DPDP Act: Rules, Deadlines and Penalties

DPDP Act explained: rules, deadlines and penalties

The DPDP Act is India’s data protection law. It sets the rules for how organisations may collect, use and store the personal data of people in India, and what those people are entitled to ask for in return.

  • Glossary
  • Compliance

The short answer

The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India. It requires organisations to obtain consent, use data only for the stated purpose, keep it secure, report breaches, and delete it once the purpose is served. The supporting DPDP Rules were notified on 14 November 2025, with full compliance required by 14 May 2027.

It applies to any company processing the personal data of people in India, including companies based outside India that sell into the country. A startup with Indian users is in scope whether or not it is registered in India.

Key roles under the Act

DPDP gives each party a specific name, and the obligations follow those names. This is how they relate to one another.

Consent Manager Optional. One place to manage consent Data Principal The individual. Holds the rights the Act creates gives data Data Fiduciary You. Decides why and how data is used, carries the duties instructs Data Processor Your cloud and SaaS vendors investigates and penalises Data Protection Board of India The regulator. Operational since Nov 2025
Swipe to see the full diagram. Almost every company is a Data Fiduciary, which is where the obligations sit. A Fiduciary handling large volumes may be designated a Significant Data Fiduciary, adding an India-based DPO, annual audits and impact assessments.

What it requires

Seven obligations. The engineering work sits mostly in safeguards, breach reporting and erasure.

ObligationWhat it means in practice
Notice and consentClear itemised notice before collection. Withdrawal as easy as consent.
Purpose limitationUse data only for the stated purpose. New purpose, fresh consent.
Security safeguardsEncryption, access control, logging and monitoring.
Breach notificationTell affected individuals without delay. Board within 72 hours.
ErasureDelete once the purpose is served, with advance notice.
Children’s dataVerifiable parental consent under 18. No tracking or ad targeting.
Grievance redressalA published contact point and a response process.

On cross-border transfers

DPDP takes a negative-list approach. Personal data may be transferred outside India unless the central government specifically restricts a country by notification. This is more permissive than the data localisation many organisations expected from the draft rules.

Key deadlines and what to do

The Act passed in 2023 but had no operative detail until the DPDP Rules were notified in November 2025. Obligations switch on across three dates, and the work sits in the gap between them.

WHAT SWITCHES ON, AND WHEN 14 Nov 2025 Rules in force Board can accept complaints from today YOU ARE HERE Build time Safeguards, consent flows, breach process, erasure 14 Nov 2026 Consent managers Registration and duties begin for that role 14 May 2027 Everything else Notice, consent, rights and breach reporting The security safeguards obligation has no grace period in practice A breach today is judged on the measures you had in place at the time, not on the 2027 date
Swipe to see the full chart. The 2027 date is when the paperwork obligations bite. The technical controls are what a breach would be judged against long before then.

Penalties

MAXIMUM PENALTY BY FAILURE Security safeguards ₹250 crore Breach notification ₹200 crore Children's data ₹200 crore Significant Data Fiduciary duties ₹150 crore
Swipe to see the full chart. Penalties are imposed by the Data Protection Board and set against the failure, not against turnover.

How Osto supports DPDP

Security safeguards is where DPDP becomes an engineering problem rather than a legal one. Osto maps DPDP controls alongside 200+ frameworks and draws the evidence from its own modules: access management and MFA, file access DLP, endpoint control, cloud posture, logging and vulnerability testing. The detection timeline needed for a 72-hour breach report comes from the same system that enforces the controls.

Free security assessment

Reasonable security safeguards, actually deployed

Osto covers the technical controls DPDP expects and maps the evidence automatically. Tell us your scope and we will tailor a plan.

Get a free security assessment Book a platform walkthrough

200+ frameworks · Built for Indian startups · One platform, everything

Frequently asked questions

What does DPDP stand for?

DPDP stands for Digital Personal Data Protection. The full name is the Digital Personal Data Protection Act, 2023, India’s law governing how digital personal data is collected, used and stored.

Does DPDP apply to companies outside India?

Yes, where the processing relates to offering goods or services to individuals in India. A company registered elsewhere with Indian users falls within scope.

When do organisations have to comply?

The DPDP Rules were notified on 14 November 2025. Consent manager registration and obligations begin on 14 November 2026, and the remaining obligations, including notice, consent, data principal rights and breach processes, are enforceable from 14 May 2027. The Data Protection Board has been operational since November 2025.

How is DPDP different from GDPR?

DPDP is shorter and more consent-centred. It has no separate category of sensitive personal data, no general right to data portability, and takes a negative-list approach to cross-border transfers, permitting them unless a country is specifically restricted. GDPR relies on multiple lawful bases including legitimate interest, which DPDP replaces with a narrower list of legitimate uses.

What are the penalties under DPDP?

Penalties are imposed by the Data Protection Board and reach ₹250 crore for failing to take reasonable security safeguards, and ₹200 crore for failing to notify a breach or for breaching obligations relating to children’s data.