Skip to content

DPDP compliance

What DPDP compliance takes, and what you have to prove

The Act puts the duty on each business. Here is what it expects, when it applies, and what it costs to get wrong.

No licence makes you compliant. You have to be able to prove it.

Each Data Fiduciary is responsible for its own compliance and must show it if a person complains or the Data Protection Board investigates. Your privacy policy only holds up if the practice behind it matches.

  1. 1Assess

    Check yourself against every obligation in the Act and Rules.

    GRC Flow: Guided intake mapped to every obligation; AI-drafted gaps citing the exact section.

  2. 2Fix

    Close the gaps: notices, consent, security, contracts, deletion, rights.

    GRC Flow: Risk register, readiness plan and tasks with owners and due dates.

  3. 3Document

    Policies, a record of processing and evidence for each control.

    GRC Flow: Privacy notice, RoPA, breach playbook and DPA drafts; an evidence library checked by AI.

  4. 4Prove

    Show it when a person complains or the Board investigates.

    GRC Flow: Controls that need evidence, human-reviewed findings and a tamper-evident audit log.

  5. 5Keep it running

    Handle requests, consent changes and breaches on time.

    GRC Flow: Consent records, rights requests on a 90-day clock, breaches on a 72-hour clock, policy reviews.

The main duties apply from 13 May 2027

  1. 11 August 2023

    The DPDP Act receives Presidential assent.

  2. November 2025

    The DPDP Rules are notified and the Data Protection Board is set up.

  3. November 2026

    Rules on registering Consent Managers take effect.

  4. 13 May 2027

    Notice, consent, security, breach reporting, erasure, children's data and Data Principal rights all apply.

Maximum penalty per instance

₹250 crore
Failing to take reasonable security safeguards (Section 8(5))
₹200 crore
Failing to report a breach to the Board and affected people (Section 8(6))
₹200 crore
Breaking the additional rules for children's data (Section 9)
₹150 crore
A Significant Data Fiduciary missing its extra duties (Section 10)
₹50 crore
Breaching any other provision of the Act or Rules

Read more on the Act