AMLEGALS — Strategic Lawyering
DPDPA compliance · Services

DPDPA compliance services: what the work covers, step by step

What a DPDPA compliance programme involves for a business in India: the workstreams, the provision each one answers to, what each one produces, and the dates set by the DPDP Rules, 2025.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 7 min read

A closed laptop between a navy tabbed binder, a gold pen and a small brass padlock on a walnut desk
Short answer

DPDPA compliance services help an organisation meet the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The work usually covers seven areas: a map of personal data; lawful grounds, notices and consent (Sections 4 to 7, Rule 3); security safeguards (Section 8(5), Rule 6); breach response (Section 8(6), Rule 7); rights and grievances (Sections 11 to 14, Rule 14); retention and erasure (Section 8(7), Rule 8); and processor contracts (Section 8(2)). Each area should leave a record that shows the step was taken. The core duties apply from 13 May 2027.

  • DPDPA compliance
  • DPDP Rules 2025
  • Data Fiduciary
  • Data Processor
  • Consent and notice
  • Breach readiness
  • Data mapping
  • Evidence of compliance
Applies to
Organisations processing digital personal data in India, and offshore businesses offering goods or services to people in India (Section 3)
Core duties apply from
13 May 2027. The Data Protection Board has been in place since 13 November 2025
Highest penalty ceiling
Up to ₹250 crore, for failing to take reasonable security safeguards
Workstreams
Seven, each tied to a Section of the Act or a Rule

What DPDPA compliance work covers

The DPDPA sets duties for any organisation that decides why and how digital personal data is processed. The Act calls that organisation a Data Fiduciary. An organisation that processes personal data on behalf of a Data Fiduciary is a Data Processor (Section 2(k)). Many businesses are both, depending on the activity.

Compliance work turns the duties in the Act and the Rules into processes, contracts, system settings and records. For each duty, the organisation should be able to say what it does, who owns it and where the proof is kept.

The work is easier to plan when it is split into workstreams. Each one below is tied to the provision it answers to and the output it should produce.

The seven workstreams and what each one produces

The table lists each workstream, the provision behind it and its main output. The outputs are working documents and system changes that people use day to day.

DPDPA compliance workstreams mapped to provisions and outputs
WorkstreamProvisionMain output
Data mapSections 4 to 8A register of each personal data set: whose data, source, purpose, lawful ground, systems, vendors, retention period and owner
Lawful ground and noticeSections 4, 5 and 7; Rule 3A lawful ground for each purpose, and notices in clear and plain language that list the data and the purpose
ConsentSection 6; Section 6(4)Consent requests specific to each purpose, consent records, and a way to withdraw that is as easy as giving consent
Security safeguardsSection 8(5); Rule 6Controls for encryption, access control, monitoring and backups, with logs kept for at least one year
Breach responseSection 8(6); Rule 7A breach plan covering intimation without delay to the Board and affected people, and a detailed report to the Board within 72 hours
Rights and grievancesSections 11 to 14; Rule 14A published process for access, correction, erasure, nomination and grievances, with grievances resolved within 90 days at most
Vendors and retentionSection 8(2) and 8(7); Rule 8Processor contracts, a vendor register, and a retention schedule with erasure once the purpose is served

Two more areas apply only to some organisations. If you process personal data of children (anyone under 18), Section 9 and Rule 10 require verifiable consent of a parent or lawful guardian and bar tracking, behavioural monitoring and targeted advertising directed at children. If the Central Government notifies you as a Significant Data Fiduciary, Section 10 and Rule 13 add an India-based Data Protection Officer, an independent data auditor, a data protection impact assessment and audit every 12 months, and checks on algorithmic software.

The first question: Data Fiduciary, Data Processor or both

Most of the duties in the Act sit with the Data Fiduciary. Under Section 8(1), the Data Fiduciary stays responsible for processing done on its behalf by a Data Processor. Section 8(2) allows a Data Fiduciary to engage a Data Processor only under a valid contract.

A software company is a common example. When it processes a client's customer records on the client's instructions, it acts as a Data Processor. When it uses data about its own website visitors for marketing, it acts as a Data Fiduciary for that activity. The role is decided activity by activity, not company by company.

Settling the role first prevents two common errors: building consent flows for data you only process for a client, and missing duties for data you use for your own purposes.

How the work is usually sequenced

A typical programme runs in four phases. How long each phase takes depends on the number of systems, vendors and data sets involved.

  • Phase 1, scope and map: confirm roles, list systems and vendors, and build the data map. The other phases depend on it.
  • Phase 2, gap assessment: compare current practice with each Section and Rule, and rate each gap by the penalty ceiling it carries and the effort needed to close it.
  • Phase 3, build: draft notices and consent flows, update vendor contracts, set retention periods, write the breach plan and set up the rights request process.
  • Phase 4, test and record: run a breach exercise, test withdrawal of consent, test a rights request from start to finish, and file the evidence for each step.

Phase 4 matters because the Board looks at what happened in practice. Under Section 33(2), the Board considers factors such as the nature, gravity and duration of a breach, the type of personal data involved, and whether the organisation took timely steps to reduce its effect. Records made at the time are how an organisation shows those steps.

Dates that set the timetable

The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). They contain 23 Rules and 7 Schedules and bring the Act into force in stages.

  • 13 November 2025: the provisions setting up the Data Protection Board took effect.
  • 13 November 2026: Rule 4 on Consent Managers takes effect. A Consent Manager must be a company incorporated in India with a net worth of at least ₹2 crore.
  • 13 May 2027: the core duties of Data Fiduciaries apply, including notice, consent, security safeguards, breach intimation, rights, retention and children's data.

Tasks that depend on vendors and system changes, such as contract updates and consent records, usually take the longest. Starting with the data map and the vendor list gives those tasks the most time.

Who does this work at AMLEGALS

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

An engagement can cover the full programme or a single workstream, such as vendor contracts or breach readiness. To scope the work, the team needs your sector, whether you act as a Data Fiduciary, a Data Processor or both, the approximate number of people whose data you hold, your main systems and vendors, any children's data, any transfers outside India, and any past incident.

Questions and answers

DPDPA Compliance Services: common questions

What do DPDPA compliance services include?

They usually include a data map, a gap assessment against the Act and the DPDP Rules, 2025, notices and consent flows (Sections 5 and 6, Rule 3), security and breach procedures (Section 8(5) and 8(6), Rules 6 and 7), a rights and grievance process (Sections 11 to 14, Rule 14), a retention schedule (Section 8(7), Rule 8), processor contracts (Section 8(2)) and a file of evidence for each step.

When does a business need to be DPDPA compliant?

The core duties of Data Fiduciaries apply from 13 May 2027. The Data Protection Board has been in place since 13 November 2025, and Rule 4 on Consent Managers applies from 13 November 2026.

Does the DPDPA apply to companies outside India?

Yes, in some cases. Under Section 3, the Act applies to processing outside India if it is connected with offering goods or services to people in India.

Is consent the only lawful ground under the DPDPA?

No. Section 4 allows processing on consent or for certain legitimate uses. Section 7 lists those uses, such as specified employment purposes, compliance with law and medical emergencies. Other processing generally needs consent.

Do we need a Data Protection Officer?

Only a Significant Data Fiduciary must appoint a Data Protection Officer, and that officer must be based in India (Section 10(2)(a)). Every Data Fiduciary must publish the business contact details of a Data Protection Officer or of a person who can answer questions about its processing (Rule 9).

What are the penalties under the DPDPA?

The Schedule sets maximum amounts, and the Board decides the actual amount after an inquiry, having regard to the factors in Section 33(2). The ceilings are up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for breaching the duties on children's data, up to ₹150 crore for breaching the additional duties of a Significant Data Fiduciary, up to ₹50 crore for other breaches of the Act or Rules, and up to ₹10,000 for breach of the duties of a Data Principal.

How long does a DPDPA compliance programme take?

It depends on the number of systems, vendors and data sets. The data map and vendor contracts usually take the longest. A gap assessment gives a firmer estimate because it lists each gap and the work needed to close it.

Contact

Discuss the scope of your DPDPA compliance work

Tell us your sector, your role (Data Fiduciary, Data Processor or both) and what you want covered. Your message goes to the AMLEGALS data privacy team.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPDPA Compliance Services: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Compliance Services?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Compliance Services under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Compliance Services under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Compliance Services?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Compliance Services rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Compliance Services?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Compliance Services · DPDPA Exposure Assessment