AMLEGALS — Strategic Lawyering
Data privacy compliance · India

Data privacy compliance in India: the DPDPA and the rules around it

How the Digital Personal Data Protection Act, 2023 fits with CERT-In's directions, the IT Act, and RBI, SEBI and IRDAI requirements, and how to meet overlapping duties with one plan.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 7 min read

Gold light strands passing through three glass panels, showing several layers of data privacy rules applying to the same data
Short answer

Data privacy compliance in India rests on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. They apply to every organisation that processes digital personal data in India, and to processing outside India connected with offering goods or services to people in India (Section 3). Other rules apply alongside them: CERT-In's April 2022 directions require specified cyber security incidents to be reported within six hours; sector regulators such as RBI, SEBI and IRDAI set their own data and cyber security duties; and Section 43A of the IT Act and the SPDI Rules continue until Section 44 of the DPDPA, which omits Section 43A, takes effect. The DPDPA applies in addition to other laws and prevails where there is a conflict (Section 38).

  • Data privacy compliance
  • DPDPA
  • CERT-In
  • RBI
  • SEBI
  • IRDAI
  • Cross-border transfers
  • Incident reporting
Base law
DPDPA, 2023 and the DPDP Rules, 2025 (23 Rules and 7 Schedules)
Cyber incident reporting
Within 6 hours to CERT-In, under its April 2022 directions
Personal data breach
Intimation without delay to the Board and affected people, and a detailed report to the Board within 72 hours (Rule 7)
When laws overlap
The DPDPA applies in addition to other laws and prevails in a conflict (Section 38)

The DPDPA is the base law for personal data

The Digital Personal Data Protection Act, 2023 applies to personal data collected in digital form, and to personal data collected in other forms and digitised later. It applies to processing in India and, under Section 3, to processing outside India connected with offering goods or services to people in India.

It does not apply to personal data used by an individual for personal or domestic purposes. It also does not apply to personal data made publicly available by the person it relates to, or by someone under a legal duty to publish it.

The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The provisions setting up the Data Protection Board took effect that day. Rule 4 on Consent Managers takes effect on 13 November 2026, and the core duties of Data Fiduciaries apply from 13 May 2027.

The other rules that apply alongside the DPDPA

Most organisations are subject to more than one set of rules on data. The table lists the main ones and the duty in each that most often overlaps with the DPDPA. Sector rules are updated regularly, so check the current version of each before relying on it.

Data privacy and cyber security rules in India that overlap with the DPDPA
RuleWho it applies toDuty that overlaps with the DPDPA
DPDPA, 2023 and DPDP Rules, 2025Every Data Fiduciary processing digital personal dataNotice, consent, security safeguards, breach intimation, rights, retention and erasure
CERT-In Directions, April 2022 (under Section 70B of the IT Act)Service providers, intermediaries, data centres, body corporates and government organisationsReport specified cyber security incidents within 6 hours of noticing them, and keep ICT system logs for a rolling 180 days within India
IT Act Section 43A and the SPDI Rules, 2011Body corporates handling sensitive personal data or informationReasonable security practices. Section 44 of the DPDPA omits Section 43A when it takes effect
RBI directionsBanks, NBFCs, payment system operators and other regulated entitiesIT governance, outsourcing and cyber security duties, and storage of payment system data in India
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)SEBI-regulated entitiesCyber security and cyber resilience controls, including incident reporting
IRDAI information and cyber security guidelinesInsurers and insurance intermediariesInformation security controls and incident reporting
Guidelines for Prevention and Regulation of Dark Patterns, 2023 (Consumer Protection Act)Platforms, advertisers and sellersNo deceptive design, such as false urgency or basket sneaking, which also affects how consent is asked for

Health, telecom and other sectors have their own rules as well. Listing the rules that apply to your organisation is the first step in any data privacy compliance plan.

How the rules fit together

Section 38 of the DPDPA says the Act applies in addition to other laws, and that where a provision of the Act conflicts with another law, the Act prevails to the extent of the conflict.

For transfers outside India, Section 16(2) keeps in place any other law that gives a higher degree of protection or a stricter restriction on transfer. A sector rule that requires certain data to be stored in India therefore still applies.

For retention, Section 8(7) requires erasure once the purpose is served, unless keeping the data is necessary to comply with a law. Records a law requires to be kept can be kept for that purpose and period. Other data is erased.

One incident, several reporting duties

A single cyber incident that exposes customer data can start several clocks at once. CERT-In's directions require specified incidents to be reported within six hours of noticing them. Under Section 8(6) and Rule 7, the Data Fiduciary must intimate the Board and each affected person without delay, and give the Board a detailed report within 72 hours, or a longer period the Board allows. A sector regulator may require its own report as well.

Each report goes to a different recipient, in a different format, on a different timeline. Reporting to CERT-In or a regulator does not replace intimation to the people whose data was affected.

  • Put every reporting duty that applies on one page: trigger, recipient, deadline and content.
  • Name one person who leads the response across security, legal and communications.
  • Draft the notice to affected people in advance, in plain language.
  • Require vendors, by contract, to tell you about incidents quickly.
  • Run one exercise in which all the clocks start together.

Transfers outside India

Under Section 16, personal data may be transferred outside India except to countries or territories the Central Government restricts by notification. Rule 15 adds that the Government may set requirements for making such data available to a foreign State or to entities under its control.

Sector rules can be stricter, and Section 16(2) keeps them in force. A list of each transfer, with the destination, recipient and purpose, makes it possible to respond quickly if a restriction is notified.

Penalties under the DPDPA

The Schedule to the Act sets maximum amounts. The Board decides the actual amount after an inquiry, having regard to the factors in Section 33(2).

  • Up to ₹250 crore: failing to take reasonable security safeguards to prevent a personal data breach.
  • Up to ₹200 crore: failing to intimate a personal data breach to the Board or affected people.
  • Up to ₹200 crore: breaching the additional duties on children's data.
  • Up to ₹150 crore: breaching the additional duties of a Significant Data Fiduciary.
  • Up to ₹50 crore: breaching any other provision of the Act or the Rules.

Sector regulators have their own powers under their own laws, so one incident can lead to action under more than one regime.

Where to start

A combined plan avoids building the same control twice for different regulators.

  • List the rules that apply to you: the DPDPA, the CERT-In directions, and any sector regulator.
  • Build a data map: each personal data set with its purpose, lawful ground, systems, vendors and retention period.
  • Keep one register of duties that shows, for each duty, every rule it comes from and one owner.
  • Write one incident plan that covers every reporting duty.
  • Set a retention schedule that cites the law for any data kept beyond its purpose.
  • Keep a record for each step, so the evidence can be produced when asked.

Who does this work at AMLEGALS

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

To scope the work, the team needs your sector and regulator, your role (Data Fiduciary, Data Processor or both), the approximate number of people whose data you hold, your main systems and vendors, any transfers outside India, and any past incident.

Questions and answers

Data Privacy Compliance in India: common questions

What is the main data privacy law in India?

The Digital Personal Data Protection Act, 2023, with the DPDP Rules, 2025 notified on 13 November 2025. The core duties of Data Fiduciaries apply from 13 May 2027.

Does the DPDPA replace Section 43A of the IT Act and the SPDI Rules?

Section 44 of the DPDPA omits Section 43A of the IT Act, and with it the basis for the SPDI Rules. Until that omission takes effect, the SPDI Rules continue to apply to body corporates handling sensitive personal data or information.

What is the CERT-In reporting timeline?

CERT-In's April 2022 directions require specified cyber security incidents to be reported within six hours of noticing them. This is separate from the DPDPA duty to intimate a personal data breach to the Board and to affected people.

Do sector rules override the DPDPA?

No. Section 38 says the DPDPA applies in addition to other laws and prevails in a conflict. Two provisions work the other way: Section 8(7) allows data to be kept where a law requires it, and Section 16(2) keeps in force any law with stricter rules on transfers outside India.

Can a company store Indian personal data outside India?

Under Section 16, yes, except in countries the Central Government restricts by notification. Sector rules can be stricter; for example, RBI requires payment system data to be stored in India.

Does the DPDPA apply to employee data?

Yes. It applies to digital personal data of any individual, including employees and job candidates. Section 7 allows certain processing for employment purposes without consent. Other processing may need consent.

What is the highest penalty under the DPDPA?

Up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach. The Board decides the actual amount after an inquiry, having regard to Section 33(2).

Contact

Discuss data privacy compliance for your organisation

Tell us your sector, your regulator and what you want covered. Your message goes to the AMLEGALS data privacy team.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Data Privacy Compliance in India: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Data Privacy Compliance in India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Data Privacy Compliance in India under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Data Privacy Compliance in India under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Data Privacy Compliance in India?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Data Privacy Compliance in India rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Data Privacy Compliance in India?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Data Privacy Compliance in India · DPDPA Exposure Assessment