DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act, 2023 is India’s law governing digital personal data. It sets out responsibilities for organisations that decide how such data is used and rights for the individuals it concerns. The DPDP Rules, 2025 supply implementation details. They are final rules, distinct from the January 2025 consultation draft. Official Act, sections 1–2 · Final Rules, rule 1
For a founder, the useful question is where personal data enters the business, why it is needed, who receives it, and how its use ends. Website enquiries, employee records, customer accounts and uploaded identity documents are good places to begin that review.
What is the DPDP Act? Full form and key terms#
The Act received presidential assent on 11 August 2023. You may see the abbreviation DPDPA, meaning Digital Personal Data Protection Act. Searches for “DPDP Act 2025” generally refer to the 2023 Act together with its 2025 Rules; the official title of the statute remains Digital Personal Data Protection Act, 2023. Act, title and enactment
| Term | Meaning | Business example |
|---|---|---|
| Personal data | Information about an identifiable individual | A named customer’s email address or an employee’s bank details |
| Data Principal | The individual the data concerns | The customer submitting an enquiry |
| Data Fiduciary | A person or organisation deciding the purpose and means of processing, alone or with others | A retailer deciding what customer details to collect and why |
| Data Processor | A person processing personal data on behalf of a Data Fiduciary | A hosting provider operating the retailer’s customer database |
| Consent Manager | A Board-registered person providing a platform to give, manage, review and withdraw consent | A registered service through which an individual manages permissions |
| Significant Data Fiduciary | A fiduciary or class designated by the Central Government under section 10 | An organisation subject to additional governance duties after designation |
These roles come from section 2 of the Act. In Data Fiduciary, “fiduciary” is a statutory role with specific duties; it does not mean every business collecting data becomes a bank or financial trustee.
What is data privacy? In everyday business terms, it concerns appropriate collection and use of information about people: the reason for collecting it, the choices offered, and who can access it. Security concerns protecting that information from compromise. A secure system can still use data for an inappropriate purpose, so both questions belong in a readiness review.
Who does the DPDP Act apply to?#
When section 3 commences, the Act covers personal data processed digitally in India, including information first collected on paper and later digitised. It also covers processing outside India connected with offering goods or services to individuals in India. A scanned employee form is therefore relevant to scope even if it began on paper. Act, section 3
Section 3 excludes personal or domestic processing by an individual and specified publicly available personal data. The latter concerns data made public by the individual or by someone legally obliged to publish it. Do not assume a leaked database qualifies merely because it can be found online.
There are further, specific exemptions in section 17. A startup or MSME is not automatically exempt from the entire Act. Section 17(3) allows notified exemptions from specified provisions for particular fiduciaries or classes, including startups. Check an applicable notification rather than relying on company size alone. Act, sections 3 and 17
For a new private limited company or LLP, map customer, staff, supplier-contact and director data alongside the incorporation paperwork. The business’s legal form does not answer its data-protection scope question.
DPDP Rules 2025 and commencement timeline#
The Gazette instruments are dated 13 November 2025. The government’s public announcement on 14 November 2025 describes an 18-month phased implementation. Notification, institutional commencement and commencement of everyday business duties are separate milestones. Gazette commencement notification, G.S.R. 843(E) · Government announcement
| Phase | Act provisions | Rules | Planning significance |
|---|---|---|---|
| On Gazette publication | Section 1(2), section 2, sections 18–26, 35, 38–43, and section 44(1) and (3) | Rules 1, 2 and 17–21 | Definitions, institutional arrangements and specified enabling provisions |
| One year from publication | Section 6(9) and section 27(1)(d) | Rule 4 | Consent Manager registration and oversight |
| Eighteen months from publication | Sections 3–5; section 6(1)–(8) and (10); sections 7–17; section 27 except 27(1)(d); sections 28–34, 36–37; section 44(2) | Rules 3, 5–16, 22–23 | Most operational duties, rights, enforcement provisions and the specified IT Act amendments |
The phase allocations above follow G.S.R. 843(E) and rule 1 of the final Rules.
For project planning, counting from the printed Gazette publication date of 13 November 2025 produces 13 November 2026 and 13 May 2027. These are calendar calculations from the instruments, not separately stated dates in those instruments. Some summaries use the 14 November announcement date. Keep the operative “one year” and “eighteen months from publication” language in your compliance register and confirm the date applicable to your organisation before scheduling launch-critical work.
The December 2025 corrigendum, G.S.R. 892(E) corrects, among other wording, the Rules’ commencement reference to publication “in the Official Gazette”. Read the final Rules together with that correction. Official corrigendum
Under the DPDP Act, personal data can generally be processed based on user what?#
The short answer to that search query is consent. The complete answer is that section 4 permits processing for a lawful purpose based on the individual’s consent or certain legitimate uses specified in section 7. Act, sections 4, 6 and 7
Consent must meet the Act’s requirements: a real, informed and specific choice, expressed through an unambiguous affirmative action and limited to data necessary for the purpose. Withdrawal must be comparably easy to giving consent. A privacy-policy link alone does not establish that consent was obtained.
What a consent notice should explain#
Rule 3 requires an independently understandable notice describing the personal data, the purposes and the relevant goods, services or uses. It must provide a way to withdraw consent, exercise rights and complain to the Board. The Act provides a language choice of English or a language in the Constitution’s Eighth Schedule for the relevant notice and consent request. Act, sections 5–6 · Rules, rule 3
Practical design recommendation: show the explanation where the person supplies the data. For an enquiry form, explain why you need the person’s name and contact details. Treat optional promotional messages as a separate purpose to assess. Keep a record of the notice version, action, purpose and time, and test the withdrawal path on mobile.
Certain legitimate uses are specific statutory cases#
Section 7 includes defined situations such as voluntarily provided data used for the specified purpose, qualifying employment purposes and medical emergencies. It is not a general permission to reuse any data whenever a business finds that useful. Match the actual activity to the section’s conditions and record the reasoning.
For example, a customer giving a phone number to receive an order update does not automatically justify using it for unrelated campaigns. When a planned use changes, review the legal basis and notice before the new use begins. Act, section 7
What does DPDP compliance require from a business?#
The following summarises the substantive duties to prepare for under the phased commencement schedule. It is a planning guide; the precise requirements depend on your processing, applicable exemptions and other laws.
Accountability and vendor contracts#
A Data Fiduciary remains responsible for processing undertaken on its behalf. Section 8 requires a valid processor contract for the specified goods-or-services context, accuracy where data affects decisions or is disclosed to another fiduciary, and appropriate technical and organisational measures. Outsourcing hosting or payroll does not transfer all responsibility to the vendor. Act, section 8
Recommended vendor review: document the permitted purpose, staff access, subcontractors, hosting locations, security controls, incident escalation and deletion or return process. Ask how data can be located across backups and connected systems. A vendor questionnaire is useful evidence only when its answers lead to controls you can verify.
Reasonable security safeguards#
Rule 6 specifies minimum safeguards, including appropriate protection such as encryption or masking, access controls, logging and monitoring, continuity measures such as backups, relevant retention for investigation and appropriate processor-contract provisions. Rules, rule 6
Practical implementation: assign named owners for privileged accounts; remove former employees’ access; use multi-factor authentication where suitable; patch exposed systems; review bulk exports; test backup recovery; and close vulnerabilities after assessment. Choose controls for the actual data flow rather than buying a tool and assuming the task is finished.
Retention, erasure and the one-year rule#
Section 8(7) addresses erasure when consent is withdrawn or the purpose ends, subject to legally required retention. The final Rules add important detail: rule 8(3) requires personal data, associated traffic data and processing logs to be retained for at least one year for Seventh Schedule purposes, followed by erasure unless further retention is legally required or government-notified. Rule 6 also has a one-year security-related retention provision. Act, section 8(7) · Rules, rules 6 and 8
Do not promise immediate deletion of every record without reconciling those requirements. Equally, a retention duty is not permission to keep using the record for unrelated marketing. Separate active use from restricted retention in your system design.
Rule 8 and the Third Schedule also prescribe inactivity-based erasure for specified classes and purposes, with an advance notice requirement. The scheduled three-year period is not a universal retention limit for every Indian business. Create a record-by-record schedule covering the purpose, relevant rule, other statutory periods, vendor copies and deletion trigger.
Children and lawful guardians#
The Act defines a child as someone under 18. Section 9 provides for verifiable parental or lawful-guardian consent, prohibits processing detrimental to a child’s wellbeing, and restricts tracking, behavioural monitoring and targeted advertising directed at children. Rules 10–12 and the Fourth Schedule provide verification details and conditional exemptions. An education or healthcare label does not establish a blanket exemption. Act, sections 2(f) and 9 · Rules, rules 10–12 and Fourth Schedule
If children may use your product, review age handling, parental verification, analytics, advertising SDKs and access settings together. Also assess the lawful-guardian provisions for persons with disabilities where applicable; do not assume every disabled adult needs a guardian to give consent.
Rights, contact information and grievances#
Sections 11–14 establish rights to obtain information about processing, seek correction and erasure, raise grievances and nominate someone to exercise rights in the specified circumstances. Erasure remains subject to retention needed for the specified purpose or legal compliance. Section 13 requires using the fiduciary’s grievance process before approaching the Board. Act, sections 11–14
Rule 9 requires a published business contact. Rule 14 requires accessible rights-request information and a published grievance response period no longer than 90 days. That grievance limit should not be described as a universal 90-day deadline for every access or erasure request. Rules, rules 9 and 14
A useful readiness exercise is to simulate a request: authenticate the requester proportionately, locate the relevant records, notify the responsible teams, decide what can be corrected or erased, and record the response. Avoid gathering a full identity-document copy by default if a less intrusive verification method will work.
Personal data breaches: what does the 72-hour rule mean?#
Under rule 7, once that rule commences, breach communications have separate stages:
- Affected individuals: notify each affected Data Principal without delay, in clear language, explaining the breach, likely consequences, mitigation, protective steps and a contact.
- The Board’s initial notification: provide the initial description without delay.
- The Board’s detailed follow-up: supply the prescribed further information within 72 hours of becoming aware, unless the Board permits longer on a written request.
The 72-hour period is therefore not a general waiting period before first reporting a breach. Final Rules, rule 7
Existing cybersecurity reporting duties need a separate assessment. CERT-In’s directions and FAQs require covered entities to report specified qualifying cyber incidents within six hours of noticing them or being brought to notice. A DPDP workflow does not replace CERT-In reporting or a sector regulator’s requirements. CERT-In directions and updates · CERT-In FAQs, incident-reporting questions
Recommended drill: rehearse an accidental customer-file disclosure. Record when the team became aware, who can contain it, who evaluates each reporting obligation, how affected people can be reached, and who approves communications outside office hours. Keep initial reporting possible while investigation continues.
DPIA, RoPA and VAPT: how they support readiness#
These terms describe different tasks. They should not be treated as interchangeable certificates of DPDP compliance.
| Term | Full form | Question it helps answer |
|---|---|---|
| DPIA | Data Protection Impact Assessment | How could a processing activity affect people, and how will those risks be addressed? |
| RoPA | Record of Processing Activities | What data is processed, for which purpose, by whom and for how long? |
| VAPT | Vulnerability Assessment and Penetration Testing | Where can a system be compromised, and what must be remediated? |
Significant Data Fiduciaries and DPIAs#
Section 10 requires notified Significant Data Fiduciaries to appoint an India-based Data Protection Officer and an independent data auditor, and undertake impact assessments and audits. Rule 13 specifies a DPIA and audit once in each 12-month period from designation, alongside other duties. These enhanced obligations depend on designation; not every small company must appoint a statutory DPO or perform that annual process simply because it collects emails. Act, section 10 · Rules, rule 13
A voluntary impact review can still help a smaller business before introducing identity matching, profiling or a new AI feature. Write down the purpose, people affected, necessary data, possible harms, alternatives and safeguards. Keep that recommendation distinct from the statutory SDF requirement.
RoPA as a practical data inventory#
RoPA is an established GDPR accountability concept under Article 30. The DPDP framework does not impose the same universal Article 30-style document by that name. Nevertheless, a processing inventory is a useful way to organise readiness work. EDPB guidance on processing records
Start with one row per activity. Include the owner, data fields, purpose, legal basis to assess, people affected, vendors, locations, notice, retention period and rights-request route. Review the rows when a new form, integration or campaign is introduced.
VAPT as security evidence#
VAPT can help identify technical weaknesses and demonstrate remediation. Rule 6 requires reasonable safeguards; it does not make a single VAPT report a substitute for consent, notices, retention or grievance handling. Sector requirements and contracts may independently call for testing.
For procurement, ask what was tested, when it was tested, whether production changes invalidate the findings, and whether critical issues were fixed and retested. A report that lists weaknesses without a remediation owner leaves the practical risk unresolved. Rules, rule 6
DPDP Act versus the IT Act 2000 and SPDI Rules#
The Information Technology Act, 2000 covers a wider set of technology-law matters. The SPDI Rules, 2011 address reasonable security practices and sensitive personal data or information in their applicable body-corporate context, including specified categories such as passwords, financial information and health information. DPDP’s scope instead centres on digital personal data. Official SPDI Rules text hosted by WIPO Lex
Section 44(2) of the DPDP Act provides for omitting IT Act section 43A and making related amendments. Section 44(2) is in the 18-month commencement group. As of this article’s review date, do not describe section 43A as already omitted merely because the DPDP Act was enacted in 2023. Review existing SPDI, cybersecurity and sector obligations during transition. The DPDP Act does not repeal the entire IT Act. Act, section 44(2) · Commencement notification
For an existing business, keep a transition register: the controls required now, the controls being prepared for DPDP, and the evidence that both have been assessed. A future commencement date does not suspend duties under other laws.
DPDP versus GDPR, CCPA and HIPAA#
GDPR full form is General Data Protection Regulation. It is an EU regulation, even though people sometimes search for “GDPR Act”. Its six legal bases differ from DPDP’s consent-or-certain-legitimate-uses structure. Do not import a GDPR “legitimate interests” justification into India without checking the DPDP provision that actually applies. EDPB: legal bases
| Framework | Main focus | What to assess separately |
|---|---|---|
| DPDP Act and Rules | Digital personal data within the Act’s Indian and extraterritorial scope | Indian notices, processing grounds, rights, safeguards and commencement |
| GDPR | Personal-data protection within its European territorial scope | Applicable legal basis, European rights and international-transfer requirements |
| CCPA, as amended | California consumer privacy for businesses within its scope | Applicability and rights including opting out of sale or sharing |
| HIPAA | US health-information protections for covered entities and business associates | Whether the entity and relationship fall within HIPAA’s regulated scope |
The comparison uses EDPB guidance, the California Attorney General’s CCPA guidance and US HHS guidance on HIPAA covered entities and business associates. HIPAA does not apply to every business merely because it handles some health-related information.
A business may need to assess more than one framework. Reuse a well-maintained inventory and control evidence, but review each law’s scope, rights and reporting rules independently. A global privacy-policy template will need to reflect the actual business and each applicable regime.
Cross-border transfers: must all data stay in India?#
The DPDP Act does not impose a blanket localisation rule for all personal data. Section 16 permits government restrictions on transfer to specified countries or territories and preserves stronger protections or restrictions under other laws. Rule 15 addresses government requirements concerning availability to foreign states or related entities. Rule 13(4) concerns government-specified data and related traffic data for Significant Data Fiduciaries. Act, section 16 · Rules, rules 13 and 15
Before selecting a cloud vendor, map storage, backups, support access and subprocessors. Check the orders and sector rules applicable to those flows. “India region” on a sales page may not describe overseas support access or every connected integration.
DPDP Act penalties#
The Schedule sets maximum monetary penalties for specified breaches. They are ceilings, not automatic fines; section 33 provides for an inquiry, an opportunity to be heard and consideration of factors including gravity, duration and mitigation. Their application must also be read with commencement. Act, section 33 and Schedule
| Specified breach | Maximum in the Schedule |
|---|---|
| Failure to take reasonable security safeguards under section 8(5) | ₹250 crore |
| Failure to notify the Board or affected individuals under section 8(6) | ₹200 crore |
| Breach of children’s-data obligations under section 9 | ₹200 crore |
| Breach of Significant Data Fiduciary obligations under section 10 | ₹150 crore |
| Breach of Data Principal duties under section 15 | ₹10,000 |
| Other breaches of the Act or Rules | ₹50 crore |
The Schedule separately addresses breach of an accepted voluntary undertaking by reference to the applicable underlying breach. Read the official Schedule for its complete wording. The figures should inform risk planning without replacing the assessment of which obligations apply.
A practical DPDP compliance checklist for startups and MSMEs#
This is a recommended readiness workflow, not a prescribed government timetable or a compliance certificate. Assign an owner and evidence for each item, then prioritise work against the commencement schedule and your current obligations.
Build a readiness file
- Scope assessment: list processing activities, roles, applicable laws and any exemption relied on.
- Data inventory: map website forms, customer systems, HR, document uploads, spreadsheets, backups and vendors.
- Purpose review: remove unnecessary fields and assess the processing ground for each remaining purpose.
- Notice and consent records: keep approved text, versions, purpose-level choices and a working withdrawal route.
- Processor agreements: record permitted use, safeguards, incident escalation, subcontractors and erasure arrangements.
- Retention schedule: reconcile purpose limits, Rules 6 and 8, other legal periods and vendor copies.
- Security evidence: maintain access reviews, patch records, monitoring, recovery tests and resolved findings.
- Rights and grievances: publish the appropriate contact and test an end-to-end request with documented handling.
- Children and guardians: review verification and any claimed exemption against the precise conditions.
- Transfer assessment: map overseas access and check applicable restrictions rather than assuming all flows are allowed.
- Incident playbook: distinguish DPDP notices, CERT-In reporting and any sector reporting requirement.
- Governance review: assess whether SDF duties apply and schedule reassessment when the business changes.
A suggested first 90 days of preparation#
| Preparation window | Suggested focus | Useful evidence |
|---|---|---|
| Days 1–30 | Assign ownership, map data and identify the largest gaps | Inventory, scope note, prioritised action register |
| Days 31–60 | Fix high-priority collection flows, access and vendor arrangements | Reviewed notices, agreement changes, access review |
| Days 61–90 | Test withdrawal, rights requests, retention and incident response | Test records, drill findings, remediation owners |
These windows are a project-management example, not a statutory 90-day grace period. Start sooner where existing duties or your planned launch require it. The process should continue when you add a vendor, change a purpose or introduce a new product feature.
For founders organising their wider obligations, browse our business setup and compliance services. If you need help deciding the next step, contact SigmaTenders with a short description of your business and data flows; avoid sending customer databases or unnecessary identity documents in an initial enquiry.
DPDP Act 2023 PDF and DPDP Rules 2025 PDF: official downloads#
Use the authoritative documents below. The Rules PDF contains Hindi and English; the English Rules begin on printed page 24. Read it with the corrigendum, and distinguish the final November Rules from the January consultation draft.
- DPDP Act 2023 PDF — official Gazette copy, MeitY.
- DPDP Rules 2025 PDF — final G.S.R. 846(E), MeitY.
- DPDP Act commencement notification PDF — G.S.R. 843(E).
- December 2025 Rules corrigendum PDF — G.S.R. 892(E).
- Data Protection Board establishment notification — G.S.R. 844(E).
- India Code record of the DPDP Act.
MeitY is the Ministry of Electronics and Information Technology. It publishes the Rules and related instruments; the Act establishes the Data Protection Board. Prefer the underlying legal text when an explainer simplifies a deadline or a right.
Frequently asked questions#
What is DPDP and what is the DPDP Act full form?
DPDP means Digital Personal Data Protection. The DPDP Act’s full name is the Digital Personal Data Protection Act, 2023. DPDPA is another abbreviation for the same statute. See the definitions and scope sections above.
Is the DPDP Act fully in force in October 2026?
No. Commencement is phased. Institutional provisions have commenced, while the one-year Consent Manager group and the 18-month operational group follow the Gazette schedule. Use the timeline and official commencement notification above when planning your deadline.
Is there a separate DPDP Act 2025?
The framework discussed here is the DPDP Act, 2023 together with the final DPDP Rules, 2025. Use those official titles when searching for the PDFs so you do not confuse the Rules with a separate Act or the consultation draft.
What is the meaning of Data Fiduciary?
It is the person or organisation deciding why and how personal data is processed, alone or jointly with others. A service provider may instead act as a Data Processor for an activity carried out on the fiduciary’s behalf. Assess the role for each activity.
Can personal data be processed without consent under DPDP?
Section 4 also recognises the specific certain legitimate uses in section 7. The circumstances and conditions must fit the activity. This is not a general exemption from the rest of the applicable framework. See the consent and legitimate-uses section above.
Does every company need a Data Protection Officer or a DPIA?
The enhanced statutory DPO, independent-auditor and periodic DPIA duties concern notified Significant Data Fiduciaries. Other fiduciaries still need the appropriate published business contact and applicable controls. A voluntary impact review may be useful even where the enhanced duty does not apply.
Does VAPT or buying a compliance platform make a business DPDP compliant?
A test or platform can support part of the work. Review what it actually covers: technical remediation, data inventory, consent evidence, vendor controls, retention, requests or incident response. The business must still determine its duties and verify that the relevant processes work.
What should I remember about the DPDP Act for UPSC preparation?
Focus on the Act’s official year and full name, digital-data scope, consent and certain legitimate uses, Data Principal rights, fiduciary duties, children’s protections, the Data Protection Board and phased commencement. The business examples in this guide help distinguish those concepts; the official Act and Rules remain the source for exact provisions.
