KryptoMindz Technologies

Flagship Compliance Guide · 2026 Edition

DPDP Act India Compliance Guide

A decision-oriented field guide to India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 — scope, consent, data principal rights, Significant Data Fiduciary obligations, breach response, penalties and an 18-month readiness roadmap.

Mustafa HusainExecutive, risk, legal and technical audience35 minute readReviewed August 7, 2026

1. Executive Context

India's data protection regime is now operational. The Digital Personal Data Protection Act, 2023 (the DPDP Act) received assent in August 2023, and the DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025. The Rules trigger an 18-month, three-phase implementation that concludes in May 2027 with full enforcement of Data Fiduciary obligations.

This matters well beyond Indian borders. The Act applies extraterritorially to processing of digital personal data outside India when it is connected with offering goods or services to individuals within India. Global companies — from the United States, the Gulf, Europe and Asia — that serve Indian customers must plan for the regime alongside GDPR, sector laws and customer contracts.

Executive rule: DPDP compliance is a product and operating-model discipline, not a document exercise. Consent flows, notices, retention schedules, breach response and evidence architecture must be designed into systems before May 2027 — and the window to do that deliberately is closing.

2. What the DPDP Act Is

The DPDP Act is India's national data protection law. It provides for the processing of digital personal data in a manner that recognizes both the right of individuals to protect their personal data and the need to process such data for lawful purposes. It is Act No. 22 of 2023, drafted in a deliberately simple, plain-language style ("SARAL" — Simple, Accessible, Rational and Actionable), with illustrations rather than dense legal prose.

A framework law

The Act is intentionally principles-based. It relies on delegated legislation — the DPDP Rules, 2025 — to define operational details such as notice formats, retention periods, breach reporting procedures and the functioning of the Data Protection Board of India (DPB). Teams that read only the Act will miss the enforceable detail, which now lives in the Rules.

What it replaced

The Act followed a long lineage: the 2017 Puttaswamy right-to-privacy judgment, the 2018 Srikrishna committee report, the Personal Data Protection Bill 2019 (withdrawn in 2022) and the draft DPDP Bill 2022. The final 2023 Act is leaner than earlier drafts and closer to a consent-and-accountability model than a broad rights-based code.

Who it covers

The Act applies to Data Fiduciaries (entities that determine the purpose and means of processing) and grants rights to Data Principals (the individuals whose data is processed). It establishes the Data Protection Board of India as an independent adjudicatory body and relies on financial penalties rather than criminal sanctions.

For a full treatment of the operational rules, see the DPDP Act timeline and compliance deadlines article.

3. Scope and Applicability

Territorial scope (Section 3)

The Act applies to the processing of digital personal data within the territory of India, whether the data was collected digitally, or collected offline and subsequently digitized.

Extraterritorial reach

The Act also applies to processing of digital personal data outside India if that processing is in connection with offering goods or services to individuals within India. This is the single most important clause for international companies: serving Indian residents — through apps, e-commerce, SaaS, fintech, gaming, insurance or B2B platforms — can place the processing in scope even when the company has no physical presence in India.

What is excluded

The Act does not apply to non-personal data, offline data that remains in physical formats and data processed by an individual for purely personal or domestic purposes. State instrumentalities can be exempted by the Central Government in the interest of sovereignty, national security, friendly relations with foreign states or public order (Section 17). Exemptions also cover research, archiving, statistical purposes, judicial duties and ascertainment of financial liabilities for loan defaults.

Scope question to answer first: do you process digital personal data of individuals in India, or process data in connection with offering goods or services to them? If yes, plan for the DPDP regime even if your operations are elsewhere.

4. Key Definitions

TermMeaning
Personal dataAny data about an individual who is identifiable by or in relation to such data.
Data PrincipalThe individual to whom the personal data relates.
Data FiduciaryAny person who, alone or with others, determines the purpose and means of processing personal data.
Significant Data Fiduciary (SDF)A Data Fiduciary or class of fiduciaries designated by the Central Government based on volume and sensitivity of data, risk to electoral democracy, public order or sovereignty.
Consent ManagerA registered digital intermediary that provides a platform to enable a Data Principal to give, manage, review and withdraw consent across Data Fiduciaries.
Data Protection Board of India (DPB)The independent body that directs investigations into breaches, inquires into complaints and imposes financial penalties.
Data Protection Officer (DPO)An individual, based in India, that an SDF must appoint and register to represent the SDF under the Act.

These definitions drive everything else. For example, a "Consent Manager" is a separate, registered category — it does not describe your own consent screen. Your product collects consent; a Consent Manager is an independent platform through which users can manage consent across multiple fiduciaries.

5. Section-by-Section Walkthrough

The Act is short enough to walk through section by section. This is the map most executives need before they dive into detailed controls.

SectionTopicCore obligation
S.3ApplicationDigital personal data in India; extraterritorial reach for goods/services to Indian residents.
S.4Lawful processingProcessing only for a lawful purpose, with consent or under specified grounds.
S.5NoticeItemized notice before or at the time of collecting personal data or seeking consent.
S.6ConsentFree, specific, informed, unconditional and unambiguous consent with easy withdrawal.
S.7Consent request rulesConsent requests clear and accessible; no denial of goods/services if data is not necessary for the purpose.
S.8General obligationsReasonable security safeguards, purpose limitation, retention limits and grievance mechanism.
S.9ChildrenVerifiable parental consent; no tracking, behavioral monitoring or targeted advertising directed at children.
S.10SDF designationAdditional obligations for Significant Data Fiduciaries.
S.11-14Data Principal rightsAccess, correction, erasure, grievance redressal and nomination.
S.15Data Principal dutiesNo false or frivolous complaints, no impersonation, no suppression of material information.
S.16Cross-border transferGlobal transfers permitted unless the Central Government restricts a territory.
S.17ExemptionsState instrumentalities, research, archiving, statistics, judicial functions, loan-default ascertainment.
S.18DPBEstablishment of the Data Protection Board of India.
SchedulePenaltiesFinancial penalties up to ₹250 crore and ₹200 crore for specified violations.

Note that the Act's numbering changed in the version that was passed; always verify section numbers against the official gazette text, which is cited in Sources and Review.

7. Data Principal Rights and Duties

Rights of the Data Principal (Sections 11-14)

  • Right to access: obtain a summary of personal data being processed and the identities of third parties with whom it has been shared.
  • Right to correction and erasure: correct inaccurate or misleading data and request erasure once the purpose is fulfilled.
  • Right to grievance redressal: register complaints with the Data Fiduciary; where the fiduciary fails to resolve, appeal to the Data Protection Board.
  • Right to withdraw consent: withdraw consent with the same ease as giving it; processing based on consent must stop after withdrawal.
  • Right to nominate: nominate an individual who can exercise rights on the Data Principal's behalf in the event of death or incapacity.

Under the 2025 Rules, fiduciaries must build clear channels for exercising these rights and must redress grievances within a defined period (generally 90 days).

Duties of the Data Principal (Section 15)

Unlike the GDPR, the DPDP Act imposes statutory duties on individuals. A Data Principal must not register false or frivolous grievances, impersonate another person or suppress material information while providing personal data. Violations can incur a financial penalty of up to ₹10,000.

8. Children's Data and Verifiable Parental Consent

Section 9 and the 2025 Rules place strict conditions on processing the personal data of children (individuals under 18).

  • Verifiable parental consent: Data Fiduciaries must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data.
  • Age verification: the Rules require mechanisms to verify the identity and age of the parent or guardian.
  • Prohibited uses: fiduciaries may not process children's data for tracking, behavioral monitoring or targeted advertising directed at children.
  • Exemptions: certain categories — such as healthcare professionals, educational institutions and child-transport providers — are exempt from parts of the parental-consent requirement because of the nature of their services.

Failure to comply with children's-data obligations can attract penalties up to ₹200 crore, the same tier as breach-notification failure. Product teams building edtech, gaming, social or health services that touch minors must treat this as a first-class design requirement, not a policy footnote. See verifiable parental consent explained.

9. Significant Data Fiduciaries

The Central Government may designate a Data Fiduciary or a class of fiduciaries as a Significant Data Fiduciary (SDF) based on factors such as the volume and sensitivity of personal data processed, the risk of harm to Data Principals, the risk to electoral democracy, and potential impact on public order and sovereignty.

SDF obligations

Once designated, an SDF faces heightened duties under Section 10 and the Rules:

  • Data Protection Officer: appoint a DPO based in India and register the DPO with the Board, representing the SDF under the Act.
  • Data Protection Impact Assessment (DPIA): conduct a DPIA before processing that poses a high risk to Data Principals, and review it periodically (annual DPIA per the Rules).
  • Independent data audit: undergo an annual independent data audit by a registered auditor and publish the audit report.
  • Algorithmic transparency: undertake algorithmic transparency and fairness assessments where decisions materially affect Data Principals.
  • Enhanced due diligence: apply stricter technical due diligence for data processing systems and any new technologies used.

Most organizations will not be designated SDFs, but the SDF regime signals where the regulator expects the strongest evidence. Non-SDF fiduciaries should still adopt proportionate versions of these controls — see SDF obligations, DPO and DPIA.

10. Cross-Border Data Transfer

Section 16 takes a "blacklist" approach, which is a deliberate contrast to the GDPR's "whitelist" of adequacy-approved countries.

ModelHow it works
DPDP (blacklist)Transfers of personal data outside India are permitted to any country unless the Central Government notifies a restriction for a specific territory.
GDPR (whitelist)Transfers outside the EEA are permitted only to countries with an adequacy decision or with appropriate safeguards such as SCCs.

For international companies, this means Indian personal data can generally flow to your existing infrastructure in the US, Europe, the Gulf or Asia without country-level blocking — until and unless a restriction is notified. Practical planning still matters: contracts with Indian counterparties, customer expectations and sector rules may impose their own transfer conditions, and future notifications could change the picture. Keep an eye on MeitY notifications and review transfer architecture whenever new restrictions are published.

See cross-border data transfer under the DPDP Act.

11. Breach Response and the Data Protection Board

Breach notification (Section 8(6) and the Rules)

When a Data Fiduciary becomes aware of a personal data breach, it must notify the Data Protection Board and each affected Data Principal "without delay." The initial notification must be followed by a detailed report to the Board within 72 hours, covering the nature of the breach, the number of affected users and the mitigation steps taken.

Why response design matters

A 72-hour detailed report cannot be assembled from scratch. Teams need pre-built playbooks, a breach register, contacts at the Board, templates for affected-user communication and evidence trails that show when a breach was detected, assessed and reported. Breach-response readiness is one of the highest-leverage investments an organization can make before May 2027.

The Data Protection Board of India

The DPB is an adjudicatory body, not a proactive regulator. It directs investigations into breaches, inquires into complaints and imposes penalties. Under the 2025 Rules, its proceedings are "digital-first": electronic filings, virtual hearings and digital evidence submissions. Practical consequence: expect written, evidence-driven interactions with the Board rather than in-person hearings.

12. Penalties

The DPDP Act relies on financial deterrence. There are no criminal penalties — no jail terms — which is a major difference from older drafts and from some other jurisdictions.

ViolationMaximum penalty
Failure to take reasonable security safeguards leading to a personal data breach₹250 crore
Failure to notify the Board and affected users of a breach₹200 crore
Violation of children's data obligations (S.9)₹200 crore
Other specified violations₹50 crore per the Schedule (verify current Schedule)
Data Principal duty violations (S.15)Up to ₹10,000

Penalties are per-violation, and the Board may direct remediation or compounding in addition to monetary penalties. The absolute numbers matter less for planning than the pattern: the regime prices negligence in security and transparency far above administrative friction. See DPDP Act penalties explained.

13. DPDP vs GDPR: What Changes for Global Teams

Global companies often assume a GDPR-style compliance program is enough for India. Much carries over, but the differences are consequential.

DimensionGDPRDPDP Act
Data categoriesSpecial categories (sensitive data) get heightened rulesNo special-category concept; consent-based model applies broadly
Legal basesMultiple (consent, contract, legitimate interest, legal obligation...)Consent is central; other lawful-purpose grounds exist but the regime is consent-led
Cross-borderWhitelist + safeguardsBlacklist — transfers permitted unless a territory is restricted
Individual dutiesNoneData Principal duties with penalties up to ₹10,000
Criminal penaltiesAdministrative finesFinancial penalties only; no jail terms
DPORequired in defined casesRequired for SDFs, India-based
Consent ManagersNo equivalent platform conceptRegistered Consent Managers from Phase 2 (Nov 2026)
NoticesPrivacy notices in accessible languageItemized notices in English + 22 scheduled Indian languages
Breach reporting72 hours to supervisory authorityNotify Board and affected individuals "without delay" + detailed report within 72 hours

The practical takeaway: reuse the muscle you built for GDPR — data mapping, ROPA-style records, incident response, vendor review — and then adapt the Indian-specific parts: consent-led flows, 22-language notices, Consent Manager integration, India DPO planning for SDFs and blacklist-aware transfer architecture. See DPDP vs GDPR.

14. Timeline and the 18-Month Readiness Roadmap

The three phases

PhaseDateWhat applies
Phase 1November 2025Data Protection Board of India establishment, composition and procedural functioning.
Phase 2November 2026Consent Manager framework, cross-border transfer mechanisms and SDF obligations.
Phase 3May 2027Full enforcement of all substantive Data Fiduciary obligations: notices, security safeguards, rights management, retention and breach penalties.

A practical 18-month roadmap

  1. Months 0-6 — Assessment: data discovery and mapping, ROPA-style records, processing activity documentation, gap analysis against the Rules, scope decisions (Indian residents? children? SDF?).
  2. Months 6-12 — Core controls: update privacy notices (English + 22 languages where required), rebuild consent flows for withdrawal ease, strengthen security safeguards (encryption, access controls, log retention), build breach response, define retention schedules and erasure workflows.
  3. Months 12-18 — Advanced and sustained: DPIAs and independent audits for SDFs, vendor contract review, Consent Manager integration readiness, privacy-enhancing technologies, monitoring and management reporting.

If your program starts today, the Phase 2 date (November 2026) for Consent Manager readiness is closer than it looks, and Phase 3 (May 2027) is the hard deadline for the substantive program. See the full DPDP timeline article.

15. Sector Notes

Fintech and banking

Fintech firms already operate under RBI digital-lending and KYC rules; the DPDP Act adds a consent-and-notice overlay and 72-hour breach reporting. Credit information and CIBIL-style reporting connect to the loan-default ascertainment exemption. See DPDP for fintech and banking.

Healthcare

Healthcare providers that serve minors are among the exempt categories for parts of the parental-consent requirement, but all providers still need consent architecture, security safeguards and breach response. Health data has no special-category tier in the Act, so the discipline comes from the fiduciary's own risk assessment and sector regulators.

Government and public sector

Section 17 exemptions can remove state instrumentalities from the Act for sovereignty, security and public-order reasons — but exemptions are not automatic, and government digital platforms serving citizens should still plan for rights, notices and security best practice. KryptoMindz has delivered trust and identity work with Indian government organizations, including Smart City Ranchi, the Income Tax Department, DRDO and COAL India.

AI and data-driven products

AI systems that process personal data of Indian residents sit inside the DPDP regime like any other processing. Consent-led data minimization, purpose limitation and DPIAs for high-risk processing map naturally onto AI governance programs. This guide's approach to compliance by design is the bridge between the two disciplines.

16. Compliance by Design and Evidence Architecture

Compliance by design means embedding DPDP obligations and control checks into delivery workflows rather than layering them on at audit time. Evidence should be captured when work happens, linked to the governed version of a system or product and protected from unauthorized change.

One traceability chain

Map requirement to policy, control, owner, implementation, test, result, exception, approval and monitoring. Use identifiers and versioning so an auditor or the Board can establish which evidence supported which decision — for example, which notice text was live when consent was captured, or which breach report was submitted and when.

Consent as state, not event

Record consent lifecycle state: notice version, consent timestamp, affirmative action evidence, withdrawal timestamp and downstream stop-processing confirmation. If a Consent Manager revokes consent on behalf of a user, your systems must honor that state change.

Protect evidence

Apply access control, integrity, retention, confidentiality and legal hold. Avoid collecting sensitive or unnecessary personal data merely because storage is cheap — retention limits are a legal requirement, not just a hygiene preference.

17. DPDP Implementation Roadmap

  1. Establish mandate: executive sponsor, scope, risk appetite and budget for the May 2027 deadline.
  2. Map the data estate: inventory personal data, sources, processors, storage locations and Indian-resident exposure.
  3. Determine designation risk: assess SDF designation factors and plan DPO, DPIA and audit readiness if relevant.
  4. Redesign consent and notices: itemized notices, affirmative consent, easy withdrawal, 22-language coverage and Consent Manager readiness.
  5. Build rights workflows: access, correction, erasure, grievance (90-day) and nomination channels.
  6. Establish security and retention: safeguards, retention schedules, erasure automation and vendor obligations.
  7. Build breach response: playbooks, 72-hour detailed report templates, Board and user notification paths.
  8. Measure and improve: report readiness, incidents, rights-response times and audit evidence quarterly.
  • Scope decisions are documented, including extraterritorial exposure.
  • Every processing purpose has a notice version and a lawful basis.
  • Consent withdrawal is tested end-to-end, including Consent Manager paths.
  • Rights requests have owners, SLAs and escalation.
  • Retention schedules are enforced, not just published.
  • Breach detection triggers a tested 72-hour response.
  • SDF obligations (DPO, DPIA, audit) are planned if designation is plausible.
  • Evidence is versioned and traceable.

Related capabilities include DPDP Compliance Consulting, AI Governance Consulting, Digital Identity Consulting and the DPDP Act topic hub.

18. DPDP Compliance Anti-Patterns

Consent checkbox theater

Pre-ticked boxes and buried consent do not meet the "clear affirmative action" standard and invite scrutiny. Remedy: design consent as an explicit, itemized, withdrawable state.

Notice after collection

Collecting data first and posting a privacy policy later inverts the statutory sequence. Remedy: notice must precede or accompany collection and consent requests.

GDPR copy-paste

Reusing GDPR lawful-basis architecture ignores the consent-led structure and 22-language notice requirement. Remedy: adapt, do not copy; map each obligation to its DPDP equivalent.

No retention enforcement

Publishing a retention policy while data accumulates forever is a legal exposure. Remedy: enforce schedules with automation and deletion workflows.

72-hour breach fiction

Expecting a team to assemble a detailed breach report in 72 hours without a playbook is unrealistic. Remedy: build and rehearse response before an incident.

India as an afterthought

Treating India as a small market while routing Indian-user data through uncontrolled flows ignores extraterritorial scope. Remedy: include Indian-resident processing in global data maps and vendor reviews.

Evidence after the fact

Rebuilding history for audits and Board inquiries is unreliable. Remedy: capture versioned evidence continuously through delivery workflows.

19. Frequently Asked Questions

What is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 is India's national data protection law. It regulates how organizations process digital personal data, grants individuals rights over their data and establishes the Data Protection Board of India.

When do the DPDP Rules 2025 apply?

The DPDP Rules 2025 were notified in November 2025 with an 18-month phased rollout: Board provisions from November 2025, Consent Manager and cross-border mechanisms from November 2026, and full Data Fiduciary enforcement from May 2027.

Who is a Data Fiduciary under the DPDP Act?

A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data, alone or with others. Fiduciaries must issue notices, obtain consent, secure data, honor rights and respond to breaches.

Who is a Data Principal under the DPDP Act?

A Data Principal is the individual to whom personal data relates. Data Principals have rights to access, correct, erase, obtain grievance redressal, withdraw consent and nominate a representative.

What is a Significant Data Fiduciary?

An SDF is a Data Fiduciary designated by the Central Government based on factors such as data volume and sensitivity and risk to electoral democracy or public order. SDFs must appoint an India-based DPO, conduct annual DPIAs and undergo annual independent data audits.

What are the penalties under the DPDP Act?

Penalties are financial, up to ₹250 crore for failure to take reasonable security safeguards leading to a breach and up to ₹200 crore for breach-notification failures or violations of children's data obligations. The Act does not impose criminal penalties.

Does the DPDP Act apply to companies outside India?

Yes. The Act applies to processing of digital personal data outside India when that processing is in connection with offering goods or services to individuals within India.

What consent is required under the DPDP Act?

Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and it must be easy to withdraw. A request for consent must be preceded by an itemized notice.

Is a Data Protection Officer mandatory for all companies?

No. Only Significant Data Fiduciaries are required to appoint an India-based Data Protection Officer. Other fiduciaries still need accountable ownership for consent, rights, security and breach response.

Does the DPDP Act allow cross-border data transfer?

Yes, with a blacklist approach. Transfers to other countries are generally permitted unless the Central Government restricts transfers to a specific country or territory.

Does DPDP compliance replace GDPR compliance?

No. Both regimes apply in their own territories. Global programs should share data mapping, incident response and vendor management muscle, then adapt the consent-led, 22-language, Consent Manager and blacklist-transfer specifics of the DPDP regime.

Is this guide legal advice?

No. This guide provides architecture, governance and engineering guidance. Applicability and conformity decisions require qualified legal counsel and relevant specialists.

Sources, Author and Technical Review

This guide prioritizes primary regulation, government sources and authoritative technical resources. Requirements and rules evolve; verify current editions and obtain qualified legal, privacy and security advice.

  1. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India
  2. Digital Personal Data Protection Rules, 2025 (official text, MeitY)
  3. MeitY, Data Protection Framework
  4. Press Information Bureau, DPDP Rules 2025 notified
  5. EY India, Transforming data privacy: DPDP Act 2023 and DPDP Rules 2025
  6. Latham & Watkins, DPDP Act vs GDPR comparison
  7. Data Protection Board of India (official site)
  8. The Hindu, What are the DPDP Rules and when do they apply?
  9. Reuters, India strengthens privacy law with new data collection rules

Author and technical reviewer: Mustafa Husain

Founder, KryptoMindz Technologies. Enterprise architecture focus across trusted AI, digital identity, cryptography and compliance-by-design programs for global and Indian government clients.

Turn DPDP into an Operating Capability

KryptoMindz can translate the DPDP Act and Rules into a readiness assessment, consent and notice architecture, rights workflows, breach response and evidence design for global and India-facing organizations.

Discuss Your DPDP Program