Clear, itemised notice before processing
Versioned notices in 23 languages, with shown-notice snapshots
A plain-English guide to India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, for the teams that have to comply with them. Each section answers one question first, then gives the detail and the source.
Last reviewed · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice
The DPDP Act, 2023 is India's law on how organisations may collect and use digital personal data, enforced by the Data Protection Board and detailed by the DPDP Rules, 2025.
The Digital Personal Data Protection Act, 2023 is India’s first law dedicated to personal data. It was passed by Parliament in August 2023 and applies to digital personal data processed in India, and to processing abroad that serves people in India. It puts duties on the organisation deciding how data is used (the Data Fiduciary) and gives the individual (the Data Principal) rights to notice, access, correction, erasure, grievance redress and nomination.
The Act needed detailed rules to work. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. They set the form of the notice, how consent is verified for children, what “reasonable security safeguards” means, the 72-hour breach report, retention and erasure notice periods, and how Consent Managers register. The Rules also fix the phased dates on which each duty starts.
The Data Protection Board of India is the body that enforces the Act. It receives breach reports and complaints, can direct a Data Fiduciary to fix a failure, and can impose monetary penalties up to the amounts in the Schedule to the Act. It is an adjudicating body: it does not issue certifications, and it does not need to be involved before you start processing.
In three steps: the Rules were notified on 13 November 2025, Consent Manager provisions start on 13 November 2026, and every Data Fiduciary duty applies in full from 13 May 2027.
Rules notified. Data Protection Board set up.
Consent Manager provisions start.
Proposed: earlier date for Significant Data Fiduciaries
Notice, consent, rights, security, breach and erasure duties apply in full.
Confirm the dates that apply to you with your legal team. Check whether the proposed Significant Data Fiduciary date has been notified.
Give a clear notice, take specific consent for each purpose, make withdrawal as easy as consent, stop and erase when the purpose ends, answer rights requests, keep security safeguards, report breaches, and get verifiable consent for children. The nine duties below carry the section and rule that create them.
Versioned notices in 23 languages, with shown-notice snapshots
A separate choice per purpose; required and optional handled apart
One-click withdrawal in the banner and the privacy portal
A stop-processing task per withdrawal, with overdue alerts
Per-purpose retention, legal holds, 48-hour notice and confirmed deletion
Self-service portal and a request queue with deadlines
Breach log, 72-hour countdown and a structured report
Guardian verified as an adult through DigiLocker; child-restriction flags
Recorded for the organisation and applied per purpose
Up to ₹250 crore per instance. The Schedule to the Act sets a ceiling for each kind of failure, and the Data Protection Board decides the amount after considering the nature, gravity and duration of the breach and the steps taken to fix it.
| Maximum penalty | Failure | Provision |
|---|---|---|
| ₹250 cr | Security safeguards Failing to take reasonable security safeguards to prevent a personal data breach. | S. 8(5) · Rule 6 |
| ₹200 cr | Breach notice · Children Failing to notify the Board and affected Data Principals of a breach; breaching the duties on children’s data. | S. 8(6) · S. 9 |
| ₹50 cr | Other duties Any other breach of the Act or the Rules, including notice, consent, withdrawal, erasure and rights requests. | Any other provision |
Source: Schedule to the DPDP Act, 2023. Amounts are ceilings per instance, not fixed fines. The Schedule also lists entries for Significant Data Fiduciary duties and for Data Principal duties; confirm the full table with your legal team.
The Act calls the individual a Data Principal, the organisation that decides how data is used a Data Fiduciary, and the regulator the Data Protection Board. The twelve terms below cover the rest of the vocabulary you will meet in notices, contracts and the Rules.
Short answers to the questions compliance, legal and product teams ask most. Not answered here? Ask us in a demo.
In phases. The DPDP Rules, 2025 were notified on 13 November 2025, when the Data Protection Board was set up. Consent Manager provisions start on 13 November 2026. The duties on notice, consent, rights, security, breach and erasure apply in full from 13 May 2027.
If you process digital personal data in India, yes. It also applies to processing outside India when it is for offering goods or services to people in India. There is no turnover or headcount threshold. The Central Government can exempt some classes of Data Fiduciary (section 17) and can notify large or high-risk ones as Significant Data Fiduciaries; confirm your position with your legal team.
You must inform each affected Data Principal and the Data Protection Board without delay, and send the Board a detailed report within 72 hours of becoming aware of the breach (Rule 7). The Board can extend the 72 hours on a written request.
The Data Protection Board can impose a monetary penalty for each instance of non-compliance, up to the amount in the Schedule to the Act: ₹250 crore for failing to keep reasonable security safeguards, ₹200 crore for failing to notify a breach or for breaching the duties on children, and ₹50 crore for other duties.
For consent given before the Act started, the Act asks you to send a notice as soon as reasonably practicable. Ask your legal team whether you also need fresh consent. Promiz can send consent requests by email link.
No. Promiz is software that you, the Data Fiduciary, use to run your own consent and rights processes. A Consent Manager is a separate role registered with the Data Protection Board.
If a cookie identifies or profiles a person, treat it as personal data. The website script blocks each tag until its purpose is allowed and records the choice.
English and the 22 languages of the Eighth Schedule. Translate by hand or with background auto-translation. Customers can switch language inside the notice.
By signed webhook, sent at once. Failed deliveries are retried, then held for review. Your system confirms back to Promiz to close the task.
No. Promiz supports your compliance programme. Your legal team decides purposes, legal bases and retention periods.
Twelve yes / partly / no questions across notice, rights, security and retention. Two minutes, no sign-up. Then see the gaps closed live in a 30-minute demo.