India · Data Protection

DPDP Act 2023:
What compliance actually requires

India's Digital Personal Data Protection Act 2023 now has its implementing rules. The DPDP Rules 2025 were notified on 14 November 2025, and the substantive obligations apply from 13 May 2027. That runway sounds generous until you scope the gap between "we've read the law and have a privacy policy" and "we can demonstrate compliance to the Data Protection Board."

2023 / 2025

Act / Rules

Rules notified 14 Nov 2025

13 May 2027

Core obligations from

18-month phased runway

₹250 Cr

Max penalty

Per instance, largest violation tier

DPB

Regulator

Data Protection Board of India

Where enforcement stands

Now · from Nov 2025

Provisions establishing the Data Protection Board of India are in force. Definitions and the Board's operating rules apply.

~12 months · ~Nov 2026

Consent Manager registration and obligations take effect — the framework for the intermediaries that manage consent on data principals' behalf.

18 months · 13 May 2027

Substantive duties bind data fiduciaries — notice, consent, data principal rights, breach notification, children's data, and Significant Data Fiduciary obligations.

Who DPDP applies to

Data Fiduciary

Any organisation that determines the purpose and means of processing personal data of individuals in India — the baseline set of obligations applies here.

Data Processor

Processes personal data on behalf of a Data Fiduciary under contract — obligations flow down contractually from the fiduciary relationship.

Significant Data Fiduciary

Classified by volume and sensitivity of data processed — triggers additional obligations including data protection officer appointment and periodic audits.

What operational compliance actually requires

1

Consent Management, Operationalised

Granular, purpose-specific consent captured across web, mobile, and server-side touchpoints, with an immutable record of every grant, withdrawal, and renewal.

2

Data Principal Rights, With an Actual SLA

Access, correction, erasure, and grievance requests fulfilled within statutory windows — automated with SLA tracking, not a theoretical process.

3

Records of Processing Activities (RoPA)

A maintained inventory of what personal data is processed, mapped to lawful basis, retention period, and cross-border transfers — only as accurate as the data discovery feeding it.

4

Breach Notification, Ready Before It's Needed

Detection, classification, and notification to the Data Protection Board within statutory timelines — tested before an actual breach happens.

5

Significant Data Fiduciary (SDF) Assessment

Assessed from real evidence of data volume and sensitivity, not a self-reported estimate — getting it wrong in either direction is a real risk.

6

Cross-Border Transfer Tracking

Where personal data moves outside India, and under what safeguards, tracked as its own register.

Already GDPR compliant? That's a foundation, not a substitute.

Consent structure, legal basis, and breach notification routing all diverge between DPDP and GDPR.

Read GDPR vs DPDP

Frequently Asked Questions

When do DPDP obligations actually take effect?
The DPDP Act was passed in 2023, and the DPDP Rules that operationalise it were notified on 14 November 2025. Enforcement is phased: the provisions establishing the Data Protection Board of India took effect immediately, consent-manager registration follows roughly twelve months later, and the substantive obligations — privacy notices, consent, data principal rights, breach notification, and Significant Data Fiduciary duties — apply from 13 May 2027. The phased runway is intended for building compliance infrastructure, not deferring the work.
Which compliance frameworks does DPDP compliance typically get implemented alongside?
DPDP Act 2023, GDPR, HIPAA, ISO 27001, SOC 2, and PCI DSS commonly share underlying controls, and a well-designed compliance program maps shared evidence across multiple frameworks simultaneously rather than running separate, duplicated efforts for each — significantly reducing audit overhead.
How is DPDP Act compliance actually operationalised, not just documented?
End-to-end: data mapping to establish where personal data of Indian residents actually lives, consent management infrastructure that captures granular, purpose-specific consent, data principal rights automation for access/correction/erasure requests, Records of Processing Activities (RoPA), breach notification workflows, and documentation ready for the Data Protection Board.
How is compliance evidence collected on an ongoing basis rather than scrambled together at audit time?
Compliance automation tooling (Drata, Vanta, Sprinto, and similar) integrates with cloud infrastructure, identity providers, code repositories, and ticketing systems to continuously collect control evidence. Instead of an emergency evidence-gathering exercise right before an audit, evidence accumulates daily.
What is Significant Data Fiduciary (SDF) status and why does it matter?
Significant Data Fiduciary is a DPDP Act classification that applies based on factors like the volume and sensitivity of personal data processed, triggering additional obligations beyond the baseline requirements every data fiduciary faces. Determining SDF status accurately requires real evidence of what data is actually being processed, not a self-reported checklist.

Not sure if DPDP applies to your organisation?

Our compliance team scopes applicability in a 30-minute call — no charge.

Book a scoping call