The Digital Personal Data Protection Act received assent on 11 August 2023, but sat dormant for over two years because it carried no commencement date. The DPDP Rules were notified on 13 November 2025 and brought only the Data Protection Board provisions into force. Every substantive obligation — notice, consent, data principal rights, children’s data, breach reporting — and the entire penalty regime commence after an eighteen-month transition, around May 2027.
Until then the Information Technology Act 2000 and the SPDI Rules 2011 remain the operative data protection law in India. Any vendor telling you DPDP fines are being levied today is wrong.
The timeline that matters
Act No. 22 of 2023 is passed with no commencement date, leaving the Central Government to appoint dates for different provisions.
Published in the Gazette via G.S.R. 846(E). Only definitions and the Data Protection Board provisions (Rules 1, 2, 17–21) commence immediately. MeitY announced this publicly on 14 November, but the 13th is the operative date from which all transition periods run.
Rule 4 commences twelve months after notification, allowing entities to register with the Board as Consent Managers. This binds organisations that want to be Consent Managers — it is not a compliance deadline for ordinary Data Fiduciaries.
Rules 3 and 5–16 and the corresponding sections of the Act take effect together: notice, consent, security safeguards, retention, children’s data, Significant Data Fiduciary duties, data principal rights, breach reporting — and the penalty regime. There is no further staggering by company size, sector or revenue.
Advisers compute the anniversaries differently depending on whether the counting is inclusive — you will see both 12 and 13 November 2026, and both 12 and 13 May 2027, in print. Plan to the month, not the day, and confirm the precise date with your counsel before it drives a contractual commitment.
Who the Act applies to
DPDP covers digital personal data only — data collected in digital form, or collected on paper and subsequently digitised. Paper records that are never scanned fall entirely outside the Act. There is no separate category of sensitive personal data: health information and a shipping address carry the same statutory treatment, which is a deliberate departure from both GDPR and India’s own SPDI Rules.
The vocabulary you will be held to
- Data Principal — the individual the data is about. GDPR calls this the data subject. Where the individual is a child, it includes the parent or lawful guardian.
- Data Fiduciary — whoever determines the purpose and means of processing. Functionally the GDPR controller, but the word is deliberate: it imports a trust-based framing, and the Data Fiduciary remains liable regardless of any contrary contract with a processor.
- Data Processor — processes on behalf of a Data Fiduciary. Notably, the Act imposes almost no direct statutory obligations on processors; they are reached only through the mandatory contract. An Indian IT or BPO vendor’s DPDP posture is contractual, not statutory.
- Significant Data Fiduciary — a Data Fiduciary notified as such by the Central Government, having regard to volume and sensitivity of data, risk to Data Principals, sovereignty, electoral democracy, State security and public order.
- Consent Manager — a Board-registered single point of contact through which a Data Principal can give, manage, review and withdraw consent. Uniquely, the Consent Manager is accountable to the Data Principal.
Significant Data Fiduciary status is not self-assessed and not automatic on crossing a threshold — it requires a government notification, and none has been issued yet. There is no user-count or revenue threshold for SDF status anywhere in the Act or Rules.
The 2 crore and 50 lakh user figures circulating in DPDP content come from the Third Schedule and relate to retention and erasure for e-commerce, social media and online gaming intermediaries. They have nothing to do with SDF designation.
What every Data Fiduciary has to do
The obligations below commence around May 2027. The work behind them — particularly the data inventory — takes considerably longer than the drafting.
- Notice that is standalone and independently understandable, itemising the data collected and each purpose, in plain language, with links to withdraw consent, exercise rights and complain to the Board. It must be offered in English and the Eighth Schedule languages.
- A lawful ground for every activity. There are only two: consent, or one of the enumerated legitimate uses. There is no legitimate-interest balancing test, which is the single biggest re-papering exercise for anyone running a GDPR-shaped programme.
- Consent that is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, limited to the data necessary for the stated purpose — and withdrawal that is as easy as giving it, propagated to processors and downstream systems.
- Security safeguards including encryption, obfuscation, masking or tokenisation, access control, logging and monitoring sufficient to detect and investigate unauthorised access, backups, and one-year log retention.
- Retention and erasure against a “purpose no longer served” test, with erasure propagating into backups, warehouses, logs and vendors.
- A grievance redressal mechanism and published contact details for the person able to answer questions about processing.
- Contracts with every processor — the only route by which the Act reaches them.
The Act puts the burden of proving valid notice and valid consent on the Data Fiduciary. There is no GDPR Article 30 records-of-processing requirement in DPDP — but that burden of proof makes a consent audit trail mandatory in substance. You need evidence of what notice was shown, in which language, when, and exactly what was consented to.
Data Principal rights
Four rights: access to a summary of the personal data processed and the identities of everyone it has been shared with; correction, completion, updating and erasure; grievance redressal; and nomination — appointing someone to exercise rights on death or incapacity, which has no GDPR equivalent.
Note what is absent. DPDP has no right to data portability, no right to object, no right to restriction of processing, and no right against solely automated decision-making. Rights also attach only to consent-based processing and to data voluntarily provided — not to every lawful basis.
The Rules attach the ninety-day cap to the grievance redressal mechanism, and require you to publish the response period you commit to. They do not set a statutory deadline for access or erasure requests, although the Government’s own press release blurred this and most vendor blogs have repeated it.
The safe operating posture: publish your stated response period, and treat ninety days as the practical outer limit for rights requests generally.
Breach reporting — stricter than GDPR in two ways
A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability. Critically, there is no harm threshold and no materiality threshold: every breach is reportable, to both the Board and every affected Data Principal.
- To affected Data Principals — without delay. Through their user account or a registered channel, in concise plain language, covering the nature, extent and timing of the breach; the consequences relevant to them; what you have done to mitigate it; what they should do to protect themselves; and a business contact who can respond.
- To the Data Protection Board — without delay, describing the nature, extent, timing and location of the breach and its likely impact.
- To the Board again — within 72 hours of becoming aware, with updated detail, the broad facts and circumstances, mitigation measures, findings on who caused it, remedial steps to prevent recurrence, and a report on the intimations given to Data Principals. This deadline is extendable on written request to the Board.
The CERT-In Directions of April 2022 require reporting of specified cyber incidents within six hours of noticing them. That obligation is live today and is entirely unaffected by DPDP. From May 2027 an Indian organisation will run parallel six-hour CERT-In and DPDP breach workflows off the same incident. Build one runbook that satisfies both, rather than two that compete during an incident.
Penalties
Penalties are civil monetary penalties imposed by the Data Protection Board after inquiry. The Act creates no criminal offences, and there is no turnover-linked penalty anywhere in the regime. These are ceilings, not fixed fines — the Board must weigh the nature, gravity and duration of the breach, whether you gained from it, and whether you mitigated promptly.
| Failure | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a breach | ₹250 crore |
| Failure to notify a personal data breach to the Board or affected Data Principals | ₹200 crore |
| Breach of the additional obligations relating to children | ₹200 crore |
| Breach of the additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of any other provision of the Act or Rules | ₹50 crore |
| Breach of the duties of a Data Principal (false or frivolous complaints) | ₹10,000 |
Two features have no GDPR analogue: DPDP penalises the Data Principal for frivolous complaints or false information, and the Board may accept a voluntary undertaking at any stage, which bars further proceedings on that breach. Appeals lie to the TDSAT within sixty days.
Children’s data
India sets the child threshold at under 18 — the highest of any major regime, with no sectoral or state-level variation, against 16 (reducible to 13) under GDPR and 13 under COPPA. Processing a child’s data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising to children are prohibited outright. For most consumer businesses this is a direct adtech, analytics and recommender-system change rather than a policy exercise.
How DPDP differs from GDPR
If you are extending an existing GDPR programme, these are the gaps that will actually bite.
That DPDP operates a country whitelist (it is a blacklist, currently empty); that it mandates data localisation (the only localisation hook applies to Significant Data Fiduciaries and is dormant until the Government specifies categories); that DPIAs are required for all high-risk processing (SDF-only); that it carries a plain GDPR-style 72-hour rule; and that it captures mere monitoring of behaviour from outside India (extraterritorial reach is limited to offering goods or services to Data Principals in India).
A readiness checklist
Roughly in dependency order. Items 1 and 2 have the longest lead time and everything else depends on them.
What to do between now and May 2027
The transition period is not idle time. The inventory, the lawful-ground remapping and the vendor contract remediation are each multi-quarter exercises in a mid-sized organisation, and they are sequential — you cannot rebuild notices until you know what you collect and why. Organisations that treat May 2027 as the start of the work rather than the end of it will be re-papering consent under enforcement pressure.
The one genuinely soft obligation worth planning for early: where consent was obtained before commencement, you must give the Data Principal fresh notice as soon as reasonably practicable. Legacy consent refresh across an existing customer base is a project, not a task.
DPSuite operationalises all of this
Consent and preference management, data principal request workflows, RoPA and data mapping, DPIAs, breach reporting and grievance redressal — running well before the deadline.
About this guide. Prepared by ProbityGRC and reviewed in July 2026 against the DPDP Act 2023 and the DPDP Rules 2025 as notified on 13 November 2025. The DPDP regime is still being operationalised: the Data Protection Board was in the process of being constituted at the time of writing, no Significant Data Fiduciaries had been designated, no countries had been restricted for transfers, and no localisation categories had been specified. This guide is general information about the law as we understand it, not legal advice, and it is no substitute for advice from qualified counsel on your specific circumstances. Confirm any date or figure that will drive a contractual or regulatory commitment.