If your business holds a single email address, phone number, or customer name in a database, India now has a law that governs what you can do with it — and it carries fines of up to ₹250 crore. For two decades, Indian data protection lived in a thin set of IT Act rules that almost nobody enforced. That era ended on 13 November 2025, when the government notified the rules that bring the Digital Personal Data Protection Act, 2023 to life.
The headlines fixate on the penalties. The more useful truth is that you have a defined runway to get ready, the obligations are learnable, and most of the work is operational rather than legal. This guide walks through the whole thing in plain English: who it applies to, what you must do, by when, and what it costs to get wrong.
Quick answer: The Digital Personal Data Protection (DPDP) Act, 2023, with its Rules notified on 13 November 2025, is India's first comprehensive privacy law. It applies to any business processing the digital personal data of people in India — including foreign companies serving Indian users. Obligations roll out in phases: the Data Protection Board is already live, the Consent Manager framework starts 13 November 2026, and full compliance is mandatory by 13 May 2027. Penalties reach ₹250 crore for poor security and ₹200 crore for breach or children's-data failures. Treat 2026 as your build year.
What is the DPDP Act, and does it apply to you?
The DPDP Act governs the processing of digital personal data — any information about an identifiable individual, collected in digital form (or collected on paper and later digitised). It does not touch non-personal data, or data that stays purely on paper.
The reach is wide. The Act applies to you if you:
- process personal data inside India, or
- process the personal data of people in India while offering them goods or services — even if your company sits entirely outside India.
So a Singapore SaaS firm with Indian users is covered. A Delhi ed-tech startup is covered. A neighbourhood clinic with a digital patient register is covered. If you decide why and how personal data gets used, the law calls you a Data Fiduciary, and the obligations are yours — even when a vendor does the actual processing.
There are sensible carve-outs. Standard HR processing (recruitment, onboarding, payroll) falls under "legitimate uses" and doesn't need separate consent. Data an individual has voluntarily made public, or that the law requires to be public, sits outside the Act.
The three roles you need to understand
The whole law turns on three plain-English roles:
- Data Principal — the individual whose data it is (GDPR calls this the "data subject"). Your customer, user, or employee.
- Data Fiduciary — the business that decides the purpose and means of processing (GDPR's "controller"). That's you.
- Data Processor — a vendor that processes data on your behalf (a cloud host, a payroll provider). Crucially, you remain accountable for what your processors do, so you need proper contracts with them.
The compliance timeline: three phases
The Rules created an 18-month runway, split into three phases. This is the single most important thing to internalise, because it tells you what's urgent and what can wait.
- Phase 1 — 13 November 2025 (already in force): The Data Protection Board of India is established and operational, with online complaint filing live. The penalty framework is switched on. The first enforcement actions were reportedly initiated in early 2026.
- Phase 2 — 13 November 2026: The Consent Manager framework goes live. Consent Managers (only India-incorporated entities meeting a minimum net-worth threshold) can register with the Board to help users give, manage, and withdraw consent across services.
- Phase 3 — 13 May 2027: The hard deadline. Every substantive obligation becomes enforceable — privacy notices, consent, breach reporting, security safeguards, retention limits, children's-data protections, and Data Principal rights.
📅 Plan against 13 May 2027, build through 2026. "Soft enforcement" — guidance and warnings — is expected through 2026, but the Board is already operational, so this is preparation time, not a holiday.
[VISUAL: a horizontal timeline — Nov 2025 (Board live) → Nov 2026 (Consent Managers) → May 2027 (full compliance). This is the cluster's anchor graphic.]
What you must actually do
Strip away the jargon and DPDP compliance is six concrete workstreams:
1. Give clear notice. Before you collect data, show a standalone, itemised notice: exactly what you collect, the specific purpose, how to exercise rights, and how to complain. It must be available in English and any of the scheduled Indian languages.
2. Get real consent. Consent must be free, specific, informed, and unambiguous, through a clear affirmative action. Dark patterns are banned — no pre-ticked boxes, no giant "Accept" beside a hidden "Reject," no bundling unrelated purposes. Withdrawing consent must be as easy as giving it.
3. Honour Data Principal rights. Individuals can access a summary of their data, correct it, erase it, raise grievances, and nominate someone to act for them after death or incapacity. You need a published request channel, a named Grievance Officer, and a process that resolves grievances within 90 days.
4. Secure the data. Implement "reasonable security safeguards" — encryption, access controls, logging. This is the obligation with the heaviest penalty attached.
5. Limit retention and delete on time. Keep data only as long as the purpose needs it; delete when the purpose is served or consent is withdrawn. For some sectors the Rules set hard limits — large e-commerce platforms, for instance, must delete personal data three years after a user's last interaction. You must warn a user at least 48 hours before an automated deletion.
6. Be ready for breaches. Have an incident playbook that can intimate the Board and affected users without delay, and file a detailed report with the Board within 72 hours. (See the dedicated breach guide for the mechanics.)
What is a Significant Data Fiduciary?
The government can designate any business, or a whole class of businesses, as a Significant Data Fiduciary (SDF) based on factors like the volume and sensitivity of data, and risks to individuals or the state. SDFs carry extra duties: appoint a dedicated Data Protection Officer based in India, appoint an independent data auditor, run annual Data Protection Impact Assessments and audits, and meet stricter due-diligence and localisation rules.
As of mid-2026, the SDF list has not yet been notified. If you're in fintech, health, telecom, large e-commerce, or a major social platform, assume you're a likely candidate and prepare accordingly.
Cross-border data transfers
DPDP takes a "negative list" approach: you may transfer personal data outside India except to countries the government specifically restricts. That restricted-country list has not yet been published. The practical move is to map your data flows now — know which workloads hold what personal data and where they run — so you can react quickly when the list lands. Expect BFSI, healthcare, and government-adjacent data to face the most localisation pressure.
The penalties
The Schedule to the Act sets upper limits; the Data Protection Board fixes the actual amount after weighing the statutory factors. The ceilings:
| Failure | Maximum penalty |
|---|---|
| Failure to implement reasonable security safeguards | ₹250 crore |
| Failure to notify a breach / process children's data lawfully / process without valid consent | ₹200 crore |
| Failure to meet SDF-specific obligations | ₹150 crore |
| General / other non-compliance | ₹50 crore |
Two things make this sharper than it looks. Penalties are applied per contravention and can stack, and the Board can publish the violation — reputational damage on top of the fine.
DPDP vs GDPR: the key differences
If your team knows GDPR, you have a head start, but don't assume they're identical. DPDP is consent-led with a short list of "legitimate uses," where GDPR offers six lawful bases. DPDP covers only digital personal data and has no separate "sensitive data" category. Its penalties are absolute rupee ceilings, not a percentage of global turnover. And it carries India-specific quirks — broad government exemptions and investigative powers — that a copy-pasted GDPR programme won't cover. If you already run GDPR controls, the work here is an India overlay, not a rebuild.
Worked example: a SaaS startup's gaps
A 30-person Bengaluru SaaS company with users across India and abroad runs a quick self-audit and finds the typical picture:
- A privacy policy copied from a US template, with no itemised purposes and no Indian-language version. ❌
- A cookie banner with a prominent "Accept" and a buried "Manage." ❌ (a banned dark pattern)
- Customer data stored on a US cloud region, with no data-flow map. ⚠️ (fine for now, but unmapped)
- No named Grievance Officer, no rights-request channel. ❌
- "Just in case" analytics data kept indefinitely. ❌ (a retention violation)
None of this is catastrophic in 2026 — but every item is a clear gap against the May 2027 deadline, and the consent-banner and retention issues are exactly the kind that drew the Board's first enforcement attention.
Common mistakes
- Treating it as "GDPR but India." The overlap is real but incomplete; the India-specific rules will catch you.
- Waiting for May 2027. The Consent Manager deadline lands in November 2026, and legacy-data consent is already a focus.
- Forgetting processor accountability. You're liable for your vendors; fix the contracts.
- Ignoring Indian-language notices. Notices must be available in scheduled languages, not just English.
- Hoarding data "just in case." Data minimisation is now a clear legal duty, not best practice.
Your build-year checklist (2026)
- Map every data flow: what you collect, why, where it's stored, who can access it, how long you keep it.
- Rewrite your privacy notice to be itemised, plain, and available in scheduled languages.
- Redesign consent capture — kill the dark patterns, make withdrawal one-click, and get ready for Consent Manager integration by November 2026.
- Name and publish a Grievance Officer; build a Data Principal rights workflow.
- Set retention periods per data category and automate deletion (with 48-hour notice).
- Write a breach-response playbook covering both the Board (72 hours) and CERT-In.
- Update processor contracts with security and audit clauses.
- If you might be an SDF, start DPO, DPIA, and audit planning now.
Frequently asked questions
When does the DPDP Act take full effect? Full substantive compliance is mandatory from 13 May 2027. The Data Protection Board is already operational, and the Consent Manager framework starts 13 November 2026.
Does the DPDP Act apply to foreign companies? Yes. It applies to any business processing the personal data of people in India in connection with offering goods or services to them, regardless of where the business is based.
What are the maximum penalties? Up to ₹250 crore for security-safeguard failures, ₹200 crore for breach-notification or children's-data violations, ₹150 crore for SDF failures, and ₹50 crore for general non-compliance — per contravention.
Is my business a Significant Data Fiduciary? Only if the government notifies you as one. The list isn't out yet, but large or high-risk processors (fintech, health, telecom, big platforms) are likely candidates.
Do I need a Data Protection Officer? A dedicated DPO is mandatory only for Significant Data Fiduciaries. Every other business must name a reachable Grievance Officer.
This article is for legal awareness and education only and is not legal advice. The DPDP framework is being implemented in phases and several notifications (SDF list, restricted countries) are still pending; confirm the current position and consult a qualified professional before acting.