Skip to main content

What is the DPDP Act in India? A plain-English guide for businesses.

What is the DPDP Act? India's Digital Personal Data Protection Act 2023 and DPDP Rules 2025 explained: who it applies to, key duties, deadlines and penalties.

Senior Consultant, Summit
7 min read
Timeline of India's DPDP Act and Rules from November 2025 to May 2027 with the maximum penalty
DPDP Act and DPDP Rules 2025 · phased timeline
On this page
  1. What is the DPDP Act?
  2. Who does the DPDP Act apply to?
  3. DPDP Act timeline: when each part applies
  4. Key obligations for businesses under the DPDP Act
    1. 1. Lawful basis: consent or legitimate use
    2. 2. Notice
    3. 3. Reasonable security safeguards
    4. 4. Personal data breach notification
    5. 5. Data retention and erasure
    6. 6. Children’s data
    7. 7. Rights of data principals
    8. 8. Significant data fiduciaries
  5. DPDP Act penalties
  6. DPDP Act vs GDPR: key differences
  7. A DPDP compliance checklist
  8. Where security testing fits
  9. Common misconceptions about the DPDP Act
  10. What the DPDP Act means for a typical SaaS company
  11. How Summit helps with DPDP readiness
  12. Frequently asked questions

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (often written DPDPA or DPDP Act) is India’s first comprehensive law dedicated to personal data protection. Parliament passed it in August 2023, and the Ministry of Electronics and Information Technology (MeitY) notified the DPDP Rules, 2025 on 13 November 2025, which put the law into operation in phases.

The Act has a simple structure. Data principals (individuals) have rights over their personal data. Data fiduciaries (organisations that decide why and how data is processed) have duties. Data processors process data on a fiduciary’s behalf. The Data Protection Board of India enforces the law, investigates breaches and imposes penalties.

Personal data
Any data about an individual who is identifiable by or in relation to that data
Digital personal data
Personal data collected in digital form, or collected offline and later digitised
Data principal
The individual the data relates to; for a child, includes the parent or lawful guardian
Data fiduciary
The organisation that determines the purpose and means of processing
Data processor
An organisation that processes data on behalf of a data fiduciary
Significant data fiduciary (SDF)
A fiduciary notified by the government based on volume and sensitivity of data and risk, with extra obligations
Consent manager
A registered entity that lets individuals give, manage and withdraw consent through one platform

Who does the DPDP Act apply to?

The Act applies to the processing of digital personal data within India, and to processing outside India when it is connected to offering goods or services to people in India. That reach matters for foreign SaaS and e-commerce companies with Indian customers.

It applies regardless of company size. A five-person startup with an app and a large bank are both data fiduciaries; what differs is the volume and risk of their data, and whether the government designates them as significant data fiduciaries.

Certain processing is exempt or partly exempt, including personal or domestic use, personal data an individual has made publicly available themselves, specified government functions, and some research, archiving and statistical purposes. Exemptions are narrow, so assume the Act applies unless your counsel confirms otherwise.

DPDP Act timeline: when each part applies

The Rules set a phased start from their notification on 13 November 2025:

  1. 13 November 2025: framework in force

    Definitions, the Data Protection Board of India and the government's rule-making powers take effect. The Board is set up to receive complaints and breach notices.

  2. November 2026: consent managers

    Registration and obligations of consent managers apply, 12 months after notification.

  3. May 2027: core obligations

    Notice and consent, data fiduciary duties including security safeguards and breach reporting, children's data, data principal rights, cross-border transfers, significant data fiduciary duties and Board penalties, 18 months after notification.

18 months is less time than it sounds

Mapping personal data, rewriting consent flows, building rights-request processes, adding security controls and testing them is a multi-quarter programme for most organisations. Teams that start in 2027 will be doing it under enforcement.

Key obligations for businesses under the DPDP Act

You may process personal data only for a lawful purpose, with consent or for a specified legitimate use (for example, data an individual voluntarily provides for a specific purpose, or certain employment and legal obligations). Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the data needed for the stated purpose. Withdrawing consent must be as easy as giving it.

2. Notice

When you ask for consent, you must give a clear notice describing the personal data, the purpose, how the individual can exercise their rights and withdraw consent, and how to complain to the Board. The Rules require notices to be understandable on their own and available in plain language.

3. Reasonable security safeguards

This is where security teams come in. A data fiduciary must protect personal data in its possession or under its control, including data processed by its processors, by taking reasonable security safeguards to prevent a personal data breach. The Rules describe minimum measures, including:

  • Encryption, obfuscation, masking or virtual tokens to secure personal data
  • Access control over the computer resources used to process personal data
  • Visibility of access through logs, monitoring and review, so unauthorised access can be detected and investigated
  • Measures for continued processing if confidentiality, integrity or availability is compromised, such as backups
  • Retention of logs and related personal data for at least one year, to support detection and investigation
  • Contractual obligations on data processors to take reasonable security safeguards

Failing to take reasonable security safeguards carries the largest penalty in the Act: up to ₹250 crore.

4. Personal data breach notification

If a personal data breach occurs, the data fiduciary must inform each affected data principal and the Data Protection Board without delay. Within 72 hours of becoming aware of the breach (or longer if the Board allows), it must give the Board a detailed report covering the facts, causes, impact, measures taken to mitigate it and the findings about the person responsible, if known.

5. Data retention and erasure

Personal data must be erased when the purpose is fulfilled or consent is withdrawn, unless the law requires keeping it. For large e-commerce, online gaming and social media platforms, the Rules set a specific period: data must be erased after three years of inactivity by the user, with at least 48 hours’ notice before erasure.

6. Children’s data

Processing the personal data of a child (anyone under 18) requires verifiable consent of a parent or lawful guardian. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited. The Rules allow limited exemptions, for example for healthcare, educational institutions and childcare in specified circumstances.

7. Rights of data principals

Individuals can request a summary of their personal data and how it is processed, correction, completion, updating and erasure, grievance redressal, and nominate someone to exercise their rights after death or incapacity. You must publish contact details for a person or data protection officer who can answer questions, and respond within the timelines the Rules set.

8. Significant data fiduciaries

Organisations designated as significant data fiduciaries must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out a Data Protection Impact Assessment and audit every 12 months, reporting significant observations to the Board. They must also verify that algorithmic software they deploy does not pose a risk to data principals’ rights.

DPDP Act penalties

The Schedule to the Act sets maximum penalties per instance of breach:

Failure to take reasonable security safeguards
Up to ₹250 crore
Failure to notify a personal data breach
Up to ₹200 crore
Breach of obligations relating to children
Up to ₹200 crore
Breach of significant data fiduciary obligations
Up to ₹150 crore
Breach of duties of data principals
Up to ₹10,000
Breach of any other provision
Up to ₹50 crore

The Board considers factors such as the nature, gravity and duration of the breach, the type of data affected, whether the fiduciary gained from it, and the steps taken to mitigate it. Tested, documented safeguards are the strongest evidence you can bring to that conversation.

DPDP Act vs GDPR: key differences

Companies already compliant with the EU’s GDPR have a head start, but the laws differ:

Scope of data

DPDP covers digital personal data only; GDPR covers all personal data and adds special categories such as health data.

Lawful bases

DPDP relies mainly on consent plus a short list of legitimate uses. GDPR has six bases, including legitimate interests.

Children

DPDP defines a child as under 18 and requires parental consent; GDPR lets member states set an age between 13 and 16.

Breach reporting

DPDP requires notifying every affected individual and the Board for all personal data breaches, not only high-risk ones.

Consent managers

DPDP introduces registered consent managers, a concept GDPR does not have.

Penalties

DPDP uses fixed maximum amounts per breach type; GDPR uses percentages of global turnover.

A DPDP compliance checklist

  1. Map personal data. Inventory what personal data you collect, where it is stored, who can access it and which vendors process it.
  2. Confirm lawful basis and rewrite notices. Replace bundled consents with clear, purpose-specific notices and simple withdrawal.
  3. Review vendors. Update processor contracts to require security safeguards and breach cooperation.
  4. Implement security safeguards. Encryption, access control, logging with one-year retention, monitoring and backups for systems holding personal data.
  5. Test the safeguards. Run penetration tests of applications, APIs and cloud environments that handle personal data, and fix what they find.
  6. Build a breach response process. Detection, assessment, notification to individuals and the Board within 72 hours, and evidence collection. Rehearse it.
  7. Set up rights handling. Request intake, identity verification, response tracking and grievance redressal.
  8. Handle children’s data correctly. Age assurance and verifiable parental consent where children use your service.
  9. Set retention and erasure rules. Delete data you no longer need, with notice where required.
  10. Assign ownership. Name accountable owners, brief the board and track progress to May 2027.

Where security testing fits

The DPDP Act does not mention penetration testing, but “reasonable security safeguards” is a standard you have to be able to demonstrate. If a breach happens, the Board will ask what you did to prevent it. A record of regular, independent security testing, findings fixed and retested, is concrete evidence that your safeguards were real.

Applications holding personal data

Test access control between users and tenants, the most common route to mass data exposure.

APIs and integrations

Test the APIs behind mobile apps and partner integrations, where personal data often flows with weaker checks.

Cloud storage and databases

Check for public buckets, exposed databases and over-privileged access.

Logging and detection

Confirm that access is logged and that suspicious activity would be noticed, as the Rules require.

Our IDOR case study shows how a single access-control flaw exposed 12,000 customer records, exactly the kind of incident the DPDP Act’s safeguards and breach rules are designed to prevent. For framework-level guidance, see our India DPDP compliance guide.

General information, not legal advice

This article summarises the DPDP Act and Rules for business readers. Confirm how they apply to your organisation with qualified counsel, and check the official texts published by MeitY for current requirements.

Common misconceptions about the DPDP Act

"It only applies to big companies"

Every organisation processing digital personal data of people in India is a data fiduciary. Size affects risk and designation as a significant data fiduciary, not whether the Act applies.

"We are outside India, so it does not apply"

Processing outside India is covered when it is connected to offering goods or services to people in India.

"A privacy policy is enough"

The Act requires working consent, rights handling, security safeguards and breach processes. A policy document alone does not demonstrate any of them.

"We have until 2027, so there is nothing to do yet"

Data mapping, consent redesign and security improvements take months. The 18-month window is the time to do them.

"ISO 27001 makes us DPDP compliant"

ISO 27001 helps with security safeguards, but it does not cover consent, notices, data principal rights or children's data.

What the DPDP Act means for a typical SaaS company

Take an Indian SaaS company with a web app, a mobile app, a customer database in the cloud and a handful of third-party tools for email, analytics and support. In practical terms the Act means:

  • Signup and marketing consents become separate, purpose-specific choices, with an easy way to withdraw
  • Each third-party tool that receives personal data needs a contract requiring security safeguards
  • The production database, backups and logs need encryption, access control and monitoring, and access logs need to be kept for at least a year
  • The customer API and admin console need testing for access-control flaws that could expose many users at once
  • Support needs a process to answer access, correction and erasure requests within the required time
  • The incident response plan needs a step for notifying users and the Data Protection Board, with the 72-hour detailed report in mind

How Summit helps with DPDP readiness

Summit is based in New Delhi and helps Indian and international companies test and evidence the security safeguards the DPDP Act requires: web application VAPT, API security testing and cloud security assessment, with reports and retest letters you can keep as evidence.

Preparing for May 2027?

We can test the systems that hold your users’ personal data and give you a prioritised fix list well before the deadline. Read the DPDP compliance guide or get a quote.

Frequently asked questions

What is the DPDP Act?

The Digital Personal Data Protection Act, 2023 is India's law on how organisations collect, use, store and protect digital personal data. It gives individuals rights over their data and requires organisations to obtain valid consent or rely on a permitted legitimate use, protect the data with reasonable security safeguards and report breaches.

When does the DPDP Act come into force?

The DPDP Rules, 2025 were notified on 13 November 2025 and set a phased start. Provisions establishing the Data Protection Board took effect immediately, consent manager rules after 12 months, and most substantive obligations, including notice, consent, security, breach reporting and data principal rights, after 18 months, in May 2027.

Who does the DPDP Act apply to?

It applies to processing of digital personal data within India, and to processing outside India if it is connected to offering goods or services to people in India. Companies of every size are covered, with some exemptions, for example for certain government functions, research and personal or domestic purposes.

What are the penalties under the DPDP Act?

The Schedule to the Act sets penalties per instance of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to notify a breach and for breaching obligations relating to children, up to ₹150 crore for breaching obligations of significant data fiduciaries, and up to ₹50 crore for other breaches.

How quickly must a data breach be reported under the DPDP Rules?

The data fiduciary must inform affected individuals and the Data Protection Board without delay after becoming aware of a personal data breach, and must give the Board a detailed report, including causes, impact and measures taken, within 72 hours unless the Board allows longer.

Does the DPDP Act require penetration testing?

The Act does not name penetration testing. It requires reasonable security safeguards to prevent breaches, and the Rules list measures such as encryption, access control, logging and monitoring. Regular security testing is the most direct way to show those safeguards work.

  • DPDP Act
  • India
  • Data Protection
  • Privacy
  • Compliance

Nishant Sharma

Nishant Sharma is a Senior Consultant at Summit, working on security testing evidence and compliance engagements for SOC 2, ISO 27001 and data protection frameworks.

Talk to a tester

Want us to look at your application?

Scoped quote within a day. Manual testing, verified findings, a fix-and-retest cycle and a report your auditors accept.