Skip to main content
DPDP Act compliance, India

The DPDP Rules started an eighteen-month clock in November 2025. Most of the work is engineering, not legal.

Almost everything written about the Digital Personal Data Protection Act has been written by lawyers, which is useful for understanding your obligations and close to useless for discharging them. Consent, erasure, breach reporting and data principal rights are all features somebody has to build into systems that were never designed for them. This is the engineering half: what has to change in your tenant, your applications and your logs before substantive compliance falls due in May 2027.

DPDP Act compliance assessment for Indian businesses
  • May 2027Substantive compliance due
  • 72 hoursDetailed breach report
  • 90 daysTo answer a rights request
  • 1 yearMinimum log retention
What the Act actually asks of you

Seven obligations, and what each one costs you in engineering.

The Act is short and the Rules are specific. Read as requirements rather than as law, they resolve into seven things a business has to be able to do. Each is easy to state, and each one fails in practice for the same reason: nobody can do it without first knowing what personal data they hold and where it lives.

Give notice that stands on its own

Rule 3 requires a notice in clear, plain language that works as a standalone document rather than a clause buried in terms of service, and it must carry an itemised list of the personal data you collect and the specific purpose for each. Itemised is the operative word. A notice saying you collect information to improve services does not survive this test. Producing a genuine itemised notice forces the data inventory, which is why most businesses discover they need a data map at the notice stage rather than earlier.

Collect consent you can prove and unwind

Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and withdrawal has to be as easy as giving it was. That last clause is where systems break. Most applications can record a yes; comparatively few can record which specific purpose it applied to, produce that record two years later on demand, and cascade a withdrawal through every downstream system and processor that received the data.

Apply safeguards that are proportionate and evidenced

Rule 6 asks for technical and organisational measures proportionate to the sensitivity and volume of what you process, and names the shape of them: encryption, obfuscation, masking or virtual tokens mapped to the personal data, and role-based access control that restricts access to authorised personnel. It also requires that logs and associated traffic data be retained for at least one year so a breach can be detected, investigated and remediated. Log retention is the requirement most estates fail on today, quietly, because default retention windows are shorter than a year.

Report a breach on the clock

On becoming aware of a personal data breach you inform the Data Protection Board without delay with the nature, extent, timing and location of the breach and its likely impact, and you inform affected data principals without delay too. Within seventy two hours you provide the Board an updated account: the circumstances that led to the breach, the remedial and mitigation measures taken, and your findings on who caused it. Extensions exist but must be requested in writing. Seventy two hours is not long enough to build a process from scratch, which is the entire argument for having one already.

Erase when the purpose is finished

Rule 8 permits retention only for as long as the specified purpose is being served, after which the data must be erased. For the classes listed in the Third Schedule, erasure follows a defined period, currently three years, unless the data principal re-engages, and you must give advance notice before erasing. Purpose limitation is the obligation that clashes hardest with how Indian businesses actually operate, because the prevailing default is to keep everything forever in case it is useful.

Answer data principal requests

Individuals can ask for a summary of the personal data you hold about them, ask you to correct or complete what is inaccurate, and ask for erasure. You have a maximum of ninety days to respond. Ninety days sounds generous until you try it: answering honestly requires querying every system that holds personal data, which is a different problem from having a policy that says you will.

Handle children and guardianship properly

Processing the personal data of anyone under eighteen requires verifiable consent from a parent or lawful guardian, and the same applies to persons with disability who have a lawful guardian. Targeted advertising and behavioural profiling directed at minors are prohibited outright. If your service is not intended for children, the engineering task is proving that: age assurance, and a documented basis for the assurance you chose.

Carry the extra load if you are designated significant

A Significant Data Fiduciary, designated by the government on the volume and sensitivity of what it processes and the risk it presents, takes on more: a Data Protection Officer based in India and answerable to the board, a Data Protection Impact Assessment, and an independent compliance audit, the latter two on a twelve month cycle. Most businesses will not be designated. Those that might should build assuming they will be, because retrofitting a DPIA discipline onto a live estate is materially harder than starting with one.

The clock

What is already in force, and what is coming.

The Rules were notified in November 2025 and switch on in three stages rather than all at once. The staging matters for planning, because the deadline that gets quoted in headlines is not the one most businesses should be working back from.
  1. 01
    In force now· Since November 2025

    The Data Protection Board exists

    The rules establishing the Board and its procedures took effect on notification. The adjudicating body is standing up while the substantive obligations are still phasing in, which is the normal sequence and means the enforcement machinery will be operational well before the compliance deadline arrives.

    • Board constituted and procedural rules live
    • No substantive obligations enforceable yet
    • The right window for gap assessment and remediation
  2. 02
    November 2026· Twelve months from notification

    Consent Manager registration begins

    Rule 4 comes into force, allowing registered, India-based, independent Consent Managers to operate an interoperable platform where an individual gives, reviews, manages and withdraws consent across multiple data fiduciaries from one place. Most businesses will never be a Consent Manager. Every business will eventually have to interoperate with one.

    • Consent Manager registration framework live
    • Consent architecture needs to be interoperable, not bespoke
    • Consent records must be exportable and purpose-scoped
  3. 03
    May 2027· Eighteen months from notification

    Substantive compliance falls due

    Notice, consent, security safeguards, breach reporting, retention and erasure, data principal rights and the Significant Data Fiduciary obligations all become enforceable together. There is no indication of a general grace period beyond the eighteen months already given, and penalties at the top of the scale run into the hundreds of crores per violation.

    • Rules 3 and 5 to 16 enforceable
    • Full notice, consent, retention and rights machinery live
    • Breach reporting process operational and tested
Why bring us in

We do the half your law firm hands back.

Your counsel tells you what the Act requires and reviews the notice. Somebody still has to change the tenant, the applications and the logging. That is the work we do, and we do it as engineers rather than as a documentation exercise.

We start with discovery, not with templates

Every DPDP engagement we run starts by finding the personal data, because every other obligation depends on that answer and because the answer is always more surprising than the client expects. Exports in shared drives, a former employee mailbox nobody closed, a test database seeded with production records, a vendor portal holding customer identity documents. Templates cannot find those. Discovery can.

Microsoft Partner, so the controls are ones you already own

For estates on Microsoft 365, a large share of Rule 6 is achievable with entitlements already held: sensitivity labels and encryption, data loss prevention, retention policies that actually delete, Entra role-based access control and unified audit logging extended past its default window. We check what your licences already include before recommending anything new, and we regularly find businesses paying separately for a capability sitting unused in their tenant.

We plan back from the lead times, not forward from today

Log retention only evidences a year of history after a year has passed. Data mapping gates four other obligations. Consent rework needs to be in place before Consent Managers arrive. We sequence the programme against those constraints so the slow items start first, rather than delivering a tidy plan that runs out of calendar.

We are explicit about where we stop

We are not lawyers and this is not legal advice. We do not draft your notice, determine your lawful basis, or advise on whether you are likely to be designated a Significant Data Fiduciary. We build and evidence the controls, and we work alongside your counsel rather than around them. Being clear about the boundary is worth more to you than a vendor claiming to cover both.

Where this lands hardest

Sectors with the most to change.

Every business processing personal data is in scope. These are the ones where the gap between current practice and the Rules is widest in the assessments we run.

Healthcare and diagnostics

High-sensitivity data, long clinical retention requirements that genuinely conflict with purpose limitation, and shared counter logins that make record access unattributable. The retention conflict is resolvable but has to be reasoned and documented rather than assumed.

BFSI and fintech

Already carrying sectoral obligations from RBI and SEBI, so the controls largely exist. The work is mapping what is already built onto the DPDP obligations, closing the gaps that sectoral rules do not cover, and avoiding a second parallel compliance programme.

Retail and consumer brands

Loyalty databases, marketing lists of uncertain provenance, and consent captured years ago in ways nobody can now evidence. Frequently the largest volume of personal data and the weakest record of why it was collected.

Education

Processing children data at scale, which pulls in verifiable parental consent and the prohibition on targeted advertising and profiling of minors. Age assurance and guardian verification are engineering problems most institutions have not started on.

Manufacturing and logistics

Workforce data, contractor records, biometric attendance and vehicle telematics. Often the least mature identity and access management, with attendance and CCTV systems sitting outside IT governance entirely.

GCCs and SaaS

Processing on behalf of overseas parents or customers, so the contractual chain matters as much as the technical controls. Existing SOC 2 or ISO 27001 work covers a useful share of Rule 6 and none of the consent, notice or rights machinery.

Where businesses actually are

The gap between having a policy and being able to do the thing.

Almost every organisation we assess has documents. Far fewer have systems that can execute what the documents promise. This is the distinction the Rules care about, because a retention policy nothing implements provides no protection to anybody.
Feature
Obligation
What most businesses have
What the Rules require
Notice
A privacy policy on the website, written once, describing categories of data in general termsA standalone, plain-language notice with an itemised list of data collected and the specific purpose for each
Consent
A checkbox recorded as a boolean, with no record of which purpose it coveredPurpose-scoped, provable consent with withdrawal as easy as granting, cascading to processors
Data inventory
Institutional memory, plus a spreadsheet somebody made for an audit and did not maintainA current record of what personal data exists, where, why, who can reach it and how long it stays
Access control
Shared logins at reception, clinic counters and tills, and broad access granted at joining and never reviewedRole-based access restricting personal data to authorised personnel, attributable to an individual
Logs
Default retention, typically ninety days or less, and frequently not centralisedLogs and traffic data retained at least a year, sufficient to detect, investigate and remediate
Erasure
A retention policy describing deletion, with nothing implementing itErasure once the purpose is served, on schedule, with notice given in advance where required
Rights requests
An email address in the privacy policy that nobody has ever received a request onA process that queries every system holding personal data and answers within ninety days
Breach response
An incident response plan covering availability, written with ransomware in mindImmediate notification to the Board and affected individuals, detailed report inside seventy two hours

The deadline to plan against is not May 2027.

Substantive compliance falls due in May 2027, so that is the date everyone quotes. It is the wrong one to plan against, because two of the seven obligations have lead times measured in quarters rather than weeks. Log retention has to be extended and then has to actually accumulate a year of history before it evidences anything. Data mapping across a mid-sized estate is a discovery exercise, not a form-filling one, and it gates the notice, the rights process and the erasure schedule behind it.

  • Working back from May 2027, log retention changes need to land by roughly May 2026 to have a full year of history
  • Data mapping gates notice, consent, retention and rights, so it is the first task rather than one of them
  • Consent architecture needs to be interoperable before Consent Managers go live in November 2026
  • Breach response is the one obligation you cannot build after you need it
How we run it

Five stages, sequenced by lead time.

A DPDP programme that starts with policy documents produces documents. This sequence starts with the two tasks that take the longest to bear fruit and works outward from there.
  1. 1

    Discover what personal data you hold

    Systems, applications, file shares, mailboxes, SaaS tools, vendor platforms, backups and the places nobody lists. We build the record of what exists, where it lives, why you have it, who can reach it and how long it stays. This gates everything downstream, so it goes first and it gets done properly rather than quickly.

  2. 2

    Assess against the seven obligations

    Each obligation scored against what your estate can currently do, not against what your policies say. The output is a gap register with an owner, an effort estimate and a dependency chain for every item, and an explicit note where an obligation is a legal determination rather than an engineering one so it routes to your counsel.

  3. 3

    Fix the long-lead items first

    Log retention extended and centralised so a year of history starts accumulating. Access control tightened, shared accounts eliminated, joiner-mover-leaver made real. Encryption, labelling and data loss prevention configured on the entitlements you already hold. These take time to take effect, which is why they cannot be last.

  4. 4

    Build the machinery for consent, rights and erasure

    Consent capture reworked to be purpose-scoped, provable and interoperable. A rights request process that can actually query every system inside ninety days. Retention schedules implemented as something that deletes rather than something that describes deletion. This is the largest block of application work and it depends on stage one being right.

  5. 5

    Test breach response, then keep it warm

    A tabletop exercise against the seventy two hour clock: who declares, who assesses scope, who drafts the Board notification, who tells affected individuals, and how you evidence what you did. Then a review cadence, because an estate drifts and a control nobody re-checks is a control you no longer have.

Questions we get asked

DPDP compliance, answered plainly.

Next step

Find out how far you actually are.

Most businesses are further from DPDP compliance than their policy documents suggest, and closer than the panic in the market implies. A readiness review tells you which, with a gap register you can plan and budget against. Remote-first from Hyderabad, serving all of India, and we will tell you plainly if the honest answer is that you have less to do than you feared.