The Digital Personal Data Protection Act is India's first dedicated privacy law. Its Rules are now in force, with full enforcement due by May 2027. Here's why it's pathbreaking, what changes, and what your business must do — no jargon, just pictures and plain words.
Wrong — and it's the costliest myth. DPDP applies to every organisation processing the personal data of people in India, regardless of size or sector. There is no small-business exemption from the core duties — a five-person clinic or a single-founder startup is covered just like a large enterprise. Only extra "Significant Data Fiduciary" duties are reserved for bigger players, and even those are assigned by government, not chosen.
You gave your number to one app — food delivery, a loan check, a lucky-draw form. Weeks later, strangers call about insurance, plots, and trading tips. It wasn't a leak. Under the old rules, selling your data onward was a business model.
A company you trusted gets breached. Millions of records surface online. Under the old regime, there was no duty to tell you — many breaches stayed quiet for months while your credentials circulated.
Diagnostic reports, prescriptions, admission forms — copied, stored, shared with insurers and labs with no retention limit and no way to ask "who has this?" Health data flowed with less protection than a bank OTP.
AccessKnow exactly what personal data a company holds about you.
CorrectionFix data that's wrong, outdated, or incomplete.
ErasureHave your data deleted once its purpose is served.
Grievance & the BoardEscalate to a dedicated regulator when a company won't listen.
NominationName someone to exercise your rights if you can't — a uniquely Indian feature.
These are the obligations auditors will test. Mapped to the Act and the DPDP Rules 2025.
Free, specific, informed, unambiguous — and as easy to withdraw as to give. Standalone plain-language notice.
Reasonable safeguards, data minimisation, and one-year retention of security logs.
Notify the Board and affected individuals; detailed report within 72 hours.
Delete personal data once its purpose is served or consent is withdrawn; documented schedules.
"Negative list" model — allowed except to countries the government restricts. Map your data flows now.
Annual DPIA, independent audit, India-based DPO, and algorithmic due-diligence — for those government notifies.
Weak IT-Act protections, rarely used.
Privacy declared a fundamental right.
India's first privacy statute passed.
Act operationalised; Board established; 18-month clock starts.
Consent-manager framework goes live.
All obligations enforceable; penalties bite.
A focused readiness assessment: your data map, consent gaps, breach-response plan, and retention practices — scored against the Act and Rules 2025, evidenced, and turned into a prioritised fix list. Well ahead of May 2027.
Sources: Ministry of Electronics & Information Technology (MeitY) / PIB — DPDP Rules 2025 notification (Nov 2025); Digital Personal Data Protection Act, 2023. Figures reflect the enacted Act and notified Rules as reviewed on 10 Jul 2026. This page is general information, not legal advice.