The DPDPA is the base law for personal data
The Digital Personal Data Protection Act, 2023 applies to personal data collected in digital form, and to personal data collected in other forms and digitised later. It applies to processing in India and, under Section 3, to processing outside India connected with offering goods or services to people in India.
It does not apply to personal data used by an individual for personal or domestic purposes. It also does not apply to personal data made publicly available by the person it relates to, or by someone under a legal duty to publish it.
The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The provisions setting up the Data Protection Board took effect that day. Rule 4 on Consent Managers takes effect on 13 November 2026, and the core duties of Data Fiduciaries apply from 13 May 2027.
The other rules that apply alongside the DPDPA
Most organisations are subject to more than one set of rules on data. The table lists the main ones and the duty in each that most often overlaps with the DPDPA. Sector rules are updated regularly, so check the current version of each before relying on it.
| Rule | Who it applies to | Duty that overlaps with the DPDPA |
|---|---|---|
| DPDPA, 2023 and DPDP Rules, 2025 | Every Data Fiduciary processing digital personal data | Notice, consent, security safeguards, breach intimation, rights, retention and erasure |
| CERT-In Directions, April 2022 (under Section 70B of the IT Act) | Service providers, intermediaries, data centres, body corporates and government organisations | Report specified cyber security incidents within 6 hours of noticing them, and keep ICT system logs for a rolling 180 days within India |
| IT Act Section 43A and the SPDI Rules, 2011 | Body corporates handling sensitive personal data or information | Reasonable security practices. Section 44 of the DPDPA omits Section 43A when it takes effect |
| RBI directions | Banks, NBFCs, payment system operators and other regulated entities | IT governance, outsourcing and cyber security duties, and storage of payment system data in India |
| SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) | SEBI-regulated entities | Cyber security and cyber resilience controls, including incident reporting |
| IRDAI information and cyber security guidelines | Insurers and insurance intermediaries | Information security controls and incident reporting |
| Guidelines for Prevention and Regulation of Dark Patterns, 2023 (Consumer Protection Act) | Platforms, advertisers and sellers | No deceptive design, such as false urgency or basket sneaking, which also affects how consent is asked for |
Health, telecom and other sectors have their own rules as well. Listing the rules that apply to your organisation is the first step in any data privacy compliance plan.
How the rules fit together
Section 38 of the DPDPA says the Act applies in addition to other laws, and that where a provision of the Act conflicts with another law, the Act prevails to the extent of the conflict.
For transfers outside India, Section 16(2) keeps in place any other law that gives a higher degree of protection or a stricter restriction on transfer. A sector rule that requires certain data to be stored in India therefore still applies.
For retention, Section 8(7) requires erasure once the purpose is served, unless keeping the data is necessary to comply with a law. Records a law requires to be kept can be kept for that purpose and period. Other data is erased.
One incident, several reporting duties
A single cyber incident that exposes customer data can start several clocks at once. CERT-In's directions require specified incidents to be reported within six hours of noticing them. Under Section 8(6) and Rule 7, the Data Fiduciary must intimate the Board and each affected person without delay, and give the Board a detailed report within 72 hours, or a longer period the Board allows. A sector regulator may require its own report as well.
Each report goes to a different recipient, in a different format, on a different timeline. Reporting to CERT-In or a regulator does not replace intimation to the people whose data was affected.
- Put every reporting duty that applies on one page: trigger, recipient, deadline and content.
- Name one person who leads the response across security, legal and communications.
- Draft the notice to affected people in advance, in plain language.
- Require vendors, by contract, to tell you about incidents quickly.
- Run one exercise in which all the clocks start together.
Transfers outside India
Under Section 16, personal data may be transferred outside India except to countries or territories the Central Government restricts by notification. Rule 15 adds that the Government may set requirements for making such data available to a foreign State or to entities under its control.
Sector rules can be stricter, and Section 16(2) keeps them in force. A list of each transfer, with the destination, recipient and purpose, makes it possible to respond quickly if a restriction is notified.
Penalties under the DPDPA
The Schedule to the Act sets maximum amounts. The Board decides the actual amount after an inquiry, having regard to the factors in Section 33(2).
- Up to ₹250 crore: failing to take reasonable security safeguards to prevent a personal data breach.
- Up to ₹200 crore: failing to intimate a personal data breach to the Board or affected people.
- Up to ₹200 crore: breaching the additional duties on children's data.
- Up to ₹150 crore: breaching the additional duties of a Significant Data Fiduciary.
- Up to ₹50 crore: breaching any other provision of the Act or the Rules.
Sector regulators have their own powers under their own laws, so one incident can lead to action under more than one regime.
Where to start
A combined plan avoids building the same control twice for different regulators.
- List the rules that apply to you: the DPDPA, the CERT-In directions, and any sector regulator.
- Build a data map: each personal data set with its purpose, lawful ground, systems, vendors and retention period.
- Keep one register of duties that shows, for each duty, every rule it comes from and one owner.
- Write one incident plan that covers every reporting duty.
- Set a retention schedule that cites the law for any data kept beyond its purpose.
- Keep a record for each step, so the evidence can be produced when asked.
Who does this work at AMLEGALS
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
To scope the work, the team needs your sector and regulator, your role (Data Fiduciary, Data Processor or both), the approximate number of people whose data you hold, your main systems and vendors, any transfers outside India, and any past incident.

