DPDP compliance requirements for businesses: the obligations map (2026)
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 13 min read
What are the essential compliance requirements for a business under the DPDP Act?
The short answer
A business that determines why and how digital personal data is processed is a Data Fiduciary. Its core duties: process only on consent or a section 7 legitimate use (section 4), give a Rule 3 notice with every consent request (section 5), meet the section 6 consent standard, and carry the section 8 obligations, including valid processor contracts, completeness, accuracy and consistency where data is likely to feed a decision that affects the individual or be disclosed to another Data Fiduciary, security safeguards detailed by Rule 6, breach intimation to affected individuals and the Board with detailed Board information within 72 hours, or such longer period as the Board allows on a written request, under Rule 7, and erasure when consent is withdrawn or the purpose is spent, unless retention is necessary for compliance with law. Add the section 8(9) duty to publish a contact, with the Rule 9 mechanics, rights handling under Rule 14, whose sub rule (3), on our reading printed with a word missing, ties a reasonable period not exceeding 90 days to responding to grievances, section 9 children's duties, section 10 Significant Data Fiduciary duties where notified, and the section 16 and Rule 15 position on transfers outside India. Not 1 of these duties is in force: read as at 29 September 2026, they all sit in 18 month commencement groups computed at 13 May 2027, interpretation until officially confirmed.

Ask 5 advisors what DPDP compliance requires and you get 5 different checklists. The Act is more orderly than the advice around it: if your business determines the purpose and means of processing digital personal data, it is a Data Fiduciary, and every duty below is addressed to it, whoever owns the task internally. This article maps those duties in 6 groups, each cited to the Gazette text, and says at the end which regimes it leaves out, because a map that claims to be complete is a claim no page of either instrument can support. For the same material as a sequenced action list, the small business checklist walks the steps.
Every use of personal data needs one of 2 grounds
Section 4 is the gate everything passes through:
"(1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,— (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses."
Section 4(1) of the DPDP Act 2023.
There is no third ground. The certain legitimate uses are the closed list in section 7, covering purposes such as voluntary provision for a specified purpose, employment, medical emergencies and State functions. The first requirement is therefore an inventory: every purpose you process personal data for must be tagged either consent or a named section 7 use. A lawful purpose, section 4(2) adds, is any purpose not expressly forbidden by law.
A notice must accompany or precede every consent request
Where consent is the ground, section 5 requires a notice with or before the request, describing the personal data and purpose, how to exercise rights and how to complain to the Data Protection Board. Consent collected before commencement gets no quiet pass: section 5(2) requires a notice as soon as reasonably practicable, after which processing may continue until consent is withdrawn, and section 5(3) requires the option to read the notice in English or any Eighth Schedule language.
Rule 3 sets the content standard: the notice must be understandable on its own, use clear and plain language, itemise the personal data, describe the goods, services or uses each purpose enables, and give the communication link and any other means to withdraw consent, exercise rights and complain to the Board. The privacy notice generator assembles a draft from these elements, and the notice provisions are set out element by element separately.
Consent must meet the section 6 standard
Section 6 defines what counts as consent: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. Withdrawing consent must be comparable in ease to giving it, and on withdrawal you must, within a reasonable time, stop processing and cause your processors to stop, unless processing without consent is required or authorised under the Act, the rules or another law. Section 6(10) puts the burden of proof on you: in a proceeding, the Data Fiduciary must prove notice was given and consent validly taken. Keeping consent records able to discharge that burden is the practical consequence; the Act mandates the burden, not any record format, so record design is a recommendation.
The section 8 obligations: the operational core
Section 8 carries the duties that consume most compliance effort, and section 8(1) frames them strictly: you are responsible for compliance in respect of any processing done by you or on your behalf by a Data Processor, irrespective of any agreement to the contrary.
Valid processor contracts. Under section 8(2) you may engage a Data Processor to process personal data on your behalf, for any activity related to offering goods or services to Data Principals, only under a valid contract, and Rule 6(1)(f) requires that contract to provide for reasonable security safeguards. The clause checklist in our templates goes further; clauses beyond safeguards are recommendation, not statute.
Accuracy. Where personal data is likely to be used for a decision that affects the person, or disclosed to another Data Fiduciary, section 8(3) requires you to ensure its completeness, accuracy and consistency.
Measures to ensure observance. Section 8(4) requires you to implement appropriate technical and organisational measures to ensure effective observance of the Act and the rules made under it. It is the general accountability duty sitting behind the specific ones, and it is why a control that answers to no single sub section can still be required.
Security safeguards. Section 8(5) requires reasonable security safeguards to prevent a personal data breach, covering data held by your processors too. Rule 6 makes that concrete with a minimum list: measures such as encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review able to detect unauthorised access; backups; 1 year retention of logs and related personal data for detection and investigation; the contract provision above; and technical and organisational measures.
Breach intimation. Section 8(6) requires intimation of any personal data breach to the Board and to each affected Data Principal. Rule 7 starts 2 clocks at the moment you become aware: affected individuals must be told without delay, in concise, clear and plain terms, what happened, the likely consequences for them, what you are doing about it, what they can do, and whom to contact; the Board must get a description without delay and updated, detailed information within 72 hours, extendable by the Board on written request.
Erasure. Section 8(7) requires erasure once consent is withdrawn or as soon as it is reasonable to assume the specified purpose is no longer served, whichever is earlier, unless a law requires retention; you must cause your processors to erase too. Rule 8 adds mechanics: timed erasure clocks for the classes listed in its Third Schedule, at least 48 hours notice before an erasure under those clocks, and 1 year minimum retention of personal data, traffic data and processing logs under Rule 8(3).
A published contact. Section 8(9) requires you to publish the business contact information of a Data Protection Officer, if you have one, or of a person able to answer a Data Principal's questions about the processing of her personal data. Rule 9 sets the mechanics, and it asks for 2 things rather than 1: the contact must be published prominently on your website or app, and it must also be mentioned in every response to a communication exercising a right under the Act.
Grievance machinery. Section 8(10) requires an effective mechanism to redress the grievances of Data Principals, which is the operational half of the section 13 right and is dealt with under rights below.
Rights you must be ready to answer
Sections 11 to 14 give individuals rights against you, and the first 2 are scoped: the access right in section 11(1) and the correction, completion, updating and erasure rights in section 12(1) run against a Data Fiduciary to whom the person has previously given consent, including consent as referred to in section 7(a), while grievance redressal under section 13 and nomination under section 14 are not so limited. The rights themselves: access to a summary of their personal data, your processing activities and the identities of everyone you shared it with; correction, completion, updating and erasure; grievance redressal through readily available means, which a person must exhaust before going to the Board; and nomination of someone to act after death or incapacity. Rule 14 requires you to publish how these requests are made, and Rule 14(3) names 90 days in a sentence printed with no object for "publish", so what the 90 days caps is not stated on its face; this site reads it as the response period you publish, which the grievance redressal guide works through. 1 owner and 1 tracked queue is a sensible implementation, not an official requirement.
Duties that apply only in specific situations
Children's data. If you process personal data of children, section 9 requires verifiable consent of the parent or lawful guardian first, and prohibits processing likely to cause any detrimental effect on the well being of a child, tracking or behavioural monitoring of children, and targeted advertising directed at children. The mechanics live in the Rules: Rule 10 sets out the technical and organisational measures and the due diligence for verifiable parental consent, including the identity and age details you may rely on and the virtual token route, Rule 11 carries the parallel duty for a lawful guardian of a person with disability, with a different check: due diligence that the guardian was appointed by a court of law, or by a designated authority, or by a local level committee under the law applicable to guardianship, and Rule 12 with the Fourth Schedule carries the exemptions from section 9(1) and section 9(3) prescribed under section 9(4). See the children's data rules explained and the children's data tool.
Significant Data Fiduciaries. If the Central Government notifies your business as a Significant Data Fiduciary, based on factors including the volume and sensitivity of data you process, section 10 adds an India based Data Protection Officer answerable to your board, an independent data auditor, and periodic Data Protection Impact Assessments and audits. The full picture is in Significant Data Fiduciary explained. Rule 13 fixes the cadence at once in every period of twelve months from notification, requires the Significant Data Fiduciary to cause the person carrying out the assessment and audit to furnish the Board a report containing significant observations, adds due diligence over algorithmic software, and adds a restriction on transferring specified personal data and its traffic data outside India.
Transfers of personal data outside India. This is the duty class most often described as a ban and it is neither a ban nor a free pass. Section 16 is a POWER: the Central Government may, by notification, restrict transfer to a notified country or territory, and section 16(2) preserves any Indian law in force that gives a higher degree of protection or restriction. Rule 15 then permits transfer outside India subject to meeting such requirements as the Central Government may specify, by general or special order, about making that data available to a foreign State or to a person, entity or agency under its control. So the operative content of section 16(1) and of Rule 15 is delegated, and nothing has been located that fills it: re enumerated on 4 September 2026, MeitY's published document library held 2,411 records, of which 28 mention the DPDP framework, and not 1 of the 28 is a notification under section 16(1) or an order under Rule 15. That is a negative about a named library on a named date, and not a statement that no such instrument exists anywhere; it is also not a check of the Gazette of India, where such an instrument would be notified. An SDF carries the additional Rule 13(4) restriction above, which attaches to personal data the Central Government specifies on the recommendation of a committee rather than to a country list, and no such specification is among the 28 records either.
What noncompliance costs
Under section 33, the Board may impose the monetary penalties specified in the Schedule after an inquiry finds a significant breach and the person has been heard. The headline figures: up to 250 crore rupees for failing the section 8(5) security safeguards duty, up to 200 crore rupees for failing breach intimation or the children's data duties, up to 150 crore rupees for Significant Data Fiduciary failures, and up to 50 crore rupees for any other provision. The penalties explainer covers the Board's assessment factors.
When these requirements take effect
None of the duties above is enforceable yet. Commencement notification G.S.R. 843(E) places sections 3 to 5, section 6 except the Consent Manager registration provision in 6(9), and sections 7 to 17 and 28 to 34 in the group commencing 18 months from its Gazette's publication, and Rule 1(4) places Rules 3, 5 to 16, 22 and 23 on the same clock. That computes to 13 May 2027, interpretation until officially confirmed, which makes this the build window. Read as at 4 September 2026, not 1 of the 6 groups above is in force, and neither is the section 33 penalty power behind them.
What this map does not cover
A map of duties is only honest if it says where its edges are, so here are the regimes deliberately left outside it.
Consent Manager registration. Section 6(9) requires a Consent Manager to be registered with the Board, and Rule 4 with the First Schedule carries the registration conditions and the ongoing obligations. Those are duties on a Consent Manager and not on a business generally, and they also run on a different clock: paragraph (b) of G.S.R. 843(E) puts section 6(9) in the group commencing one year from publication and Rule 1(3) does the same for Rule 4, which computes to 13 November 2026, interpretation until officially confirmed. The consent managers explainer covers them.
State processing, and research. Rule 5 with the Second Schedule governs processing for the provision or issue of a subsidy, benefit, service, certificate, licence or permit by the State, and Rule 16 disapplies the Act for research, archiving or statistical purposes carried on to the Second Schedule standards. Both attach to a kind of processing rather than to every business.
Exemptions, and the Board's own machinery. Section 17 exemptions, the Board's constitution and procedure under sections 18 to 26, and appeals under section 29 and Rule 22 are not duties on you at all. The section 17 exemptions article and the Board article take those.
That is the boundary of this page, not the boundary of the law. Where a duty above depends on delegated content that has not been issued, this page says so and dates the reading rather than filling the gap.
Turn the map into a plan
Start by confirming the Act applies to you with the applicability checker, then run the company compliance plan: it turns every obligation on this page into a tracked, exportable action list ordered for your role, with the official source behind each action. If you need the answer to one question rather than the whole map, the questions page collects the short answers, each linked to its full article.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Compliance Plan
Generate 1 company level action plan and see the work for your role first.
Open
Related tool
Privacy Notice Generator
Assemble a starting template for your privacy notice from the Rule 3 minimums, which are not in force yet.
Open
Section 8, official text with sources →DPDP compliance checklist for small businesses →DPDP penalties and the Schedule explained →DPDP for legal and privacy counsel →