Reference
DPDP frequently asked questions
Direct answers to the questions organisations and individuals ask most about the DPDP Act 2023 and the DPDP Rules 2025. Each answer below is the short version; the linked article carries the context, the what to do section and the official sources.
Applicability
Does the DPDP Act apply to B2B SaaS companies?
Usually yes, in two roles at once. For your own site visitors, trial users and account holders you decide the purposes, which makes you a Data Fiduciary with the full duty set. For your customers' end user data you process under instructions, which makes you a Data Processor, where the duties reach you mainly through the mandatory valid contract with your customer and the safeguards that must cover processing done on a fiduciary's behalf.
Does the DPDP Act apply to companies outside India?
It can. The Act applies to processing of digital personal data outside India if it is in connection with any activity related to offering goods or services to Data Principals within India, so a foreign company serving Indian users is reached. In the other direction, the Act largely steps back from Indian outsourcing: where personal data of people not in India is processed by a person based in India under a contract with a person outside India, most of the operational chapters are disapplied by the statutory exemption.
Does the DPDP Act apply to startups?
If your startup handles digital personal data in India, the Act's application section covers you: it applies to digital personal data processed within India, and there is no company size threshold in that section. Nothing in the rules on file gives small companies an automatic carve out, though the Act allows the government to notify exemptions for classes of Data Fiduciaries in future. Settle your position once with a traceable answer rather than assuming either way.
Current status
What is in force under the DPDP framework in 2026?
The DPDP Act 2023 was enacted on 11 August 2023 and its commencement was notified as G.S.R. 843(E) on 13 November 2025: the definitions and the Data Protection Board provisions operate now, while the main obligations and rights follow eighteen months after publication. The DPDP Rules 2025 were notified the same day, and Rules 1, 2 and 17 to 21 took effect at once. The main operational obligations in Rules 3, 5 to 16, 22 and 23 and the core Act sections follow eighteen months after publication, which computes to 13 May 2027, and the Consent Manager provisions follow one year after publication, which computes to 13 November 2026. The computed dates are interpretation until officially confirmed.
Definitions
Is a name or email address personal data under the DPDP Act?
Yes. The Act defines personal data as any data about an individual who is identifiable by or in relation to such data. A name identifies a person; an email address identifies and reaches a person; both are data about an identifiable individual. Handled digitally, they are digital personal data, which is what the Act applies to.
Consent
What is a Consent Manager under the DPDP framework?
A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact for individuals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Rule 4 sets up Board registration against the First Schedule conditions, which include incorporation in India and a net worth of at least two crore rupees, and the obligations include keeping consent records and being unable to read the personal data passing through. Rule 4 comes into force one year after the Rules publication, which computes to 13 November 2026, interpretation until confirmed.
What are the requirements for valid consent under the DPDP Act?
Consent must be free, specific, informed, unconditional and unambiguous, given with a clear affirmative action, and it covers only the personal data necessary for the specified purpose. Any part of consent infringing the Act or another law is invalid to that extent. Withdrawal must be as easy as giving consent, and after withdrawal the Data Fiduciary must stop processing and cause its processors to stop, within a reasonable time, unless another basis allows it. In a proceeding, the Data Fiduciary carries the burden of proving notice was given and consent taken.
Notice
What must a privacy notice contain under the DPDP Rules?
Under Rule 3, the notice must be understandable on its own, give in clear and plain language a fair account enabling specific and informed consent including at minimum an itemised description of the personal data and the specified purposes with a specific description of the goods, services or uses, and give the communication link and other means through which the person can withdraw consent as easily as they gave it, exercise their rights and complain to the Board.
Rights
How does grievance redressal work under the DPDP framework?
The Act gives every Data Principal a right to readily available grievance redressal from the Data Fiduciary or Consent Manager, and requires the grievance channel to be exhausted before approaching the Data Protection Board. Rule 14 requires publishing the response period, which must not exceed ninety days, backed by technical and organisational measures that make the system effective within it.
What rights do individuals have under the DPDP Act?
Four rights: access to a summary of your personal data, its processing and who it was shared with, and correction, completion, updating and erasure, both exercised against the Data Fiduciary you previously gave consent to; readily available grievance redressal against the Data Fiduciary or Consent Manager concerned, with a published response period capped at ninety days, to be exhausted before approaching the Board; and nomination of another individual to exercise your rights on your death or incapacity. The Act pairs these with duties, including not impersonating anyone and not filing false or frivolous complaints.
Children
What are the DPDP rules for processing children's personal data?
A child is anyone under eighteen. Before processing a child's personal data, verifiable consent of the parent or lawful guardian is required, with due diligence that the person consenting is an identifiable adult. The Act separately prohibits processing likely to cause detrimental effect on a child's wellbeing, and tracking, behavioural monitoring and targeted advertising directed at children. Exemptions exist for prescribed classes and purposes, subject to conditions, and deciding whether one fits you is legal judgment.
What does verifiable consent mean under the DPDP framework?
Verifiable consent is the consent required before processing personal data of a child or of a person with disability who has a lawful guardian: it must come from the parent or guardian. For parents, Rule 10 requires due diligence that the individual identifying as the parent is an adult who is identifiable, through two verification paths: reliable identity and age details already held, or details voluntarily provided directly or through a virtual token issued by an authorised entity, including via Digital Locker. For guardians, Rule 11 requires verifying court or authority appointment under guardianship law.
Security
What security safeguards does DPDP Rule 6 require?
Rule 6 requires reasonable security safeguards to prevent a personal data breach, and it names the minimums: data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; visibility over access through logs, monitoring and review; measures for continued processing such as backups; retention of logs and personal data for one year for detection and investigation; safeguard provisions in processor contracts; and technical and organisational measures for effective observance. The duty covers processing done on your behalf by a Data Processor.
Breach response
What does DPDP Rule 7 require after a personal data breach?
On becoming aware of a personal data breach, a Data Fiduciary must intimate each affected Data Principal without delay, in plain language, covering the breach, its likely consequences, the mitigation under way, the safety steps they can take and a contact who can answer questions. It must also intimate the Data Protection Board: a description without delay, then updated and detailed information within seventy two hours of becoming aware, unless the Board allows longer on a written request. Rule 7 is in the group of Rules due to come into force eighteen months after publication, which computes to 13 May 2027, interpretation until confirmed.
Retention
What does DPDP Rule 8 require for data retention and erasure?
Rule 8 has three mechanics. Data Fiduciaries of the classes in the Third Schedule must erase personal data for the listed purposes at the listed periods when the person neither returns for the purpose nor exercises rights, unless law requires retention. At least forty eight hours before that erasure completes, the person must be warned so they can keep their data alive by logging in or making contact. And personal data, traffic data and processing logs must be kept at least one year from processing for the Seventh Schedule purposes, then erased unless another law or government notification requires longer.
Transfers
Can personal data be transferred outside India under the DPDP framework?
Yes, by default. Rule 15 permits transfer subject to requirements the Central Government may specify by order about making personal data available to any foreign State or entities under its control, and section 16 lets the government restrict transfers to notified countries. No such restriction is on file on this site as of its verification date. Any Indian law with stronger transfer protection continues to apply, and localisation can reach Significant Data Fiduciaries for specified data.
Roles
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides the purpose and means of processing; a Data Processor processes on a Data Fiduciary's behalf. The roles attach per processing activity, so one company can be a fiduciary for its own users and a processor for client data at the same time. The fiduciary stays responsible for compliance even for processing done on its behalf, and it may engage a processor only under a valid contract.
Vendors
What does the DPDP framework require in a Data Processor contract?
Two anchors are explicit in the official text: a Data Fiduciary may engage a processor for activity related to offering goods or services only under a valid contract, and the reasonable security safeguards must include appropriate provisions in that contract for the processor to take reasonable safeguards. Around those anchors, the fiduciary's own duties make erasure flow down, one year log retention at the processor, and a contracted breach workflow the practical content of the agreement, because responsibility never transfers.
Compliance
What does a CTO need to build for DPDP compliance?
The obligations belong to your organisation, not to the CTO, but engineering usually leads the security safeguards, the retention and erasure timers with the forty eight hour warning, the one year log retention, breach detection, and the product surfaces for consent withdrawal and rights requests. Most CTO owned work depends on inputs from legal and compliance, so run it as one company plan with explicit dependencies rather than an engineering side quest.
How should a startup approach DPDP compliance?
Settle applicability once with a traceable answer, map what personal data you hold and why, then work five clusters in dependency order: the notice and consent surfaces, the security safeguard minimums, breach readiness, retention timers, and the rights and grievance machinery. The main operational duties compute to May 2027, a date that is interpretation until confirmed, which is runway a small team should spend deliberately.
What is a Significant Data Fiduciary and what extra duties apply?
A Significant Data Fiduciary is any Data Fiduciary or class the Central Government notifies as such, weighing factors the Act names: volume and sensitivity of data, risk to Data Principal rights, potential impact on sovereignty and integrity, electoral democracy, security of the State and public order. Once notified, you must appoint an India based Data Protection Officer answerable to your board who fronts grievance redressal, appoint an independent data auditor, and run periodic Data Protection Impact Assessments and audits; the Rules make that an annual cycle with significant observations reported to the Board, algorithmic due diligence and possible localisation restrictions.
Penalties
What are the penalties under the DPDP Act 2023?
Penalties under the DPDP Act 2023 are monetary, imposed by the Data Protection Board after an inquiry, and capped by the Act's Schedule. The highest cap is two hundred and fifty crore rupees for a Data Fiduciary failing its reasonable security safeguards obligation under section 8(5). Failing to notify a breach or breaching children's data obligations may each draw up to two hundred crore rupees, Significant Data Fiduciary obligations up to one hundred and fifty crore rupees, any other breach up to fifty crore rupees, and a Data Principal breaching statutory duties up to ten thousand rupees. These provisions sit in the commencement group due eighteen months from the notification gazette, which computes to 13 May 2027; that calendar date is interpretation until officially confirmed.
Every answer links to an article whose legal claims carry exact official source references. If your question is missing, the site search covers the Act, the Rules and every tool, and the corrections page is the fastest way to tell us what to add.