AMLEGALS — Strategic Lawyering

DPDPA compliance in India, mapped to controls and evidence — the AMLEGALS hub for the Digital Personal Data Protection Act, 2023 and the final DPDP Rules, 2025.

Insights & Answers

What practitioners and boards are asking

What is DPDPA 2023 and who does it apply to?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's comprehensive data privacy legislation. It applies to all entities processing digital personal data in India, and to foreign entities processing personal data in connection with offering goods or services to Data Principals within India under Section 3. There is no revenue or size threshold. every Data Fiduciary processing digital personal data is within scope.

What are the maximum penalties under DPDPA?

DPDPA prescribes penalties up to ₹250 Crore under Section 33 read with the Schedule. The penalty for failure to protect children's data is up to ₹200 Crore. The Data Protection Board of India determines penalties based on the nature, gravity, and duration of the breach.

What is the Vibe Data Privacy Framework by AMLEGALS?

Vibe Data Privacy™ is AMLEGALS' proprietary governance framework built from the DPDPA 2023 statutory text. It measures compliance across five operational layers. Signal (privacy frequency across consent records and data flows), Pulse (governance stance against all 44 Sections and 23 Rules), Drift (compliance entropy and deviations from baseline), Dividend (privacy ROI through trust metrics and audit readiness), and Culture (organisational privacy maturity). producing a single Board ready Vibe Pulse Score (VPS) from 0 to 100.

When will DPDPA be fully enforceable?

DPDPA received Presidential Assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: the institutional provisions, including the Data Protection Board, commenced on 13 November 2025; the Consent Manager framework (Rule 4) commences on 13 November 2026; and the substantive obligations on notice, consent, breach reporting, children data, Significant Data Fiduciaries, rights and cross-border transfers commence on 13 May 2027. Organisations should treat the current period as the build window.

How does DPDPA compare to GDPR?

DPDPA and GDPR are structurally independent frameworks. Key differences: (1) DPDPA uses a negative list approach for cross border transfers under Section 16 versus GDPR's adequacy model; (2) No right to data portability under DPDPA; (3) Centralised Data Protection Board versus multiple supervisory authorities; (4) Fixed penalty amounts versus revenue percentages; (5) DPDPA applies only to digital personal data, not paper records.

What is a Significant Data Fiduciary under DPDPA?

Under Section 10, the Central Government may notify a Data Fiduciary as Significant based on volume and sensitivity of data processed, risk to Data Principals, and other prescribed factors. SDFs have enhanced obligations including mandatory DPO appointment (based in India), periodic audits by independent auditors, and Data Protection Impact Assessments.

Does DPDPA apply to foreign companies?

Yes. Section 3 of DPDPA extends its applicability to processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. This extraterritorial scope means foreign companies offering goods or services to Data Principals within India must comply regardless of their physical location.

What are the DPDP Rules 2025 and when were they notified?

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)) under Section 40 of DPDPA. They contain 23 Rules and 7 Schedules covering notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), breach notification form and manner (Rule 7), children's data processing safeguards (Rule 10), Significant Data Fiduciary obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), cross-border transfer requirements (Rule 15), and the Data Protection Board (Rules 17 to 22). Commencement is phased, with the substantive obligations commencing on 13 May 2027.

What are the consent requirements under DPDPA Section 6?

Section 6 of DPDPA requires consent that is free, specific, informed, unconditional, and unambiguous with clear affirmative action. Section 5 mandates an itemised notice before or at the time of data collection specifying the personal data to be processed and the purpose. Consent must be as easy to withdraw as to give under Section 6(6). Section 7 provides certain legitimate uses (historically termed deemed consent) including employment purposes, public interest, and medical emergencies.

What is the data breach notification obligation under DPDPA?

Section 8(6) of DPDPA requires every Data Fiduciary to inform both the Data Protection Board of India and each affected Data Principal of a personal data breach. Rule 7 of DPDP Rules 2025 prescribes a staged model: affected Data Principals must be intimated without delay; the Data Protection Board must receive an initial intimation without delay; and a detailed report must follow within 72 hours, or such longer period as the Board may allow on request. Failure to implement reasonable security safeguards attracting a breach carries penalties up to Rs 250 Crore under the Schedule.

How does DPDPA protect children's personal data?

Section 9 of DPDPA requires verifiable parental consent before processing any child's data (below 18 years). Data Fiduciaries must not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Rule 10 of DPDP Rules 2025 prescribes the manner of obtaining verifiable parental consent. Processing children's data that may cause detrimental effect is prohibited. Penalty for non-compliance is up to Rs 200 Crore under the Schedule.

Does DPDPA apply to US SaaS companies selling to Indian customers?

Yes. Section 3 of DPDPA applies extraterritorially to the processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. US SaaS companies collecting personal data from Indian users through sign-ups, analytics, payment processing, or support are Data Fiduciaries under DPDPA. Compliance obligations include Section 5 notice, Section 6 consent, Section 8 breach notification, and appointing a representative under the DPDP Rules 2025.

What happens if a foreign company ignores DPDPA compliance?

Non-compliance exposes the entity to penalties up to Rs 250 Crore per instance under Section 33 read with the Schedule. The Data Protection Board can issue directions, impose penalties, and require remedial measures. Beyond monetary penalties, non-compliance risks reputational damage, contract termination by Indian partners, and potential blocking of services. The Data Protection Board can issue directions and impose remedial measures. Non-compliance with Board directions attracts further penalties under the Act.

How is DPDPA different from PDPA Singapore and LGPD Brazil?

DPDPA differs from Singapore PDPA and Brazil LGPD in several structural ways. DPDPA applies exclusively to digital personal data (not paper records), uses a negative-list approach for cross-border transfers (unlike PDPA accountability model and LGPD adequacy model), prescribes fixed penalty amounts rather than revenue percentages, does not include a right to data portability, and centralises enforcement in a single Data Protection Board. All three share a consent-centric architecture, but DPDPA Section 7 on certain legitimate uses is narrower than the legitimate interests bases in LGPD and PDPA exceptions.

What is algorithmic due diligence under DPDP Rules 2025?

Rule 13 of the DPDP Rules 2025 introduces algorithmic due diligence as an obligation for Significant Data Fiduciaries. It requires SDFs to verify that algorithmic systems processing personal data do not pose a risk to the rights of Data Principals. This includes ensuring algorithms used for profiling, automated decision-making, or content recommendation do not produce outcomes that are detrimental. This is one of the first statutory algorithmic accountability requirements in Indian law.

What are the DPDPA compliance obligations for the BFSI sector?

Banks, insurers, NBFCs, and payment aggregators face overlapping compliance obligations. Under DPDPA: Section 5 notice, Section 6 consent, Section 8 breach notification, and Section 10 SDF obligations (if notified). Additionally, RBI data localisation circulars mandate payment system data be stored exclusively in India. IRDAI requires health and claims data retention. SEBI mandates KYC data governance. The BFSI sector must reconcile these sectoral mandates with DPDPA to avoid regulatory conflict.

How should a multinational structure its DPDPA compliance programme?

Multinationals should structure their DPDPA programme across four layers: (1) Entity mapping to identify which group entities qualify as Data Fiduciaries or Data Processors, (2) Data flow mapping to trace cross-border transfers under Section 16 and Rule 15, (3) Consent architecture design reconciling DPDPA Section 6 consent with GDPR consent or legitimate interests already in place, and (4) Governance documentation including privacy notices, Data Processing Agreements, breach response protocols, and DPO appointment for SDF-designated entities.

What is a DPDPA Data Protection Impact Assessment?

Rule 13 of the DPDP Rules 2025 requires Significant Data Fiduciaries to conduct Data Protection Impact Assessments evaluating risk to Data Principals, mitigation measures, and safeguard adequacy. The DPIA must be reviewed periodically and shared with the Data Protection Board on request. Unlike GDPR Article 35 which requires DPIAs for all high-risk processing, DPDPA limits this obligation to notified Significant Data Fiduciaries.

What is the Rule 15 cross-border data transfer requirement under DPDP Rules 2025?

Rule 15 supplements Section 16 of DPDPA. While Section 16 empowers the Central Government to restrict transfers to notified countries (negative-list approach), Rule 15 further allows requiring that personal data made available to any foreign State or its agencies meet prescribed requirements. Sectoral localisation mandates under RBI, IRDAI, and SEBI continue to apply independently. Unlike GDPR, DPDPA does not require adequacy decisions for permitted jurisdictions.

Who provides DPDPA compliance services in Delhi NCR?

AMLEGALS provides counsel-led DPDPA compliance services from its New Delhi office at A-24, ILBS Colony, Vasant Kunj, New Delhi 110070. The firm advises on DPDP Act 2023 implementation, DPDP Rules 2025 compliance, consent architecture, breach notification, DPO services, cross-border transfers, and Significant Data Fiduciary obligations. Contact [email protected] or +91-8448548549.

Who provides DPDPA compliance services in Mumbai?

AMLEGALS provides DPDPA compliance advisory from its Mumbai office. Services include DPDPA implementation, consent management, breach notification protocols, DPO advisory, cross-border transfer structuring, and the proprietary Vibe Data Privacy Framework assessment. The firm serves BFSI, pharmaceutical, e-commerce, and technology entities across Maharashtra.

Who provides DPDPA compliance services in Ahmedabad?

AMLEGALS operates from its Ahmedabad office, providing comprehensive DPDPA compliance services to manufacturing, pharmaceutical, chemical, and technology companies in Gujarat. Services include DPDP Act implementation, DPDP Rules compliance, consent architecture, Significant Data Fiduciary advisory, and the Vibe Pulse Score assessment.

What is the Consent Manager framework under DPDP Rules 2025?

Rule 4 of the DPDP Rules 2025 establishes the Consent Manager framework. A Consent Manager is an entity registered with the Data Protection Board under the First Schedule Part A that acts as a single point of contact for Data Principals to give, manage, review, and withdraw consent. Foreign companies can engage a registered Consent Manager, but legal responsibility for lawful processing remains with the Data Fiduciary. The Consent Manager registration framework commences on 13 November 2026.

How does DPDPA apply to the insurance sector?

Insurance companies face DPDPA obligations overlaid with IRDAI regulatory requirements. Under DPDPA: Section 5 notice for policy data, Section 6 consent for health and claims data, Section 8 breach notification, and potential Section 10 SDF obligations. IRDAI mandates on data retention, claims processing, and policyholder data governance must be reconciled with DPDPA requirements. AMLEGALS builds sector-specific reconciliation matrices mapping each IRDAI requirement to the corresponding DPDPA provision.

What DPDPA obligations apply to e-commerce platforms?

E-commerce platforms processing customer data face Section 5 notice obligations at scale, Section 6 consent challenges for multiple processing purposes (marketing, analytics, personalisation, payment), Section 8 breach notification for large user bases, and potential SDF designation under Section 10 for high-volume processors. AMLEGALS advises e-commerce entities on consent architecture design, vendor data processing agreements, cross-border transfer mechanisms for international fulfilment, and children data protection under Section 9.

Does DPDPA apply to the online gaming industry?

Yes. Online gaming platforms face acute Section 9 challenges because they cannot simply add an age gate. Verifiable parental consent under Rule 10 is required before processing any child's data. Behavioural monitoring, tracking, and targeted advertising directed at children are prohibited. Gaming companies must also address Section 6 consent for gameplay analytics, in-app purchase data, and social features, plus Section 8 breach notification obligations.

What is the DPDPA compliance cost for organisations in India?

DPDPA compliance costs vary by organisation size, sector, data processing complexity, and existing governance maturity. Key cost heads include legal advisory, consent architecture implementation, privacy notice drafting, data mapping and flow analysis, breach notification infrastructure, DPO appointment (for SDFs), Data Protection Impact Assessments, vendor agreement restructuring, and ongoing compliance monitoring. AMLEGALS provides structured scope assessments to help organisations understand their specific compliance investment requirements.

Is there a DPDPA certification body in India?

No. As of 2026, no DPDPA certification body exists in India. The DPDP Act 2023 and DPDP Rules 2025 do not establish any certification framework. Any vendor claiming DPDPA certification, DPDPA-ready status, or DPDPA audit compliance is making a claim without statutory backing. Organisations should evaluate vendor compliance claims against the actual statutory text rather than relying on self-declared certifications.