AMLEGALS — Strategic Lawyering
Updated February 2026 · DPDP Rules 2025 Notified

India's DPDP Law: The Definitive Compliance Guide

The Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 establish India's first comprehensive data privacy regime. With penalties reaching ₹250 Crores and an 18-month compliance window closing May 2027, every organization processing personal data of individuals in India must act now.

₹250 CrMaximum Penalty
18 MoCompliance Window
1.4 BnCitizens Protected
72 HrBreach Notice

Understanding India's DPDP Law

On November 13, 2025, the Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection (DPDP) Rules, 2025, bringing India's first comprehensive data protection legislation into full operational effect.

The DPDP law represents a paradigm shift in India's approach to data governance. Unlike the earlier patchwork of provisions under the Information Technology Act, 2000, the DPDPA creates a unified, consent-driven, rights-based framework governing the entire lifecycle of digital personal data.

The DPDP Act applies to every entity processing digital personal data within India, regardless of organizational size. It also extends to foreign entities that process personal data of individuals in India in connection with offering goods or services.

The Compliance Timeline: Three Phases

Phase 1 — November 2025

Foundation

Data Protection Board of India (DPBI) becomes operational. Citizens can file complaints through dedicated portal.

Phase 2 — November 2026

Infrastructure

Consent Manager registration framework activates. Organizations must prepare to interface with registered Consent Managers.

Phase 3 — May 2027

Full Compliance

Complete operational compliance mandatory — privacy notices, consent mechanisms, breach reporting (72-hour), security safeguards, rights management.

Core Obligations Under DPDP Law

Privacy Notices (Rule 3)

Standalone notices itemizing every category of personal data, purposes, consent withdrawal mechanisms, and complaint channels. Must be presented before or at time of seeking consent.

Consent Architecture (Rule 4)

Consent must be free, specific, informed, unconditional, and unambiguous. Consent Managers are registered intermediaries for consent management — unique to India.

Security Safeguards (Rule 6)

Encryption, obfuscation, masking, tokenization, and access control. Technical and organizational measures proportionate to risk.

Breach Notification (Rule 7)

72-hour notification to DPBI and affected Data Principals. Must detail breach nature and actionable mitigation steps.

Data Principal Rights (Rule 8)

Rights to access, correct, update, and erase personal data. 90-day response requirement. Nomination rights for post-death data management.

Children's Data (Rules 10-11)

Verifiable parental consent required for under-18 processing. Tracking, behavioral monitoring, and targeted advertising to children restricted.

Penalty Framework

The DPDP Act imposes substantial financial penalties for non-compliance, with the highest penalty reaching ₹250 Crores. Unlike earlier drafts, the final Act does not prescribe criminal penalties — all consequences are monetary.

₹250 CrFailure to implement reasonable security safeguards
₹200 CrFailure to notify Board and individuals of data breach
₹150 CrNon-compliance with children's data obligations
₹50 CrFailure to fulfil Data Principal rights

DPDP Act vs. GDPR Comparison

ParameterDPDP Act (India)GDPR (EU)
Legal BasisPrimarily consent; legitimate uses definedSix legal bases including legitimate interest
Data CategoriesNo distinction — all personal data treated uniformlySeparate categories for sensitive/special data
Cross-Border TransfersNegative list (allowed unless restricted)Adequacy decisions, SCCs, BCRs
Consent ManagersRegistered intermediaries (unique to India)No equivalent
Maximum Penalty₹250 crore (~$30M) under Schedule€20M or 4% global annual turnover
Breach Notification72 hours to Board + affected individuals72 hours to supervisory authority

Frequently Asked Questions

The Compliance Clock Is Ticking

AMLEGALS' privacy practice delivers end-to-end DPDPA compliance through the proprietary Inviolum™ framework. 28+ years of Indian regulatory experience.

Schedule Compliance Advisory →
Insights & Answers

What practitioners and boards are asking

What is the data protection law in India?

India's data protection law is the Digital Personal Data Protection Act, 2023 (DPDPA), which received Presidential Assent on 11 August 2023, operationalised by the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)). Together they govern the processing of digital personal data by Data Fiduciaries in India and, extraterritorially, abroad under Section 3.

What are the core obligations under India's DPDP law?

Data Fiduciaries must give an itemised notice (Section 5), obtain valid consent (Section 6), process only for lawful purposes, maintain reasonable security safeguards (Section 8), honour Data Principal rights of access, correction, erasure and grievance (Sections 11-14), report breaches (Rule 7), and comply with cross-border transfer restrictions (Section 16). Significant Data Fiduciaries carry additional duties under Section 10.

When does India's data protection law take effect?

Commencement is phased. The Data Protection Board and institutional provisions commenced on 13 November 2025; the Consent Manager framework commences 13 November 2026; and the substantive obligations on notice, consent, breach, children's data, SDFs, rights and cross-border transfers commence on 13 May 2027.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Dpdp Law India?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Dpdp Law India under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Dpdp Law India under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Dpdp Law India?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Dpdp Law India rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Dpdp Law India?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.