← Back to Knowledge Hub

Somewhere in your business there is a spreadsheet of customer names, phone numbers and email addresses. For twenty years nobody asked what you did with it. India now has a law that does, and the ceiling for handling it badly is β‚Ή250 crore.

The Digital Personal Data Protection Act, 2023, whose Rules were notified on 13 November 2025, governs any business processing the digital personal data of people in India, with full compliance mandatory from 13 May 2027.

The bottom line

Who it covers: anyone processing digital personal data in India, and any foreign company processing the data of people in India while offering them goods or services.

The dates: the Data Protection Board is already operating. Consent Manager registration opens 13 November 2026. Everything that takes real work β€” notice, security, breach reporting, retention limits, children's data, data principal rights β€” bites on 13 May 2027.

What it costs: up to β‚Ή250 crore for weak security, β‚Ή200 crore for breach or children's-data failures, per contravention.

Does it apply to you

The Act governs the processing of digital personal data: information about an identifiable individual, collected in digital form, or collected on paper and later digitised. Non-personal data is outside it. So is data that never leaves paper.

Beyond that the reach is wide. You are covered if you process personal data inside India, or if you process the personal data of people in India while offering them goods or services β€” even with no Indian presence at all. A Singapore SaaS firm with Indian users is covered. So is a Delhi ed-tech startup, and so is a neighbourhood clinic keeping its patient register on a laptop.

If you decide why and how personal data gets used, the law calls you a Data Fiduciary. The obligations are yours even when a vendor does the actual processing.

There are sensible carve-outs. Ordinary HR processing β€” recruitment, onboarding, payroll β€” falls under "legitimate uses" and needs no separate consent. Data an individual has voluntarily made public, or that the law requires to be public, sits outside the Act.

Three roles, and which one you are

The whole law turns on who is doing what.

  • Data Principal β€” the individual whose data it is, called the "data subject" under GDPR. Your customer, user or employee.
  • Data Fiduciary β€” the business deciding the purpose and means of processing, GDPR's "controller". That is you.
  • Data Processor β€” a vendor processing data on your behalf, such as a cloud host or a payroll provider.

The point that trips businesses up is the last one. You stay accountable for what your processors do, which means the contracts with them have to carry security and audit obligations rather than a generic confidentiality line.

The compliance timeline

The Rules were notified on 13 November 2025 and commence in three stages. The Board and the penalty framework are live now. Consent Manager registration opens on 13 November 2026. The substantive obligations land on 13 May 2027.

Plan against that last date, and start earlier than feels necessary β€” the data inventory alone takes most organisations several months. Our guide to the DPDP Rules commencement timeline sets out which rule numbers land in which phase.

What you must actually do

Strip the jargon away and compliance is six pieces of work.

1. Give clear notice. Before you collect data, show a standalone, itemised notice: what you collect, the specific purpose, how to exercise rights, how to complain. It has to be available in English and in the scheduled Indian languages.

2. Get real consent. Consent must be free, specific, informed and unambiguous, given by a clear affirmative action. Dark patterns are banned. No pre-ticked boxes, no giant "Accept" beside a hidden "Reject", no bundling unrelated purposes into one tick. Withdrawing consent has to be as easy as giving it.

3. Honour Data Principal rights. Individuals can ask for a summary of their data, correct it, erase it, raise a grievance, and nominate someone to act for them after death or incapacity. That needs a published request channel, a named Grievance Officer, and a process that closes grievances within 90 days.

4. Secure the data. Reasonable security safeguards β€” encryption, access controls, logging. This is the obligation carrying the heaviest penalty.

5. Limit retention and delete on time. Keep data only as long as the purpose needs it, and delete it when the purpose is served or consent is withdrawn. Some sectors have hard limits: large e-commerce platforms must delete personal data three years after a user's last interaction. Users get at least 48 hours' warning before an automated deletion.

6. Be ready for breaches. You need an incident playbook that can intimate the Board and the affected users without delay, and file a detailed report with the Board within 72 hours.

Significant Data Fiduciaries

The government can designate a business, or a whole class of them, as a Significant Data Fiduciary, weighing the volume and sensitivity of data it holds and the risk to individuals or to the state. An SDF carries extra duties: a dedicated Data Protection Officer based in India, an independent data auditor, annual Data Protection Impact Assessments and audits, and stricter due-diligence and localisation rules.

As of mid-2026 the SDF list has not been notified. Fintech, health, telecom, large e-commerce and the major social platforms are the obvious candidates, and anyone in those sectors should prepare on the assumption they will be named.

Sending data abroad

DPDP works off a negative list. You may transfer personal data outside India except to countries the government specifically restricts, and that restricted list has not been published yet.

Which makes the useful move a mapping exercise rather than a legal one: know which workloads hold what personal data and where they run, so you can move quickly once the list appears. BFSI, healthcare and government-adjacent data will face the most localisation pressure.

The penalties

The Schedule to the Act sets upper limits. The Data Protection Board fixes the actual amount after weighing the statutory factors, so these are ceilings rather than tariffs.

FailureMaximum penalty
Failure to implement reasonable security safeguardsβ‚Ή250 crore
Failure to notify a breach / process children's data lawfully / process without valid consentβ‚Ή200 crore
Failure to meet SDF-specific obligationsβ‚Ή150 crore
General or other non-complianceβ‚Ή50 crore

Two features make the numbers sharper than they look. Penalties apply per contravention and can stack. And the Board can publish the violation, so the reputational cost arrives alongside the fine.

DPDP against GDPR

A team that knows GDPR has a head start, and will still get caught out by the differences. DPDP is consent-led, with a short list of "legitimate uses", where GDPR gives you six lawful bases. It covers only digital personal data, and has no separate category for sensitive data. Its penalties are absolute rupee ceilings rather than a percentage of global turnover. And it carries India-specific features β€” broad government exemptions and investigative powers β€” that a copy-pasted GDPR programme does not address. If your GDPR controls are already running, treat this as an India overlay rather than a rebuild.

A worked example

A thirty-person Bengaluru SaaS company with users in India and abroad runs a self-audit. The picture is typical.

  • A privacy policy copied from a US template, with no itemised purposes and no Indian-language version.
  • A cookie banner with a prominent "Accept" and a buried "Manage" β€” a banned dark pattern.
  • Customer data on a US cloud region, with no data-flow map. Permitted for now, but unmapped.
  • No named Grievance Officer and no rights-request channel.
  • Analytics data kept indefinitely, "just in case". That is a retention violation.

None of it is catastrophic in 2026. Every item is a clear gap against the May 2027 deadline, and the consent banner and the retention practice are precisely what draws early enforcement attention.

Common mistakes

  • Treating it as GDPR with Indian branding. The overlap is real but partial, and the India-specific rules are where the gaps are.
  • Waiting for May 2027. Consent Manager integration lands in November 2026, and consent for data you already hold is a live question now.
  • Forgetting processor accountability. You are liable for your vendors, so the contracts need fixing.
  • Publishing notices in English only. They must be available in the scheduled languages.
  • Hoarding data in case it turns out to be useful. Minimisation is a legal duty now, not good practice.

Where to start

Sequence matters here, because most of these depend on knowing what data you hold.

  1. Map every data flow: what you collect, why, where it sits, who can reach it, how long you keep it. Nothing below can be done properly without this.
  2. Rewrite the privacy notice so it is itemised, plain and available in the scheduled languages.
  3. Redesign consent capture β€” remove the dark patterns, make withdrawal one click, and prepare for Consent Manager integration by November 2026.
  4. Name and publish a Grievance Officer, and build the rights-request workflow behind them.
  5. Set a retention period for each data category and automate deletion, with the 48-hour notice built in.
  6. Write the breach playbook, covering the Board within 72 hours and CERT-In alongside it.
  7. Reopen processor contracts and add security and audit clauses.
  8. If you might be named an SDF, start on the DPO, the DPIA process and audit planning now rather than after the notification.

Frequently asked questions

When does the DPDP Act take full effect? Full substantive compliance is mandatory from 13 May 2027. The Data Protection Board is already operational and the Consent Manager framework starts 13 November 2026.

Does the DPDP Act apply to foreign companies? Yes. It applies to any business processing the personal data of people in India in connection with offering goods or services to them, wherever the business is based.

What are the maximum penalties? Up to β‚Ή250 crore for security-safeguard failures, β‚Ή200 crore for breach-notification or children's-data violations, β‚Ή150 crore for SDF failures and β‚Ή50 crore for general non-compliance, per contravention.

Is my business a Significant Data Fiduciary? Only if the government notifies you as one. The list is not out yet, but large or high-risk processors in fintech, health, telecom and the big platforms are likely candidates.

Do I need a Data Protection Officer? A dedicated DPO is mandatory only for Significant Data Fiduciaries. Every other business must name a reachable Grievance Officer.

What about data we collected before the law? It is still personal data, and the notice and consent requirements reach it. Reviewing legacy consent is part of the build, not an optional extra.