Skip to main content
Independent DPDP information & compliance resource

DPDP Compliance: Your Guide to Data Protection in India

Understand the Digital Personal Data Protection Act, DPDP Rules, compliance requirements, data protection concepts and practical resources for businesses in India.

Plain-language guidanceUpdated for the DPDP Rules, 2025Not affiliated with the Government of India
DPDP Act enacted
2023
DPDP Act enacted
DPDP Rules notified
2025
DPDP Rules notified
Core obligations apply
May 2027
Core obligations apply
Start here

What Is DPDP Compliance?

DPDP compliance refers to the practices an organisation follows to meet its obligations under the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the DPDP Rules, 2025 whenever it collects, stores, uses or shares the personal data of individuals in India.

It applies to any organisation that processes personal data as a Data Fiduciary or on its behalf as a Data Processor — companies, non-profits, startups and public bodies alike — regardless of size, though specific obligations scale with the volume and sensitivity of the data involved and whether the entity is classified as a Significant Data Fiduciary.

Read the full DPDP Compliance guide

Who needs to consider it

Any business, institution or platform that handles personal data of people in India — from a two-person startup to a large enterprise.

Why it matters

The Act creates enforceable rights for individuals and statutory obligations for organisations, backed by the Data Protection Board of India.

Act vs. Rules

The Act lays down the legal framework and principles; the Rules explain how those obligations are implemented in practice.

The building blocks

DPDP Compliance Requirements

An overview of the major areas organisations typically need to address to work toward DPDP compliance.

  1. Notice

    Informing individuals in clear language what personal data is collected and why, before or at the time of collection.

  2. Consent

    Obtaining free, specific, informed and unambiguous consent, with an equally easy way to withdraw it.

  3. Personal data processing

    Using personal data only for the notified purpose or other permitted "legitimate uses," and limiting collection to what's necessary.

  4. Data Principal rights

    Building processes to receive and respond to access, correction, erasure and nomination requests.

  5. Data security safeguards

    Reasonable technical and organisational measures to prevent unauthorised access, disclosure or loss of data.

  6. Data breach obligations

    Processes to detect a breach and notify the Data Protection Board and affected individuals as required.

  7. Grievance redressal

    An accessible channel for complaints, with defined response timelines before escalation to the Board.

  8. Retention & deletion

    Keeping personal data only as long as necessary for its purpose, then deleting or anonymising it.

  9. Vendor & processor management

    Contracts and oversight where personal data is shared with third-party Data Processors.

  10. Documentation & records

    Internal records of processing activities, consent artefacts and breach response steps to demonstrate accountability.

Note: This is a general overview, not an exhaustive list or legal advice. Obligations vary by the nature of processing and whether an entity qualifies as a Significant Data Fiduciary — organisations should assess their own position, and no software or checklist by itself makes an organisation "compliant."
Get practical

DPDP Compliance Checklist

A starting point for organising your compliance work — not a substitute for legal review.

Compliance readiness checklist

PREVIEW · 10 OF 24 ITEMS
  • Understand applicability to your organisation
  • Identify what personal data you hold
  • Map how that data is processed
  • Review your privacy notices
  • Review consent mechanisms
  • Establish Data Principal request processes
  • Review security safeguards
  • Prepare breach response procedures
  • Review retention and deletion practices
  • Document your compliance activities
Know the difference

DPDP Act & Rules

The DPDP Act sets out the law's principles, rights and obligations. The DPDP Rules explain how those obligations work in practice — the forms, timelines and technical detail organisations need to follow.

Legislation · 2023

DPDP Act 2023

Enacted in August 2023, the Digital Personal Data Protection Act is India's primary law on personal data. It defines key terms — Data Principal, Data Fiduciary, personal data — sets out rights and obligations, establishes the Data Protection Board of India, and prescribes penalties for non-compliance.

Read about the DPDP Act
Subordinate rules · 2025

DPDP Rules

The Digital Personal Data Protection Rules, 2025 were notified in November 2025 to operationalise the Act. They cover notices, Consent Manager registration, breach-reporting timelines and children's data safeguards, with obligations phased in through November 2026 and May 2027.

Read about the DPDP Rules
Individual rights

Data Principal Rights

The DPDP Act gives individuals — Data Principals — a defined set of rights over their personal data.

  1. 01

    Right to access information

    Request a summary of the personal data being processed and the processing activities carried out on it.

  2. 02

    Right to correction

    Request that inaccurate, incomplete or outdated personal data be corrected or updated.

  3. 03

    Right to erasure

    Request erasure of personal data once it is no longer necessary for the purpose it was collected for, subject to legal retention requirements.

  4. 04

    Right to grievance redressal

    Raise a complaint with the Data Fiduciary or its Consent Manager, and escalate to the Data Protection Board if unresolved.

  5. 05

    Right to nominate

    Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

Stay current

Latest DPDP Updates

Regulatory developments, government notifications and compliance milestones as they happen.

  1. Regulatory notificationPublished Nov 2025 · Updated Sep 2026

    DPDP Rules, 2025 notified

    MeitY notified the Digital Personal Data Protection Rules, 2025 along with the DPDP Act's enforcement notification, bringing the framework into force.

  2. InstitutionalPublished Nov 2025 · Updated Sep 2026

    Data Protection Board of India established

    The Rules provide for the constitution of the Board, the body responsible for grievances, investigations and enforcement under the Act.

  3. Compliance timelineEffective Nov 2026 · Updated Sep 2026

    Consent Manager framework activates

    Twelve months after notification, the registration framework for Consent Managers becomes operational.

  4. Compliance timelineEffective May 2027 · Updated Sep 2026

    Core compliance obligations come into force

    Eighteen months after notification, most substantive obligations take effect — notice, consent, breach reporting, security safeguards and Data Principal rights.

Dates reflect publicly available government notifications as of September 2026. Always verify current requirements against official sources such as the Ministry of Electronics and Information Technology (meity.gov.in) and the Gazette of India.
About this website

About DPDP Compliance

Read our editorial approach