securion.ai
  • Solutions
  • Cyber & Cloud Security
  • Frameworks
  • Resources
  • Contact Us
SolutionsCyber & Cloud SecurityFrameworksResourcesContact Us
securion.ai

Advanced AI agents for cybersecurity automation and threat detection.

Resources

  • Resources
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Securion.ai. All rights reserved.

Back to Resources
Compliance & Frameworks 14 min read

DPDPA Explained: India's Data Protection Law and How to Get Compliant

A complete, jargon-free guide to India's Digital Personal Data Protection Act, 2023 — who it applies to, consent and notice, data principal rights, penalties up to ₹250 crore, the 2027 deadline, and how to get compliant.

DPDPA Explained: India's Data Protection Law and How to Get Compliant
In This Article
  • Overview
  • Watch: the DPDP Act explained
  • What the DPDP Act 2023 is
  • What it replaces: from a patchwork to a real law
  • The key players: who's who under the DPDPA
  • Consent and notice: the foundation
  • What you must do: the obligations of a Data Fiduciary
  • How to comply: the security controls the Rules require (Rule 6)
  • The rights it gives people
  • Significant Data Fiduciaries: the higher bar
  • Children's data and moving data across borders
  • Enforcement: the Data Protection Board and the penalties
  • The timeline: when you actually have to comply
  • DPDPA vs GDPR: how they differ
  • Who needs to care
  • Why it matters for your organisation
  • The honest part: it's a lot of work — securion.ai can help
  • Free download: the DPDPA readiness kit
  • FAQ
  • Official reference

Overview

DPDPA Explained: India's Data Protection Law and How to Get Compliant

If your business touches the personal data of anyone in India — customers, users, employees — a new law now decides how you're allowed to handle it. It's the Digital Personal Data Protection Act, 2023 (DPDPA), India's first comprehensive data-protection law, and after years of waiting, it finally has teeth: the DPDP Rules, 2025 were notified in November 2025, and the clock to full compliance is now running.

This is the complete, jargon-free guide: what the DPDPA actually is, who it applies to, what it asks of you, the penalties for getting it wrong, and how to get ready before the deadline arrives.

Watch: the DPDP Act explained

Prefer to watch? Here's the full guide in under 4 minutes.

What the DPDP Act 2023 is

The DPDPA is India's law for protecting the digital personal data of individuals. In simple terms, it sets the rules for how organisations may collect, use, store, and share the personal data of people in India — built around one core idea: you hold that data in trust, and the person it belongs to has rights over it.

It applies to digital personal data — data in digital form, or physical data that's later digitised. Crucially, it's extraterritorial: it covers processing that happens inside India, and processing done anywhere in the world if it relates to offering goods or services to people in India. So a company with no office in India can still be squarely on the hook.

What it replaces: from a patchwork to a real law

For more than a decade, India had no dedicated privacy statute — just a patchwork stretched over the Information Technology Act, 2000. The main hook was Section 43A and the SPDI Rules, 2011, and it was thin: it bound only "body corporates," covered just a handful of "sensitive personal data" categories, accepted implied or pre-ticked consent, and had no regulator to enforce any of it.

The DPDPA sweeps that away. It omits Section 43A from the IT Act, effectively retires the SPDI Rules as the governing standard, and even amends the Right to Information Act to strengthen protection of citizens' personal data. And under Section 38(2), where any other law conflicts with the DPDPA, the DPDPA prevails. This is no longer a set of rules bolted onto an IT statute — it is a standalone data-protection law with real teeth.

From a patchwork of IT-Act rules to a standalone data-protection law

The key players: who's who under the DPDPA

The Act gives everyone a specific role. Get these straight and the rest of the law reads much more easily.

Term Who they are
Data Principal the individual the data is about (the equivalent of a "data subject")
Data Fiduciary the organisation that decides why and how personal data is processed (like a "controller")
Data Processor a third party that processes data on a Fiduciary's behalf (a vendor, a cloud tool)
Consent Manager a registered platform where people grant, review, and withdraw consent in one place
Significant Data Fiduciary (SDF) a Fiduciary the government designates for large-scale or high-risk processing — with extra duties

The word "fiduciary" is deliberate: it frames the organisation as a trustee of the individual's data, not just a collector of it.

How the roles connect: the Data Principal gives consent to a Data Fiduciary, which may engage Data Processors — all overseen by the Data Protection Board

Consent and notice: the foundation

Under the DPDPA, you generally need a valid legal basis to process someone's personal data. In most cases that means consent — and the bar is high. Consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action, and it must be as easy to withdraw as it was to give.

Before you take consent, you must give a clear notice that spells out what data you're collecting, the purpose, how the person can exercise their rights, and how to complain to the Board. That notice has to be available in English or any of the 22 languages in the Indian Constitution's Eighth Schedule.

There's a narrow set of "legitimate uses" where consent isn't required — for example, a person voluntarily sharing data for a requested service, or processing for certain state functions, medical emergencies, or employment purposes. But unlike other regimes, the DPDPA has no broad "legitimate interests" escape hatch — if it isn't consent or a listed legitimate use, you can't process the data.

What a compliant sign-up looks like: an itemised notice, an unticked consent toggle per purpose, and an easy way to withdraw

What you must do: the obligations of a Data Fiduciary

If you're a Data Fiduciary, the Act and Rules give you a clear set of duties:

  • Have a valid basis — consent or a defined legitimate use — for every processing activity.
  • Give clear, itemised notice before collecting data, in plain language.
  • Purpose limitation and data minimisation — only collect what you need, only use it for the stated purpose.
  • Keep data accurate where it's used to make decisions or shared with others.
  • Erase data when the purpose is met or consent is withdrawn (unless the law requires you to keep it).
  • Maintain reasonable security safeguards — encryption, access control, logging, backups — to prevent breaches. This is the single most important obligation, and the one with the biggest penalty.
  • Report breaches — notify the Data Protection Board and every affected individual, without delay, in clear language.
  • Provide a grievance-redressal mechanism and respond within set timelines.
  • Bind your processors by contract to the same protections — you stay responsible for what your vendors do.

Taken together, these obligations track the life of every piece of data you hold — from the moment you collect it to the moment you're required to erase it.

The data lifecycle under the DPDPA: collect with consent, use for the stated purpose, retain only as long as needed, then erase

How to comply: the security controls the Rules require (Rule 6)

This is where the DPDPA differs from ISO 27001. ISO hands you a catalogue of 93 named controls to work through. The DPDPA instead asks for "reasonable security safeguards" — a principle, not a checklist. That sounds vaguer, but Rule 6 of the DPDP Rules, 2025 pins it down to a concrete, minimum set of measures every Data Fiduciary (and its processors) must have. These are your controls — and each one is measurable.

Rule 6 safeguard What it means in practice How to measure / evidence it
Encryption & masking Encrypt personal data at rest and in transit; mask, obfuscate, or tokenise it where you can % of data stores encrypted, key-management policy, tokenisation coverage
Access controls Least-privilege access to every system holding personal data; multi-factor authentication access-review reports, MFA coverage, joiner–mover–leaver records
Logging & monitoring Log and review who accesses personal data, to detect unauthorised access, investigate, and remediate log coverage, alerting rules, review cadence
Log retention (1 year) Keep those access logs for at least one year retention configuration, log-store audit
Backups & resilience Be able to keep processing if data is destroyed or compromised backup success rate, tested restore (RTO / RPO)
Breach detection & response Detect, investigate, and remediate breaches quickly detection tooling, an incident runbook, drill records
Processor safeguards Contractually bind every vendor to the same measures — you stay accountable signed data-processing agreements, vendor security reviews

The breach clock (Rule 7). If a breach does happen, the timing is strict: notify affected individuals without delay (in clear language — what happened, the likely impact, what you're doing, and what they should do), and file a detailed report to the Data Protection Board within 72 hours of becoming aware. You can only hit that clock if your logging and detection (the controls above) are already working.

The 72-hour breach protocol: detect the breach, notify affected people without delay, and report to the Data Protection Board within 72 hours

So how do you measure compliance? Because "reasonable" isn't a number, you prove it by adopting a recognised control framework and keeping live evidence against it. In practice, that means mapping the Rule 6 safeguards onto a control set you already understand — ISO 27001, SOC 2, or NIST — then scoring every control as implemented, partial, or not started, assigning an owner, and keeping the evidence current for the day the Board asks. That control-by-control, evidence-backed view is exactly how you turn a principle into something you can measure.

The rights it gives people

The other half of the Act is the set of rights it hands to every Data Principal:

  • Right to access — a summary of the personal data being processed and who it's shared with.
  • Right to correction, completion, updating, and erasure of their personal data.
  • Right to grievance redressal — a clear channel to raise problems with the Fiduciary first.
  • Right to nominate another person to exercise their rights in the event of death or incapacity.

Rights aren't only one-way. Data Principals also carry duties — a distinctive feature of the Indian law. They must not impersonate someone else when giving data, not suppress material information, not register false or frivolous grievances, and only provide verifiably authentic information when exercising the right to correction or erasure. Filing a false complaint can itself attract a penalty.

Significant Data Fiduciaries: the higher bar

The government can designate certain organisations as Significant Data Fiduciaries based on the volume and sensitivity of data they handle, the risk to individuals, and impact on national interests. If you're an SDF, you take on extra obligations:

  • Appoint a Data Protection Officer (DPO) based in India, reporting to your board or governing body.
  • Appoint an independent Data Auditor and undergo regular data audits.
  • Carry out periodic Data Protection Impact Assessments (DPIAs).

In short, the bigger your data footprint, the more you have to prove.

Children's data and moving data across borders

Children (under 18): processing a child's data needs verifiable parental consent, and you may not track or behaviourally monitor children or run targeted advertising at them. This is stricter than most global regimes.

Cross-border transfers: the DPDPA takes a negative-list approach — you may transfer personal data outside India except to countries the central government specifically restricts. That's more permissive than a strict data-localisation rule, but the restricted list can change, so transfers need to stay under review.

Enforcement: the Data Protection Board and the penalties

Enforcement sits with the Data Protection Board of India (DPB) — a digital-first body that investigates breaches and complaints and imposes penalties. The financial stakes are serious; penalties are per instance, set against a schedule:

Failure Penalty up to
Failure to take reasonable security safeguards (leading to a breach) ₹250 crore
Failure to notify a personal data breach (Board / affected individuals) ₹200 crore
Breach of obligations relating to children ₹200 crore
An SDF's failure to meet its additional obligations ₹150 crore
Breach of any other provision of the Act or Rules (residuary) ₹50 crore

The pattern is clear: the law reserves its heaviest penalty for organisations that fail to secure the data in the first place.

The Board works digital-first — complaints, notices, and hearings run online. If you disagree with its order, the route of appeal is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and the appeal must be filed within 60 days of the Board's order. The Act also encourages voluntary undertakings and mediation to resolve matters before they reach a penalty.

The timeline: when you actually have to comply

The DPDPA is arriving in phases, which is good news — you have a runway, but it's finite:

  • 13 November 2025 — Rules notified; the Data Protection Board is constituted and the governance machinery switches on.
  • ~November 2026 — the Consent Manager registration framework comes into effect.
  • ~Mid-2027 (about 18 months after notification) — the core operational obligations become enforceable: notice and consent, data-principal rights, breach reporting, and the SDF duties.

The takeaway: the substantive compliance work is due in 2027, but building the security safeguards, mapping your data, and standing up your processes is a months-long effort. The organisations that wait until 2027 to start will be the ones scrambling.

DPDPA vs GDPR: how they differ

If you already comply with the EU's GDPR, you have a head start — but the DPDPA is not a copy of it.

DPDPA (India) GDPR (EU)
Scope digital personal data only personal data in any form
Lawful bases consent + a few defined "legitimate uses" (no "legitimate interests") six bases, including legitimate interests
Children under 18 need verifiable parental consent; no tracking or targeted ads 16 (or 13 in some states)
Cross-border allowed except to restricted countries (negative list) adequacy decisions / standard clauses
Regulator Data Protection Board of India (digital-first) national data-protection authorities
Headline penalty ₹250 crore per instance up to 4% of global turnover

The DPDPA is deliberately leaner and more consent-centric — which sounds simpler, but the narrow lawful bases mean you can't lean on "legitimate interests" the way GDPR programmes often do.

Who needs to care

Practically everyone handling Indian personal data at scale:

  • SaaS, technology, and internet businesses
  • Banking, fintech, and financial services
  • Healthcare and life sciences
  • E-commerce, retail, and consumer apps
  • Any global company offering goods or services to people in India

If you collect email addresses, run a login, process payments, or use analytics on Indian users, the DPDPA applies to you.

Why it matters for your organisation

  • It's the law — with penalties up to ₹250 crore per instance and a regulator now standing up.
  • It builds trust — demonstrable data protection is fast becoming a condition of doing business, and of enterprise procurement.
  • It aligns with global regimes — a solid DPDPA programme overlaps heavily with GDPR, ISO 27001, and SOC 2, so one effort supports many obligations.
  • It reduces breach risk — the "reasonable security safeguards" duty pushes you to fix the exact weaknesses attackers exploit.

Put plainly: the DPDPA turns data protection from a nice-to-have into a board-level obligation with a deadline.

The honest part: it's a lot of work — securion.ai can help

Here's what nobody tells you: the Act is readable, but the doing is heavy. You have to find every system that touches personal data, prove you have reasonable security safeguards around it, keep that evidence current, and be ready to detect and report a breach on the clock. That's months of work, usually pulled from the team you can least spare.

This is where Securion.ai comes in. Our AI agents map your cloud and systems to the DPDPA's Rule 6 safeguards — the "reasonable security safeguards" duty that carries the largest penalty — scored against a control framework like ISO 27001, and give you a live, control-by-control view of exactly where you stand: implemented, partial, or exposed. Instead of guessing, you get a clear picture of your security posture, a prioritised path to close the gaps, and continuous monitoring so you don't drift back out of compliance between now and the deadline. (Securion helps you meet the security and evidence side of the DPDPA; it isn't a substitute for legal advice on consent and notice.)

👉 Want to know where you stand on the DPDPA's security requirements? Talk to us at securion.ai — we'll map your systems to the obligations and show you the gaps, so you know exactly what to fix first.

Free download: the DPDPA readiness kit

Want to turn this guide into action? We've packaged the full control set into two free, ready-to-use documents:

  • 📋 DPDPA Readiness Checklist (PDF) — all 53 controls across 7 domains, each with a Not started / Partial / Implemented status and an owner/evidence column. Score exactly where you stand.
  • 🗂️ DPDPA Legal Cross-Reference Index (PDF) — every DPDP Act section and Rule mapped to the controls that satisfy it: the view your auditor will ask for.

FAQ

1. When do businesses have to comply with the DPDPA?

The Rules were notified on 13 November 2025 and the law is rolling out in phases. The core operational obligations — notice and consent, data-principal rights, breach reporting, and SDF duties — become enforceable around mid-2027, roughly 18 months after notification. The Data Protection Board and governance provisions are already live.

2. What are the penalties under the DPDP Act?

Up to ₹250 crore per instance for failing to maintain reasonable security safeguards, up to ₹200 crore for breach-notification and children-related failures, up to ₹150 crore for an SDF's lapses, and up to ₹50 crore for other breaches.

3. Is the DPDPA the same as GDPR?

No. The DPDPA is digital-only, more consent-centric, and has narrower lawful bases (no "legitimate interests"), stricter rules for children, and a negative-list approach to cross-border transfers. Many companies will comply with both, and the security controls overlap heavily.

4. Can one company be the Data Fiduciary, Data Processor, and Consent Manager?

Partly. A Data Fiduciary can process the data itself — so it is effectively its own processor — and it can capture, store, and let people withdraw consent directly; you do not need a Consent Manager to collect consent. But the Consent Manager is a separate, regulated role: under the DPDP Rules, 2025 it must be an independent, Board-registered company (with a minimum net worth and strict conflict-of-interest rules) and it is barred from also being the Data Fiduciary or Processor for the same person's data. So one party can handle the fiduciary role, the processing, and in-house consent capture — but it cannot also be the official registered Consent Manager for its own users.

Official reference

This guide is a practical explainer. For the authoritative text, read the official government documents:

  • The Digital Personal Data Protection Act, 2023 (PDF) — the Act as passed by Parliament (No. 22 of 2023, dated 11 August 2023).
  • The DPDP Rules, 2025 (PDF) — the operative Rules notified by India's Ministry of Electronics and Information Technology (MeitY) on 13 November 2025 (G.S.R. 846(E)).

Both are official public documents published by MeitY. For a section-by-section breakdown, see dpdpa.com.


Written by Saravanakumar Malaichami, Founder of Securion.ai — 20+ years building secure systems. Securion helps cloud-native teams find risk, fix it, and prove it. Follow along for security, made simple.

Why Securion?

  • AI-driven threat detection across cloud and SaaS
  • Continuous compliance for SOC 2, ISO 27001, and more
  • Hundreds of security agents — no extra headcount
  • Live audit trail your auditors can self-serve
Try Securion Free
Article Info
Author
Saravanakumar Malaichami, Founder, Securion.ai
Published
1 September 2026
Read time
14 min read
Tags
dpdp actdpdpadata protectionprivacyindiacompliance
securion.ai
  • Solutions
  • Cyber & Cloud Security
  • Frameworks
  • Resources
  • Contact Us
Login
SolutionsCyber & Cloud SecurityFrameworksResourcesContact Us
Login