
What is the DPDP Act 2023? Complete Guide for Indian Companies
15 min read

Quick Answer: DPDP compliance means following India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 — collecting clear consent, mapping your data, appointing a grievance officer, signing processor agreements, and building a breach response plan. The government notified the Rules in November 2025, with full enforcement due by May 2027. Businesses that start now avoid the last-minute rush and heavy fines of up to ₹250 crore.
If you run a business in India that collects any personal data — customer names, phone numbers, emails, payment details, or even website cookies — this law applies to you. This guide breaks down exactly what to do, in what order, so you are not left guessing.
Many Indian business owners think this law is "still far away." That is no longer true. The DPDP Rules are already notified, and the government is currently in a "soft enforcement" phase — meaning warnings and guidance are being issued instead of heavy fines, mostly to give businesses time to fix gaps.
But this soft period will not last. Hard enforcement is expected from May 2027, and there is an active proposal to move up the deadline for larger companies to November 2026. Building compliance takes months — data mapping alone can take several weeks for a mid-sized company. Starting in 2026 gives you breathing room. Starting in 2027 does not.
There is also a business reason beyond fines: customers and partners are starting to ask about data protection practices before signing contracts, especially in B2B and fintech. Being DPDP-ready is becoming a trust signal, not just a legal checkbox.
DPDP compliance is not only for large corporations. The law uses three simple categories:
In short: if your business touches Indian customer data in any way, you are covered by this law — the only question is which category, and how strict your obligations are.
| Phase | Date | What It Means |
|---|---|---|
| Phase 1 — Notification | November 13–14, 2025 | DPDP Rules officially notified. Foundational obligations (like appointing a grievance officer) begin to apply. |
| Phase 2 — Expanded obligations | November 14, 2026 | Additional rules kick in, including stricter obligations for Significant Data Fiduciaries. (A proposal exists to make this the final SDF deadline instead of May 2027.) |
| Phase 3 — Full enforcement | May 14, 2027 | All provisions of the DPDP Act and Rules become fully enforceable — the "hard enforcement" date. |
For a deeper, section-by-section breakdown of what falls in each phase, see our dedicated DPDP compliance timeline and checklist.
Important note: "Soft enforcement" does not mean "no risk." The Data Protection Board of India can still act on serious complaints or data breaches during this period. Treat 2026 as your implementation window, not a free pass.
This is the practical part. These ten steps cover what almost every Indian business needs to do, roughly in the order that makes sense to tackle them.
Every Data Fiduciary must have a named person who handles data-related complaints from users. Significant Data Fiduciaries must go further and appoint a dedicated Data Protection Officer (DPO) based in India. Smaller businesses often start with an existing employee handling this part-time, then move to a dedicated or outsourced DPO as data volume grows. Full details are in our guide to appointing a DPO under DPDP.
You cannot protect data you have not accounted for. Data mapping means listing every place personal data enters your business — signup forms, payment gateways, support tickets, marketing tools — and tracking where it goes after that. This document is called a Record of Processing Activities (RoPA), and it becomes the foundation for almost every other compliance step. See our full walkthrough on data mapping and RoPA for DPDP.
A pre-ticked checkbox or a buried line in your terms and conditions is not valid consent under DPDP. Consent must be specific, informed, and freely given — the user must clearly understand what data is collected and why, in plain language, before they say yes. Many businesses need to rebuild their signup and checkout flows to meet this bar. Our consent management implementation guide covers exactly how to do this without hurting conversion rates.
Your privacy policy needs to say, in simple words, what data you collect, why, how long you keep it, and how users can request access or deletion. Legal jargon copied from a template will not meet DPDP's transparency requirement — it needs to be genuinely understandable to an average user.
If you use a cloud host, email marketing tool, payment processor, or any third party that touches your customers' personal data, you need a written agreement defining their responsibilities and security obligations. This is one of the most commonly missed steps because businesses forget vendors count too. See our processor agreements (DPA) guide for a practical checklist.
DPDP expects "reasonable security safeguards" — encryption of sensitive data, access controls so only authorized staff can view personal data, and regular security reviews. This does not have to mean expensive enterprise tools; it means proportional protection based on how sensitive and how much data you hold.
If a data breach happens, you are required to notify affected users and, in significant cases, the Data Protection Board — quickly. Waiting until a breach happens to figure out your notification process is a serious risk. Our breach notification playbook lays out a ready-to-use response plan.
You cannot hold personal data forever "just in case." DPDP requires you to define how long you keep each type of data and delete it once the purpose is served — with limited exceptions for legal recordkeeping. Document this clearly so it is auditable.
Most data-protection failures come from human error, not hackers — a support agent emailing the wrong file, a marketer exporting a customer list carelessly. Basic training on what counts as personal data and how to handle it goes a long way, and shows genuine effort if the Data Protection Board ever reviews your practices.
DPDP compliance is not a project you finish once. New vendors, new products, and new data types mean your data map and consent flows need periodic review — most businesses review quarterly at minimum.
| Typical Cost | |
|---|---|
| DPDP compliance for a small/mid-size business | Ranges widely based on current data maturity — see our detailed DPDP compliance cost and ROI breakdown |
| General DPDP violation | Up to ₹5 crore |
| Serious violation (e.g., mishandling sensitive data) | Up to ₹250 crore per instance |
| Reputational cost of a public data breach | Often larger than the fine itself — lost customer trust, contract cancellations, negative press |
The math is straightforward: proactive compliance is a planned, one-time cost. Non-compliance is an unplanned, much larger, and repeated risk.
Core requirements apply to every business, but certain industries carry extra obligations because of the sensitivity of the data involved:
DPDP compliance means following India's Digital Personal Data Protection Act 2023 — the law that controls how businesses collect, store, and use personal data of Indian residents. In practice, it means getting clear consent before collecting data, telling users exactly what you do with their data, keeping it secure, and deleting it once it's no longer needed. Every business that handles Indian customer data, regardless of size, falls under this law.
The DPDP Rules were notified in November 2025, starting a phased rollout across three dates: November 2025, November 2026, and May 2027. Full "hard enforcement" is expected by May 14, 2027, though a proposal is being discussed to move the deadline for large data processors up to November 2026. Businesses should treat 2026 as the year to complete implementation, not wait for the final deadline.
Any business that decides why and how personal data is collected — called a Data Fiduciary — must comply, including e-commerce stores, clinics, schools, SaaS platforms, and financial services firms. This applies regardless of company size, so a small startup with even a modest user base is covered. Companies processing especially large or sensitive data volumes are further classified as Significant Data Fiduciaries with extra obligations.
Non-compliant businesses face financial penalties that scale with the severity of the violation — up to ₹5 crore for general violations and up to ₹250 crore for serious ones, such as mishandling sensitive personal data. Beyond fines, non-compliance risks reputational damage, lost customer trust, and cancelled B2B contracts, which often costs more than the penalty itself. The Data Protection Board of India can also order corrective action beyond financial penalties.
For a small to mid-size business, a realistic implementation timeline runs 8 to 16 weeks, covering data mapping, consent redesign, privacy notice updates, and processor agreements. Larger or more complex organizations, especially Significant Data Fiduciaries, often need several months due to the volume of data and vendor relationships involved. Starting early in 2026 avoids the compressed, high-pressure timeline businesses will face closer to the 2027 enforcement deadline.
Yes — DPDP does not exempt businesses based on size or revenue, only based on the type and volume of data they process. A small startup collecting customer names, emails, and payment details is still a Data Fiduciary under the law. The compliance workload is typically lighter for small businesses, but the core obligations, like valid consent and a grievance officer, still apply.
A Data Fiduciary is the business that decides why and how personal data is collected and used, such as an online retailer running its own store. A Data Processor handles data on behalf of a Data Fiduciary under a contract, such as a cloud hosting company or payroll platform. Most businesses are Data Fiduciaries for their own customer data, while also acting as a client of several Data Processors for tools they use.
A Significant Data Fiduciary (SDF) is a Data Fiduciary that the government classifies as higher-risk, typically based on the volume, sensitivity, or scale of personal data it processes. SDFs face extra obligations beyond standard Data Fiduciaries, including appointing a dedicated Data Protection Officer based in India and conducting periodic data protection audits. Large platforms, fintech companies, and healthtech firms commonly fall into this category.
Valid consent under DPDP must be specific, informed, and freely given — meaning the user clearly understands what data is being collected and why, before they agree. Pre-ticked boxes, bundled consent hidden in lengthy terms and conditions, or vague language do not meet this standard. Users must also be able to withdraw consent as easily as they gave it, and businesses must honor that withdrawal promptly.
Yes — DPDP applies to any business, Indian or foreign, that processes the personal data of individuals located in India, as long as that processing relates to offering goods or services to them. A foreign SaaS company with Indian customers is covered by the law just as an Indian company would be. This is similar in spirit to how GDPR applies beyond the EU's own borders.
Data breach penalties under DPDP can reach up to ₹250 crore for serious cases involving mishandling of personal data, decided based on the nature and impact of the breach. Businesses are also required to notify affected individuals and, in significant cases, the Data Protection Board of India promptly after discovering a breach. Failing to notify on time is treated as a separate violation, on top of the breach itself.
DPDP is generally considered simpler and more prescriptive than the EU's GDPR, with fewer legal bases for processing data and a more straightforward consent-first approach. Both laws share core ideas, like the 72-hour-style urgency around breach notification and strong user rights to access and delete data. However, businesses cannot assume GDPR compliance automatically satisfies DPDP — the specific Indian requirements need their own review, covered in our detailed DPDP vs GDPR comparison.
DPDP compliance is not a single document you file once — it is a set of practical business habits: honest consent, careful data handling, clear vendor agreements, and a plan for when things go wrong. The good news is that none of the ten steps in this guide require enterprise budgets or a legal department. With the Rules already notified and enforcement dates locked in through 2027, businesses that start in 2026 will implement calmly, on their own schedule — businesses that wait will be racing the clock.
Cor Advance Solutions helps Indian businesses build practical, working DPDP compliance programs — from data mapping to consent systems to processor agreements. Start with our free DPDP compliance assessment or get in touch to talk through your specific situation.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. DPDP Rules and enforcement timelines are subject to government notification and may change. Consult a qualified data protection professional or lawyer for guidance specific to your business.
Let's discuss how these insights apply to your specific challenges.
Get in Touch