Digital Personal Data Protection Act, 2023

Get your organisation DPDP ready — before the deadlines do it for you.

India's DPDP framework is being brought into force in phases. Most operational obligations are scheduled to apply from May 2027, making this the time to build practical, auditable processes.

Start with something useful

Review your position privately, inspect the deliverable structure, or download implementation-ready starter templates.

Readiness report

Answer ten control questions and print a category-based report without sending answers to us.

Run the self-check

📊

Sample deliverables

See how findings, remediation, data inventories and rights requests are structured.

View samples

⬇️

Free templates

Download data-map, vendor-review, retention and breach-response starter files.

Browse resources

Why this matters now

The DPDP Act applies to virtually every business that handles personal data digitally in India — and the penalties are among the steepest in Indian regulatory law.

₹250 crore
Maximum penalty per instance for failing to maintain reasonable security safeguards.
₹200 crore
For failing to notify the Data Protection Board and affected individuals of a personal data breach.
Most organisations
The Act has no general turnover threshold, although its scope, notified exemptions and commencement dates must be assessed case by case.

What the Act expects of you

If your organisation decides why and how personal data is processed, you are a Data Fiduciary with obligations that include:

📋

Notice & Consent

Clear, itemised notices and free, specific, informed consent before processing — with the ability for individuals to withdraw as easily as they gave it.

🛡️

Security Safeguards

Reasonable security safeguards to prevent personal data breaches, including for processing done on your behalf by vendors and processors.

🚨

Breach Notification

Intimation of every personal data breach to the Data Protection Board of India and to each affected data principal.

🗂️

Retention & Erasure

Erase personal data once its purpose is served or consent is withdrawn — with evidence that the erasure actually happened.

🙋

Data Principal Rights

Working processes for access, correction and erasure requests, plus a grievance redressal mechanism with defined timelines.

🧒

Children's Data

Verifiable parental consent for anyone under 18, and no tracking, behavioural monitoring or targeted advertising directed at children.

How we help

Structured, fixed-scope engagements that take you from "where do we stand?" to a defensible, documented compliance position.

🔍

DPDP Gap Assessment

A section-by-section review of your data practices against the Act and Rules, ending in a prioritised remediation roadmap.

✍️

Consent & Notice Framework

Compliant notices, consent capture and withdrawal flows, and records that prove consent when the regulator asks.

⚙️

Rights & Erasure Workflows

End-to-end processes for access, correction and erasure requests — including secure, evidenced data erasure with tamper-evident audit trails.

See all services

Not sure where you stand?

Start with a no-obligation conversation. We'll tell you plainly which obligations apply to you and how far you are from meeting them.

Talk to us