DPDP, explained for everyone

India just rewrote the rules of your data — and the clock is running

The Digital Personal Data Protection Act is India's first dedicated privacy law. Its Rules are now in force, with full enforcement due by May 2027. Here's why it's pathbreaking, what changes, and what your business must do — no jargon, just pictures and plain words.

—
Months
—
Days
—
Hours
—
Minutes
—
Seconds
Until the 13 May 2027 full-compliance deadline
✔ Facts verified against the MeitY / PIB Rules notification · Last reviewed 10 Jul 2026
1.4 Bn
Citizens covered
₹0 Cr
Max penalty per breach
1st
Dedicated privacy law of India
0 mo
Runway: Nov 2025 → May 2027
✕

"DPDP is only for big tech companies."

Wrong — and it's the costliest myth. DPDP applies to every organisation processing the personal data of people in India, regardless of size or sector. There is no small-business exemption from the core duties — a five-person clinic or a single-founder startup is covered just like a large enterprise. Only extra "Significant Data Fiduciary" duties are reserved for bigger players, and even those are assigned by government, not chosen.

Life without DPDP — three everyday stories

You've lived these. That's the point.

Scenario 01 · The spam call

They know your name. And your car's loan.

You gave your number to one app — food delivery, a loan check, a lucky-draw form. Weeks later, strangers call about insurance, plots, and trading tips. It wasn't a leak. Under the old rules, selling your data onward was a business model.

WHAT DPDP CHANGESYour data can be used only for the purpose you agreed to. Selling it onward without fresh consent becomes a punishable violation.
Scenario 02 · The hidden breach

Your password leaked. Nobody told you.

A company you trusted gets breached. Millions of records surface online. Under the old regime, there was no duty to tell you — many breaches stayed quiet for months while your credentials circulated.

WHAT DPDP CHANGESBreaches must be reported to the Data Protection Board and to affected users, with a detailed report within 72 hours. Silence itself becomes an offence.
Scenario 03 · The hospital file

Your medical history, photocopied forever.

Diagnostic reports, prescriptions, admission forms — copied, stored, shared with insurers and labs with no retention limit and no way to ask "who has this?" Health data flowed with less protection than a bank OTP.

WHAT DPDP CHANGESYou can ask what's held, demand correction or erasure, and providers must delete data once its purpose is served — with the Board to complain to.
Maximum penalty · per breach
₹5Cr
and DPDP doesn't stop at one number — it's a whole schedule of fines.
₹150
₹200
₹250
₹5 Cr · old ceiling₹250 Cr · DPDP ceiling
The full penalty schedule
TIER 1 · CEILING
₹250 Cr
Security-safeguard failure
Not protecting personal data
TIER 2
₹200 Cr
Breach & children's data
Non-notification · unlawful child data
TIER 3
₹150 Cr
SDF-duty failure
Missed DPIA, audit, or DPO
FOR CONTEXT   the old IT-Act maximum — often unenforced ₹5 Cr
Under the old law, getting data wrong cost almost nothing — ₹5 crore at the very most. DPDP changes that completely. A single slip can now cost up to ₹250 crore, with heavy fines below that too. Keeping people's data safe isn't paperwork anymore — it's something your leadership needs to care about.

Where your data travels: one signup

Left is today; right is DPDP fully in force — all six paths blocked but the one you agreed to
Without DPDP — all six paths open With DPDP — six blocked, one agreed
VS Brokers Ad tech Spam Unknown Resellers Scammers YOU Brokers Ad tech Spam Unknown Resellers Scammers YOU AGREED USE ✓
Open path (before) Consent gate & agreed path Blocked / severed path
In plain words: today, one signup can send your data down all six paths at once — brokers, ad-tech, spammers, resellers, and parties you've never heard of. Under DPDP, a consent gate rings your data: those same six paths are blocked, and only the single purpose you agreed to gets through — which you can withdraw whenever you want.
Without DPDP — the old default

Your data, everyone's asset

  • Numbers and emails sold to brokers — spam that knows your name
  • Breaches hidden for months; victims never informed
  • "Delete my data" — legally ignorable
  • Consent buried in 40-page terms nobody reads
  • No regulator dedicated to your privacy
With DPDP fully operational

Your data, your rules

  • Consent must be specific, informed — and as easy to withdraw as to give
  • Breaches reported to the Board and to you within 72 hours
  • Erasure and correction are enforceable legal rights
  • Notices in plain language, in Indian languages
  • A fully-digital Data Protection Board with real penalty power
What you can now demand

Five rights every Indian gains

1

AccessKnow exactly what personal data a company holds about you.

2

CorrectionFix data that's wrong, outdated, or incomplete.

3

ErasureHave your data deleted once its purpose is served.

4

Grievance & the BoardEscalate to a dedicated regulator when a company won't listen.

5

NominationName someone to exercise your rights if you can't — a uniquely Indian feature.

If you run a business — your duties

What a Data Fiduciary must do

These are the obligations auditors will test. Mapped to the Act and the DPDP Rules 2025.

Section 6

Valid consent

Free, specific, informed, unambiguous — and as easy to withdraw as to give. Standalone plain-language notice.

Section 8 · Rule 6

Security & logs

Reasonable safeguards, data minimisation, and one-year retention of security logs.

Rule 7

Breach notification

Notify the Board and affected individuals; detailed report within 72 hours.

§8(7) · Rule 8

Retention & erasure

Delete personal data once its purpose is served or consent is withdrawn; documented schedules.

Section 16 · Rule 15

Cross-border transfer

"Negative list" model — allowed except to countries the government restricts. Map your data flows now.

Rule 13 (SDFs)

If you're an SDF

Annual DPIA, independent audit, India-based DPO, and algorithmic due-diligence — for those government notifies.

The road to full operation

Fifteen years in the making — now on a deadline

2011

SPDI Rules

Weak IT-Act protections, rarely used.

2017

Puttaswamy

Privacy declared a fundamental right.

Aug 2023

DPDP Act

India's first privacy statute passed.

Nov 2025

Rules notified

Act operationalised; Board established; 18-month clock starts.

Nov 2026

Consent Managers

Consent-manager framework goes live.

May 2027

Full enforcement

All obligations enforceable; penalties bite.

Straight answers

DPDP questions we hear most

Does DPDP apply to my small business?+
Yes. If you process the personal data of people in India — customers, patients, employees, website visitors — you're covered, whatever your size. There's no revenue or headcount exemption from the core duties. Only additional "Significant Data Fiduciary" obligations are reserved for larger entities the government specifically notifies.
We already follow GDPR — aren't we covered?+
Not automatically. DPDP overlaps with GDPR but differs in important ways: it leans on consent plus a few limited legitimate uses rather than GDPR's multiple lawful bases, has its own breach-notification and cross-border rules, and its own penalty structure. GDPR work is a head start, not a finish line.
When do we actually have to comply?+
The Rules were notified in November 2025, starting an 18-month runway. The consent-manager framework goes live around November 2026, and full compliance — with penalties — is due by 13 May 2027. A stakeholder consultation has floated compressing this to 12 months; it isn't confirmed, so plan for May 2027 but be ready to move faster.
What happens if we don't comply?+
The Data Protection Board can impose penalties up to ₹250 crore for failing to maintain reasonable security safeguards, with further tiers for breach-notification and children's-data failures. Beyond the fine, there's reputational damage and lost enterprise deals, since clients increasingly require DPDP assurances.
Where do we start?+
With a gap assessment: map what personal data you hold and where it flows, check your consent and retention practices, and test your breach-response readiness. That produces a prioritised, scored plan — which is exactly what our DPDP readiness assessment delivers.
From understanding to action

Is your business DPDP-ready?

A focused readiness assessment: your data map, consent gaps, breach-response plan, and retention practices — scored against the Act and Rules 2025, evidenced, and turned into a prioritised fix list. Well ahead of May 2027.

Book a DPDP readiness assessment hello@indicshield.ai SCORED · EVIDENCED · PRIORITISED

Sources: Ministry of Electronics & Information Technology (MeitY) / PIB — DPDP Rules 2025 notification (Nov 2025); Digital Personal Data Protection Act, 2023. Figures reflect the enacted Act and notified Rules as reviewed on 10 Jul 2026. This page is general information, not legal advice.