Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Tool

Build your company's DPDP compliance plan

Answer a few questions and get 1 organisation level compliance checklist with owners, dependencies and official sources. Your role decides what you see first, never what the company owes. Answers and progress stay in your browser.

Loading your saved answers from this browser…

Plans are decided by the Compliance Plan rules pack, version 1. Identical answers always produce identical plans.

What this tool asks

  1. What should we call your organisation?Optional. Used only to label your plan on this device. It never leaves your browser.
  2. Does your organisation handle information about identifiable people?For example names, phone numbers, email addresses, delivery addresses, account details, photos or employee records. Customers, users, employees and vendors all count.
  3. Is any of that information handled on computers or phones?Includes information collected on paper and typed into a computer later. Spreadsheets, apps, email and cloud services all count.
  4. Where does your organisation operate?
  5. Is this information handled only by one individual for personal or family matters?For example a personal contact list or family photo collection. Answer no if any of it is for business, work or an organisation.
  6. Can people under 18 use your service or appear in your data?
  7. What is your role, so we can show your work first?This only changes the ordering and framing of results. The organisation's obligations stay the same whoever is reading.

The company actions the plan draws from

  • Map what personal data you hold and why
  • Draft the standalone plain language notice
  • Ship consent withdrawal and complaint paths
  • Implement the minimum security safeguards
  • Put safeguard terms in processor contracts
  • Build the breach response runbook
  • Stand up the Board intimation process
  • Design the retention and erasure schedule
  • Build erasure timers and the forty eight hour warning
  • Publish the contact for processing questions
  • Publish rights request channels and identifiers
  • Stand up grievance handling within a published period
  • Support nomination in your rights flow
  • Build verifiable parental consent for children
  • Verify lawful guardians where they consent for others
  • If notified as significant: annual assessment and audit cycle

The provisions this tool rests on

The provisions below are the sources for the legal statements on this page. Each links to the official document it was verified against, and to the provision on this site wherever this site publishes that provision. The label says whether the site is reporting a requirement, explaining it, reading it, recommending something, or pointing at a text it does not restate.

  • DPDP Rules 2025, r. 3

    Practical recommendation · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    Rule 3 on this site Official source ↗ Also on MeitY (byte identical) ↗

    The mapping step itself is a practical recommendation; the notice content duty it serves, Rule 3, is official. Retyped from explanation to recommendation on 27 August 2026, when the claim type label became visible page content on /tools/compliance-checklist and contradicted this note in the same card.

  • DPDP Rules 2025, r. 3

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    The notice given by the Data Fiduciary to the Data Principal shall — (a) be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary; (b) give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, which shall include, at the minimum, — (i) an itemised description of such personal data; and (ii) the specified purpose or purposes of, and specific description of the goods or services to be provided or uses to be enabled by, such processing; and (c) give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may — (i) withdraw her consent, with the ease of doing so being comparable to that with which such consent was given; (ii) exercise her rights under the Act; and (iii) make a complaint to the Board.

    Rule 3 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 6

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum, — (a) appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data; (b) appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable; (c) visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence; (d) reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups; (e) for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise; (f) appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards; and (g) appropriate technical and organisational measures to ensure effective observance of security safeguards.

    Rule 6 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 7

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; (b) the consequences relevant to her, that are likely to arise from the breach; (c) the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk; (d) the safety measures that she may take to protect her interests; and (e) business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal. (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.

    Rule 7 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 7, (2)

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.

    Rule 7 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 8

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing. (2) At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary for the performance of the specified purpose or exercises her rights in relation to the processing of such personal data. (3) Without prejudice to sub-rules (1) and (2), a Data Fiduciary shall retain, in respect of any processing of personal data undertaken by it or on its behalf by a Data Processor, such personal data, associated traffic data and other logs of the processing for a minimum period of one year from the date of such processing, for the purposes as specified in the Seventh Schedule, after which the Data Fiduciary shall cause such personal data and logs to be erased, unless further retention is required for compliance with any other law for the time being in force or notified by the Government.

    Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 8, (2)

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (2) At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary for the performance of the specified purpose or exercises her rights in relation to the processing of such personal data.

    Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 9

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data.

    Rule 9 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 14, (1)

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) For enabling Data Principals to exercise their rights under the Act, the Data Fiduciary and, where applicable, the Consent Manager, shall prominently publish on its website or app, or both, as the case may be, — (a) the details of the means using which a Data Principal may make a request for the exercise of such rights; and (b) the particulars, if any, such as the username or other identifier of such a Data Principal, which may be required to identify her under its terms of service.

    Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Act 2023, s. 8, (10)

    Official requirement · Verified 26 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (10) A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.

    Section 8 on this site Official source ↗

    Section 8(10), Gazette page 8: "A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals." This is the source of the duty to have the mechanism at all; Rule 14(3) adds publication and technical and organisational measures.

  • DPDP Act 2023, s. 13, (2)

    Official requirement · Verified 26 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries.

    Section 13 on this site Official source ↗

    Section 13(2), Gazette page 10, leaves the response period to be prescribed: the Data Fiduciary or Consent Manager "shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt".

  • DPDP Rules 2025, r. 14, (3)

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (3) Every Data Fiduciary and Consent Manager shall prominently publish on its website or app, or both, as the case may be, within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals and shall, for ensuring the effectiveness of the system in responding within such period, implement appropriate technical and organisational measures.

    Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Act 2023, s. 40, (2)(o)

    Interpretation, requires judgment · Verified 26 August 2026

    In force since 13 November 2025

    Section 40 on this site Official source ↗

    Rule 14(3) as printed carries no object for "publish", so what the words "not exceeding ninety days" cap is not stated on the face of the text. This site reads them as capping the response period the Data Fiduciary must publish, because section 40(2)(o) describes the thing to be prescribed as "the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13", and the same sub rule requires measures for responding "within such period". That reading is this site's and not a statement the printed rule makes.

  • DPDP Rules 2025, r. 14, (4)

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (4) To exercise the rights of the Data Principal under the Act, she may, in accordance with the terms of service of the Data Fiduciary and such law as may be applicable, nominate one or more individuals, using the means and furnishing the particulars required by such Data Fiduciary for the exercise of such right.

    Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 10

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary shall adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained before the processing of any personal data of a child and shall observe due diligence, for checking that the individual identifying herself as the parent is an adult who is identifiable if required in connection with compliance with any law for the time being in force in India, by reference to — (a) reliable details of identity and age of the individual available with the Data Fiduciary; or (b) details of identity and age, voluntarily provided — (i) by the individual; or (ii) through a virtual token mapped to such details, which is issued by an authorised entity.

    Rule 10 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 11

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary, while obtaining verifiable consent from an individual identifying herself as the lawful guardian of a person with disability, shall observe due diligence to verify that such guardian is appointed by a court of law, or by a designated authority or by a local level committee, under the law applicable to guardianship.

    Rule 11 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Rules 2025, r. 13

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder. (2) A Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit. (3) A Significant Data Fiduciary shall observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals. (4) A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India.

    Rule 13 on this site Official source ↗ Also on MeitY (byte identical) ↗

Sources cited on this page

  1. [1]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 3, p. 24. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Practical recommendation · Verified 16 August 2026The mapping step itself is a practical recommendation; the notice content duty it serves, Rule 3, is official. Retyped from explanation to recommendation on 27 August 2026, when the claim type label became visible page content on /tools/compliance-checklist and contradicted this note in the same card.
  2. [2]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 3, p. 24. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  3. [3]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  4. [4]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  5. [5]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, (2), p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  6. [6]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  7. [7]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, (2), p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  8. [8]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 9, p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  9. [9]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (1), p. 29. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  10. [10]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (10), p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 26 August 2026Section 8(10), Gazette page 8: "A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals." This is the source of the duty to have the mechanism at all; Rule 14(3) adds publication and technical and organisational measures.
  11. [11]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 13, (2), p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 26 August 2026Section 13(2), Gazette page 10, leaves the response period to be prescribed: the Data Fiduciary or Consent Manager "shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt".
  12. [12]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (3), p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  13. [13]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 40, (2)(o), p. 18. Published 11 August 2023. Official source ↗ · Interpretation, requires judgment · Verified 26 August 2026Rule 14(3) as printed carries no object for "publish", so what the words "not exceeding ninety days" cap is not stated on the face of the text. This site reads them as capping the response period the Data Fiduciary must publish, because section 40(2)(o) describes the thing to be prescribed as "the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13", and the same sub rule requires measures for responding "within such period". That reading is this site's and not a statement the printed rule makes.
  14. [14]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (4), p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  15. [15]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 10, p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  16. [16]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 11, p. 28. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  17. [17]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026

Read the guide

DPDP compliance requirements for businesses The obligations map behind the plan, in 6 groups, each duty with the provision it comes from and the commencement group it sits in.