If your business collects names, phone numbers, email IDs, employee records or customer purchase histories, the Digital Personal Data Protection Act, 2023 applies to you. The DPDP Act is India’s first comprehensive law on digital personal data. With the DPDP Rules, 2025 now notified, DPDP Act 2023 compliance has moved from a future concern to an active project with fixed deadlines.
This guide explains what the law requires, who it covers, what non-compliance can cost, and the practical steps businesses should take now.
The DPDP Act 2023 governs how organisations collect, use, store and delete digital personal data of individuals in India. To comply, a business must process personal data only with valid consent or for a recognised legitimate use. It must give clear privacy notices, protect data with reasonable security safeguards, report data breaches, honour individuals’ rights, and erase data once its purpose is served. Most substantive obligations become enforceable in May 2027 under the phased DPDP Rules, 2025. Penalties go up to ₹250 crore per instance.
What Is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. The Ministry of Electronics and Information Technology (MeitY) notified the DPDP Rules, 2025 in November 2025, which operationalise the Act in phases. Once fully in force, the Act replaces the earlier data protection framework under Section 43A of the Information Technology Act, 2000.
The law uses its own vocabulary. It helps to understand these terms before looking at obligations:
| Term | Meaning |
|---|---|
| Data Principal | The individual whose personal data is processed (a customer, employee or website visitor) |
| Data Fiduciary | The business that decides why and how personal data is processed |
| Data Processor | A vendor that processes data on the fiduciary’s behalf (payroll provider, CRM, cloud host) |
| Significant Data Fiduciary (SDF) | A fiduciary notified by the government based on data volume, sensitivity and risk, with extra obligations |
| Consent Manager | A registered entity that helps individuals give, manage and withdraw consent |
| Data Protection Board of India | The body that inquires into breaches and imposes penalties |
Does the DPDP Act Apply to Your Business?
The Act applies to the processing of digital personal data within India. This includes data collected online, and data collected offline that is later digitised. It also applies to businesses outside India if they process personal data in connection with offering goods or services to people in India.
There is no general turnover threshold. A 20-person manufacturing company in Noida that keeps employee records in a spreadsheet and customer leads in a CRM is a Data Fiduciary. So is a D2C brand, a hospital, a coaching institute and a fintech startup. The government can exempt certain classes of fiduciaries, including startups, from specific provisions. Businesses should check official notifications rather than assume they are exempt.
The main exclusions are data processed by an individual for personal or domestic purposes, and data that the individual has made publicly available themselves.
DPDP Act Compliance: The Core Obligations
1. Process data only on a lawful basis
Personal data can be processed with the individual’s consent, or for specific “legitimate uses” defined in the Act, such as certain employment purposes or complying with a legal obligation. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. Withdrawing consent must be as easy as giving it. Pre-ticked boxes and bundled “accept all” consents will not hold up.
2. Give a clear privacy notice
Before or at the time of seeking consent, you must tell individuals what data you collect and why. The notice must also explain how they can exercise their rights and how they can complain to the Data Protection Board. It must be available in English or any of the 22 languages in the Eighth Schedule of the Constitution.
3. Collect only what you need
Collect only the data needed for the stated purpose, and use it only for that purpose. A lead form that asks for date of birth and home address to send a brochure is a common example of over-collection.
4. Implement reasonable security safeguards
Businesses must protect personal data against breaches. This applies whether the data sits with them or with their processors. The Rules point to measures such as encryption or masking, access controls, monitoring, backups and maintaining logs. Failing to take reasonable safeguards carries the highest penalty under the Act.
5. Report personal data breaches
If a breach occurs, you must inform affected individuals and the Data Protection Board. The Rules require a detailed report to the Board within 72 hours of becoming aware of the breach. That timeline is only achievable if a breach response plan exists before an incident happens.
6. Honour Data Principal rights
Individuals can request information about how their data is processed. They can also seek correction, completion, updating or erasure, access grievance redressal, and nominate someone to exercise their rights. Businesses need a working process to receive, verify and respond to these requests. They must also publish contact details of a person who can answer data-related questions.
7. Erase data when the purpose is served
Personal data must be deleted once consent is withdrawn or the purpose is no longer served, unless another law requires you to retain it. Processors must delete it too, which means vendor contracts need clear deletion clauses.
8. Take extra care with children’s data
For anyone under 18, businesses need verifiable parental consent. They must not carry out tracking, behavioural monitoring or targeted advertising directed at children.
Significant Data Fiduciaries carry additional duties. They must appoint a Data Protection Officer based in India and an independent data auditor, and conduct periodic Data Protection Impact Assessments.
What Are the Penalties Under the DPDP Act?
Penalties are imposed by the Data Protection Board after an inquiry. They can apply per instance of breach:
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify a personal data breach | ₹200 crore |
| Breach of obligations related to children’s data | ₹200 crore |
| Breach of additional obligations of an SDF | ₹150 crore |
| Breach of any other provision | ₹50 crore |
DPDP Compliance Timeline
The DPDP Rules, 2025 roll out in three phases. Provisions establishing the Data Protection Board took effect on notification in November 2025. Consent Manager registration follows at 12 months, around November 2026. The substantive obligations, including notice and consent, security safeguards, breach reporting, children’s data and Data Principal rights, apply at 18 months, around May 2027.
Eighteen months sounds generous. In practice, data mapping, rebuilding consent flows and renegotiating vendor contracts can take most of that window, especially for businesses with several systems and legacy databases.
A Practical DPDP Compliance Checklist
- Map your data. List every point where personal data enters the business: website forms, WhatsApp, CRM, HR, payroll, billing, CCTV.
- Run a gap assessment against the Act and Rules.
- Rewrite privacy notices and redesign consent capture and withdrawal.
- Review processor contracts for security, breach-reporting and deletion clauses.
- Strengthen security controls and set up log retention.
- Prepare a breach response plan that can meet the 72-hour reporting requirement.
- Build a process for rights requests and grievances.
- Define retention periods for each category of data.
- Train employees who handle personal data.
- Document everything so you can demonstrate compliance to the Board.
Where Businesses Commonly Get Stuck
The hardest part is rarely the website privacy policy. The difficult areas are usually the less visible ones. Employee data is often scattered across HR, payroll and email. Old customer databases were collected without clear consent. Leads arrive through WhatsApp and personal phones. Marketing lists come from third parties. These gaps need to be found through a structured assessment rather than a template policy.
Getting DPDP Compliance Right
DPDP Act 2023 compliance is not a one-time document exercise. It affects how your business collects data, which vendors you use, how your teams work and how quickly you can respond to incidents. Businesses that start now have time to fix gaps properly instead of rushing before May 2027.
AAPT & Associates helps organisations assess their current data practices, close compliance gaps and build processes that stand up to scrutiny.
Frequently Asked Questions
Does the DPDP Act apply to small businesses?
Yes. There is no general size or turnover exemption. Any business processing digital personal data of individuals in India is covered, although the government may exempt certain classes, including startups, from specific provisions.
What is the deadline for DPDP compliance?
Most substantive obligations apply 18 months after the DPDP Rules, 2025 were notified, which is around May 2027.
Is consent always required under the DPDP Act?
No. Personal data can also be processed for legitimate uses defined in the Act, such as certain employment purposes or compliance with a legal obligation.
Who enforces the DPDP Act?
The Data Protection Board of India inquires into breaches and can impose penalties of up to ₹250 crore per instance.







