DPDP compliance requirements for businesses: the complete obligations map (2026)
By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 7 min read
The short answer
A business that determines why and how digital personal data is processed is a Data Fiduciary. Its core duties: process only on consent or a section 7 legitimate use (section 4), give a Rule 3 notice with every consent request (section 5), meet the section 6 consent standard, and carry the section 8 obligations: valid processor contracts, accuracy where data feeds decisions, security safeguards detailed by Rule 6, breach intimation to affected individuals and the Board with detailed Board information within seventy two hours under Rule 7, and erasure when consent is withdrawn or the purpose is spent. Add rights handling under Rule 14, which caps the published grievance response period at ninety days, section 9 children's duties and section 10 Significant Data Fiduciary duties where notified. These duties commence on the computed date of 13 May 2027, interpretation until officially confirmed.
Ask five advisors what DPDP compliance requires and you get five different checklists. The Act is more orderly than the advice around it: if your business determines the purpose and means of processing digital personal data, it is a Data Fiduciary, and every duty below is addressed to it, whoever owns the task internally. This article maps those duties, each cited to the Gazette text; for the same material as a sequenced action list, the small business checklist walks the steps.
The DPDP obligations map: every processing purpose needs a lawful ground under section 4; notice under section 5 and Rule 3 and consent meeting the section 6 standard sit on top of it; the section 8 core runs continuously, covering processor contracts, accuracy, security safeguards, breach intimation, erasure and grievance machinery; Data Principal rights under sections 11 to 14 must be answered; and the special regimes for children's data and Significant Data Fiduciaries apply where triggered, with penalty exposure under section 33 and the Schedule.
Every use of personal data needs one of two grounds
Section 4 is the gate everything passes through:
"(1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,— (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses."
Section 4(1) of the DPDP Act 2023.
There is no third ground. The certain legitimate uses are the closed list in section 7, covering purposes such as voluntary provision for a specified purpose, employment, medical emergencies and State functions. The first requirement is therefore an inventory: every purpose you process personal data for must be tagged either consent or a named section 7 use. A lawful purpose, section 4(2) adds, is any purpose not expressly forbidden by law.
A notice must accompany or precede every consent request
Where consent is the ground, section 5 requires a notice with or before the request, describing the personal data and purpose, how to exercise rights and how to complain to the Data Protection Board. Consent collected before commencement gets no quiet pass: section 5(2) requires a notice as soon as reasonably practicable, after which processing may continue until consent is withdrawn, and section 5(3) requires the option to read the notice in English or any Eighth Schedule language.
Rule 3 sets the content standard: the notice must be understandable on its own, use clear and plain language, itemise the personal data, describe the goods, services or uses each purpose enables, and give the communication link and any other means to withdraw consent, exercise rights and complain to the Board. The privacy notice generator assembles a draft from these elements.
Consent must meet the section 6 standard
Section 6 defines what counts as consent: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent was, and on withdrawal you must, within a reasonable time, stop processing and cause your processors to stop, unless processing without consent is required or authorised under the Act, the rules or another law. Section 6(10) puts the burden of proof on you: in a proceeding, the Data Fiduciary must prove notice was given and consent validly taken. Keeping consent records able to discharge that burden is the practical consequence; the Act mandates the burden, not any record format, so record design is a recommendation.
The section 8 obligations: the operational core
Section 8 carries the duties that consume most compliance effort, and section 8(1) frames them strictly: you are responsible for compliance in respect of any processing done by you or on your behalf by a Data Processor, irrespective of any agreement to the contrary.
Valid processor contracts. Under section 8(2) you may engage a Data Processor to process personal data on your behalf, for any activity related to offering goods or services to Data Principals, only under a valid contract, and Rule 6(1)(f) requires that contract to provide for reasonable security safeguards. The clause checklist in our templates goes further; clauses beyond safeguards are recommendation, not statute.
Accuracy. Where personal data is likely to be used for a decision that affects the person, or disclosed to another Data Fiduciary, section 8(3) requires you to ensure its completeness, accuracy and consistency.
Security safeguards. Section 8(5) requires reasonable security safeguards to prevent a personal data breach, covering data held by your processors too. Rule 6 makes that concrete with a minimum list: measures such as encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review able to detect unauthorised access; backups; one year retention of logs and related personal data for detection and investigation; the contract provision above; and technical and organisational measures.
Breach intimation. Section 8(6) requires intimation of any personal data breach to the Board and to each affected Data Principal. Rule 7 starts two clocks at the moment you become aware: affected individuals must be told without delay, in concise, clear and plain terms, what happened, the likely consequences for them, what you are doing about it, what they can do, and whom to contact; the Board must get a description without delay and updated, detailed information within seventy two hours, extendable by the Board on written request.
Erasure. Section 8(7) requires erasure once consent is withdrawn or as soon as it is reasonable to assume the specified purpose is no longer served, whichever is earlier, unless a law requires retention; you must cause your processors to erase too. Rule 8 adds mechanics: timed erasure clocks for the classes listed in its Third Schedule, at least forty eight hours notice before an erasure under those clocks, and one year minimum retention of personal data, traffic data and processing logs under Rule 8(3).
Section 8 also requires publishing the business contact of a person able to answer questions about processing (8(9)) and an effective grievance redressal mechanism (8(10)).
Rights you must be ready to answer
Sections 11 to 14 give individuals rights against you: access to a summary of their personal data, your processing activities and the identities of everyone you shared it with; correction, completion, updating and erasure; grievance redressal through readily available means, which a person must exhaust before going to the Board; and nomination of someone to act after death or incapacity. Rule 14 requires you to publish how these requests are made and caps the grievance response period you publish at ninety days. One owner and one tracked queue is a sensible implementation, not an official requirement.
Duties that apply only in specific situations
Children's data. If you process personal data of children, section 9 requires verifiable consent of the parent or lawful guardian first, and prohibits processing likely to cause detrimental effect on the well being of a child, tracking or behavioural monitoring of children, and targeted advertising directed at children. The mechanics live in the Rules; see the children's data rules explained and the children's data tool.
Significant Data Fiduciaries. If the Central Government notifies your business as a Significant Data Fiduciary, based on factors including the volume and sensitivity of data you process, section 10 adds an India based Data Protection Officer answerable to your board, an independent data auditor, and periodic Data Protection Impact Assessments and audits. The full picture is in Significant Data Fiduciary explained.
What noncompliance costs
Under section 33, the Board may impose the monetary penalties specified in the Schedule after an inquiry finds a significant breach and the person has been heard. The headline figures: up to two hundred and fifty crore rupees for failing the section 8(5) security safeguards duty, up to two hundred crore rupees for failing breach intimation or the children's data duties, up to one hundred and fifty crore rupees for Significant Data Fiduciary failures, and up to fifty crore rupees for any other provision. The penalties explainer covers the Board's assessment factors.
When these requirements take effect
None of the duties above is enforceable yet. Commencement notification G.S.R. 843(E) places sections 3 to 5, section 6 except the Consent Manager registration provision in 6(9), and sections 7 to 17 and 28 to 34 in the group commencing eighteen months from its Gazette's publication, and Rule 1(4) places Rules 3, 5 to 16, 22 and 23 on the same clock. That computes to 13 May 2027, interpretation until officially confirmed, which makes this the build window.
Turn the map into a plan
Start by confirming the Act applies to you with the applicability checker, then run the company compliance plan: it turns every obligation on this page into a tracked, exportable action list ordered for your role, with the official source behind each action.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Compliance Plan
Generate one company level action plan and see the work for your role first.
Open
Related tool
Privacy Notice Generator
Assemble a starting template for your privacy notice from the Rule 3 minimums.
Open
Section 8, official text with sources →DPDP compliance checklist for small businesses →DPDP penalties and the Schedule explained →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2, p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 2(i): a Data Fiduciary is any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. Section 2 begins on Gazette page 2 and concludes on page 3.
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 4, p. 4. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 4: the two grounds for processing. Section 4(2) defines lawful purpose as any purpose which is not expressly forbidden by law.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 5, p. 4. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 5: every consent request must be accompanied or preceded by a notice describing the personal data and purpose, how to exercise rights under sections 6(4) and 13, and how to complain to the Board; section 5(2) requires a notice as soon as reasonably practicable for consent given before commencement; section 5(3) requires the option to access the notice in English or any Eighth Schedule language. Section 5 begins on Gazette page 4 and concludes on page 5.
- [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 6, p. 5. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 6: consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, limited to necessary data, as easy to withdraw as to give (6(4)); on withdrawal the fiduciary must cease and cause its processors to cease within a reasonable time (6(6)); the fiduciary bears the burden of proving notice and consent (6(10)). Section 6 begins on Gazette page 5 and concludes on page 6.
- [5]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 8: the general obligations, including responsibility for processing by processors irrespective of any agreement to the contrary (8(1)), engaging processors only under a valid contract (8(2)), completeness, accuracy and consistency where data feeds decisions or is disclosed to another fiduciary (8(3)), reasonable security safeguards (8(5)), breach intimation to the Board and each affected Data Principal (8(6)), erasure (8(7)), publishing contact details (8(9)) and grievance redressal (8(10)). Section 8 begins on Gazette page 7 and concludes on page 8.
- [6]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 9, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 9: verifiable consent of the parent or lawful guardian before processing a child's personal data (9(1)), no processing likely to cause detrimental effect on the well being of a child (9(2)), and no tracking, behavioural monitoring or targeted advertising directed at children (9(3)), with exemption powers in 9(4) and 9(5).
- [7]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 10: the Central Government may notify Significant Data Fiduciaries on factors including volume and sensitivity of data; an SDF must appoint an India based Data Protection Officer responsible to its board, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessments and audits. Section 10 begins on Gazette page 8 and concludes on page 9.
- [8]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 11, p. 9. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 11: right to obtain a summary of personal data and processing activities, and the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of the data shared. Section 11 begins on Gazette page 9 and concludes on page 10.
- [9]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 12, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Sections 12, 13 and 14 all appear on Gazette page 10: correction, completion, updating and erasure on request (12), readily available grievance redressal with response within a prescribed period and exhaustion before approaching the Board (13), and nomination (14).
- [10]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 33, p. 16. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 33: on conclusion of an inquiry, if the Board determines the breach is significant, it may, after giving the person an opportunity of being heard, impose the monetary penalty specified in the Schedule, having regard to the listed factors including nature, gravity and duration and mitigation. Section 33 begins on Gazette page 16 and concludes on page 17.
- [11]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), The Schedule Schedule, p. 21. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026The Schedule: penalties may extend to two hundred and fifty crore rupees for breach of the section 8(5) security safeguards obligation, two hundred crore rupees for breach of the section 8(6) intimation obligation, two hundred crore rupees for breach of section 9, one hundred and fifty crore rupees for breach of section 10, and fifty crore rupees for breach of any other provision of the Act or rules.
- [12]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 3, p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 3: the notice must stand alone, use clear and plain language, itemise the personal data, state the specified purposes and the goods or services or uses enabled, and give the communication link and other means to withdraw consent with comparable ease, exercise rights and complain to the Board. Rule 3 begins on Gazette page 24 and concludes on page 25.
- [13]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 6: reasonable security safeguards including at minimum measures such as encryption, obfuscation, masking or virtual tokens, access control, logs, monitoring and review, backups, one year retention of logs and personal data for detection and investigation of unauthorised access, contractual safeguard provisions with processors, and technical and organisational measures.
- [14]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 7: on becoming aware of a breach, intimation to each affected Data Principal without delay in a concise, clear and plain manner, and to the Board without delay, with updated and detailed information to the Board within seventy two hours of becoming aware or such longer period as the Board allows on a written request.
- [15]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, p. 27. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 8: timed erasure clocks for the classes of Data Fiduciaries and purposes specified in the Third Schedule, at least forty eight hours notice to the Data Principal before erasure under Rule 8(2), and a minimum one year retention of personal data, associated traffic data and logs of processing under Rule 8(3).
- [16]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 14: rights handling and grievance redressal, requiring publication of the means and particulars for exercising rights and of a response period not exceeding ninety days. Rule 14 begins on Gazette page 29 and its response period provision appears on page 30.
- [17]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026The obligations mapped in this article sit in the eighteen month commencement groups of G.S.R. 843(E) paragraph (c) and Rule 1(4) of the DPDP Rules 2025.
- [18]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026For the Act sections, the calendar date 13 May 2027 is computed from the publication date printed on Gazette issue No. 757, which carries commencement notification G.S.R. 843(E), and is presented as interpretation until officially confirmed.
- [19]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026For the Rules, the calendar date 13 May 2027 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.