What DPDPA compliance work covers
The DPDPA sets duties for any organisation that decides why and how digital personal data is processed. The Act calls that organisation a Data Fiduciary. An organisation that processes personal data on behalf of a Data Fiduciary is a Data Processor (Section 2(k)). Many businesses are both, depending on the activity.
Compliance work turns the duties in the Act and the Rules into processes, contracts, system settings and records. For each duty, the organisation should be able to say what it does, who owns it and where the proof is kept.
The work is easier to plan when it is split into workstreams. Each one below is tied to the provision it answers to and the output it should produce.
The seven workstreams and what each one produces
The table lists each workstream, the provision behind it and its main output. The outputs are working documents and system changes that people use day to day.
| Workstream | Provision | Main output |
|---|---|---|
| Data map | Sections 4 to 8 | A register of each personal data set: whose data, source, purpose, lawful ground, systems, vendors, retention period and owner |
| Lawful ground and notice | Sections 4, 5 and 7; Rule 3 | A lawful ground for each purpose, and notices in clear and plain language that list the data and the purpose |
| Consent | Section 6; Section 6(4) | Consent requests specific to each purpose, consent records, and a way to withdraw that is as easy as giving consent |
| Security safeguards | Section 8(5); Rule 6 | Controls for encryption, access control, monitoring and backups, with logs kept for at least one year |
| Breach response | Section 8(6); Rule 7 | A breach plan covering intimation without delay to the Board and affected people, and a detailed report to the Board within 72 hours |
| Rights and grievances | Sections 11 to 14; Rule 14 | A published process for access, correction, erasure, nomination and grievances, with grievances resolved within 90 days at most |
| Vendors and retention | Section 8(2) and 8(7); Rule 8 | Processor contracts, a vendor register, and a retention schedule with erasure once the purpose is served |
Two more areas apply only to some organisations. If you process personal data of children (anyone under 18), Section 9 and Rule 10 require verifiable consent of a parent or lawful guardian and bar tracking, behavioural monitoring and targeted advertising directed at children. If the Central Government notifies you as a Significant Data Fiduciary, Section 10 and Rule 13 add an India-based Data Protection Officer, an independent data auditor, a data protection impact assessment and audit every 12 months, and checks on algorithmic software.
The first question: Data Fiduciary, Data Processor or both
Most of the duties in the Act sit with the Data Fiduciary. Under Section 8(1), the Data Fiduciary stays responsible for processing done on its behalf by a Data Processor. Section 8(2) allows a Data Fiduciary to engage a Data Processor only under a valid contract.
A software company is a common example. When it processes a client's customer records on the client's instructions, it acts as a Data Processor. When it uses data about its own website visitors for marketing, it acts as a Data Fiduciary for that activity. The role is decided activity by activity, not company by company.
Settling the role first prevents two common errors: building consent flows for data you only process for a client, and missing duties for data you use for your own purposes.
How the work is usually sequenced
A typical programme runs in four phases. How long each phase takes depends on the number of systems, vendors and data sets involved.
- Phase 1, scope and map: confirm roles, list systems and vendors, and build the data map. The other phases depend on it.
- Phase 2, gap assessment: compare current practice with each Section and Rule, and rate each gap by the penalty ceiling it carries and the effort needed to close it.
- Phase 3, build: draft notices and consent flows, update vendor contracts, set retention periods, write the breach plan and set up the rights request process.
- Phase 4, test and record: run a breach exercise, test withdrawal of consent, test a rights request from start to finish, and file the evidence for each step.
Phase 4 matters because the Board looks at what happened in practice. Under Section 33(2), the Board considers factors such as the nature, gravity and duration of a breach, the type of personal data involved, and whether the organisation took timely steps to reduce its effect. Records made at the time are how an organisation shows those steps.
Dates that set the timetable
The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). They contain 23 Rules and 7 Schedules and bring the Act into force in stages.
- 13 November 2025: the provisions setting up the Data Protection Board took effect.
- 13 November 2026: Rule 4 on Consent Managers takes effect. A Consent Manager must be a company incorporated in India with a net worth of at least ₹2 crore.
- 13 May 2027: the core duties of Data Fiduciaries apply, including notice, consent, security safeguards, breach intimation, rights, retention and children's data.
Tasks that depend on vendors and system changes, such as contract updates and consent records, usually take the longest. Starting with the data map and the vendor list gives those tasks the most time.
Who does this work at AMLEGALS
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
An engagement can cover the full programme or a single workstream, such as vendor contracts or breach readiness. To scope the work, the team needs your sector, whether you act as a Data Fiduciary, a Data Processor or both, the approximate number of people whose data you hold, your main systems and vendors, any children's data, any transfers outside India, and any past incident.

