Regulation & assurance

DPDP Compliance: Scope, Phases and Preparation

Plan DPDP compliance using a provision-level commencement register, data-purpose inventory, processor review and separate breach-notification responsibilities.

A layered paper data-lifecycle map connects purpose, accountable use, sharing, retention, deletion, breach response and evidence.
In this article 8 sections
ShareLinkedInWhatsAppEmail

India’s Digital Personal Data Protection Act establishes a framework for digital personal data. DPDP Act compliance starts with understanding which processing activities are in scope, the lawful purpose for holding data, the safeguards around it and the duties that apply as provisions commence. This article is a readiness guide for business owners planning that work.

Use this as a business preparation guide, with scope and commencement decisions checked against the linked legislation. It separates the legal framework from suggested inventory and evidence practices.

Does it apply to us?

Assess the digital personal data your organisation processes in India, including information collected digitally and paper records subsequently digitised. Customer records, payroll and support systems are sensible starting points for the assessment. Check the Act’s scope and exemptions against the actual processing activity rather than assuming every record has identical treatment.

Company size alone does not determine applicability. The Act also addresses processing outside India connected with offering goods or services to people within India. Record the basis for each scope decision, particularly where the organisation operates in several markets.

Section 3 sets out exclusions, including personal or domestic processing by individuals and certain publicly available data. Check the conditions for an exclusion rather than treating anything found online as unrestricted personal data.

What does it actually ask you to do?

Provide a clear notice before or with the consent request, explaining the personal data and processing purpose and the applicable routes for exercising rights. Check section 5 and the Rules rather than relying on a general terms-and-conditions link.

Identify the applicable ground for each processing purpose. Sections 6 and 7 distinguish consent from specified legitimate uses; do not assume either a consent tick-box or a general business interest is sufficient for every activity.

Let it go when the reason ends. If someone withdraws consent, or the purpose you collected it for is finished, the data should be deleted — unless another law requires you to keep it. Your suppliers have to delete their copies too.

When Rule 7 applies, affected individuals and the Board receive initial notification without delay after awareness of a personal data breach. The fuller Board submission follows within 72 hours of awareness, unless the Board allows an extension on written request. The fuller report does not postpone initial notification. DPDP Rules 1 and 7

Answer the person whose data it is. They can ask what you hold, ask you to correct it, ask you to delete it, and complain if you do not. There has to be a route they can actually find.

Significant Data Fiduciaries designated under section 10 have additional duties. Assess that status separately rather than assuming every organisation has a statutory DPO or annual independent audit requirement.

When do we have to be ready?

Track Act commencement and Rules commencement separately.

The November 2025 notifications phase commencement by provision. The legal trigger is publication in the Official Gazette, not an assumed date derived solely from the notification heading. Record the official publication date in the organisation’s implementation register and calculate its milestones consistently. G.S.R. 843(E): staged Act commencement

Treat the phased implementation period as time to prepare. It does not remove obligations under other laws, contracts or sector rules that already apply to your organisation.

Three practical gaps to investigate

The following are review prompts, not survey findings about the prevalence of non-compliance.

Inventory gaps: personal data may exist outside the principal application, including exports, support records and backups. Reconcile the inventory with the teams that use and administer those copies.

Purpose and permission gaps: check whether the stated purpose, appropriate legal ground and supporting record can be connected to the actual processing. Do not infer valid consent from a field marked yes.

Supplier gaps: identify processors, relevant subcontractors and the terms governing their work. Compare the agreement with actual access and retention behaviour.

What is a sensible first step?

This part is our recommendation rather than anything the law prescribes: start with a list. What personal data you hold, where it lives, why you have it, who can reach it, and how long it stays.

It is unglamorous and it is the step everything else depends on. Decide the reason for each purpose only once you know what the purposes are. Fix the gaps that carry real exposure before the ones that are simply easy. And keep the evidence as you go, because on the day it matters you will be asked to show your working, not describe it.

The available preparation time is easier to use when someone owns each action. Put the inventory, supplier review, notice updates and response exercise into a dated plan, and revisit the commencement position before each compliance milestone.

The detail, for whoever needs it

Use the Act, commencement notification and notified Rules for legal requirements. The preparation register below is a suggested working tool.

  • Who it covers, and the exclusions — Act, section 3.
  • Notice before or with the consent request — Act, section 5. Consent — section 6. The other permitted uses — section 7.
  • Deleting when consent is withdrawn or the purpose ends — Act, section 8(7).
  • Extra duties for designated organisations — Act, section 10(2); annual assessment and audit, Rules, rule 13.
  • Breach reporting, and the seventy-two hours — Rules, rule 7.
  • Commencement — G.S.R. 843(E) for Act provisions and Rule 1 of G.S.R. 846(E) for Rules. Consult the official publication and any subsequent amendments.
  • Penalties — the Act's Schedule. The largest attaches to not having taken reasonable security measures, rather than to the breach itself.

This article explains the law in general terms. It is not legal advice, and it is not a substitute for counsel on your own position.

Provision-level commencement and preparation register

  • At publication: Act section 1(2), section 2, sections 18–26, 35, 38–43 and 44(1), 44(3); Rules 1, 2 and 17–21. These include institutional provisions. Record the source and do not equate creation of the framework with commencement of every business duty.
  • One year after publication: Act section 6(9), section 27(1)(d), and Rule 4. Track the consent-manager provisions separately from ordinary fiduciary preparation.
  • Eighteen months after publication: Act sections 3–5, section 6(1)–(8), 6(10), sections 7–17, the remaining section 27, sections 28–34, 36–37 and 44(2); Rules 3, 5–16, 22–23. Recheck later notifications before relying on a milestone.
  • Suggested inventory row: processing purpose; personal data; system and supplier; applicable ground; access owner; retention reason; deletion process; supporting record; unresolved gap; action owner. Validate one end-to-end process before expanding the register.

Sources and further guidance

Regulatory applicability depends on the organisation and the provisions in force. Check the linked primary sources before acting.

Related reading and capabilities

Frequently asked questions

Does this apply to us if we are a small company?

Small size is not a general exemption. Assess your digital personal data processing against section 3, the relevant exemptions and the provisions in force. A small business handling customer or employee data should perform that assessment rather than relying on headcount.

We already follow GDPR. Are we done?

GDPR work can provide a useful starting point, but the frameworks differ. Map the DPDP requirements for notices, consent and other permitted uses, children’s data, individual rights and breach notification against your existing controls. Record the gaps and their owners instead of assuming one programme satisfies both laws.

How much time do we actually have?

Track the notification’s publication-based phases: commencement at publication, after one year and after eighteen months. Core business duties are in the May 2027 phase, but other laws and contracts may already impose requirements. Use a provision-level register rather than one organisation-wide deadline.