Skip to main content
KreupAI Logo
GLOSSARY GUIDEApplies to: IndiaCohortaOS
KB-005

What Is the DPDP Act? Scope, Obligations and Timelines, Explained

India's DPDP Act 2023 and its 2025 Rules: who counts as a Data Fiduciary, what you must actually do, the penalty caps and the phased commencement dates.

Author:Bosco Sabu John
5 min read

What Is the DPDP Act? Scope, Obligations and Timelines, Explained

The Digital Personal Data Protection Act 2023 is India's general data protection statute. It covers digital personal data processed in India, and processing abroad connected to offering goods or services in India. Its Rules were notified in November 2025 and commence in phases, with most substantive duties landing eighteen months later.

What the DPDP Act is

The Digital Personal Data Protection Act, 2023 is India's first cross-sector statute dedicated to personal data. It runs to 44 sections and pushes most operating detail into subordinate rules.

Two design choices shape everything else. It covers digital personal data only: collected in digital form, or on paper and later digitised. And it recognises two lawful bases, consent under section 6 or one of the "certain legitimate uses" in section 7. There is no legitimate-interests balancing test and no separate category of sensitive personal data.

The Act sat uncommenced for two years. On 13 November 2025 MeitY notified the Digital Personal Data Protection Rules, 2025 as G.S.R. 846(E), with a companion notification staging the Act into force.

Who it applies to

Section 3(a) covers processing within India. Section 3(b) reaches abroad, to "processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India". A company with no Indian entity that sells to Indian consumers is in scope. Excluded: purely personal or domestic processing, and data the Data Principal has herself made public.

There is no revenue threshold, no headcount threshold and no business-to-business carve-out. Determine the purpose and means of processing and you are a Data Fiduciary, with your customers' employee contact records in scope.

Five roles matter. The Data Principal is the individual. The Data Fiduciary determines purpose and means. The Data Processor acts on a Fiduciary's behalf. A Significant Data Fiduciary (SDF) is one notified under section 10(1), on volume and sensitivity of data, risk to Data Principals' rights, and risk to sovereignty, electoral democracy, security of the State and public order. A Consent Manager gives a Data Principal one interoperable place to give, review and withdraw consent.

[NEEDS SOURCE: whether any Data Fiduciary or class of Data Fiduciaries has yet been notified as a Significant Data Fiduciary, and the notification reference.]

What it requires

ObligationSourceIn practice
Notices.5; Rule 3Itemised data and purposes, plain language, standalone, with links to withdraw consent and complain to the Board
Consents.6Free, specific, informed, unconditional, unambiguous; limited to necessary data; withdrawable with comparable ease
Erasures.8(7); Rule 8On withdrawal, or when the specified purpose is no longer served, whichever is earlier
Securitys.8(5); Rule 6Encryption, masking or tokenisation, access control, monitoring, backups; logs kept at least one year
Breach intimations.8(6); Rule 7Affected Data Principals without delay; particulars to the Board within seventy-two hours
Rights and grievancesss.11 to 14; Rule 14Publish the means to exercise rights; respond within ninety days at the outside
Contact persons.8(9); Rule 9Publish details of the DPO, or of someone who can answer processing questions
SDF additionss.10; Rule 13India-based DPO, independent auditor, DPIA and audit every twelve months, algorithmic due diligence, Rule 13(4) localisation
Consent Managers.6(9); Rule 4Indian company, net worth at least two crore rupees, certified platform, records kept seven years

Rule 1(2) sets the phasing. Rules 1, 2 and 17 to 21 came into force on publication in the Official Gazette; Rule 4 (Consent Manager registration) one year after; Rules 3, 5 to 16, 22 and 23 eighteen months after. The Act is staged the same way: definitions, the Board's establishment and the amendments to the Right to Information Act 2005 and the TRAI Act 1997 are live now, and everything in the table above lands at eighteen months.

The Rules are dated 13 November 2025 and were published the next day, so the milestones fall on 13 or 14 November 2026 and 13 or 14 May 2027. Plan to the earlier date. In early 2026 MeitY also circulated a proposal to shorten the SDF window to twelve months and advance Rules 13(4) and 15. [NEEDS SOURCE: date of publication in the Official Gazette, gazette number of the Act's commencement notification, and whether the 2026 amendment proposal has been notified.]

What happens if you do not comply

The Data Protection Board of India inquires into breaches and imposes penalties under section 33. The Schedule sets the caps:

BreachCap
Failure to take reasonable security safeguards250 crore rupees
Failure to notify a breach to the Board or Data Principals200 crore rupees
Children's-data obligations200 crore rupees
SDF obligations150 crore rupees
A Data Principal's own duties10,000 rupees
Any other breach50 crore rupees

The Board runs as a digital office under Rule 20; appeals go to the Appellate Tribunal under Rule 22.

One caveat. As of mid-2026 the Board existed in law but had no appointed Chairperson or Members, nominations having been sought in May and June 2026. A body with no members cannot impose a penalty, which is why the eighteen-month date matters more today than enforcement risk. [NEEDS SOURCE: current constitution of the Data Protection Board of India, names and dates of appointment.]

  • Consent Manager: Board-registered Indian company letting a Data Principal manage consent across many Fiduciaries; records kept at least seven years.
  • Significant Data Fiduciary: Fiduciary notified under section 10, carrying an annual DPIA and audit plus algorithmic due diligence.
  • Notice: the standalone, itemised, plain-language statement required at or before consent (s.5, Rule 3).
  • Purpose limitation: consent covers only the specified purpose, and data must go once that purpose ends.
  • Breach intimation: Rule 7 duty to tell affected individuals without delay and file particulars with the Board within seventy-two hours.

FAQ

Is the DPDP Act in force yet? Partly. Definitions, the Board's establishment and the consequential amendments took effect in November 2025. Consent Manager registration follows at twelve months. Notice, consent, security, breach reporting, rights and enforcement follow at eighteen months, in mid-May 2027.

Does it apply to employee data? Yes. Section 7 treats employment purposes, and safeguarding the employer from loss or liability, as legitimate uses, so consent is not always the basis. Notice, security, erasure and grievance duties still apply.

Does the Act block sending data abroad? Not by default. Rule 15 permits transfer subject to requirements the Central Government may specify, and Rule 13(4) lets it confine specified categories held by SDFs to India. [NEEDS SOURCE: whether any country, territory or data category has been notified under Rule 15 or Rule 13(4).]

Where a system helps

If you run AI agents over customer data, the duty with no natural owner is showing what an automated process collected, why, and where it wrote. CohortaOS records that on every agent run, so a notice, an erasure request or a breach timeline can be rebuilt from evidence.

Related reading: The DPDP Act and AI Systems: Consent Managers, Notices and Data Principal Rights (KB-006).

Sources