ROC

DPDP Act 2023 & Rules 2025: A Practical Compliance Guide for Businesses

India's Digital Personal Data Protection law is now live in phases — the core obligations (consent, notice, security, breach reporting, data-principal rights) apply from 13 May 2027, with penalties up to ₹250 crore. Here's what every business must do, and why to start now.

Mohan—·8 min read
Law
DPDP Act 2023 + DPDP Rules 2025
Rules notified
13 November 2025
Core provisions live
13 May 2027
Top penalty
Up to ₹250 crore

The short version

  • India's Digital Personal Data Protection (DPDP) Act 2023 and the DPDP Rules 2025 (notified 13 Nov 2025) create a single, dedicated law for handling digital personal data.
  • It rolls out in phases — the Data Protection Board and some rules are already live; the big operational duties (consent, notice, security, breach reporting, data-principal rights) apply from 13 May 2027.
  • Any business that collects personal data — of customers, employees or users — is likely a Data Fiduciary with real obligations.
  • Penalties are steep: up to ₹250 crore for security failures. This is a board-level risk, not just an IT checkbox.

For years, India handled personal data through a patchwork of sectoral rules. That era is ending. The DPDP Act 2023, now backed by the DPDP Rules 2025, gives the country a single framework for digital personal data — and it places concrete, enforceable duties on almost every business that holds customer or employee information. Here's what it means and how to prepare.

Who the law applies to

The framework covers digital personal data collected in India, or collected in connection with offering goods or services to people in India. If your business holds data about identifiable individuals — customers, employees, job applicants, contractors, website users — it's in scope. A few key roles decide your obligations:

  • Data Principal — the individual the data is about (your customer, employee or user).
  • Data Fiduciary — the organisation deciding why and how data is processed. Most businesses are Data Fiduciaries; an employer is a Data Fiduciary for its staff data.
  • Data Processor — a vendor processing data on your behalf (payroll provider, HR tech, cloud host, background-check agency).
  • Significant Data Fiduciary (SDF) — larger or higher-risk organisations the government notifies, with extra duties (see below).
  • Consent Manager — a registered, India-incorporated platform through which individuals give, review and withdraw consent.

The phased timeline — and why to start now

The DPDP framework doesn't switch on all at once. It commences in stages, which is exactly why the smart move is to begin early rather than wait for the deadline:

  1. Already in force (13 Nov 2025): the Data Protection Board provisions and Rules 1, 2 and 17–21 — the institutional and procedural backbone.
  2. One year on (13 Nov 2026): Rule 4 and certain specified Act provisions — further operational requirements.
  3. Eighteen months on (13 May 2027): the heart of the law — consent, notice, processing, data-principal rights, security safeguards and breach notification (Rules 3, 5–16, 22–23).

Why "we'll deal with it in 2027" is the wrong plan

Mapping where personal data lives, rewriting notices, fixing vendor contracts and building rights-and-breach workflows is a months-long programme across HR, legal, IT and procurement — not a document you draft the week before. The phased window is an opportunity to transform deliberately, not a licence to delay.

What businesses must actually do

Notice and consent

Before processing personal data, give a clear, standalone notice — an itemised list of what you collect, the specific purposes, and how people can withdraw consent, exercise rights and complain. A generic global privacy policy may not meet Indian requirements. Where you rely on consent, it must be free, specific, informed, unambiguous and given by clear affirmative action — and withdrawing it must be as easy as giving it. Blanket employee consent forms won't do.

Purpose limitation and retention

Use data only for the purposes you stated, and delete it once it's no longer needed — subject to genuine legal, statutory or litigation requirements. You need a documented retention-and-deletion framework, not ad-hoc storage forever.

Security safeguards

Adopt real technical and organisational measures: encryption, masking or tokenisation, access controls, logging and monitoring, backups and resilience, and detection and remediation of unauthorised access — plus contractual safeguards with your processors. This is where the heaviest penalty sits.

Breach response

Build an incident-response capability covering detection, containment, assessment, notification to the Board, communication to affected individuals, remediation and post-incident review. The Rules prescribe breach-reporting procedures and timelines.

Data-principal rights

Individuals can seek access to their data, correction and erasure, grievance redressal, and can nominate someone to exercise their rights on death or incapacity. These need working systems, not just policy statements.

Children's data

The Act treats anyone under 18 as a child. Processing their data needs verifiable parental consent, with restrictions on behavioural monitoring and on targeted advertising directed at children.

Vendor (processor) governance

Outsourcing doesn't outsource the liability. As a Data Fiduciary you remain responsible, so you must know who processes your data, why, what they hold, where it's stored, how it's secured, how breaches are reported, and what happens to the data when the contract ends.

Extra duties for Significant Data Fiduciaries

If the government notifies you as an SDF, you must additionally appoint a Data Protection Officer, appoint an independent data auditor, run periodic data-protection impact assessments, and undergo regular audits.

The penalties — why this reaches the board

ViolationMaximum penalty
Failure to take reasonable security safeguards₹250 crore
Breach notification failures₹200 crore
Children's data non-compliance₹200 crore
SDF obligations non-compliance₹150 crore
Other breaches of the Act / Rules₹50 crore
Data Principal duty violations₹10,000

These are maximums — actual penalties depend on the violation — but the scale makes the point: data protection is now a governance and risk-management issue for leadership, enforced by a dedicated Data Protection Board of India (established 13 November 2025, headquartered in the National Capital Region).

A practical path to compliance

You don't need to do everything at once, but you do need to start in the right order:

  • Understand & map. Identify every category of personal data you hold and trace where it lives and who it goes to.
  • Assess the basis. For each use, pin down the purpose and lawful basis — consent or a legitimate use — and check your notices.
  • Assign ownership. Name a privacy owner (or DPO), define roles and set escalation paths.
  • Remediate. Update notices, fix processor contracts, strengthen consent and security, and document retention and breach-response.
  • Operationalise rights. Build working flows for access, correction, erasure, nomination and grievances — and test them.
  • Audit & evidence. Keep audit trails and documented proof of compliance, ready for any inquiry.

Substance over paperwork

The law rewards demonstrable capability, not pretty policies. If a customer asks to see or delete their data, or a breach happens at 2am, what matters is whether your systems can actually respond — on time and on record. Build for that, and the documentation follows.

Not sure where your business stands on DPDP?

efiletax can help you map your personal-data footprint, assess your obligations, fix your notices and vendor contracts, and build a compliance plan that's ready well before May 2027.

Talk to our compliance team

Disclaimer: This article explains the DPDP Act 2023 and DPDP Rules 2025 for general understanding and is current as at the date of publication. Commencement dates are phased and specific obligations, thresholds and procedures are governed by the Act, the Rules and notifications in force — verify the current position and your specific status before acting. This is not legal advice; please consult a qualified professional. Talk to efiletax if you need help.

#DPDP Act#Data Protection#Compliance#Corporate Law#Privacy