India’s Digital Personal Data Protection Act establishes a framework for digital personal data. DPDP Act compliance starts with understanding which processing activities are in scope, the lawful purpose for holding data, the safeguards around it and the duties that apply as provisions commence. This article is a readiness guide for business owners planning that work.
Use this as a business preparation guide, with scope and commencement decisions checked against the linked legislation. It separates the legal framework from suggested inventory and evidence practices.
Does it apply to us?
Assess the digital personal data your organisation processes in India, including information collected digitally and paper records subsequently digitised. Customer records, payroll and support systems are sensible starting points for the assessment. Check the Act’s scope and exemptions against the actual processing activity rather than assuming every record has identical treatment.
Company size alone does not determine applicability. The Act also addresses processing outside India connected with offering goods or services to people within India. Record the basis for each scope decision, particularly where the organisation operates in several markets.
Section 3 sets out exclusions, including personal or domestic processing by individuals and certain publicly available data. Check the conditions for an exclusion rather than treating anything found online as unrestricted personal data.
What does it actually ask you to do?
Provide a clear notice before or with the consent request, explaining the personal data and processing purpose and the applicable routes for exercising rights. Check section 5 and the Rules rather than relying on a general terms-and-conditions link.
Identify the applicable ground for each processing purpose. Sections 6 and 7 distinguish consent from specified legitimate uses; do not assume either a consent tick-box or a general business interest is sufficient for every activity.
Let it go when the reason ends. If someone withdraws consent, or the purpose you collected it for is finished, the data should be deleted — unless another law requires you to keep it. Your suppliers have to delete their copies too.
When Rule 7 applies, affected individuals and the Board receive initial notification without delay after awareness of a personal data breach. The fuller Board submission follows within 72 hours of awareness, unless the Board allows an extension on written request. The fuller report does not postpone initial notification. DPDP Rules 1 and 7
Answer the person whose data it is. They can ask what you hold, ask you to correct it, ask you to delete it, and complain if you do not. There has to be a route they can actually find.
Significant Data Fiduciaries designated under section 10 have additional duties. Assess that status separately rather than assuming every organisation has a statutory DPO or annual independent audit requirement.
When do we have to be ready?
Track Act commencement and Rules commencement separately.
The November 2025 notifications phase commencement by provision. The legal trigger is publication in the Official Gazette, not an assumed date derived solely from the notification heading. Record the official publication date in the organisation’s implementation register and calculate its milestones consistently. G.S.R. 843(E): staged Act commencement
Treat the phased implementation period as time to prepare. It does not remove obligations under other laws, contracts or sector rules that already apply to your organisation.
Three practical gaps to investigate
The following are review prompts, not survey findings about the prevalence of non-compliance.
Inventory gaps: personal data may exist outside the principal application, including exports, support records and backups. Reconcile the inventory with the teams that use and administer those copies.
Purpose and permission gaps: check whether the stated purpose, appropriate legal ground and supporting record can be connected to the actual processing. Do not infer valid consent from a field marked yes.
Supplier gaps: identify processors, relevant subcontractors and the terms governing their work. Compare the agreement with actual access and retention behaviour.
What is a sensible first step?
This part is our recommendation rather than anything the law prescribes: start with a list. What personal data you hold, where it lives, why you have it, who can reach it, and how long it stays.
It is unglamorous and it is the step everything else depends on. Decide the reason for each purpose only once you know what the purposes are. Fix the gaps that carry real exposure before the ones that are simply easy. And keep the evidence as you go, because on the day it matters you will be asked to show your working, not describe it.
The available preparation time is easier to use when someone owns each action. Put the inventory, supplier review, notice updates and response exercise into a dated plan, and revisit the commencement position before each compliance milestone.
The detail, for whoever needs it
Use the Act, commencement notification and notified Rules for legal requirements. The preparation register below is a suggested working tool.
- Who it covers, and the exclusions — Act, section 3.
- Notice before or with the consent request — Act, section 5. Consent — section 6. The other permitted uses — section 7.
- Deleting when consent is withdrawn or the purpose ends — Act, section 8(7).
- Extra duties for designated organisations — Act, section 10(2); annual assessment and audit, Rules, rule 13.
- Breach reporting, and the seventy-two hours — Rules, rule 7.
- Commencement — G.S.R. 843(E) for Act provisions and Rule 1 of G.S.R. 846(E) for Rules. Consult the official publication and any subsequent amendments.
- Penalties — the Act's Schedule. The largest attaches to not having taken reasonable security measures, rather than to the breach itself.
This article explains the law in general terms. It is not legal advice, and it is not a substitute for counsel on your own position.
Provision-level commencement and preparation register
- At publication: Act section 1(2), section 2, sections 18–26, 35, 38–43 and 44(1), 44(3); Rules 1, 2 and 17–21. These include institutional provisions. Record the source and do not equate creation of the framework with commencement of every business duty.
- One year after publication: Act section 6(9), section 27(1)(d), and Rule 4. Track the consent-manager provisions separately from ordinary fiduciary preparation.
- Eighteen months after publication: Act sections 3–5, section 6(1)–(8), 6(10), sections 7–17, the remaining section 27, sections 28–34, 36–37 and 44(2); Rules 3, 5–16, 22–23. Recheck later notifications before relying on a milestone.
- Suggested inventory row: processing purpose; personal data; system and supplier; applicable ground; access owner; retention reason; deletion process; supporting record; unresolved gap; action owner. Validate one end-to-end process before expanding the register.

