DPDP Compliance: Your Guide to Data Protection in India
Understand the Digital Personal Data Protection Act, DPDP Rules, compliance requirements, data protection concepts and practical resources for businesses in India.
- DPDP Act enacted
- 2023
- DPDP Act enacted
- DPDP Rules notified
- 2025
- DPDP Rules notified
- Core obligations apply
- May 2027
- Core obligations apply
What Is DPDP Compliance?
DPDP compliance refers to the practices an organisation follows to meet its obligations under the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the DPDP Rules, 2025 whenever it collects, stores, uses or shares the personal data of individuals in India.
It applies to any organisation that processes personal data as a Data Fiduciary or on its behalf as a Data Processor — companies, non-profits, startups and public bodies alike — regardless of size, though specific obligations scale with the volume and sensitivity of the data involved and whether the entity is classified as a Significant Data Fiduciary.
Read the full DPDP Compliance guideWho needs to consider it
Any business, institution or platform that handles personal data of people in India — from a two-person startup to a large enterprise.
Why it matters
The Act creates enforceable rights for individuals and statutory obligations for organisations, backed by the Data Protection Board of India.
Act vs. Rules
The Act lays down the legal framework and principles; the Rules explain how those obligations are implemented in practice.
Explore the DPDP Ecosystem
DPDP compliance touches many interlinked concepts. Start with the one most relevant to you.
DPDP Act
Learn moreDPDP Rules
Procedural detail notified in 2025 that operationalises the Act's obligations.
DPDP Compliance
What organisations need to do, in practice, to meet their obligations.
Consent
The primary legal basis for processing personal data under the Act.
Data Principal Rights
What individuals can ask of organisations that hold their personal data.
Data Fiduciary
The entity that decides the purpose and means of processing personal data.
Personal Data
What counts as personal data under the DPDP Act, and what doesn't.
Data Breach
Obligations that arise when personal data is compromised.
Consent Manager
A registered entity that helps individuals manage consent across platforms.
DPDP Compliance Requirements
An overview of the major areas organisations typically need to address to work toward DPDP compliance.
Notice
Informing individuals in clear language what personal data is collected and why, before or at the time of collection.
Consent
Obtaining free, specific, informed and unambiguous consent, with an equally easy way to withdraw it.
Personal data processing
Using personal data only for the notified purpose or other permitted "legitimate uses," and limiting collection to what's necessary.
Data Principal rights
Building processes to receive and respond to access, correction, erasure and nomination requests.
Data security safeguards
Reasonable technical and organisational measures to prevent unauthorised access, disclosure or loss of data.
Data breach obligations
Processes to detect a breach and notify the Data Protection Board and affected individuals as required.
Grievance redressal
An accessible channel for complaints, with defined response timelines before escalation to the Board.
Retention & deletion
Keeping personal data only as long as necessary for its purpose, then deleting or anonymising it.
Vendor & processor management
Contracts and oversight where personal data is shared with third-party Data Processors.
Documentation & records
Internal records of processing activities, consent artefacts and breach response steps to demonstrate accountability.
DPDP Compliance Checklist
A starting point for organising your compliance work — not a substitute for legal review.
Compliance readiness checklist
PREVIEW · 10 OF 24 ITEMS- Understand applicability to your organisation
- Identify what personal data you hold
- Map how that data is processed
- Review your privacy notices
- Review consent mechanisms
- Establish Data Principal request processes
- Review security safeguards
- Prepare breach response procedures
- Review retention and deletion practices
- Document your compliance activities
DPDP Act & Rules
The DPDP Act sets out the law's principles, rights and obligations. The DPDP Rules explain how those obligations work in practice — the forms, timelines and technical detail organisations need to follow.
DPDP Act 2023
Enacted in August 2023, the Digital Personal Data Protection Act is India's primary law on personal data. It defines key terms — Data Principal, Data Fiduciary, personal data — sets out rights and obligations, establishes the Data Protection Board of India, and prescribes penalties for non-compliance.
Read about the DPDP ActDPDP Rules
The Digital Personal Data Protection Rules, 2025 were notified in November 2025 to operationalise the Act. They cover notices, Consent Manager registration, breach-reporting timelines and children's data safeguards, with obligations phased in through November 2026 and May 2027.
Read about the DPDP RulesData Principal Rights
The DPDP Act gives individuals — Data Principals — a defined set of rights over their personal data.
- 01
Right to access information
Request a summary of the personal data being processed and the processing activities carried out on it.
- 02
Right to correction
Request that inaccurate, incomplete or outdated personal data be corrected or updated.
- 03
Right to erasure
Request erasure of personal data once it is no longer necessary for the purpose it was collected for, subject to legal retention requirements.
- 04
Right to grievance redressal
Raise a complaint with the Data Fiduciary or its Consent Manager, and escalate to the Data Protection Board if unresolved.
- 05
Right to nominate
Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
DPDP Compliance by Industry
Every organisation shares the same core obligations — but the risk areas differ by sector.
Healthcare
Patient records and health IDs raise heightened sensitivity for hospitals, clinics and health-tech platforms.
Industry guideFintech & Banking
KYC data, transaction histories and credit information sit at the centre of compliance for banks and fintech apps.
Industry guideEcommerce
Customer accounts, addresses and behavioural data make consent and vendor management central to online retail.
Industry guideSaaS & Technology
Platforms processing data for customers need clarity on their role as Data Fiduciary or Data Processor.
Industry guideEducation
Schools, universities and edtech platforms handle student and children's data, triggering added safeguards.
Industry guideStartups & SMEs
Smaller organisations qualify as Data Fiduciaries too, and can build compliant practices from day one.
Industry guideDPDP Resources
Checklists, templates and reference material to support your compliance work.
Checklists
Step-by-step lists to organise your compliance work.
Templates
Sample notice and documentation formats to adapt for your organisation.
Guides
Plain-language explainers on DPDP concepts and processes.
Glossary
Definitions of key DPDP terms, in one place.
FAQs
Answers to common questions about DPDP compliance.
Latest DPDP Updates
Regulatory developments, government notifications and compliance milestones as they happen.
- Regulatory notificationPublished Nov 2025 · Updated Sep 2026
DPDP Rules, 2025 notified
MeitY notified the Digital Personal Data Protection Rules, 2025 along with the DPDP Act's enforcement notification, bringing the framework into force.
- InstitutionalPublished Nov 2025 · Updated Sep 2026
Data Protection Board of India established
The Rules provide for the constitution of the Board, the body responsible for grievances, investigations and enforcement under the Act.
- Compliance timelineEffective Nov 2026 · Updated Sep 2026
Consent Manager framework activates
Twelve months after notification, the registration framework for Consent Managers becomes operational.
- Compliance timelineEffective May 2027 · Updated Sep 2026
Core compliance obligations come into force
Eighteen months after notification, most substantive obligations take effect — notice, consent, breach reporting, security safeguards and Data Principal rights.

