Cyber Law • Data Protection & Corporate Compliance
DPDP Act Compliance in India: 2025 Rules, 2026–27 Timeline, Consent, Data Breaches, Children’s Data and Penalties
What is already in force, what begins on 13 November 2026 and 13 May 2027, and what businesses should implement before the substantive compliance deadline.
India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 create a national framework for processing digital personal data. The framework applies across sectors and can affect companies, LLPs, startups, employers, professional firms, e-commerce businesses, digital platforms, hospitals, schools and overseas businesses offering goods or services to individuals in India.
The most important compliance point in August 2026 is the phased commencement. The entire regime did not become enforceable on one date. Institutional provisions and the Data Protection Board framework commenced in November 2025. The Consent Manager phase begins in November 2026. Most substantive obligations of Data Fiduciaries commence in May 2027.
Current legal position as of 20 August 2026: businesses are in the implementation runway for most operational duties. They should build compliance now, but legal advice, contracts and public statements must distinguish presently commenced provisions from obligations scheduled to begin on 13 November 2026 or 13 May 2027.
1. DPDP commencement timeline
Phase 1 — effective from 13 November 2025
The notified provisions include Section 2; Sections 18–26 establishing and governing the Data Protection Board; Sections 35 and 38–43; and specified parts of Section 44. Rules 1, 2 and 17–21 also commenced on publication. The Data Protection Board of India was established with its head office in the National Capital Region.
Phase 2 — effective from 13 November 2026
Section 6(9), Section 27(1)(d) and Rule 4 are scheduled to commence one year after publication. This phase concerns Consent Managers, their registration, accountability and the mechanism through which a Data Principal may give, manage, review or withdraw consent.
Phase 3 — effective from 13 May 2027
Most substantive provisions commence eighteen months after publication: Sections 3–5; most of Section 6; Sections 7–17; most of Section 27; Sections 28–34, 36 and 37; Section 44(2); and Rules 3, 5–16, 22 and 23.
This final phase includes application of the Act, lawful grounds, notice, consent, legitimate uses, general Data Fiduciary duties, children’s data, Significant Data Fiduciaries, Data Principal rights, cross-border processing, exemptions, complaints, penalties and most operational rules.
| Date | Principal effect |
|---|---|
| 13 Nov 2025 | Definitions, Board establishment and institutional/procedural provisions |
| 13 Nov 2026 | Consent Manager framework |
| 13 May 2027 | Core processing, notice, consent, security, breach, rights, children’s data and penalty framework |
2. Which data and businesses fall within the Act?
Section 3 applies to processing of digital personal data within India where the data is collected in digital form or collected non-digitally and subsequently digitised. It also applies outside India where processing is connected with offering goods or services to Data Principals within India.
The Act excludes:
- personal data processed by an individual for a personal or domestic purpose; and
- personal data made publicly available by the Data Principal herself or by another person legally obliged to make it public.
“Personal data” means data about an individual who is identifiable by or in relation to that data. “Processing” is broad and includes collection, recording, organisation, storage, adaptation, retrieval, use, sharing, disclosure, dissemination, erasure and destruction through automated operations.
A small business is not automatically outside the Act. Scale affects regulatory risk and possible designation as a Significant Data Fiduciary, but ordinary Data Fiduciary duties are not confined to large technology companies.
3. Data Fiduciary, Data Processor and Data Principal
The Data Principal is the individual to whom the personal data relates. For a child, the term includes the parent or lawful guardian. For a person with disability, it includes the lawful guardian acting on her behalf where applicable.
The Data Fiduciary determines the purpose and means of processing. The Data Processor processes personal data on behalf of the Data Fiduciary.
Outsourcing does not transfer statutory accountability. A company using a cloud provider, payroll processor, CRM platform, recruitment agency, call centre or marketing vendor remains responsible for compliance with its duties as Data Fiduciary. Processor contracts must therefore allocate security, confidentiality, breach escalation, assistance with rights requests, retention, deletion, audit and subcontracting obligations.
4. Lawful grounds: consent and certain legitimate uses
Section 4 permits processing for a lawful purpose:
- with consent of the Data Principal; or
- for specified “certain legitimate uses” under Section 7.
Consent is not the only basis, but businesses should not invent broad “legitimate interest” grounds modelled on foreign laws. The Indian Act uses the specific statutory grounds in Section 7, including circumstances such as voluntary provision for a specified purpose, State functions, legal obligations to disclose to the State, compliance with judgments or orders, medical emergencies, disasters and employment-related purposes within the statutory conditions.
Each processing activity should be assigned a documented statutory basis. A privacy notice cannot cure processing that lacks a lawful purpose or lawful ground.
5. Consent requirements
Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, with clear affirmative action. It must signify agreement to process personal data for the specified purpose and be limited to data necessary for that purpose.
A compliant consent system should record:
- the notice version displayed;
- purpose and data categories;
- date, time and affirmative action;
- language selected;
- identity or account used;
- withdrawal mechanism;
- withdrawal date and downstream action; and
- processor or recipient actions triggered by withdrawal.
Pre-ticked boxes, bundled consent for unrelated purposes, consent hidden inside general terms, or withdrawal made substantially harder than giving consent create avoidable risk.
6. Privacy notice under Section 5 and Rule 3
The notice must inform the Data Principal about the personal data and specified purpose, the manner of exercising rights, and the manner of making a complaint to the Board. The 2025 Rules require a notice that is independently understandable, clear and in plain language, with an itemised description of the personal data and specified purpose.
A layered notice is often the stronger implementation:
- short just-in-time information beside the collection field;
- a complete privacy notice linked from the interface;
- separate notices for employees, candidates, customers and vendors;
- version control and evidence of the notice delivered; and
- language accessibility appropriate to the service.
A website policy copied from another business is unlikely to reflect actual data flows, processors, purposes, retention periods or rights channels.
7. General obligations of a Data Fiduciary
Section 8 places responsibility on the Data Fiduciary for processing undertaken by it or on its behalf. The operational programme should cover:
- completeness, accuracy and consistency where data is used for a decision or disclosed to another Data Fiduciary;
- technical and organisational measures for compliance;
- reasonable security safeguards;
- personal-data-breach notification;
- erasure when consent is withdrawn or the specified purpose is no longer served, unless retention is legally necessary;
- processor engagement under valid contract;
- publication of business contact information; and
- an effective grievance mechanism.
Compliance should be demonstrable. Policies without system controls, records, ownership and evidence are weak before a regulator or contractual counterparty.
8. Reasonable security safeguards under Rule 6
The final Rules convert the general security duty into an operational minimum. Safeguards include, as appropriate:
- encryption, obfuscation, masking or virtual tokens;
- access controls restricting computer resources used by the Data Fiduciary or processor;
- visibility through logs, monitoring and review to detect unauthorised access;
- measures to preserve confidentiality, integrity and availability;
- backups and continuity measures;
- retention of relevant logs and related data for the prescribed minimum period;
- contractual security obligations for Data Processors; and
- technical and organisational measures capable of supporting breach detection and response.
A reasonable-safeguards assessment is contextual. It should consider data volume, identifiability, access privileges, threat profile, remote access, cloud architecture, vendor dependencies and consequences of compromise.
9. Personal data breach reporting
Section 8(6) requires intimation of a personal data breach to the Board and each affected Data Principal in the prescribed form and manner. Rule 7 creates a two-track notification process once the substantive phase commences.
Notice to affected Data Principals
Each affected person must be informed without delay, in concise, clear and plain language, through the user account or a registered communication channel. The notice should describe the breach, likely consequences, mitigation measures, protective steps the person may take and business contact information for queries.
Notice to the Data Protection Board
The Board must receive an initial intimation without delay describing the nature, extent, timing, location and likely impact. A detailed update is required within seventy-two hours of awareness, unless the Board allows additional time on a written request. The update addresses circumstances, cause, mitigation, findings about the person responsible, recurrence prevention and notifications sent to affected Data Principals.
The statutory trigger is a personal data breach, not merely a reportable cyber incident under another framework. Businesses should align the DPDP playbook with CERT-In, sectoral regulator, contractual, insurance and law-enforcement reporting so that timelines and statements do not conflict.
For the criminal and evidence response to cyber incidents, see our guide to cybercrime law, reporting and electronic evidence in India.
10. Retention and erasure
The Act requires erasure when consent is withdrawn or when it is reasonable to assume that the specified purpose is no longer being served, unless retention is necessary for compliance with law.
Rule 8 prescribes special inactivity-based periods for specified large e-commerce entities, online gaming intermediaries and social media intermediaries. It also requires advance intimation at least forty-eight hours before scheduled erasure under that rule. The final Rules include a minimum one-year retention requirement for specified processing data, associated traffic data and logs for the purposes stated in the Rules, subject to longer retention required by another law.
A defensible retention schedule should map each category to:
- business purpose;
- statutory basis;
- contractual need;
- limitation and litigation hold;
- sectoral retention rule;
- minimum log requirement;
- archival access control; and
- verified deletion from active systems, processors and backups where applicable.
“Keep everything forever” increases both regulatory and breach exposure. Immediate deletion without checking tax, employment, financial, healthcare, litigation or security-retention law is equally unsafe.
11. Children’s personal data
A child is an individual below eighteen years. Section 9 requires verifiable parental consent before processing a child’s personal data, subject to prescribed exemptions. It prohibits processing likely to cause a detrimental effect on the child’s well-being and prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, again subject to the statutory and notified exception framework.
Rule 10 requires technical and organisational measures to verify that the consenting parent is an identifiable adult and, where relevant, the parent of the child. Rule 11 separately addresses lawful guardians for persons with disability who cannot take legally binding decisions even with adequate support.
Businesses should examine:
- whether the service is likely to be accessed by minors;
- age-gating and age-assurance design;
- parent identity and relationship verification;
- child-profiling and advertising technologies;
- SDKs, cookies and third-party analytics;
- school, gaming, healthcare and social features;
- exception conditions under the Rules; and
- how consent is withdrawn when the child or parent relationship changes.
12. Rights of Data Principals
Once the substantive provisions commence, the Act provides rights to:
- access information about personal data and its processing;
- seek correction, completion, updating and erasure;
- obtain grievance redressal; and
- nominate another individual to exercise rights in the event of death or incapacity.
A rights-management workflow should authenticate the requester without collecting excessive new data, locate data across systems and processors, apply legal retention exceptions, record the response and meet the prescribed grievance period.
Rule 13 requires the Data Fiduciary to publish the means by which a Data Principal may exercise rights and identify the particulars needed to verify identity. Rule 14 requires a grievance system capable of responding within a period not exceeding ninety days; a shorter internal target is prudent.
13. Significant Data Fiduciaries
The Central Government may notify a Data Fiduciary or class as a Significant Data Fiduciary based on factors including volume and sensitivity of personal data, risk to rights, sovereignty and integrity, electoral democracy, security of the State and public order.
Additional duties include:
- appointing a Data Protection Officer based in India and responsible to the board of directors or similar governing body;
- appointing an independent data auditor;
- undertaking periodic Data Protection Impact Assessments;
- periodic audits; and
- other prescribed measures under the Rules.
Even before formal designation, high-risk organisations benefit from assigning senior ownership, performing impact assessments and establishing independent audit evidence.
14. Cross-border processing
Section 16 permits the Central Government to restrict transfer of personal data to notified countries or territories. Rule 15 permits the Government to impose requirements concerning making personal data available to a foreign State, or an entity or person under its control.
A cross-border review should identify:
- cloud hosting and backup locations;
- foreign SaaS vendors and subprocessors;
- remote administrator access;
- group-company sharing;
- customer support and analytics locations;
- sector-specific localisation or secrecy rules; and
- Government notifications issued from time to time.
The DPDP Act does not displace stricter sectoral localisation, banking, insurance, telecom, health, defence or contractual restrictions.
15. Data Protection Board and complaints
The Data Protection Board of India has been established as a digital office. It may act on personal-data-breach intimations, complaints by Data Principals, references by Government and matters within the commenced statutory framework.
Once the complaint provisions applicable to ordinary Data Fiduciaries commence, the Data Principal is generally expected to exhaust the Data Fiduciary’s grievance mechanism before approaching the Board. The Board may inquire into a significant breach, issue interim measures, accept voluntary undertakings and impose monetary penalties after applying the statutory factors.
Appeals from Board orders lie to the Appellate Tribunal under Section 29 within sixty days from receipt of the order, subject to condonation for sufficient cause. The notified appellate mechanism is digital under Rule 22 when it commences.
16. Penalties
The Schedule authorises substantial monetary penalties. The maximum for breach of the obligation to take reasonable security safeguards is two hundred and fifty crore rupees. Other scheduled contraventions—including breach notification, children’s-data duties and Significant Data Fiduciary obligations—carry their own maxima.
The Board must consider statutory factors such as nature, gravity and duration; type and nature of personal data; repetitive character; gain or loss avoided; mitigation; proportionality; and likely impact of the penalty on the person.
The Act creates an administrative monetary-penalty framework. A data incident may nevertheless trigger separate liability under the Information Technology Act, Bharatiya Nyaya Sanhita, consumer law, contract, employment law, sectoral regulation or other statutes depending on the facts.
17. Relationship with the Information Technology Act
Section 44(2) of the DPDP Act, scheduled to commence with the substantive phase, omits Section 43A of the Information Technology Act, 2000. Until that commencement, the existing IT Act and applicable data-security framework remain relevant. Other IT Act provisions concerning unauthorised access, identity theft, cheating by personation, privacy violations and intermediary obligations continue according to their own terms.
For misuse of personal data to create fake profiles or impersonate an individual, see our guide to online identity theft and fake-profile remedies.
18. Contracts that require revision
- customer and user terms;
- website and application privacy notices;
- employee and candidate notices;
- data-processing agreements;
- cloud, SaaS and managed-service contracts;
- marketing, analytics and advertising arrangements;
- data-sharing and group-company agreements;
- vendor-security schedules;
- incident-response and notification clauses;
- confidentiality and access-control undertakings;
- retention, return and certified-deletion provisions;
- audit, assistance and subprocessor controls;
- cyber-insurance notification clauses; and
- merger, acquisition and investment due-diligence warranties.
A processor contract should specify the subject matter, permitted purpose, security baseline, breach escalation period shorter than the statutory deadline, cooperation, evidence preservation, rights support, subprocessors, data location, audit rights and exit deletion.
19. Board and management governance
DPDP compliance should be treated as enterprise risk, not only as a website-policy exercise. Management should receive documented reporting on:
- data inventory and high-risk systems;
- implementation milestones to November 2026 and May 2027;
- privacy and security budget;
- major processors and cross-border flows;
- open remediation items;
- children’s-data exposure;
- breach simulations and response times;
- rights-request readiness;
- training completion;
- cyber insurance and contractual coverage; and
- evidence available to demonstrate compliance.
For companies, the board note should identify responsible executives, accepted residual risks and time-bound remediation. For LLPs and professional firms, equivalent partner-level ownership should be recorded.
20. Practical implementation roadmap
Stage 1 — discovery
- map data collection, use, sharing, storage and deletion;
- classify Data Fiduciary and processor roles;
- identify children’s data and high-risk processing;
- inventory vendors, clouds and cross-border access;
- identify existing legal bases and notices; and
- map sectoral and contractual requirements.
Stage 2 — legal design
- assign purpose and statutory basis to each processing activity;
- redraft notices and consent language;
- create rights and grievance procedures;
- prepare retention and legal-hold schedules;
- revise processor and data-sharing contracts;
- design children’s-data controls; and
- adopt governance, escalation and audit policies.
Stage 3 — technical implementation
- implement access control, encryption and logging;
- build consent and withdrawal records;
- create rights-request workflows;
- automate retention and deletion where safe;
- configure breach detection and notification;
- test processor escalation; and
- preserve evidence of control operation.
Stage 4 — testing and assurance
- conduct a breach tabletop exercise;
- test access, correction and erasure requests;
- sample consent and notice evidence;
- audit high-risk vendors;
- verify child and guardian consent controls;
- review foreign transfers; and
- place closure evidence before management.
Common Client Questions
Is the entire DPDP Act already in force?
No. Commencement is phased. Institutional provisions commenced in November 2025, the Consent Manager phase begins in November 2026, and most substantive business obligations commence in May 2027.
Should businesses wait until May 2027?
No. Data mapping, contract revision, system development, vendor remediation and breach testing require substantial lead time. Existing IT, consumer, contractual and sectoral duties also continue during transition.
Does the Act apply only to large companies?
No. Ordinary Data Fiduciary duties can apply regardless of size. Scale and risk are especially relevant to Significant Data Fiduciary designation and enforcement exposure.
Is consent required for every processing activity?
No. Processing may also rely on one of the specific legitimate uses in Section 7. Every activity still requires a lawful purpose and a correctly documented statutory ground.
Must every breach be reported?
Rule 7 does not create a risk-threshold exemption in its text for personal data breaches. Once operative, affected Data Principals and the Board must be notified in the prescribed manner and timelines.
Can personal data be stored outside India?
The Act permits cross-border processing subject to Government restrictions and other applicable laws. Sectoral localisation and contractual restrictions must also be checked.
What is the maximum penalty?
The Schedule permits a penalty up to ₹250 crore for breach of the reasonable-security-safeguards obligation, with separate maxima for other contraventions.
Authoritative legal sources
- Digital Personal Data Protection Act, 2023 — India Code
- DPDP Act commencement notification and phased dates — India Code
- Digital Personal Data Protection Rules, 2025 — MeitY
- Section 9 DPDP Act — children’s personal data
- MeitY Gazette notifications
Professional Information
Fastrack Legal Solutions LLP works on technology-law, data-protection, cybersecurity, corporate-governance and compliance matters. This statement is provided solely as general professional information.
No part of this article constitutes advertising, solicitation, an invitation to form an advocate–client relationship, or legal advice. Any communication made by a reader is entirely voluntary and on the reader’s own initiative.
Office contact information: 7697671219 · advgovind@fastracklegalsolutions.com · Contact information
Legally reviewed: 20 August 2026. Disclaimer: This article is general legal and compliance information. The DPDP commencement schedule, Government notifications, sectoral requirements and technical architecture must be verified for the relevant date, organisation and processing activity before implementation.