Last verified: 15 August 2026
DPDP Act compliance is the set of obligations the Digital Personal Data Protection Act, 2023 places on any business processing digital personal data in India, and as of August 2026 almost none of them is in force. The commencement notification of 13 November 2025 defers sections 3 to 17, the penalty provisions and rules 3 and 5 to 16 to an eighteen-month tranche ending in May 2027, with Consent Manager registration arriving in November 2026. Until then, section 43A of the Information Technology Act, 2000 and the SPDI Rules 2011 remain the operative data-security law. The Act sets no turnover, headcount or user-count threshold, so the same notice, consent, security and breach duties will bind a twenty-person firm and a listed company alike.
The obligations are not live, but the work of meeting them is: applicability first, then the ten items, then the dates and penalties behind them.
The gap between notification and commencement is why most published checklists misstate the position. A notification fixes the text of a law; a commencement date fixes when it starts to bind, and here the two sit months apart. There’s a second, independent reason nothing can be enforced right now: the Data Protection Board of India, established in law in November 2025, had no appointed Chairperson or Members as of 1 August 2026.
The eighteen-month tranche lands as a single date, not a ramp. Neither the Act nor the Rules carries transitional relief or a grace period, so every duty commences together. That’s what makes the window build time, not slack time.
Who Must Comply with the DPDP Act?
DPDP Act compliance applies to any person who, alone or with others, determines the purpose and means of processing digital personal data, and the test turns on what a business does with data rather than on its size. Section 3(a) of the Digital Personal Data Protection Act, 2023 covers processing of digital personal data within India, whether collected digitally or digitised afterwards. Section 3(b) reaches processing outside India connected with offering goods or services to Data Principals in India. Section 3(c) carves out two situations only: data processed by an individual for a personal or domestic purpose, and data made public by the Data Principal herself or by someone legally obliged to publish it.
A Data Fiduciary determines the purpose and means of processing, a Data Processor processes on its behalf, and a Data Principal is the individual concerned. Section 4 permits processing on two footings only: consent, or a legitimate use listed in section 7.
So which Indian businesses sit outside the Act on size alone? None. No turnover, revenue, headcount or user-count threshold appears anywhere in the Act or the DPDP Rules 2025.
Three sets of figures circulate as if they were exemption thresholds.
The Third Schedule’s two crore and fifty lakh registered-user figures decide only who falls under a three-year auto-erasure rule, and the two crore rupee net worth in Part A of the First Schedule is an eligibility condition for registering as a Consent Manager. The capital and turnover figures in MeitY’s May 2026 circular on Board appointments measure a candidate’s previous employer.
The startup exemption is a power, not a grant. Section 17(3) lets the Central Government notify certain Data Fiduciaries (startups included) as fiduciaries to whom section 5, sections 8(3) and 8(7), section 10 and section 11 do not apply, and it operates only on notification. None has issued as of 15 August 2026.
And the exemption would be partial even then. A notified startup would still owe consent under section 6, security safeguards under section 8(5), children’s duties under section 9, published contact information under section 8(9), grievance redressal under sections 8(10) and 13, correction and erasure under section 12, and breach notification under section 8(6). Section 17(5), the broader five-year power, is unexercised too.
A Data Protection Officer is a Significant Data Fiduciary obligation, and every other business owes a contact person instead. Section 10(2)(a) imposes it only on a Significant Data Fiduciary, and section 2(l) defines the office by reference to that section, so it doesn’t exist outside that status. No entity has been notified as significant. Everyone else owes section 8(9): publish the contact information of a DPO where applicable, or of a person able to answer questions about the processing.
Rule 9 of the Digital Personal Data Protection Rules, 2025 settles where that goes: prominently on the website or app, and in every response to a rights request. A Grievance Officer isn’t a DPO either: sections 8(10) and 13 require a grievance mechanism and rule 14(3) a ninety-day response ceiling, but neither creates the office. That split shapes building a career in data privacy in India.
Significant Data Fiduciary status arrives by designation, not self-assessment. Section 10(1) lets the Central Government notify a fiduciary or a class as significant on an assessment of data volume and sensitivity, risk to Data Principals’ rights, and impact on sovereignty, electoral democracy, security of the State and public order.
The extra duties (an independent data auditor under section 10(2)(b), a Data Protection Impact Assessment and audit every twelve months under rule 13(1), a report to the Board under rule 13(2), algorithmic due diligence under rule 13(3), and the localisation power in rule 13(4)) attach only after that. But rule 13(4) is narrower than commentary suggests: significant fiduciaries only, and only for categories specified later.
The question answers itself for almost every Indian firm. A two-person business with a website contact form, a customer list and a payroll file is a Data Fiduciary, and so is a sole proprietor running an online store. A phone number typed into a till is digital personal data, and shop CCTV is caught where images are stored digitally and identify individuals. But the carve-out in section 3(c)(i) covers an individual acting personally, never a small business.
Privacy became a fundamental right in the nine-judge Supreme Court decision of August 2017, and the Act received assent on 11 August 2023 after a Bill introduced in 2019 and withdrawn in 2022. Data portability and the right to be forgotten, both in earlier drafts, are absent from the 2023 Act. Nearly ten years separate the constitutional right from the first duty a business can be penalised for.
The DPDP Act compliance checklist
The DPDP Act compliance checklist runs to ten items, each traceable to a section of the Act or a rule in the DPDP Rules 2025, and none is enforceable before May 2027.
| # | Checklist item | What it involves | Statutory basis |
|---|---|---|---|
| 1 | Map the personal data by purpose | Every field held, and why | s.5(1)(i), rule 3(b) |
| 2 | Fix a lawful basis for each purpose | Consent, or a named section 7 use | s.4, s.6, s.7 |
| 3 | Rewrite the notice to rule 3 | A standalone notice, not a policy clause | s.5(1), s.5(3), rule 3 |
| 4 | Notice for pre-commencement consent | A fresh notice to everyone already on file | s.5(2) |
| 5 | Make withdrawal as easy as consent | As easy as giving it | s.6(4), s.6(6), rule 3(c) |
| 6 | Publish a contact and a grievance route | On the site, and in every rights reply | s.8(9), s.8(10), rule 9, rule 14 |
| 7 | Meet the rule 6 security floor | Encryption, access control, logs, backups | s.8(5), rule 6 |
| 8 | Paper every processor contract | A written contract with the rule 6 clause | s.8(1), s.8(2), rule 6(1)(f) |
| 9 | Set retention and erasure rules | Erase on withdrawal; keep data and logs a year | s.8(7), s.8(8), rule 8 |
| 10 | Write the breach playbook | Principals and Board at once; report in 72 hours | s.8(6), rule 7 |
Items 1 and 2 come first because the rest depend on them. Section 5(1)(i) and rule 3(b) require an itemised description of the personal data and a specific description of the purpose, which needs an inventory behind it, much like how a formal record of processing activities is built. Section 7(a), the purpose for which the Data Principal voluntarily provided her data, is the ground an ordinary business relies on. And a privacy policy doesn’t discharge section 5: rule 3(a) demands a notice understandable on its own.
The order below is not arbitrary either: items 3, 4 and 5 all live in the notice built from item 1’s purpose map, item 8 cannot be papered until item 7 fixes the clause it carries, and item 10 needs item 6’s contact route before a breach tests it. The rest run in parallel and never complete.
Drafted from section 5(1), section 5(3) and rule 3, a compliant notice reads close to this.
Notice under section 5, Digital Personal Data Protection Act, 2023
Personal data collected here: full name, mobile number, email address, delivery address.
Purpose: fulfilling the order placed on this site: confirmation, delivery through [logistics partner], invoicing and returns. Nothing beyond those four items is collected, and none is used for marketing.
To withdraw consent, exercise the rights of access, correction, updating, erasure or nomination, or raise a grievance: [https://example.in/privacy-request], [[email protected]] or [postal address]. Withdrawal takes the same steps as consent.
A complaint may be made to the Data Protection Board of India at [Board portal].
Available in English or any Eighth Schedule language: [language link].
Questions about this processing: [Privacy Contact], [[email protected]].
No term here waives the right to complain to the Board.
[ ] I agree to the processing of the personal data listed above for the specified purpose.
Every line maps to a provision: rule 3(a) standalone presentation, rule 3(b) itemised data and specific purpose, rule 3(c) with sections 5(1)(ii) and 5(1)(iii) for withdrawal, rights, grievance and the Board, and section 5(3) with sections 6(1) to (3) for language, contact and purpose-limited consent.
Section 5(2) catches every business already holding a customer database. Where consent was obtained before commencement, the Data Fiduciary must give a retrospective notice carrying the same three items as soon as reasonably practicable, and processing may continue until consent is withdrawn. That reaches the legacy CRM, the lead sheet and the WhatsApp broadcast list, and section 6(1) limits consent to the specified purpose, so a list built for order fulfilment doesn’t cover promotional messaging.
Rule 6 sets the security floor: encryption, obfuscation, masking or tokens; access control; logs, monitoring and review; backups; one-year retention of those logs and the data unless another law requires otherwise; a security clause in the processor contract; and appropriate technical and organisational measures. That set maps closely onto a written information security programme.
Section 8(1) holds the Data Fiduciary responsible irrespective of any agreement to the contrary, and section 8(2) permits a Data Processor only under a valid contract. So the risk can’t move to the vendor, and repapering those contracts is the drafting skill behind those data-protection clauses.
Retention runs on two rules, and the widely quoted one applies to almost nobody. Section 8(7) requires erasure on withdrawal of consent or when the purpose is no longer served, whichever is earlier, and the Data Processor must erase too unless another law requires retention. Rule 8(3) separately requires personal data, traffic data and processing logs to be kept for at least a year from processing.
The Third Schedule’s three-year auto-erasure rule reaches three classes only: an e-commerce entity with at least two crore registered users in India, an online gaming intermediary with at least fifty lakh, and a social media intermediary with at least two crore. It’s no general three-year cap.
Section 8(6) creates the breach duty; rule 7 supplies the mechanics, on two clocks. Rule 7(1) requires notification of each affected Data Principal without delay, in plain language, covering its nature, extent and timing, the consequences for her, mitigation implemented, safety measures she may take, and a contact who can respond. Rule 7(2)(a) requires the Board to be notified without delay, and rule 7(2)(b) the detailed follow-up report within seventy-two hours.
No materiality or harm threshold applies, so every breach is reportable. Most published checklists compress all of it into one seventy-two-hour rule.
Children’s data catches a whole category of Indian SME. Section 2(f) sets the age at eighteen, section 9(1) requires verifiable parental consent, section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, and rule 10 sets the due-diligence mechanics. Rule 12 and the Fourth Schedule carve out narrow, purpose-bound exemptions for healthcare, education, creche and school-transport settings. An edtech firm or paediatric clinic sits hardest.
Cross-border transfer is the shortest item: section 16(1) lets the Government notify countries to which transfer is restricted, none has been notified, and section 16(2) leaves sectoral rules intact.
DPDP compliance makes an Indian SME retain more data, not less, which runs against the instinct most privacy training installs. Rule 6(1)(e) and rule 8(3) both impose one-year floors, and the Government’s own illustration extends that through the vendor: a company using a cloud provider must ensure the provider retains data and logs for a year too. The costs land on storage, log tooling and a larger breach blast radius.
The Data Protection Board exists in law, TDSAT becomes the appellate tribunal under s.44(1), and s.8(1)(j) of the RTI Act is amended by s.44(3). No compliance obligation falls on a business.
Consent Manager registration opens. A Consent Manager is a Board registered intermediary incorporated in India with a net worth of not less than two crore rupees, not a piece of software an SME installs.
Every compliance obligation commences on one date: notice, consent, security safeguards, breach notification, children’s data, Significant Data Fiduciary duties, Data Principal rights, cross-border transfer and the s.33 penalty power. s.43A of the IT Act 2000 and the SPDI Rules 2011 fall away at the same moment.
Date note. Notified 13 November 2025. The e-Gazette identifiers on the notifications encode 14 November 2025 as the electronic publication date, so some sources compute the twelve month and eighteen month milestones one day later. Planning to the earlier date is safe under either reading.
Source: notification G.S.R. 843(E) and rule 1 of the DPDP Rules 2025, MeitY, 13 November 2025.
Compliance deadlines and penalties under the DPDP Act
The DPDP Act compliance deadlines come from a single commencement notification issued in November 2025, and the penalties from the Schedule to the Act read with section 33. Notification G.S.R. 843(E), issued under section 1(2), appoints three dates. On publication it brought into force section 2, sections 18 to 26, section 35, sections 38 to 43 and sections 44(1) and 44(3), with rules 1, 2 and 17 to 21.
At twelve months, in November 2026, section 6(9), section 27(1)(d) and rule 4 commence, and Consent Manager registration opens with them. At eighteen months, in May 2027, sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 except 27(1)(d), sections 28 to 34, sections 36 and 37 and section 44(2) commence, with rules 3, 5 to 16, 22 and 23. The notifications are dated 13 November 2025, though some sources compute the clocks from publication a day later; planning from the earlier date is safe either way.
What binds an Indian business today is the older regime. Section 44(2), which omits section 43A of the IT Act 2000 and the rule-making power in section 87(2)(ob) under which the SPDI Rules 2011 were made, sits in the eighteen-month tranche. So section 43A and those Rules still apply, including the published privacy policy, consent for sensitive personal data, the grievance officer and the reasonable-security-practices standard.
There’s a remedy inversion here, and law-firm analysis of the commencement phases reads it the same way. Section 43A gives an affected individual uncapped compensation, while DPDP penalties go to the Consolidated Fund under section 34 and the Data Principal gets nothing.
CERT-In reporting continues separately, and the DPDP breach duty doesn’t replace it: the CERT-In Directions of April 2022, issued under section 70B(6) of the IT Act, require a listed cyber incident to be reported within six hours of notice.
The penalty figures sit in the Schedule to the Act.
| Sl. | Breach | Penalty may extend to |
|---|---|---|
| 1 | Failure to take reasonable security safeguards, s.8(5) | Rs 250 crore |
| 2 | Failure to notify a personal data breach, s.8(6) | Rs 200 crore |
| 3 | Breach of the additional obligations on children, s.9 | Rs 200 crore |
| 4 | Breach of Significant Data Fiduciary obligations, s.10 | Rs 150 crore |
| 5 | Breach of the Data Principal’s duties, s.15 | Rs 10,000 |
| 6 | Breach of a voluntary undertaking accepted under s.32 | The amount applicable to the breach that prompted the s.28 proceedings |
| 7 | Breach of any other provision of the Act or the Rules | Rs 50 crore |
Three qualifications travel with that table. These are fixed rupee ceilings, not a percentage of turnover, which is a structural difference from the GDPR’s turnover-based model and an exposure that lands on the board overseeing the company. Every figure is preceded by “may extend to” in the statute, so each is a maximum rather than a tariff. And section 33(1) permits a penalty only where the Board finds, on conclusion of an inquiry and after a hearing, that the breach is significant, with section 33(2) listing seven factors that fix the amount.
Section 42, already in force, lets the Government amend the Schedule by notification.
Can the Board impose a penalty on an Indian business today? Not on either of two independent grounds. Sections 28 and 33 are not in force, and the Board (established November 2025, head office in the National Capital Region, four Members besides the Chairperson) still had no appointed Chairperson or Members as of 1 August 2026, as reported in August 2026. Three things also remain unsettled: no entity has been notified as a Significant Data Fiduciary, no country as restricted under section 16(1), and no notification under section 17(3) has issued.
A Big Four India cybersecurity practice surveyed more than 150 professionals and published the results on 27 January 2026: roughly 70 per cent were not very familiar with the Act and Rules, 81 per cent had not updated their privacy policies, and 83 per cent had not begun comprehensive implementation.
Two events are worth watching before May 2027. MeitY held a stakeholder consultation in January 2026 proposing to compress the Significant Data Fiduciary window from eighteen months to twelve and to notify cross-border restrictions under rule 13(4), though nothing has been notified as of 15 August 2026. The other is the first Significant Data Fiduciary list: nothing in section 10 or rule 13 binds anyone until the Government names classes.
Consent Manager registration opens in November 2026 against a First Schedule bar (India incorporation, a two crore rupee net worth, independent certification of an interoperable platform) that makes it a licensed intermediary, not software an SME installs.
But enforcement capacity, not the law, is the binding constraint: a five-person Board working as a digital office under rule 20, with a six-month inquiry deadline under rule 19(9), points to a few high-visibility actions, not broad sweeps.
Frequently asked questions
Does processing employee data under the DPDP Act require consent?
No. Section 7(i) treats employment purposes as a legitimate use, so staff and HR data may be used without consent. But section 8 still binds the employer in full: security, breach reporting, erasure, a published contact and a grievance route apply as they do to customer data.
Can Indian businesses continue using AWS, Microsoft Azure or Google Cloud under the DPDP Act?
Yes. Section 16(1) lets the Central Government notify countries to which transfer is restricted, and none has been notified so far. Section 16(2) preserves stricter Indian law, and sections 8(1) and 8(2) keep responsibility with the Data Fiduciary, not the cloud vendor, whatever the contract says.
Does training an AI model on customer data need separate consent under the DPDP Act?
The Act has no AI-specific provision, so purpose limitation decides it. Section 6(1) limits consent to the data necessary for the specified purpose, and rule 3(b) requires the notice to state that purpose. A use the notice never named needs fresh consent or a section 7 ground.
Does a DPDP consent notice have to be provided in all 22 scheduled languages?
No. Section 5(3) gives the Data Principal the option of accessing the notice in English or any language in the Eighth Schedule to the Constitution, and section 6(3) applies the same standard to the consent request. It is an option offered, not 22 translations published.
References
Official guidance and regulations
- CERT-In Directions under section 70B(6) of the Information Technology Act, 2000. Indian Computer Emergency Response Team, April 2022
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, G.S.R. 313(E). India Code, Government of India
- MeitY circular F. No. 2(1)/2026-Pers.I, Data Protection Board appointments. MeitY, 6 May 2026
- Notification G.S.R. 843(E), commencement of the DPDP Act, 2023. MeitY, 13 November 2025
- Notification G.S.R. 844(E), establishment of the Data Protection Board of India. MeitY, 13 November 2025
- The Digital Personal Data Protection Act, 2023, including the Schedule (see section 33(1)). MeitY, Government of India
- The Digital Personal Data Protection Rules, 2025, G.S.R. 846(E). MeitY, 13 November 2025
Case law and legislative history
- Digital Personal Data Protection Bill, 2023 Bill Track. PRS Legislative Research
- Justice K.S. Puttaswamy (Retd.) v. Union of India, 24 August 2017. Supreme Court of India
Data and research
Secondary sources
- India’s Data Protection Board: established in law, absent in fact. LiveLaw, 1 August 2026
- India’s Digital Personal Data Protection Regime Takes Effect. S&R Associates via Chambers
- MeitY proposal to compress the SDF compliance timeline. S.S. Rana & Co.
This article is informational and educational only and is not legal advice. The DPDP Act and the DPDP Rules 2025 are in phased commencement, and the position stated here is as of August 2026. Consult a qualified professional before acting.


Allow notifications