All frameworks
IndAct 22 of 2023 · Rules 2025

India DPDP compliance

India's personal-data law — consent-first, rights-centred.

India's Digital Personal Data Protection Act, 2023, read with the DPDP Rules, 2025, is India's cross-sectoral personal-data law, enforced by the Data Protection Board of India. It runs on the Data Fiduciary's accountability: a lawful basis for every processing activity, clear notice and consent, strong security, fast breach notification, and enforceable rights for individuals.

Start from the basics

The standard

India Digital Personal Data Protection Act, 2023 (+ DPDP Rules 2025)

Who needs it

Any organisation — Indian or foreign — that processes the personal data of individuals in India, or offers them goods or services. Especially consumer apps, SaaS, fintech, health, e-commerce, ed-tech and any business handling Indian customers' or employees' data.

13 May 2027

Core obligations take effect

The basics

What is India DPDP?

The DPDP Act governs how any organisation (a 'Data Fiduciary') handles the digital personal data of individuals in India. You may process personal data only with consent — preceded by a clear, itemised notice — or for one of a closed list of 'certain legitimate uses'. There is no open-ended 'legitimate interests' balancing test.

It binds you even if you sit outside India, wherever you offer goods or services to people in India. Individuals get rights to access, correct, erase, nominate and raise grievances; children get special protection; and high-impact organisations can be designated 'Significant Data Fiduciaries' with extra duties. The Board provisions are already in force; the core obligations take effect on 13 May 2027.

Why it matters

What India DPDP does for your business

The penalties are real

Fixed rupee ceilings, not a slap on the wrist: up to ₹250 crore for failing to take reasonable security safeguards, and ₹200 crore for breach-notification failures — assessed per breach.

It's a market-access requirement

If you serve Indian users, DPDP compliance becomes a condition of doing business. Enterprise buyers and partners will ask how you handle consent, rights and breaches.

The clock is ticking

The substantive obligations bite on 13 May 2027. The organisations that build consent, rights and breach workflows now will be ready; the rest will scramble.

What it covers

Notice & consent

An itemised, standalone notice (Rule 3) precedes free, specific, informed consent — withdrawable as easily as it was given (ss.5–6).

Data Fiduciary obligations

Accountability, accuracy, reasonable security safeguards, breach notification and erasure on purpose-completion (s.8, Rules 6–8).

Data Principal rights

Access, correction, erasure, grievance redressal and nomination — answered within 90 days (ss.11–14, Rule 14).

Breach & special regimes

Every breach notified to the Board within 72 hours; children's verifiable parental consent (s.9); Significant-Data-Fiduciary DPIAs & audits (s.10).

The hard way

Done by hand, DPDP means chasing consent records across systems, re-drafting notices per product, tracking 90-day rights SLAs in spreadsheets, and hoping you can prove valid consent and a 72-hour breach report if the Board ever asks. That is exactly the repetitive, deadline-driven work software should run for you.

The easier way, with Compliance One

  • Provisions the full DPDP module: Records of Processing, a Rule-3 notice builder, a consent ledger, and a rights & grievances queue with the 90-day SLA tracked automatically.
  • Runs the 72-hour breach workflow — dual Board and Data-Principal notifications off a pre-seeded Data Protection Board authority — with no harm-threshold gate.
  • Handles children's verifiable-consent records, retention & erasure schedules, Significant-Data-Fiduciary DPIAs/audits and a cross-border transfer register.
  • Cross-maps every DPDP obligation to your ISO 27701 and ISO 27001 controls, so evidence you already collect counts here too.

Do it once, reuse it everywhere. Evidence you collect for India DPDP is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

When does DPDP take effect?
The Data Protection Board provisions are already in force (13 Nov 2025). Consent Manager registration opens 13 Nov 2026, and the core substantive obligations and rights take effect on 13 May 2027 — so now is the time to build.
Does it apply to us if we're outside India?
Yes, if you offer goods or services to individuals in India. DPDP has extraterritorial reach regardless of where you're incorporated or where your servers sit.
Is consent the only lawful basis?
No — you can also rely on a closed list of 'certain legitimate uses' (s.7), such as employment, legal obligations or medical emergencies. But there's no GDPR-style open 'legitimate interests' test.
We already have ISO 27701 — does that help?
A lot. Compliance One cross-maps DPDP to ISO 27701 (PIMS) and ISO 27001, so much of your existing privacy and security evidence carries straight over.

Ready to tackle India DPDP?

See exactly how Compliance One maps India DPDP to your environment in a 30-minute walkthrough — and how much of it we handle for you.