Data Protection · India

The DPDP deadline has a date. Most companies don’t have a plan.

India’s Digital Personal Data Protection Act sat without teeth for two years. That ended on 13 November 2025, when the DPDP Rules, 2025 were notified. The core obligations become enforceable around 13 May 2027 — and the penalty for getting the basics wrong runs to ₹250 crore. We turn that pressure into a plan you can actually execute.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
13 May 2027Core obligations enforceable
₹250 CrMax penalty — security safeguards
72 HoursBreach report to the Board
Under 18Verifiable parental consent

The clock, in plain numbers

The Act was enacted on 11 August 2023 and then sat for over two years without the rules that make a statute operable. The Digital Personal Data Protection Rules, 2025 were notified in the Gazette on 13 November 2025, and they commence in three stages. Immediately, on notification: the machinery that constitutes the Data Protection Board of India. Around 13 November 2026: registration of Consent Managers. Around 13 May 2027: everything that costs you money to build — notice and consent, data-principal rights, reasonable security safeguards, children’s data, breach reporting, Significant Data Fiduciary duties and the cross-border rules. That third date is when the penalty schedule becomes real.

There is no DPDP certification. There is no accredited DPDP certifier, no scheme, and no badge, because the Act did not create one — the Data Protection Board of India adjudicates, and appeals go to TDSAT and then the Supreme Court. If someone offers you a DPDP certificate, be suspicious about everything else they have told you. What exists instead is readiness: a documented inventory, consent and rights processes that work when a real person uses them, a breach playbook that has been rehearsed, and evidence you could put in front of the Board without a week of preparation.

That distinction is not pedantry, because it is exactly what the Board weighs. Penalty amounts are set against the nature, gravity and duration of the violation, the personal data involved, whether harm was caused, and what the organisation did about it. Documented good-faith readiness is the specific thing that moves the number. An organisation that can show its data map, its consent records and its 72-hour report process is in a materially different position from one that can show a privacy policy and an apology.

Dates and penalty figures on this page are as of August 2026, and run from the notification of the Rules on 13 November 2025. We re-check them against Data Protection Board of India notifications before each update, and nothing here is legal advice.

Coverage

Why GDPR or ISO 27001 isn’t the finish line

The overlap is real and it does reduce the work. ISO 27001 carries most of the weight on security safeguards; a GDPR programme gives you a head start on records and rights. Neither of them produces these six, which are net-new for almost every organisation that arrives already certified.

Consent, with no legitimate-interest fallback

DPDP runs on consent plus a short, closed list of legitimate uses. There is no GDPR-style legitimate-interest catch-all to reason your way into. Processing you currently justify as legitimate interest needs either a consent flow or a different answer, and finding out which is a per-activity exercise rather than a policy decision.

Plain-language notice, and withdrawal that works

The notice has to be clear and in plain language, stating what is collected, for what purpose, and how the individual exercises their rights or complains. Withdrawing consent must be as easy as giving it — which in practice means a mechanism somebody has to build, not a sentence somebody has to write.

Grievance redressal as a running process

Access, correction, erasure, grievance redressal and nomination are the rights on the Indian list, and nomination has no GDPR equivalent at all. There is no general DPO mandate outside Significant Data Fiduciaries, but there is a grievance mechanism you must publish, staff and answer within time.

Verifiable parental consent for under-18s

The Indian threshold is 18. GDPR sets 16 and lets member states drop it to 13, so a consent flow tuned for Europe is under-scoped here by several years of users. Tracking, behavioural monitoring and targeted advertising aimed at children are barred, with notified exemptions in areas such as healthcare and education.

Consent Manager integration

The Rules create a registered intermediary class — Board-registered, minimum net worth ₹2 crore — through which individuals can give, manage and withdraw consent across fiduciaries. Registration switches on around 13 November 2026. Nothing in GDPR or ISO 27001 maps to it, so the integration decision is one you make from scratch.

India-specific breach reporting

Notify the Board and every affected data principal without delay, then file a detailed report with the Board within 72 hours. Different regulator, different clock, different content from anything your GDPR runbook says. And you cannot report inside 72 hours if you cannot detect inside 72 hours, which makes this a logging and monitoring problem wearing a legal hat.

Approach

How a DPDP programme runs

Six steps, run in order, because each one is worthless without the one before it. Most organisations need three to six months of real work, which is why starting in 2026 is a choice and starting in 2027 is not.

  1. 01 · Scope & data mapping

    Determine your role — Data Fiduciary, Data Processor, or both for different activities — then inventory every place personal data is collected, used, stored and shared, across product, HR, marketing, support and third-party tools. The same pass flags the volume and sensitivity triggers that would put Significant Data Fiduciary designation within reach.

  2. 02 · Gap assessment

    Clause by clause against the Act and the 2025 Rules, RAG-rated, with every gap written as a thing to build and an owner to build it rather than a section number to go and read.

  3. 03 · Prioritise

    A remediation plan weighted by two things at once: what must be true by 13 May 2027, and what is most likely to hurt you before then. Those are not the same list, and treating them as one is how programmes stall.

  4. 04 · Implement

    Notices and consent capture, the data-principal rights workflow, the breach playbook, retention and erasure with advance notice before deletion, children’s data controls, processor contracts, and security safeguards proportionate to what you actually hold.

  5. 05 · Validate

    Tabletop the breach process against the 72-hour clock, and run a real data-principal request end to end — access, then correction, then erasure. Evidence that has never been tested is a claim, not evidence.

  6. 06 · Assure

    For Significant Data Fiduciaries, the annual DPIA, the independent data audit and algorithmic due diligence. For everyone, a retainer that tracks Board notifications and re-tests the controls when the guidance moves, because it will.

Run against recognised standards

  • DPDP Act, 2023Enacted 11 August 2023
  • DPDP Rules, 2025Notified 13 November 2025
  • Notice and consentPlain language, purpose-bound, withdrawable
  • Data-principal rightsAccess, correction, erasure, grievance, nomination
  • Reasonable security safeguardsThe ₹250 crore obligation
  • Breach notificationWithout delay, detailed report in 72 hours
  • Children’s dataVerifiable parental consent under 18
  • Significant Data Fiduciary dutiesIndia-based DPO, DPIA, independent audit
  • Cross-border transferPermitted unless the destination is restricted

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Data-processing inventory

Every processing activity, its purpose, the basis it relies on, where the data goes, who touches it and how long it is kept. Everything else in a DPDP programme is built on this, which is why it is the deliverable clients most often try to skip.

Written role determination

Data Fiduciary, Data Processor, or both, reasoned per activity rather than declared once for the company — plus an honest read on whether the Significant Data Fiduciary triggers are in reach for you.

Clause-by-clause gap register

RAG-rated against the Act and the 2025 Rules, each gap owned, sized in effort and dated. It is a work plan that happens to double as an audit trail.

Notice, consent and rights machinery

The notices themselves, the consent capture and withdrawal flow, and a request workflow for access, correction, erasure, grievance and nomination that a real person on your team can operate on a Tuesday afternoon.

A rehearsed breach playbook

Who decides it is a breach, who notifies, what goes to the Board, what goes to affected principals, and the 72-hour report drafted before the day you need it rather than during it.

A roadmap dated to May 2027

Sequenced backwards from the deadline, with the dependencies made visible, so leadership can see what has to be funded in which quarter instead of discovering it in the last one.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You process the personal data of people in India and have never mapped where it goes.
  • You are ISO 27001 certified or GDPR-compliant and assumed that covered the DPDP Act.
  • A customer, investor or board member has started asking how you will be ready for May 2027.
  • You collect data from anyone who might be under 18 and have no age or parental-consent check.
  • You have a privacy policy but no working way to answer an access, correction or erasure request.
  • You could not report a breach within 72 hours, because you would not know within 72 hours.
  • Your data volumes are large enough that Significant Data Fiduciary designation is a real possibility.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

DPDP Act Compliance — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Can we get DPDP certified?

No, and nobody can issue you one. The Act created an adjudicating body — the Data Protection Board of India — not a certification scheme, and there is no accredited DPDP certifier anywhere. If a firm offers you a DPDP certificate or badge, treat it as information about the firm. What is real, and what enterprise customers and regulators actually respond to, is demonstrable readiness: a documented data inventory, consent and rights processes that work, a tested breach playbook, and evidence you can produce on request. That is also precisely what the Board weighs when it decides what a violation costs you.

We already did GDPR. How much of this is new?

Less than starting from zero, considerably more than clients expect. The security safeguards limb is where ISO 27001 and GDPR work hardest for you, and your records of processing give you a real head start on the data map. What does not carry across: consent as the primary basis with no legitimate-interest fallback, plain-language notice requirements, the grievance-redressal and nomination rights, verifiable parental consent for anyone under 18 rather than under 16, the Consent Manager framework, and breach reporting to a different regulator on a different clock. The cross-border model is inverted too — DPDP permits transfers unless the government restricts the destination, rather than requiring an adequacy finding or standard clauses first.

When do we actually have to be ready?

The Rules commence in three stages, all counted from their notification on 13 November 2025. The Data Protection Board’s constituting provisions took effect immediately. Consent Manager registration comes in around 13 November 2026. The core obligations — notice and consent, data-principal rights, security safeguards, children’s data, breach reporting, Significant Data Fiduciary duties and cross-border rules — become enforceable around 13 May 2027. The practical answer is earlier than that. Data mapping alone takes weeks in a mid-sized organisation, rights workflows need to be built and staffed, and a breach playbook is only worth anything after it has been rehearsed at least once.

How do we know if we are a Significant Data Fiduciary?

You do not decide it and you cannot volunteer for it. The government notifies a Data Fiduciary, or a class of them, as significant — the assessment turns on the volume and sensitivity of the personal data processed and the risk it carries. What matters commercially is that the extra duties are substantial: a Data Protection Officer based in India, an annual Data Protection Impact Assessment, an independent data audit, and algorithmic due diligence over the systems that process personal data. We flag the triggers during data mapping so you are planning for designation rather than reacting to it.

What does a breach actually require us to do?

Two separate things, on two clocks. You must notify the Data Protection Board and every affected data principal without delay — that is the immediate obligation and the word is deliberately unforgiving. Then you must file a detailed report with the Board within 72 hours. Failure to notify a personal data breach carries a maximum penalty of ₹200 crore in its own right, separate from any penalty for the security failure that caused it. The hard part is almost never the paperwork. It is that you cannot report inside 72 hours if your logging and monitoring will not tell you inside 72 hours, which is why breach readiness work usually starts in the detection stack rather than in the legal drafting.

Do the penalties really reach ₹250 crore?

Those are the statutory maximums in the Act’s Schedule, not typical outcomes. The ceilings are ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to notify a breach, ₹200 crore for breaching children’s-data obligations, ₹150 crore for breaching the additional Significant Data Fiduciary duties, ₹50 crore for any other provision, and up to ₹10,000 against an individual who breaches their own duties as a data principal. The Board sets the actual figure by weighing the nature, gravity and duration of the violation, the personal data involved, whether harm resulted, and the cooperation and mitigation that followed. The honest summary is that the maximums exist to make the topic a board conversation, and that documented readiness is the single lever you control over where in that range you land.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.