DPDP guide

The DPDP Act, explained: dates, duties, penalties.

A plain-English guide to India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, for the teams that have to comply with them. Each section answers one question first, then gives the detail and the source.

Last reviewed · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice

The basics

What is the DPDP Act?

The DPDP Act, 2023 is India's law on how organisations may collect and use digital personal data, enforced by the Data Protection Board and detailed by the DPDP Rules, 2025.

The Digital Personal Data Protection Act, 2023 is India’s first law dedicated to personal data. It was passed by Parliament in August 2023 and applies to digital personal data processed in India, and to processing abroad that serves people in India. It puts duties on the organisation deciding how data is used (the Data Fiduciary) and gives the individual (the Data Principal) rights to notice, access, correction, erasure, grievance redress and nomination.

The Act needed detailed rules to work. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. They set the form of the notice, how consent is verified for children, what “reasonable security safeguards” means, the 72-hour breach report, retention and erasure notice periods, and how Consent Managers register. The Rules also fix the phased dates on which each duty starts.

The Data Protection Board of India is the body that enforces the Act. It receives breach reports and complaints, can direct a Data Fiduciary to fix a failure, and can impose monetary penalties up to the amounts in the Schedule to the Act. It is an adjudicating body: it does not issue certifications, and it does not need to be involved before you start processing.

Key dates

When does the DPDP Act apply?

In three steps: the Rules were notified on 13 November 2025, Consent Manager provisions start on 13 November 2026, and every Data Fiduciary duty applies in full from 13 May 2027.

  1. Step 1 13 Nov 2025

    Rules notified. Data Protection Board set up.

  2. Step 2 13 Nov 2026

    Consent Manager provisions start.

    Proposed: earlier date for Significant Data Fiduciaries

  3. Step 3 13 May 2027

    Notice, consent, rights, security, breach and erasure duties apply in full.

Full compliance for all Data Fiduciaries
13 May 2027
-days to go
Today
13 Nov 2025Rules notified. Data Protection Board set up.
13 Nov 2026Consent Manager provisions start.Proposed: earlier date for Significant Data Fiduciaries
13 May 2027Notice, consent, rights, security, breach and erasure duties apply in full.

Confirm the dates that apply to you with your legal team. Check whether the proposed Significant Data Fiduciary date has been notified.

Obligations

What must a Data Fiduciary do?

Give a clear notice, take specific consent for each purpose, make withdrawal as easy as consent, stop and erase when the purpose ends, answer rights requests, keep security safeguards, report breaches, and get verifiable consent for children. The nine duties below carry the section and rule that create them.

The duties, and how Promiz covers them

S. 5 · Rule 3

Clear, itemised notice before processing

In Promiz

Versioned notices in 23 languages, with shown-notice snapshots

S. 6

Free, specific consent for each purpose

In Promiz

A separate choice per purpose; required and optional handled apart

S. 6(4)

Withdrawal as easy as consent

In Promiz

One-click withdrawal in the banner and the privacy portal

S. 6(6)

Stop processing after withdrawal

In Promiz

A stop-processing task per withdrawal, with overdue alerts

S. 8(7) · Rule 8

Erase when the purpose ends

In Promiz

Per-purpose retention, legal holds, 48-hour notice and confirmed deletion

S. 11–14 · Rule 14

Access, correction, erasure, grievance, nomination

In Promiz

Self-service portal and a request queue with deadlines

S. 8(6) · Rule 7

Report a personal data breach

In Promiz

Breach log, 72-hour countdown and a structured report

S. 9 · Rule 10

Verifiable consent for children's data

In Promiz

Guardian verified as an adult through DigiLocker; child-restriction flags

Rule 12 · Fourth Schedule

Exempt classes for children's data

In Promiz

Recorded for the organisation and applied per purpose

Penalties

What are the penalties under the DPDP Act?

Up to ₹250 crore per instance. The Schedule to the Act sets a ceiling for each kind of failure, and the Data Protection Board decides the amount after considering the nature, gravity and duration of the breach and the steps taken to fix it.

Maximum monetary penalties under the Schedule to the DPDP Act, 2023
Maximum penalty Failure Provision
₹250 cr Security safeguards Failing to take reasonable security safeguards to prevent a personal data breach. S. 8(5) · Rule 6
₹200 cr Breach notice · Children Failing to notify the Board and affected Data Principals of a breach; breaching the duties on children’s data. S. 8(6) · S. 9
₹50 cr Other duties Any other breach of the Act or the Rules, including notice, consent, withdrawal, erasure and rights requests. Any other provision

Source: Schedule to the DPDP Act, 2023. Amounts are ceilings per instance, not fixed fines. The Schedule also lists entries for Significant Data Fiduciary duties and for Data Principal duties; confirm the full table with your legal team.

Who is who

Who are the parties under the DPDP Act?

The Act calls the individual a Data Principal, the organisation that decides how data is used a Data Fiduciary, and the regulator the Data Protection Board. The twelve terms below cover the rest of the vocabulary you will meet in notices, contracts and the Rules.

Data Principal
The individual the personal data is about. For a child it includes the parent or lawful guardian, and for a person with disability it includes their lawful guardian.
Data Fiduciary
Any person or organisation that decides why and how personal data is processed, alone or with others. Most businesses that collect customer data are Data Fiduciaries, and the duties in the Act fall on them.
Significant Data Fiduciary
A Data Fiduciary the Central Government notifies as significant, based on factors such as the volume and sensitivity of data it handles and the risk to Data Principals. It carries extra duties, including a Data Protection Officer based in India and periodic independent audits.
Data Protection Board
The Data Protection Board of India, the adjudicating body set up under the Act. It receives breach reports and complaints, directs remedial action and imposes monetary penalties under the Schedule to the Act.
Legitimate use
A ground in section 7 of the Act that lets a Data Fiduciary process personal data without consent in listed situations, such as data a person gives voluntarily for a stated purpose, employment, medical emergencies and compliance with a law. The list is closed; confirm with your legal team before relying on it.
Personal data breach
Any unauthorised processing, or accidental disclosure, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data. A Data Fiduciary must inform affected Data Principals and the Board without delay and file a detailed report within 72 hours.
Erasure
Deleting personal data, and having your processors delete it, once its purpose is served or consent is withdrawn, unless a law requires you to keep it. Rule 8 sets retention periods for some classes of Data Fiduciary and requires at least 48 hours of notice to the Data Principal before erasure.
Nomination
The right of a Data Principal under section 14 to name another person who can exercise their rights on their behalf if they die or become incapable of doing so.
Grievance officer
The person whose contact details a Data Fiduciary must publish so Data Principals can ask about processing and raise grievances. Grievances must be answered within the period the Data Fiduciary publishes, which Rule 14 caps at 90 days.
FAQ

What do teams ask about DPDP compliance?

Short answers to the questions compliance, legal and product teams ask most. Not answered here? Ask us in a demo.

When does the DPDP Act come into force?

In phases. The DPDP Rules, 2025 were notified on 13 November 2025, when the Data Protection Board was set up. Consent Manager provisions start on 13 November 2026. The duties on notice, consent, rights, security, breach and erasure apply in full from 13 May 2027.

Does the DPDP Act apply to my business?

If you process digital personal data in India, yes. It also applies to processing outside India when it is for offering goods or services to people in India. There is no turnover or headcount threshold. The Central Government can exempt some classes of Data Fiduciary (section 17) and can notify large or high-risk ones as Significant Data Fiduciaries; confirm your position with your legal team.

How long do we have to report a personal data breach?

You must inform each affected Data Principal and the Data Protection Board without delay, and send the Board a detailed report within 72 hours of becoming aware of the breach (Rule 7). The Board can extend the 72 hours on a written request.

What happens if we do not comply with the DPDP Act?

The Data Protection Board can impose a monetary penalty for each instance of non-compliance, up to the amount in the Schedule to the Act: ₹250 crore for failing to keep reasonable security safeguards, ₹200 crore for failing to notify a breach or for breaching the duties on children, and ₹50 crore for other duties.

Do existing customers need to consent again?

For consent given before the Act started, the Act asks you to send a notice as soon as reasonably practicable. Ask your legal team whether you also need fresh consent. Promiz can send consent requests by email link.

Is Promiz a registered Consent Manager?

No. Promiz is software that you, the Data Fiduciary, use to run your own consent and rights processes. A Consent Manager is a separate role registered with the Data Protection Board.

Do we need consent for cookies?

If a cookie identifies or profiles a person, treat it as personal data. The website script blocks each tag until its purpose is allowed and records the choice.

Which languages are supported?

English and the 22 languages of the Eighth Schedule. Translate by hand or with background auto-translation. Customers can switch language inside the notice.

How do our systems learn about a withdrawal?

By signed webhook, sent at once. Failed deliveries are retried, then held for review. Your system confirms back to Promiz to close the task.

Does Promiz give legal advice?

No. Promiz supports your compliance programme. Your legal team decides purposes, legal bases and retention periods.

Where do you stand today?

Twelve yes / partly / no questions across notice, rights, security and retention. Two minutes, no sign-up. Then see the gaps closed live in a 30-minute demo.