The DPDP Act is India’s data protection law. It sets the rules for how organisations may collect, use and store the personal data of people in India, and what those people are entitled to ask for in return.
The short answer
The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India. It requires organisations to obtain consent, use data only for the stated purpose, keep it secure, report breaches, and delete it once the purpose is served. The supporting DPDP Rules were notified on 14 November 2025, with full compliance required by 14 May 2027.
It applies to any company processing the personal data of people in India, including companies based outside India that sell into the country. A startup with Indian users is in scope whether or not it is registered in India.
On this page
Key roles under the Act
DPDP gives each party a specific name, and the obligations follow those names. This is how they relate to one another.
What it requires
Seven obligations. The engineering work sits mostly in safeguards, breach reporting and erasure.
| Obligation | What it means in practice |
|---|---|
| Notice and consent | Clear itemised notice before collection. Withdrawal as easy as consent. |
| Purpose limitation | Use data only for the stated purpose. New purpose, fresh consent. |
| Security safeguards | Encryption, access control, logging and monitoring. |
| Breach notification | Tell affected individuals without delay. Board within 72 hours. |
| Erasure | Delete once the purpose is served, with advance notice. |
| Children’s data | Verifiable parental consent under 18. No tracking or ad targeting. |
| Grievance redressal | A published contact point and a response process. |
On cross-border transfers
DPDP takes a negative-list approach. Personal data may be transferred outside India unless the central government specifically restricts a country by notification. This is more permissive than the data localisation many organisations expected from the draft rules.
Key deadlines and what to do
The Act passed in 2023 but had no operative detail until the DPDP Rules were notified in November 2025. Obligations switch on across three dates, and the work sits in the gap between them.
Penalties
How Osto supports DPDP
Security safeguards is where DPDP becomes an engineering problem rather than a legal one. Osto maps DPDP controls alongside 200+ frameworks and draws the evidence from its own modules: access management and MFA, file access DLP, endpoint control, cloud posture, logging and vulnerability testing. The detection timeline needed for a 72-hour breach report comes from the same system that enforces the controls.
Free security assessment
Reasonable security safeguards, actually deployed
Osto covers the technical controls DPDP expects and maps the evidence automatically. Tell us your scope and we will tailor a plan.
Get a free security assessment Book a platform walkthrough200+ frameworks · Built for Indian startups · One platform, everything
Frequently asked questions
What does DPDP stand for?
DPDP stands for Digital Personal Data Protection. The full name is the Digital Personal Data Protection Act, 2023, India’s law governing how digital personal data is collected, used and stored.
Does DPDP apply to companies outside India?
Yes, where the processing relates to offering goods or services to individuals in India. A company registered elsewhere with Indian users falls within scope.
When do organisations have to comply?
The DPDP Rules were notified on 14 November 2025. Consent manager registration and obligations begin on 14 November 2026, and the remaining obligations, including notice, consent, data principal rights and breach processes, are enforceable from 14 May 2027. The Data Protection Board has been operational since November 2025.
How is DPDP different from GDPR?
DPDP is shorter and more consent-centred. It has no separate category of sensitive personal data, no general right to data portability, and takes a negative-list approach to cross-border transfers, permitting them unless a country is specifically restricted. GDPR relies on multiple lawful bases including legitimate interest, which DPDP replaces with a narrower list of legitimate uses.
What are the penalties under DPDP?
Penalties are imposed by the Data Protection Board and reach ₹250 crore for failing to take reasonable security safeguards, and ₹200 crore for failing to notify a breach or for breaching obligations relating to children’s data.

