AMLEGALS — Strategic Lawyering
DPDPA compliance · How-to

How to comply with the DPDPA: twelve steps, in order

A practical sequence for meeting the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Each step names the provision it answers to and the record that shows it was done.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 7 min read

Five floating steps carrying a data map, a key, a shield, a bell and a notebook, one object for each stage of DPDPA compliance
Short answer

To comply with the DPDPA, work in this order: confirm your role for each activity, map your personal data, choose a lawful ground for each purpose, rewrite your notices, fix consent and withdrawal, set security safeguards, prepare for breaches, set up rights and grievance handling, set retention periods, put processors under contract, check for children's data, and keep records of each step. The core duties apply from 13 May 2027.

  • DPDPA compliance
  • DPDP Rules 2025
  • Notice and consent
  • Section 6(4) withdrawal
  • Breach intimation
  • Data Principal rights
  • Retention and erasure
  • Processor contracts
Steps
Twelve, each tied to a Section of the Act or a Rule
Start with
Your role and a data map. Later steps depend on both
Core duties apply from
13 May 2027
Breach report to the Board
Intimation without delay, then a detailed report within 72 hours (Rule 7)

Before you start: three facts that shape the work

The Act applies to digital personal data, including personal data collected on paper and later digitised. It covers processing in India, and processing outside India connected with offering goods or services to people in India (Section 3).

It does not apply to personal data used by an individual for personal or domestic purposes. It also does not apply to personal data made publicly available by the person it relates to, or by someone under a legal duty to publish it.

The Rules were notified on 13 November 2025, and the core duties apply from 13 May 2027. Steps 1 to 5 should be finished first, because the later steps depend on them.

The twelve steps to DPDPA compliance

Each step says what to do, the provision it answers to and the record to keep. The order is the one that avoids rework.

  1. 01

    Confirm your role for each activity

    For each activity, decide whether you are a Data Fiduciary (you decide the purpose and means of processing) or a Data Processor (you process on behalf of a Data Fiduciary, Section 2(k)). Under Section 8(1), the Data Fiduciary stays responsible for processing done on its behalf. Record: a role register.

  2. 02

    Map your personal data

    List each data set: whose data it is (customers, employees, job candidates, vendor staff), where it comes from, why it is used, which systems hold it, which vendors receive it, whether it leaves India and how long it is kept. Record: a data map with an owner for each row.

  3. 03

    Choose a lawful ground for each purpose

    Section 4 allows processing on consent or for a legitimate use. Section 7 lists the legitimate uses, such as specified employment purposes, compliance with law and medical emergencies. If no legitimate use fits, you need consent. Record: a purpose and lawful ground column in the data map.

  4. 04

    Rewrite your notices

    Under Section 5 and Rule 3, a notice must be in clear and plain language, list the personal data and the purpose, and explain how to withdraw consent, exercise rights and complain to the Board. Section 5(3) requires an option to read the notice in English or in any language listed in the Eighth Schedule to the Constitution. Record: each notice version and the date it went live.

  5. 05

    Fix consent and withdrawal

    Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to the data needed for the purpose. Ask for each purpose separately. Section 6(4) requires withdrawal to be as easy as giving consent. Record: consent logs showing what was shown, when, and what the person chose.

  6. 06

    Set reasonable security safeguards

    Section 8(5) and Rule 6 require reasonable security safeguards, including encryption or similar measures, access control, monitoring of access, backups so processing can continue after an incident, and logs kept for at least one year. Record: a control list with test results.

  7. 07

    Prepare for a personal data breach

    Section 8(6) and Rule 7 require intimation without delay to the Board and to each affected person, and a detailed report to the Board within 72 hours, or longer if the Board allows. A cyber security incident may also need reporting to CERT-In within six hours under its April 2022 Directions. Record: a breach plan, named decision makers and the results of a test exercise.

  8. 08

    Set up rights and grievance handling

    Sections 11 to 14 give people rights to information about their data, to correction and erasure, to grievance redressal and to nominate another person. Rule 14 requires grievances to be resolved within 90 days at most. Rule 9 requires you to publish the business contact details of a Data Protection Officer or a person who can answer questions about your processing. Record: a request log with response dates.

  9. 09

    Set retention periods and erase on time

    Section 8(7) requires erasure once the purpose is no longer served, unless a law requires you to keep the data. Rule 8 and the Third Schedule set fixed periods for certain large e-commerce, online gaming and social media platforms. Record: a retention schedule and erasure logs.

  10. 10

    Put every processor under contract

    Section 8(2) allows you to engage a Data Processor only under a valid contract. The list usually includes cloud hosting, analytics and advertising tools, payroll and customer support vendors. Contracts should cover security, breach reporting to you, sub-processors and deletion at the end of the service. Record: a vendor register with contract dates.

  11. 11

    Check for children and persons with disabilities

    A child is anyone under 18 (Section 2(f)). Section 9 and Rule 10 require verifiable consent of a parent or lawful guardian, and bar tracking, behavioural monitoring and targeted advertising directed at children. Rule 12 and the Fourth Schedule exempt some classes and purposes. Rule 11 covers consent from the lawful guardian of a person with a disability. Record: the age and guardian consent method, and any exemption relied on.

  12. 12

    Keep records and review on a schedule

    Keep the record from each step in one place, with an owner and a review date. Review when you add a product, a vendor or a new use of data. If you are notified as a Significant Data Fiduciary, Section 10 and Rule 13 add a data protection impact assessment and an audit every 12 months. Record: a compliance file indexed by Section and Rule.

Common errors that cause rework

These are the errors seen most often when organisations start DPDPA work. Each one sends a team back to an earlier step.

  • Writing notices before the data map is finished. Notices must list the data and the purposes, so they change whenever the map changes.
  • Using one checkbox for several purposes. Section 6 requires consent to be specific to each purpose.
  • Treating withdrawal as an email to customer support. Section 6(4) requires withdrawal to be as easy as giving consent, so it belongs where consent was given.
  • Leaving advertising pixels and analytics tools off the vendor list. Tools that receive personal data on your behalf need contracts under Section 8(2).
  • Keeping data in case it is useful later. Section 8(7) requires erasure once the purpose is served, unless a law requires you to keep it.
  • Planning breach reporting only for CERT-In. The DPDPA also requires intimation to the Board and to each affected person.

What records to keep

The Board decides penalties after an inquiry. Under Section 33(2), it considers matters such as the type of personal data, the duration of the breach and whether timely steps were taken to reduce its effect. Records made at the time are how an organisation shows what it did.

  • Role register and data map
  • Notice versions and consent logs, including withdrawals
  • Security control list, access logs (kept for at least one year) and test results
  • Breach plan, exercise reports and any breach reports filed
  • Rights and grievance request log with response dates
  • Retention schedule and erasure logs
  • Vendor register and processor contracts
Questions and answers

How to Comply with the DPDPA: common questions

What is the first step to comply with the DPDPA?

Confirm your role for each activity and map your personal data. Notices, consent, retention and vendor contracts all depend on knowing what data you hold, why you hold it and who receives it.

Do small businesses have to comply with the DPDPA?

The Act does not exempt businesses by size. Section 17(3) allows the Central Government to exempt certain Data Fiduciaries, including startups, from some provisions by notification. Unless such a notification covers you, the duties apply.

Can our privacy policy serve as the DPDPA notice?

Only if it meets Section 5 and Rule 3. The notice must be in clear and plain language, list the personal data and the purposes, and explain how to withdraw consent, exercise rights and complain to the Board. Rule 3 also requires the notice to be understandable on its own, without reference to other information.

How fast must a breach be reported under the DPDPA?

Under Section 8(6) and Rule 7, a Data Fiduciary must inform the Board and each affected person without delay after becoming aware of a breach, and send the Board a detailed report within 72 hours, or a longer period if the Board allows.

How long can we keep personal data?

Until the purpose is no longer served, unless a law requires you to keep it longer (Section 8(7)). Rule 8 and the Third Schedule set fixed periods for certain large platforms.

Do employees count as Data Principals?

Yes. Employees, job candidates and vendor staff are Data Principals. Section 7 allows processing without consent for the employment purposes it lists, but duties such as security safeguards, breach intimation and erasure once the purpose is served still apply.

Does every company need a Data Protection Officer under the DPDPA?

No. Only a Significant Data Fiduciary must appoint one, based in India (Section 10(2)(a)). Every Data Fiduciary must still publish the contact details of a Data Protection Officer or of a person who can answer questions about its processing (Rule 9).

Contact

Ask about a step

Tell us which step you are working on and what is holding it up. Your message goes to the AMLEGALS data privacy team.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

How to Comply with the DPDPA: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to How to Comply with the DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on How to Comply with the DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on How to Comply with the DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on How to Comply with the DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for How to Comply with the DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on How to Comply with the DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about How to Comply with the DPDPA · DPDPA Exposure Assessment