
DPO appointment (Significant Data Fiduciaries)On designation; obligations enforceable from 13 May 2027Up to ₹150 crore

Frequently Asked Questions

Does the DPDP Act apply to small businesses and startups?

What is the difference between the DPDP Act and the IT Rules 2011?

When will the Data Protection Board start accepting complaints?

Is there a requirement to store personal data in India?

My business collects business contact details — does that count as personal data?

Does the DPDP Act apply to employee data?

Related Topics

DPDP Act 2023DPDP Rules 2025data protection compliance IndiaData Protection Board Indiapersonal data privacy India

Ready to Get Started?

Let our experts handle your legal & regulatory while you focus on your business.