The penalties are real
Fixed rupee ceilings, not a slap on the wrist: up to ₹250 crore for failing to take reasonable security safeguards, and ₹200 crore for breach-notification failures — assessed per breach.
India's personal-data law — consent-first, rights-centred.
India's Digital Personal Data Protection Act, 2023, read with the DPDP Rules, 2025, is India's cross-sectoral personal-data law, enforced by the Data Protection Board of India. It runs on the Data Fiduciary's accountability: a lawful basis for every processing activity, clear notice and consent, strong security, fast breach notification, and enforceable rights for individuals.
The standard
India Digital Personal Data Protection Act, 2023 (+ DPDP Rules 2025)
Who needs it
Any organisation — Indian or foreign — that processes the personal data of individuals in India, or offers them goods or services. Especially consumer apps, SaaS, fintech, health, e-commerce, ed-tech and any business handling Indian customers' or employees' data.
13 May 2027
Core obligations take effect
The basics
The DPDP Act governs how any organisation (a 'Data Fiduciary') handles the digital personal data of individuals in India. You may process personal data only with consent — preceded by a clear, itemised notice — or for one of a closed list of 'certain legitimate uses'. There is no open-ended 'legitimate interests' balancing test.
It binds you even if you sit outside India, wherever you offer goods or services to people in India. Individuals get rights to access, correct, erase, nominate and raise grievances; children get special protection; and high-impact organisations can be designated 'Significant Data Fiduciaries' with extra duties. The Board provisions are already in force; the core obligations take effect on 13 May 2027.
Why it matters
Fixed rupee ceilings, not a slap on the wrist: up to ₹250 crore for failing to take reasonable security safeguards, and ₹200 crore for breach-notification failures — assessed per breach.
If you serve Indian users, DPDP compliance becomes a condition of doing business. Enterprise buyers and partners will ask how you handle consent, rights and breaches.
The substantive obligations bite on 13 May 2027. The organisations that build consent, rights and breach workflows now will be ready; the rest will scramble.
An itemised, standalone notice (Rule 3) precedes free, specific, informed consent — withdrawable as easily as it was given (ss.5–6).
Accountability, accuracy, reasonable security safeguards, breach notification and erasure on purpose-completion (s.8, Rules 6–8).
Access, correction, erasure, grievance redressal and nomination — answered within 90 days (ss.11–14, Rule 14).
Every breach notified to the Board within 72 hours; children's verifiable parental consent (s.9); Significant-Data-Fiduciary DPIAs & audits (s.10).
Done by hand, DPDP means chasing consent records across systems, re-drafting notices per product, tracking 90-day rights SLAs in spreadsheets, and hoping you can prove valid consent and a 72-hour breach report if the Board ever asks. That is exactly the repetitive, deadline-driven work software should run for you.
Do it once, reuse it everywhere. Evidence you collect for India DPDP is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps India DPDP to your environment in a 30-minute walkthrough — and how much of it we handle for you.