Reference
DPDP frequently asked questions
Direct answers to the questions organisations and individuals ask most about the DPDP Act 2023 and the DPDP Rules 2025. Search or browse by category, click a question to see the short answer, and follow through to the full article with official sources.
Applicability
Does the DPDP Act apply to AI training data?
The DPDP Act 2023 and the DPDP Rules 2025 never name artificial intelligence, machine learning or profiling. Each phrase appears 0 times in both. The framework still reaches AI, because section 2(x) defines processing as a wholly or partly automated operation on digital personal data and section 2(b) defines automated as any digital process capable of operating automatically, so training, indexing, storage and retrieval are processing whether or not anyone calls the system AI. The exclusion most often relied on is section 3(c)(ii), and it turns on who made the data public rather than on whether the data is public: it reaches personal data made publicly available by the Data Principal herself, or by a person under an obligation under a law in force in India to publish it, and a third party posting someone else's data is neither. The only provision that expressly names algorithmic software is Rule 13(3), which binds only a Significant Data Fiduciary, and as at 23 September 2026 none has been notified. There is no equivalent of a right against automated decision making anywhere in the Act. Section 3, section 9 and Rule 13 sit in the group due 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed. Section 2 is already in force.
What does section 17 of the DPDP Act exempt?
Once section 17 is in force, section 17(1) disapplies Chapter III, section 16 and Chapter II other than sections 8(1) and 8(5) in 6 named situations: enforcing a legal right or claim, judicial and regulatory functions, offence prevention and investigation, offshore contracts for Data Principals outside India, approved mergers and other corporate restructurings, and loan default checks. Section 17(2) removes the whole Act for notified State instrumentalities and for research, archiving or statistical processing that is not used to take any decision specific to a Data Principal and follows the Second Schedule standards. Section 17(3) and section 17(5) add relief that waits on a Central Government notification, while section 17(4) applies to State processing by force of the text. Section 17 commences on the computed date 13 May 2027, interpretation until officially confirmed.
Does the DPDP Act apply to B2B SaaS companies?
Usually yes, in 2 roles at once, and the 2 roles are not symmetrical. For your own site visitors, trial users and account holders you decide the purposes, which makes you a Data Fiduciary with the full duty set. For your customers' end user data you process on their behalf, which makes you a Data Processor, and here is the part most guidance gets wrong: almost nothing in either instrument is addressed to a Data Processor. Data Processor appears 9 times in the Act and 6 times in the English text of the Rules, and every one of those 15 mentions is addressed to the Data Fiduciary, telling it what to do about its processor. The exception is section 4(1), which is framed on any person who processes personal data rather than on the Data Fiduciary, so a processor is not outside the Act's reach. Otherwise the framework reaches a SaaS vendor through the contract its customer is required to have under section 8(2), and Rule 6(1)(f) will require that contract to carry security safeguard provisions. Section 8 and Rule 6 are in the group commencing 18 months after publication, computed as 13 May 2027 and interpretation until officially confirmed.
Does the DPDP Act apply to companies outside India?
Yes, once it commences. Section 3(b) applies the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering of goods or services to Data Principals within India, so a foreign company with Indian users is reached on the same test as an Indian one. 2 things almost every guide leaves out. First, section 3 is itself in the group commencing 18 months after publication of notification G.S.R. 843(E), computed as 13 May 2027 and interpretation until officially confirmed, so the provision that decides application is not in force today. Second, the Act creates no local presence duty at all: representative, subsidiary and branch office each appear 0 times in it, so there is nothing to register and, unless the Central Government notifies you as a Significant Data Fiduciary under section 10(1), nobody to appoint. The route against a company with no Indian assets is section 37, which lets the Central Government order blocking of public access to information in any computer resource that enables the company to carry on an activity relating to offering goods or services to Data Principals in India, but only on a reference from the Board after monetary penalty in 2 or more instances, and section 37 sits in the same 18 month group.
Does the DPDP Act apply to startups?
On the text, yes, and no size test stands between a startup and the Act. Section 3 applies the Act to the processing of digital personal data within India, and to processing outside India in connection with any activity related to offering goods or services to Data Principals in India, and its only exclusions turn on the kind of processing or on who published the data, never on the size of the organisation. The words turnover, revenue, headcount, small, micro, MSME and threshold appear 0 times in the Act and 0 times in the Rules. Size still decides which duties bite, in 3 places: the Third Schedule attaches the Rule 8(1) erasure timer to 3 classes defined by registered user counts, section 10(1)(a) makes the volume and sensitivity of personal data 1 of the factors behind a Significant Data Fiduciary notification, and section 33(2)(g) makes the likely impact of a penalty on the person a matter the Board weighs. Sitting below the Third Schedule counts is not relief: you keep the section 8(7) purpose test, and this site reads the Rule 8(3) minimum of 1 year as reaching a Data Fiduciary of any size. Section 17(3) names startups, but it is a power to switch off 5 provisions and no notification under it has been located. Section 3 commences 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.
Current status
Are the SPDI Rules 2011 still in force after the DPDP Act 2023?
Yes, on this site's reading of the Gazette prints, read as at 6 September 2026. The Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, notified as G.S.R. 313(E) on 11 April 2011, are made under section 87(2)(ob) read with section 43A of the Information Technology Act, 2000, and both of those provisions are still in the Act: section 44(2) of the DPDP Act 2023 directs their omission, and paragraph (c) of notification G.S.R. 843(E) puts section 44(2) in the group computed here as 13 May 2027, interpretation until officially confirmed. Rule 3 of those Rules is where the term sensitive personal data or information is defined in Indian law, in 8 clauses with a proviso, and the DPDP Act has no such category at all. Neither of the 2 things commonly said about these Rules is supported by the instruments on file: that the DPDP Act has already repealed them, and that they will be repealed on a printed statutory date.
Has the DPDP compliance deadline been cut from 18 months to 12 months?
No. As at the 6 September 2026 review, this site's source registry and timeline record no instrument amending the DPDP Act, the DPDP Rules or their commencement, so the 3 phase commencement set by G.S.R. 843(E) and Rule 1 of the DPDP Rules 2025, as corrected by corrigenda G.S.R. 892(E), still runs on the same 3 periods, whose calendar dates are computed and are interpretation until officially confirmed. What exists is reporting: Business Standard reported on 22 January 2026, on unnamed sources, that MeitY had proposed at a stakeholder meeting to shorten the window for Significant Data Fiduciaries, on certain provisions, from 18 months to 12. No MeitY document about the proposal has been located, across 3 enumerations of its whole published document library on 1, 4 and 6 September 2026.
Are the DPDP compliance deadlines 13 or 14 May 2027?
Both dates circulate because the notification date itself is recorded 2 ways. The masthead of Gazette issue No. 760 is printed 13 November 2025, while the eGazette file code stamped on that same issue, CG-DL-E-14112025-267650, and a Press Information Bureau release of 17 November 2025 state 14 November 2025. PIB then published 13 November 2025 for both the Act and the Rules on 3 December 2025, so the Government has stated both dates and cannot be cited in the singular for either. The Rules and the commencement notification set periods, not calendar dates: 1 year and 18 months from publication. Rule 1(3) and Rule 1(4), as corrected by corrigenda G.S.R. 892(E), run from the date of publication in the Official Gazette. So the main compliance date computes to 13 May 2027 from the printed date and 14 May 2027 from the file code. MeitY's own document library dates its copies of those instruments 14 November 2025 as well, but the same index dates the Act's 2023 Gazette print to its masthead on an identical 1 day split, and dates the December corrigenda to 16 December 2025, a day that instrument does not carry anywhere, so on our reading it is not a consistent record of any of a document's own dates. This site computes from the printed Gazette date and treats every computed date as interpretation until officially confirmed. Plan to the earlier date, because a 1 day ambiguity is not a reason to file late.
Is the DPDP Act being challenged in the Supreme Court?
Yes. Since February 2026 the Supreme Court of India has been hearing writ petitions challenging parts of the DPDP Act 2023 and the DPDP Rules 2025, led by Venkatesh Nayak v Union of India, W.P.(C) 177/2026. The petitions target sections 17(1)(c), 17(2), 33(1), 36 and 44(3) of the Act and Rules 17 and 23(2) of the Rules, on grounds under Articles 14, 19(1)(a) and 21 of the Constitution, with the substitution of the personal information clause in section 8(1)(j) of the RTI Act at the centre. On 16 February 2026 a bench led by Chief Justice Surya Kant issued notice but refused an interim stay, and on 7 August 2026 the court gave the Central Government 2 weeks to respond. No provision has been struck down or suspended as of 23 August 2026, so the commencement schedule stands: the main obligations still arrive on the computed date of 13 May 2027, which is interpretation until officially confirmed.
What is in force under the DPDP framework in 2026?
The DPDP Act 2023 was enacted on 11 August 2023 and its commencement was notified as G.S.R. 843(E) on 13 November 2025: the definitions, the sections establishing and constituting the Data Protection Board (sections 18 to 26) and certain other sections, including the rule making power, operate now, while the main obligations, the rights and the Board's inquiry and penalty powers follow 18 months after publication. The DPDP Rules 2025 were notified the same day, and Rules 1, 2 and 17 to 21 took effect at once. The main operational obligations in Rules 3, 5 to 16, 22 and 23 and the core Act sections follow 18 months after publication, which computes to 13 May 2027, and Rule 4 on Consent Manager registration and obligations, and sections 6(9) and 27(1)(d) of the Act, follow 1 year after publication, which computes to 13 November 2026. The computed dates are interpretation until officially confirmed.
Definitions
Does the DPDP Act classify sensitive personal data separately?
No. The DPDP Act 2023 has no category of sensitive personal data. The word sensitive does not appear anywhere in the Act, and section 3, which sets the Act's application, has only clauses (a), (b) and (c), so the section 3(d) cited by many articles for a sensitive data category does not exist. Personal data is defined once, in section 2(t), by identifiability alone. Higher duties do arise, but from who is processing and who the data is about rather than from a data type: notification as a Significant Data Fiduciary under section 10, the children's provisions in section 9, and the retention classes in the Third Schedule to the Rules. None of those provisions is in force yet: notification G.S.R. 843(E) and Rule 1(4) place them in the group commencing 18 months after publication, computed to 13 May 2027 and interpretation until officially confirmed, and no Significant Data Fiduciary had been notified as of 6 September 2026.
DPDP Act क्या है और कब से लागू होगा?
DPDP का फुल फॉर्म है Digital Personal Data Protection। डिजिटल वैयक्तिक डेटा संरक्षण अधिनियम, 2023 (Act No. 22 of 2023) भारत का डेटा संरक्षण कानून है, जिसे 11 अगस्त 2023 को राष्ट्रपति की स्वीकृति मिली। DPDP Rules 2025 इस कानून को लागू करते हैं और 13 नवम्बर 2025 को अधिसूचित हुए। यह कानून चरणों में लागू हो रहा है: कुछ प्रावधान 13 नवम्बर 2025 से लागू हैं, Consent Manager पंजीकरण की गणना की गई तारीख 13 नवम्बर 2026 है, और मुख्य दायित्व, जैसे नोटिस, सहमति, सुरक्षा उपाय और डेटा उल्लंघन की सूचना, गणना की गई तारीख 13 मई 2027 से लागू होंगे। गणना की गई तारीखें आधिकारिक पुष्टि होने तक व्याख्या मानी जाती हैं। जुर्माना अधिकतम 250 करोड़ रुपये तक हो सकता है, पर जुर्माना लगाने की धारा 33 भी तीसरे समूह में है और 4 सितम्बर 2026 को लागू नहीं है।
What is DPDP and what is its full form?
DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act 2023, Act No. 22 of 2023, is India's law for processing digital personal data; it received the President's assent on 11 August 2023 and recognises both the individual's right to protect personal data and the need to process it for lawful purposes. The DPDP Rules 2025, notified on 13 November 2025, operationalise the Act. Both commence in phases: some provisions have been in force since 13 November 2025, Consent Manager registration is due on a computed date of 13 November 2026, and the main obligations are due on a computed date of 13 May 2027, both interpretation until officially confirmed. Once section 3 is in force with the main obligations, the law applies to digital personal data processed in India, and to processing abroad in connection with any activity related to offering goods or services to people in India, but not to personal or domestic processing or to data made publicly available by the individual or under a legal duty (section 3(c)).
Is a name or email address personal data under the DPDP Act?
Usually yes in ordinary business records. The Act defines personal data as any data about an individual who is identifiable by or in relation to such data, so the test is identifiability, not a list of categories. Customer, employee and account records containing names or email addresses will ordinarily meet that test. Handled digitally, they are digital personal data, which is what the Act applies to.
Consent
What consent do I need to send marketing messages in India under the DPDP Act?
2 regimes apply and only 1 of them is in force. The Telecom Commercial Communications Customer Preference Regulations, 2018, made by TRAI, are in force and govern commercial communication, which regulation 2 defines as any voice call or message using telecommunication services sent for promotional purposes. The DPDP consent standard, section 6(1), governs the personal data used for marketing in any channel, but section 6 is in the group due 18 months after publication, computed as 13 May 2027 and interpretation until officially confirmed. So a business told to obtain DPDP compliant marketing consent today is being pointed at a provision that is not yet in force, while the regime already in force in this area is the telecom one, whose reach turns on the definition in regulation 2 as currently amended. The 2 are cumulative rather than alternative, because section 38(1) makes the DPDP Act additional to other law. The DPDP provision aimed at marketing that is a prohibition rather than a consent question is section 9(3), on tracking, behavioural monitoring and targeted advertising directed at children. On its face no consent unlocks it; the routes out are section 9(4) through Rule 12 and the Fourth Schedule, a section 9(5) notification and section 17. Section 9(2), barring processing likely to cause any detrimental effect on a child's well being, is also a prohibition, and Rule 12 does not lift it. Both commence with the same 18 month group as section 6.
Does the DPDP Act have deemed consent?
No. The phrase deemed consent appears nowhere in the Digital Personal Data Protection Act, 2023, and neither does legitimate interest. Clause 8 of the November 2022 draft Bill was headed Deemed consent, but that draft was a consultation document and the enacted Act replaced it with section 7, headed Certain legitimate uses, which lists 9 clauses, (a) to (i). Section 4 makes those legitimate uses 1 of only 2 lawful grounds for processing, the other being consent. Several categories the 2022 draft would have covered, including credit scoring and a general fair and reasonable purpose weighed against the Data Fiduciary's legitimate interests, are not in the Act at all, while others, such as recovery of debt and publicly available personal data, survive only in a different shape in section 17(1)(f) and section 3(c)(ii). Section 7 is in the group of provisions due to come into force 18 months after publication, which computes to 13 May 2027, interpretation until officially confirmed.
What is a Consent Manager under the DPDP Act and what are its obligations?
A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform (section 2(g)). Section 6 lets individuals route consent through one, makes it accountable to the Data Principal, acting on her behalf, and requires registration with the Board. Rule 4 supplies the machinery: Part A of the First Schedule sets registration conditions, including incorporation in India, sufficient technical, operational and financial capacity and a net worth of at least 2 crore rupees, and Part B sets obligations, including data blindness, consent records kept for at least 7 years, fiduciary duty, conflict of interest controls and Board supervised audits. Rule 4 commences on the computed date of 13 November 2026, interpretation until officially confirmed.
Do I need to register as a Consent Manager under DPDP?
Most ordinary businesses do not need to become a Consent Manager. Under the Act, a Consent Manager is a specific kind of registered intermediary: a person registered with the Data Protection Board that acts as a single point of contact for individuals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. That is different from using consent management software on your own website, which the framework does not require to be registered. Registration under Rule 4 is for organisations that want to operate such a platform, and the First Schedule conditions include being a company incorporated in India and a net worth of at least 2 crore rupees, with obligations including keeping consent records and being unable to read the personal data passing through. Rule 4 comes into force 1 year after the Rules publication, which computes to 13 November 2026, interpretation until officially confirmed.
What are the requirements for valid consent under the DPDP Act?
Once section 6(1) is in force, consent must be free, specific, informed, unconditional and unambiguous, given with a clear affirmative action, and it covers only the personal data necessary for the specified purpose. Any part of consent infringing the Act or another law is invalid to that extent. The consent request itself must be in clear and plain language, give the Data Principal the option to access it in English or any Eighth Schedule language, and carry a contact for exercising rights. Withdrawal must be possible at any time with comparable ease, and after withdrawal the Data Fiduciary must, within a reasonable time, stop processing and cause its processors to stop, unless the Act, the Rules or another law requires or authorises processing without consent. In a proceeding, the Data Fiduciary carries the burden of proving notice was given and consent taken. Section 6 is not in force: sub sections (1) to (8) and (10) sit in the 18 month commencement group, computed at 13 May 2027, and sub section (9) in the 1 year group, computed at 13 November 2026, both interpretation until officially confirmed.
Notice
Does the DPDP notice have to be in 22 languages?
No, not in the sense most vendor content suggests. Section 5(3) requires the Data Fiduciary to give the Data Principal the option to access the contents of the notice in English or any language specified in the Eighth Schedule to the Constitution. The option belongs to the individual: your obligation is to be able to serve the notice in whichever listed language a person opts for, not to present every notice in every language up front, and not to pick one language yourself. Section 6(3) attaches the same option to every consent request, and Rule 3 sets the quality bar of a standalone, clear and plain, itemised notice. Nothing in either instrument makes consent invalid because a person could not read the notice, and the Schedule's 250 crore cap is entry 1, for security safeguards under section 8(5); this site reads a language failure as falling to the residual entry 7, up to 50 crore, and only after the Board determines on inquiry that the breach is significant. Section 5, section 6(3) and Rule 3 all sit in 18 month commencement groups, computed to 13 May 2027, interpretation until officially confirmed.
What must a privacy notice contain under the DPDP Act and Rules?
2 provisions govern it and neither is in force yet. Section 5(1) of the Act says every consent request must be accompanied or preceded by a notice informing the individual of the personal data and the purpose it will be processed for, the manner of exercising her rights under section 6(4) and section 13, and the manner of complaining to the Board. Rule 3 then sets the shape: the notice must be understandable independently of any other information the fiduciary has made available, must give in clear and plain language a fair account enabling specific and informed consent including at minimum an itemised description of the personal data and the specified purpose or purposes with a specific description of the goods, services or uses, and must give the particular communication link and a description of other means, if any, through which the person can withdraw consent with ease comparable to the ease with which she gave it, exercise her rights and complain to the Board. Section 5 sits in the 18 month commencement group of notification G.S.R. 843(E) and Rule 3 in the 18 month group of Rule 1(4).
Rights
Can I sue a company under the DPDP Act for a data breach?
No. On this site's reading of the Gazette prints, read as at 7 September 2026, the DPDP Act 2023 gives a Data Principal no right of action and no compensation: the words compensation, compensate, damages and damage appear 0 times in the Act and 0 times in the English section of the DPDP Rules 2025. What the Act offers instead is a complaint to the Data Protection Board, and section 34 sends any penalty the Board imposes to the Consolidated Fund of India rather than to the person affected. Even that route is shut today, because no part of section 27 is in force and sections 28 to 34, which carry the Board's inquiry and penalty powers, are in the group computed here as commencing 13 May 2027, which is interpretation until officially confirmed. The older route under section 43A of the Information Technology Act, 2000 has not been omitted, because section 44(2) of the DPDP Act directs that omission and sits in the same group; on the India Code consolidated print dated as on 27 June 2025 that this site holds, a section 43A claim is decided by an adjudicating officer under section 46 where the claim does not exceed Rs 5 crore, and by the competent court above that, rather than by a civil suit. Section 43A itself states no ceiling, and the twenty five thousand rupee figure sometimes attached to it was section 45's residuary amount until 30 November 2023.
How does grievance redressal work under the DPDP framework?
Once section 13 is in force, the Act gives every Data Principal a right to readily available grievance redressal from the Data Fiduciary or Consent Manager, and requires the grievance channel to be exhausted before approaching the Data Protection Board. Rule 14(3) is the only place a period appears in the rights and grievance rules, 90 days, and as printed the sentence has no object for "publish", so what the words "not exceeding ninety days" cap is not stated. 2 readings are open: that they cap the response period the fiduciary must publish, or that they are a time limit on the publishing itself. This site takes the first, because the second half of the same sub rule then uses "such period" for responding, which the earlier words can only supply if they are a response period; that is this site's reading and not what the text states. Section 13 and Rule 14 are both in the 18 month commencement group, computed at 13 May 2027 and interpretation until officially confirmed.
What rights do individuals have under the DPDP Act?
Once Chapter III of the Act is in force, it carries 4 rights, and section 6(4) carries a fifth that sits outside the chapter. Section 11 is the right to obtain a summary of your personal data and of the processing, the identities of all other Data Fiduciaries and Data Processors it was shared with, and a description of what was shared, except, under section 11(2), sharing on a written request with a Data Fiduciary authorised by law for the prevention, detection or investigation of offences or cyber incidents, or prosecution or punishment of offences. Section 12 is the right to correction, completion, updating and erasure, but under section 12(3) erasure yields where retention is necessary for the specified purpose or for compliance with law. Section 13 is the right to readily available grievance redressal from the Data Fiduciary or Consent Manager, which must be exhausted before approaching the Board. Section 14 is the right to nominate another individual to exercise the rights on death or incapacity. Section 6(4) is the right to withdraw consent at any time, with ease comparable to the ease with which it was given. Sections 11 to 15 and section 6(4) all sit in the 18 month commencement group of notification G.S.R. 843(E), so none of them binds anyone as at 29 September 2026. Sections 11 and 12 are written with a consent gate, and whether they reach processing on the section 7 legitimate uses other than clause (a) is unsettled.
Children
What does the DPDP Act require from schools and edtech companies?
Once section 9 is in force: verifiable parental consent before processing a child's data, no processing likely to harm a child's wellbeing, and no tracking, behavioural monitoring or targeted advertising directed at children. Rule 12 and the Fourth Schedule lift only sections 9(1) and 9(3), only for listed classes and purposes, and only on the printed condition: an educational institution is covered for tracking and behavioural monitoring for educational activities or enrolled child safety. On this site's reading, admissions, fees and photographs keep the consent duty, fees subject to Part B item 2 where the State provides a benefit under section 7(b). Section 9(2) is never lifted by Rule 12 or the Fourth Schedule. Section 9 and Rules 10 and 12 are not in force and commence 18 months after publication, computed 13 May 2027, interpretation until officially confirmed.
What does the DPDP Act require for processing children's data?
A child is an individual who has not completed the age of eighteen years. Section 9 sets 3 duties: obtain verifiable consent of the parent or lawful guardian before processing any personal data of a child, never process in a way likely to cause a detrimental effect on a child's wellbeing, and never undertake tracking, behavioural monitoring or targeted advertising directed at children. Rule 10 supplies the consent mechanics: due diligence that the person consenting is an identifiable adult, checked against details the Data Fiduciary already holds, details voluntarily provided, or a virtual token issued by an authorised entity. Rule 12 and the Fourth Schedule exempt listed classes and purposes, healthcare and education among them, from the consent and tracking duties only, under strict conditions. These duties commence on the computed date of 13 May 2027, interpretation until officially confirmed.
What does verifiable consent mean under the DPDP framework?
Verifiable consent is the consent that, once section 9 is in force, a Data Fiduciary must obtain from a parent or lawful guardian before processing the personal data of a child or of a person with disability who has a lawful guardian. The term is defined by cross reference: Rule 2(1)(d) says it means a consent as specified in rule 10 or 11, so its content is whatever those rules require. For a parent, Rule 10 requires appropriate technical and organisational measures plus due diligence that the individual identifying herself as the parent is an adult, identifiable if required in connection with compliance with any law in force in India, by reference to either identity and age details the Data Fiduciary already reliably holds, or details voluntarily provided, directly or through a virtual token issued by an authorised entity. Adult means having completed 18 years. For a lawful guardian, Rule 11 requires verifying appointment by a court, a designated authority or a local level committee under the applicable guardianship law. Section 9 and Rules 10 and 11 are all in 18 month commencement groups, computed as 13 May 2027 and interpretation until officially confirmed.
Security
What security safeguards does DPDP Rule 6 require?
Once Rule 6 is in force, it requires reasonable security safeguards to prevent a personal data breach, and it names the minimums: data security measures such as encryption, obfuscation, masking or virtual tokens; access control on computer resources; visibility over access through logs, monitoring and review; measures for continued processing such as backups; retention of such logs and personal data for 1 year for detection and investigation, unless compliance with any law for the time being in force requires otherwise; safeguard provisions in processor contracts; and technical and organisational measures for effective observance. The duty covers processing done on your behalf by a Data Processor. Rule 6 is not in force yet: it sits in the group commencing 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.
Breach response
डेटा ब्रीच हो जाए तो DPDP के तहत क्या करना होगा?
आज के दिन CERT In की 6 घंटे की रिपोर्टिंग लागू है, DPDP की 72 घंटे की सूचना नहीं। DPDP नियम 7 के लागू होने पर Data Fiduciary को हर प्रभावित Data Principal को बिना देरी के सूचित करना होगा, और Data Protection Board को 2 चरणों में: पहले बिना देरी के भंग का विवरण, फिर 72 घंटों के भीतर विस्तृत जानकारी। नियम 7 और धारा 8(6) 18 महीने वाले समूह में हैं, गणना की गई तारीख 13 मई 2027, जो आधिकारिक पुष्टि तक व्याख्या है।
What should my organisation do after a personal data breach?
Once Rule 7 of the DPDP Rules 2025 is in force, 2 legal clocks start the moment your organisation becomes aware of a personal data breach. First, as a matter of practice rather than of Rule 7, contain the incident, record the exact awareness time and instruct your Data Processors, because section 8 keeps you responsible for their processing. Then run 2 duties in parallel, both without delay: intimate each affected Data Principal in plain language with 5 required contents, and send the Data Protection Board a description of the breach. Within 72 hours of awareness, file the detailed Board submission with its 6 required contents; a longer period needs the Board's permission on a written request. Afterwards, again as practice rather than as a requirement of Rule 7, verify the fix, preserve the record, and be ready for a possible Board inquiry. Rule 7 sits in the commencement group computed to 13 May 2027, interpretation until officially confirmed, and building the workflow before the duty begins is the practical move.
Is the data breach reporting deadline in India 72 hours or 6 hours?
Both, because they are 2 separate legal regimes with different recipients. Under Rule 7 of the DPDP Rules 2025, once it is in force, a Data Fiduciary must intimate each affected Data Principal and send the Data Protection Board a description of the breach without delay, then file detailed information with the Board within 72 hours of becoming aware, or any longer period the Board allows on a written request. Separately, under the CERT In directions of 28 April 2022 issued under the IT Act, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents listed in Annexure I, which includes data breach and data leak, to CERT In within 6 hours of noticing them. The DPDP duty is in the commencement group computed to 13 May 2027, interpretation until officially confirmed; the CERT In duty is already in effect: the directions took effect 60 days after issue, and on 25 September 2022 for MSMEs.
What does DPDP Rule 7 require after a personal data breach?
Once Rule 7 of the DPDP Rules 2025 is in force, a Data Fiduciary that becomes aware of a personal data breach must intimate each affected Data Principal without delay, in plain language, covering the breach, its likely consequences, the mitigation under way, the safety steps they can take and a contact who can answer questions. It must also intimate the Data Protection Board: a description without delay, then updated and detailed information within 72 hours of becoming aware, unless the Board allows longer on a written request. Rule 7 is in the group of Rules due to come into force 18 months after publication, which computes to 13 May 2027, interpretation until officially confirmed.
Retention
How long can you keep personal data under the DPDP Act?
There is no DPDP retention period. The phrases retention period, retention policy, retention schedule and data retention appear 0 times in the Act and 0 times in the Rules. What the framework sets instead is a purpose test in section 8(7): erase personal data on withdrawal of consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with any law in force. Rule 8(1) adds 1 deemed timer of 3 years of inactivity, and it binds only the 3 classes in the Third Schedule, being large ecommerce entities, online gaming intermediaries and social media intermediaries above the stated user thresholds. Rule 8(2) requires a warning at least 48 hours before that erasure. 2 separate sub rules then require you to keep data rather than erase it: Rule 6(1)(e) holds security logs and personal data for 1 year, and Rule 8(3) holds personal data, traffic data and processing logs for a minimum of 1 year for the Seventh Schedule purposes. Section 8 and Rules 6 and 8 all sit in the group due 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.
Transfers
What is the difference between DPDP and GDPR?
The DPDP Act 2023 and the GDPR solve the same problem with different machinery. DPDP covers digital personal data with 2 grounds for processing, consent or certain legitimate uses, while the GDPR lists its lawful bases in Article 6(1). DPDP caps penalties per breach category at fixed rupee amounts up to Rs 250 crore, while GDPR fines scale with global turnover. DPDP treats everyone under 18 as a child and requires verifiable parental consent, subject to the exemptions under section 9(4) and Rule 12; the GDPR Article 8 baseline for consent to information society services is 16, which member states may lower to 13. DPDP has a registered Consent Manager institution with no GDPR equivalent, notifies every affected person of any breach without a risk threshold, and channels complaints through the Data Protection Board after the fiduciary's own grievance process. None of the DPDP obligations compared here is in force as at 29 September 2026: Consent Manager registration under Rule 4 and section 6(9) is computed to commence 13 November 2026 and the rest 13 May 2027, interpretation until officially confirmed, and the GDPR positions are orientation pointers to the official EUR Lex text rather than claims to rely on. A GDPR programme is a strong starting point, but it does not satisfy DPDP by default.
Does the DPDP framework require data localisation, and can personal data be transferred outside India?
Transfer is permitted by default. Rule 15 says personal data processed under the Act may be transferred outside the territory of India, subject to meeting requirements the Central Government may specify by general or special order about making that data available to a foreign State, or to any person or entity under the control of or any agency of such a State. Section 16(1) is a separate power to restrict transfer to notified countries, a negative list rather than an approved list, and we have located no such notification. The common claim that the framework contains no localisation requirement is wrong on 1 point: Rule 13(4) requires a Significant Data Fiduciary to undertake measures to ensure that personal data specified by the Central Government, on a committee's recommendation, and the traffic data about its flow, is not transferred outside the territory of India. No such specification has been located, so nothing is operative yet. Section 16(2) separately preserves any Indian law giving higher protection or a stronger transfer restriction. Section 16 and Rules 13 and 15 are all in the group due 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.
Roles
What are my obligations if I am a Data Processor under the DPDP Act?
Fewer than you expect from the Act, and more than nothing. Data Processor appears 9 times in the DPDP Act 2023 and 6 times in the English text of the DPDP Rules 2025, and every one of those 15 mentions is addressed to the Data Fiduciary, telling it what to do about its processor. Neither instrument contains a sentence beginning A Data Processor shall. You are not outside the Act though: section 4(1) is framed on a person rather than on a Data Fiduciary, and section 2(s) defines person to include a company, so whether it binds a processor acting on instructions is an open question. What binds you today is not DPDP: the CERT In directions of 2022 require a body corporate to report listed cyber incidents within 6 hours, and where you handle sensitive personal data or information the Information Technology SPDI Rules 2011 place duties on a body corporate and on any person acting on its behalf, on this site's reading of that print. Both have been in force for years. Everything else reaches you through the contract your customer must have under section 8(2), which Rule 6(1)(f) will require to carry security safeguard provisions. Section 4, section 8 and Rule 6 are in the groups commencing 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary is any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. That is the test, and it turns on decision rather than possession: nothing in either definition asks who holds the data, whose servers it sits on, who signed the contract or who is larger. On our reading, the roles attach to a processing activity and not to a company, so one organisation can be a Data Fiduciary for its own customers and a Data Processor for its clients' data at the same time. Once in force, section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary, so the label decides who answers for the processing but never moves the responsibility. Section 2, which carries both definitions, has been in force since 13 November 2025. Section 8, which carries the duties that make the distinction bite, sits in the 18 month commencement group, computed as 13 May 2027, which is interpretation until officially confirmed.
Vendors
What clauses need to be included in a Data Processing Agreement (DPA) under the DPDP Act?
Only a few points are official, and none of them binds anybody yet. Section 8(2) lets a Data Fiduciary engage a Data Processor for activity related to offering goods or services only under a valid contract, section 8(1) keeps the fiduciary responsible for processing done on its behalf irrespective of any agreement to the contrary, section 8(7)(b) requires the fiduciary to cause the processor to erase data, section 6(6) requires it to cause its processors to cease processing when consent is withdrawn, and Rule 6(1)(f) requires appropriate contract provisions for reasonable security safeguards. Everything else in a typical DPA, such as instruction limits, subprocessor approval, audit rights, indemnity, return of data and fixed notification windows, is sensible drafting that operationalises the fiduciary's own duties, not statutory text. No provision fixes a processor to fiduciary breach notification deadline; the 72 hour clock under Rule 7 is the fiduciary's own duty to the Board. Section 6, section 8 and Rules 6 and 7 all sit in 18 month commencement groups, G.S.R. 843(E) paragraph (c) for the sections and Rule 1(4) for the Rules, computed as 13 May 2027 and interpretation until officially confirmed, so no clause listed here is required of anybody today.
Do I need a contract before engaging a Data Processor under DPDP?
Yes, once section 8(2) commences, and only for activity related to offering goods or services to Data Principals. 2 anchors are explicit in the official text: a Data Fiduciary may engage a processor for activity related to offering goods or services only under a valid contract, and the reasonable security safeguards must include appropriate provisions in that contract for the processor to take reasonable safeguards. Around those anchors, the fiduciary's own duties make erasure flow down, 1 year log retention at the processor, and a contracted breach workflow the practical content of the agreement, because responsibility never transfers. None of it binds anyone yet: section 8 sits in the 18 month commencement group of notification G.S.R. 843(E) and Rules 6 and 8 in the 18 month group of Rule 1(4), computed as 13 May 2027, which is interpretation until officially confirmed.
Compliance
Who must appoint a Data Protection Officer under the DPDP Act?
Once section 10 is in force, only a Significant Data Fiduciary, notified by the Central Government under section 10, must appoint a Data Protection Officer. Section 10(2)(a) requires an individual who represents the fiduciary, is based in India, is responsible to its Board of Directors or similar governing body, and is the point of contact for grievance redressal. Every other Data Fiduciary, unless a section 17 exemption applies, will owe in place of any appointment duty the section 8(9) and Rule 9 duty to publish the business contact information of a person able to answer questions about the processing. No Significant Data Fiduciary had been notified as of 24 August 2026, and sections 8(9) and 10 and Rule 9 commence on the computed date 13 May 2027, interpretation until officially confirmed.
What are the essential compliance requirements for a business under the DPDP Act?
A business that determines why and how digital personal data is processed is a Data Fiduciary. Its core duties: process only on consent or a section 7 legitimate use (section 4), give a Rule 3 notice with every consent request (section 5), meet the section 6 consent standard, and carry the section 8 obligations, including valid processor contracts, completeness, accuracy and consistency where data is likely to feed a decision that affects the individual or be disclosed to another Data Fiduciary, security safeguards detailed by Rule 6, breach intimation to affected individuals and the Board with detailed Board information within 72 hours, or such longer period as the Board allows on a written request, under Rule 7, and erasure when consent is withdrawn or the purpose is spent, unless retention is necessary for compliance with law. Add the section 8(9) duty to publish a contact, with the Rule 9 mechanics, rights handling under Rule 14, whose sub rule (3), on our reading printed with a word missing, ties a reasonable period not exceeding 90 days to responding to grievances, section 9 children's duties, section 10 Significant Data Fiduciary duties where notified, and the section 16 and Rule 15 position on transfers outside India. Not 1 of these duties is in force: read as at 29 September 2026, they all sit in 18 month commencement groups computed at 13 May 2027, interpretation until officially confirmed.
Who needs a data protection audit under the DPDP Act and what must it cover?
Once section 10 and Rule 13 are in force, only a Significant Data Fiduciary, meaning a Data Fiduciary or class notified by the Central Government under section 10, must be audited. Section 10(2)(b) requires it to appoint an independent data auditor who shall evaluate its compliance in accordance with the provisions of the Act, and section 10(2)(c) adds a periodic audit alongside the periodic Data Protection Impact Assessment. Rule 13 sets the cadence: a DPIA and an audit once in every period of 12 months from notification, with a report containing significant observations furnished to the Data Protection Board. The report carries significant observations and not material observations: the word material appears in neither instrument in connection with it. Neither section 10 nor Rule 13, as published on 13 November 2025, prescribes auditor qualifications, an audit standard or a report format. Section 10 and Rule 13 commence on the computed date of 13 May 2027, interpretation until officially confirmed, and no Significant Data Fiduciary has been notified as of 2 September 2026.
What are the additional obligations of a Significant Data Fiduciary under the DPDP Act?
Once section 10 is in force, section 10(2) adds 3 duties for a Data Fiduciary or class the Central Government notifies as significant. First, appoint a Data Protection Officer who represents the organisation, is based in India, is responsible to the board of directors or similar governing body, and is the contact point for grievance redressal. Second, appoint an independent data auditor to evaluate compliance with the Act. Third, undertake periodic Data Protection Impact Assessments and periodic audits. Rule 13 turns periodic into a cycle of once every 12 months from notification, requires the person conducting the DPIA and audit to report significant observations to the Data Protection Board, adds due diligence over algorithmic software, and enables localisation of specified personal data. No Significant Data Fiduciary had been notified as of 23 August 2026, and section 10 and Rule 13 commence on the computed date 13 May 2027, interpretation until officially confirmed.
Who must conduct a Data Protection Impact Assessment (DPIA) under the DPDP Act?
Once section 10 and Rule 13 are in force, only a Significant Data Fiduciary, meaning a Data Fiduciary or class of Data Fiduciaries notified by the Central Government under section 10, must conduct a Data Protection Impact Assessment. Section 10(2)(c)(i) defines the DPIA as a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to those rights, and such other matters as may be prescribed. Rule 13 requires the DPIA and an audit once in every period of 12 months from notification, and a report containing significant observations must be furnished to the Data Protection Board of India. There is no high risk trigger for other Data Fiduciaries: an organisation that has not been notified has no DPIA duty under the DPDP Act. Section 10 and Rule 13 commence on 13 May 2027, a computed date that is interpretation until officially confirmed, and no notification of a Significant Data Fiduciary has been located as of 21 September 2026.
Does the DPDP Act require employee consent for HR data processing?
Not for core employment purposes. Section 7(i) of the DPDP Act 2023 lists employment among the certain legitimate uses for which personal data may be processed without consent: for the purposes of employment or those related to safeguarding the employer from loss or liability, such as preventing corporate espionage, maintaining confidentiality of trade secrets, intellectual property or classified information, or providing a service or benefit sought by an employee. Payroll, attendance and core HR administration sit naturally inside that ground. But the exemption is purpose based, not a blanket for anything touching staff: processing outside employment purposes, such as selling employee data or unrelated marketing, needs its own ground, and the fiduciary obligations of section 8, including security safeguards, breach intimation and erasure, apply to employee data regardless of the ground. These provisions sit in the commencement group computed to 13 May 2027, interpretation until officially confirmed.
How can a small business comply with the DPDP Act?
Work 10 steps before the main obligations commence on the computed date of 13 May 2027, interpretation until officially confirmed: check the Act applies to you under section 3, map what personal data you hold and why, assign each purpose a ground under section 4 (consent or a section 7 legitimate use), build the Rule 3 notice, make consent meet section 6, set security safeguards per Rule 6, prepare the Rule 7 breach workflow, set retention and erasure under section 8(7) and Rule 8, stand up rights handling and grievance redressal, where Rule 14(3) names 90 days without stating what they cap, and put a valid contract behind every Data Processor that processes personal data on your behalf, under section 8(2). There is no small business exemption in the Act's application section, though section 17(3), in the group computed to commence 13 May 2027, interpretation until officially confirmed, lets the Central Government notify certain Data Fiduciaries or classes, including startups, to whom section 5, sections 8(3) and 8(7), and sections 10 and 11 shall not apply.
What does a CTO need to build for DPDP compliance?
The obligations belong to your organisation, not to the CTO, but engineering usually leads the security safeguards, the retention and erasure timers with the 48 hour warning where the Third Schedule applies, the minimum 1 year log retention, breach detection, and the product surfaces for consent withdrawal and rights requests. Most CTO owned work depends on inputs from legal and compliance, so run it as one company plan with explicit dependencies rather than an engineering side quest. None of the rules behind this list is in force as at 29 September 2026: Rules 3, 6, 7, 8 and 14 sit in the group computed to commence 13 May 2027, interpretation until officially confirmed.
How should a startup approach DPDP compliance?
Settle applicability once with a traceable answer, map what personal data you hold and why, then work 5 clusters in dependency order: the notice and consent surfaces, the security safeguard minimums, breach readiness, retention timers, and the rights and grievance machinery. The main operational duties compute to May 2027, a date that is interpretation until confirmed, which is runway a small team should spend deliberately.
What is a Significant Data Fiduciary and is there a user or revenue threshold?
A Significant Data Fiduciary is any Data Fiduciary or class the Central Government notifies as such under section 10 once that section is in force, on an assessment of such relevant factors as it may determine, including volume and sensitivity of data, risk to Data Principal rights, potential impact on sovereignty and integrity, risk to electoral democracy, security of the State and public order. No numeric threshold exists in the official text: the Act sets no user count, revenue figure or employee number for SDF status, and no Data Fiduciary or class had been notified as an SDF as of 23 August 2026. Vendor checklists quoting 50 lakh users or revenue triggers have no basis in the official text; the only registered user thresholds in the framework sit in the Third Schedule and govern retention clocks under Rule 8, not SDF status. Once notified, and from section 10's computed commencement date of 13 May 2027, interpretation until officially confirmed, an SDF must appoint an India based Data Protection Officer answerable to its board, appoint an independent data auditor, and run a Data Protection Impact Assessment and audit every 12 months.
Penalties
What did the Jan Vishwas (Amendment of Provisions) Act, 2023 change in the Information Technology Act, 2000?
On the Gazette prints on file, read as at 6 September 2026: entry 32 of the Schedule to the Jan Vishwas (Amendment of Provisions) Act, 2023 amends the Information Technology Act, 2000 in 11 lettered limbs carrying 16 directions, which the India Code consolidated print of that Act records as taking effect on 30 November 2023. In 5 provisions the sanction stops being imprisonment and becomes a monetary penalty, but in 2 of those 5, section 33(2) and section 68(2), the words shall be guilty of an offence survive untouched, so on this site's reading decriminalisation is exact for 3 of the 5 and an approximation for the other 2. All 3 money figures in section 44 are multiplied by 10, the section 70B(7) fine ceiling for failing to comply with a CERT In direction goes from one lakh to one crore while its imprisonment limb is untouched, and section 66A, struck down by the Supreme Court in 2015, is omitted from the Act. Entry 32 does not name section 43A, section 43 or the SPDI Rules 2011, and the Jan Vishwas Act 2023 does not mention the Digital Personal Data Protection Act, 2023 anywhere in its 72 pages. A second Jan Vishwas Act, Act No. 8 of 2026, does not amend the Information Technology Act, 2000 either: the strings Information Technology and 21 of 2000 appear 0 times across its whole 186 page print, searched on 6 September 2026.
How does the Data Protection Board handle complaints and impose penalties?
Section 27 lists 5 triggers, including a Data Principal's complaint. Under section 28 the Board is, as far as practicable, a digital office, decides whether there are sufficient grounds, then inquires following the principles of natural justice. Rule 19(9), in force since 13 November 2025 under Rule 1(2) though the Board inquiries it times have not commenced, allows 6 months, extendable by 3 months at a time. Section 33(2) lists 7 matters for sizing a penalty. Appeal lies to the TDSAT within 60 days; neither text requires a deposit, checked 24 August 2026. Read as at 3 September 2026 not 1 step of this pipeline under the Act is in force: section 13, section 27 except clause (1)(d) and sections 28 to 34 all sit in the 18 month group of notification G.S.R. 843(E), computed 13 May 2027, interpretation until officially confirmed. Clause (1)(d) is in the 1 year group, computed 13 November 2026, likewise interpretation until officially confirmed.
What are the penalties under the DPDP Act 2023?
Once section 33 is in force, penalties under the DPDP Act 2023 are monetary, imposed by the Data Protection Board after an inquiry, and capped by the Act's Schedule. The highest cap is 250 crore rupees for a Data Fiduciary failing its reasonable security safeguards obligation under section 8(5). Failing to notify a breach or breaching children's data obligations may each draw up to 200 crore rupees, Significant Data Fiduciary obligations up to 150 crore rupees, any other breach up to 50 crore rupees, and a Data Principal breaching statutory duties up to 10,000 rupees. These provisions sit in the commencement group due 18 months from the notification gazette, which computes to 13 May 2027; that calendar date is interpretation until officially confirmed. As at 3 September 2026, no penalty could be imposed on anybody, for 2 independent reasons: section 33 had not commenced, and no appointment of a Chairperson or Member of the Board had been located on official channels.
What is a voluntary undertaking under the DPDP Act?
A voluntary undertaking is a commitment that, once section 32 is in force, the Data Protection Board may accept from any person at any stage of a proceeding under section 28. It can commit the person to take an action within a set time, to refrain from an action, or to publicise the undertaking, and the Board can vary its terms with the person's consent. Acceptance bars proceedings under the Act as regards the contents of the undertaking. If the person then fails to adhere to any term, the failure is deemed a breach of the Act and the Board may, after giving the person an opportunity of being heard, proceed in accordance with section 33; the Schedule caps that penalty at the amount applicable to the breach for which the original proceedings were instituted. Section 32 sits in the commencement group due 18 months from the notification gazette, computed as 13 May 2027, which is interpretation until officially confirmed.
Official documents
What did corrigenda G.S.R. 892(E) change in the DPDP Rules 2025?
Corrigenda G.S.R. 892(E), notified 10 December 2025 and published in Gazette issue No. 806 of 11 December 2025, corrects notification G.S.R. 846(E) at 5 places: Gazette pages 24, 29, 32, 34 and 38. Those 5 items carry 8 separate corrections. The corrigenda names pages and lines and never names a rule; read against the Gazette print they land on Rule 1(3), Rule 1(4), Rule 13(5), Rule 23(1), the First Schedule and the Fourth Schedule. 7 of the 8 are substitutions, a named string replaced by another. The 8th, item (v)(b), names a range of lines and a range of labels rather than a string, and this site reads it as a renumbering instruction: the Fourth Schedule Note as printed lists 2 items lettered (a), and on that reading it runs (a) to (g) after the corrigenda, which is an interpretation until officially confirmed. No period in Rule 1 changes, and on the same reading no obligation is added or removed.
Enforcement
Is the Data Protection Board of India operational?
No, and for 2 independent reasons that are usually run together. First, no appointment of a Chairperson or of any Member has been located in the primary record: the Board was established on 13 November 2025 by notification G.S.R. 844(E), MeitY was still inviting applications by a circular of 6 May 2026, and no appointment notification had been located as at 28 August 2026. Second, the Board's enforcement powers are not in force. Notification G.S.R. 843(E) commenced sections 18 to 26, which constitute the Board, on publication on 13 November 2025, and placed section 27, which carries its powers and functions, in the 18 month group, computed here as 13 May 2027 and interpretation until officially confirmed; the one exception is clause (d) of section 27(1), on breach of a Consent Manager's registration conditions, which is in the 1 year group, computed as 13 November 2026 and interpretation until officially confirmed. So appointing members would not by itself create a complaint route.
Every answer links to an article whose legal claims carry exact official source references. If your question is missing, the site search covers the Act, the Rules and every tool, and the corrections page is the fastest way to tell us what to add.