Last updated: August 28, 2026
Key Takeaways
- The Digital Personal Data Protection Act (DPDPA) was passed in August 2023, but its Rules weren't notified until November 2025. Full compliance isn't mandatory until May 13, 2027.
- DPDPA applies to any business processing personal data in India, and to any business outside India that offers goods or services to people in India, regardless of where the company is headquartered.
- Consent is the default legal basis for processing, but it isn't the only one: Section 7 lists eight specific "legitimate uses" a business can rely on instead, without collecting fresh consent for each one.
- Penalties run up to ₹250 crore for security-safeguard failures, with a separate ₹200 crore tier for breach-notification failures that can stack on the same incident.
Consent is the default legal basis a business relies on to process personal data under DPDPA, but it isn't the only one, and knowing which of the two actually applies changes what a business needs to build. Most compliance guides also get the deadline wrong: the Act itself was enacted in 2023, but nothing was actually enforceable until the Rules were notified in November 2025. Secure Privacy is a cookie and consent management platform that generates DPDPA-compliant consent flows alongside GDPR, CCPA, and 55+ other privacy laws. Below: who's actually in scope, what the two legal bases for processing require, what's exempt, and how to run a real compliance check against all of it.
What Counts as "Personal Data" Under DPDPA?
Personal data under DPDPA is any data about an individual who is identifiable by or in relation to that data. That's a broad definition on purpose: it doesn't require a name specifically, just enough information that a real person could be identified from it, directly or by combining it with other data a business already holds.
Two roles matter for figuring out who's responsible for what. A Data Fiduciary is the business (or person) that determines the purpose and means of processing personal data, the party actually accountable under the Act. A Data Principal is the individual the data belongs to. A Data Processor processes data on a Fiduciary's behalf, under instruction, without independently deciding why or how.
Does DPDPA Apply to Your Business?
Yes, if your business processes personal data of individuals in India, and yes even if your business has no office or legal presence there. The Act applies on two separate bases: processing that happens within India, and processing outside India if it's connected to offering goods or services to people in India. An e-commerce site with no Indian office but real Indian customers is in scope on the second basis alone.
A narrow set of processing is exempt. Section 3 excludes personal or domestic use, and data an individual has already made public themselves (or that's public under a legal obligation) from most of the Act's requirements. Section 17 adds a further, more specific set: processing necessary to enforce a legal right or claim, processing by a court or tribunal in a judicial or quasi-judicial function, and processing for the prevention, detection, investigation, or prosecution of an offense. Notably absent from either list: journalism or media reporting. The Act doesn't carve out an explicit exemption for that, despite it being commonly assumed.
Consent Isn't the Only Legal Basis for Processing
Most DPDPA guides describe consent as if it's the only way to process data lawfully. It's the default, but Section 7 lists eight specific "legitimate uses" a business can rely on instead of collecting fresh consent, including processing for a purpose the individual voluntarily provided data for, compliance with a legal obligation, and responding to a medical emergency. Getting this wrong in either direction causes real problems: relying on "legitimate use" for something that actually needs consent is a compliance gap, and collecting consent for something that already qualifies as a legitimate use is unnecessary friction a business didn't need to build.
Where consent is required, it has to be free, specific, informed, unconditional, and unambiguous, communicated through a clear affirmative action rather than assumed from continued use. It also has to stay limited to what's actually necessary for the stated purpose. Cookie-specific consent requirements, including the exact banner and notice standards, are covered in more depth separately, since that's a narrower, more technical topic than this overview needs to carry.
What Do You Actually Have to Do to Comply?
A real compliance check has to go beyond reading the Act. In practice, it means mapping every place personal data enters, moves through, and leaves your systems, then checking each processing activity against whichever legal basis actually applies to it, consent or one of the eight legitimate uses.
From there, four things need to be in place before an audit can call the program complete: security safeguards adequate to prevent a breach, since that's the highest-penalty failure mode in the Act; a documented breach-notification process, since the deadline for notifying the Data Protection Board runs from the moment a business becomes aware of a breach, not from when it's confirmed; a way to fulfill Data Principal requests (access, correction, erasure) within a reasonable timeframe; and records showing the compliance work actually happened, not just that a policy document exists. Data Principal rights and how to handle requests are covered in full separately.
For a Significant Data Fiduciary, a Data Fiduciary that the government designates for extra oversight based on the volume or sensitivity of data it handles, compliance carries two more requirements the baseline list above doesn't cover: an appointed Data Protection Officer who serves as the point of contact for the Data Protection Board and for Data Principals, and a Data Protection Impact Assessment for any high-risk processing activity, a documented record of what the processing does to Data Principals and what's being done to limit that impact. Neither applies to a business outside the Significant Data Fiduciary category, but for one that qualifies, having neither in place is one of the more common audit gaps. Section 10 adds two specifics on the DPO itself: they have to be based in India and report to the Fiduciary's board of directors, and the Fiduciary has to publish that DPO's business contact information publicly, not just keep it on file internally, so a Data Principal has an actual way to reach them.
Treat this as a recurring check, not a one-time project. New processing activities, new vendors, and new data flows all need to be checked against the same legal-basis test the first audit used, which is where most compliance programs quietly drift out of alignment over time without anyone deciding to let that happen.
What Are the Actual Penalties?
The Act's Schedule sets out seven separate penalty tiers. The two most relevant to a typical business's day-to-day exposure are a ceiling of ₹250 crore for inadequate security safeguards that lead to a breach, and a separate ₹200 crore tier for failing to notify the Data Protection Board and affected individuals on time. These stack: a breach caused by weak safeguards that also isn't reported on time exposes a business to both tiers on the same incident. A residual tier, up to ₹50 crore, covers violations that don't fall under one of the Act's more specific provisions.
Two figures that show up in older compliance content are wrong. DPDPA does not use a percentage-of-global-annual-turnover penalty structure the way GDPR does; every tier in the Schedule is a flat rupee ceiling. And the Act didn't become enforceable in 2023 or 2024; penalties don't apply until the relevant compliance deadlines, running through May 2027, actually pass.
Meeting these obligations takes more than a compliant banner. DSAR handling, DPIA/impact assessments, and vendor risk management, the tools an audit actually checks for, are what a real DPDPA compliance program needs beyond consent collection itself. Secure Privacy's Business tier and above covers all three alongside 55+ other privacy laws beyond DPDPA specifically.
FAQ
When does DPDPA actually take effect?
In phases. The Rules were notified November 13, 2025. The Consent Manager framework becomes operational November 13, 2026. Full substantive compliance, including consent standards, notice requirements, and security safeguards, isn't mandatory until May 13, 2027.
Does a small business need to comply with DPDPA?
Size alone doesn't exempt a business; DPDPA applies based on whether personal data of individuals in India is being processed, not company size or revenue. Certain obligations do scale with data volume and sensitivity through the Significant Data Fiduciary category, which adds extra requirements for larger-scale processors specifically.
What's the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides why and how personal data is processed and carries the primary legal accountability under the Act. A Data Processor handles data on a Fiduciary's behalf, under instruction, without independently deciding the purpose. Most businesses collecting data directly from their own customers are Data Fiduciaries, not Processors.
Can a business process personal data without consent under DPDPA?
Yes, if the processing qualifies under one of Section 7's eight "legitimate uses," such as a purpose the individual voluntarily provided the data for, a legal obligation, or a medical emergency. Outside those specific categories, consent is required.
What is the "right of nomination" under DPDPA?
A Data Principal can designate another individual to exercise their data-protection rights on their behalf if they die or become incapacitated. A rights-fulfillment process that only handles requests from the account holder themselves, with no path for a nominated representative to act, has a real gap the Act specifically anticipates.
Is journalism exempt from DPDPA?
No, not explicitly. Unlike some other jurisdictions' privacy laws, DPDPA doesn't carve out a specific exemption for journalism or media reporting. Section 3 and Section 17 exemptions cover personal/domestic use, already-public data, legal claims, judicial functions, and law enforcement, not journalism as its own category.
How is this different from the DPDPA cookie consent article on this blog?
This piece covers the Act broadly: scope, legal bases, obligations, penalties, and how to run a compliance check. The cookie consent article goes deep on one specific application of it, the exact standard a cookie banner and notice have to meet, including the emerging BRDCMS granular-consent standard specific to cookies.
What is Secure Privacy, exactly?
Secure Privacy is a cookie and consent management platform that generates DPDPA-, GDPR-, and CCPA-compliant consent banners, and covers DSAR handling, DPIA/impact assessments, and vendor risk management from its Business tier up.
Sources
- Digital Personal Data Protection Rules, 2025 (official gazette notification, G.S.R. 846(E)), notified November 13, 2025
- Section 3 of the DPDP Act, 2023, core exemptions
- Section 17 of the DPDP Act, 2023, additional exemptions
- The Schedule to the Digital Personal Data Protection Act, 2023, full penalty tier structure




