What is DPDPA compliance?+
The ability to evidence, on any given date, that every purpose for which you process digital personal data was disclosed in an itemised notice under Section 5, rests on consent under Section 6 or a legitimate use under Section 7, is protected by reasonable safeguards under Section 8(5), can be breach-reported under Rule 7 inside the clock, and can be answered when a Data Principal exercises a right under Sections 11 to 14. It is a file, not a certificate.
When does the DPDP Act become enforceable?+
In three phases from the notification of the DPDP Rules on 13 November 2025. Institutional provisions and the Board are live now. Consent Manager registration opens 13 November 2026. The substantive obligations bite on 13 May 2027. The Board can act on conduct from the date each provision commences — not from the date you finish your programme.
Is there a DPDPA certification we can obtain?+
No. The Act creates no accreditation or certification regime and empanels no certifier. A vendor certificate has no statutory standing before the Data Protection Board. What has standing is the record: notices as served, consent artefacts as captured, safeguards as tested, breach logs as timestamped, rights requests as closed.
Does the Act apply to a company outside India?+
Yes. Section 3(b) reaches processing outside India connected with offering goods or services to Data Principals in India. A Delaware SaaS company with Indian subscribers is a Data Fiduciary. There is no revenue, headcount or user threshold for the base obligations — thresholds appear only in Rule 8 retention classes and in Significant Data Fiduciary designation.
What is the penalty exposure for a breach?+
Up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to intimate the Board or affected Data Principals. Two separate heads on one incident. Quantum is decided under Section 33(2) — nature, gravity and duration of the breach, the type of data affected, repetitive conduct, gain or loss, and what you did after you found out. The last factor is the only one you can still change today.
How fast must a breach be reported?+
Rule 7 requires intimation to each affected Data Principal without delay, an initial intimation to the Board without delay, and a detailed report to the Board within seventy-two hours of becoming aware. There is no materiality filter and no de minimis carve-out. The operative words are becoming aware — which is why your detection triggers, not your legal opinion, decide when the clock started.
Who becomes a Significant Data Fiduciary?+
Whoever the Central Government notifies under Section 10(1), judged on volume and sensitivity of data, risk to Data Principals, effect on the sovereignty and integrity of India, risk to electoral democracy, security of the State and public order. Designation is not self-assessed, but it is predictable. If your data set would make a national news story, budget for the SDF duties now: DPIA, annual independent audit, algorithmic due diligence, and a DPO based in India who reports to the board.
Can we keep using US and EU cloud regions?+
Under the Act, yes. Section 16 is a negative list: transfer is free except to a country the Government restricts by notification. Two caveats do the real work. Sectoral law is untouched — RBI payment data localisation still binds. And Rule 15 lets the Government attach conditions about making personal data available to a foreign State. Build a transfer register now so that a future notification is a configuration change, not a migration project.
We are GDPR compliant. How much is left to do?+
More than the vendors admit. There is no legitimate-interest basis for a private business, so every purpose you currently run on balancing tests has to move to consent or to a Section 7 legitimate use. Notice must be itemised and available in the languages of the Eighth Schedule to the Constitution. Everyone under eighteen is a child, with verifiable parental consent and a prohibition on tracking and targeted advertising. Breach reporting has no risk threshold. In our experience a mature GDPR programme covers roughly half the DPDPA file.
Do our existing consents survive?+
Only where the original collection can be shown to meet the Section 6 standard and the purpose is unchanged. A bundled tick against a privacy policy is not consent that is free, specific, informed and unambiguous. The practical answer is a triage: keep what is provable, re-paper what is salvageable with a fresh itemised notice, and stop the purposes you cannot defend. Doing that before May 2027 costs a sprint. Doing it during an inquiry costs the inquiry.
Is a privacy tool enough?+
A tool is excellent at doing the same thing a million times and useless at deciding what that thing should be. Software cannot classify a purpose, choose between Section 6 and Section 7, draft a defensible notice, decide whether an incident is a reportable breach, or appear before the Board. Buy the tool for scale. Buy counsel for the positions the tool will execute — and keep the reasoning privileged.
What does an AMLEGALS engagement look like?+
Two weeks of diagnostic against the 56 exhibits on this page, producing a gap register with named owners and a dated remediation plan. Then a build phase: notices, consent architecture, Section 7 memoranda, processor contracts, breach runbook, rights workflow, DPIA where SDF designation is plausible. Then a standing retainer for the file — quarterly evidence review, board reporting, and representation if the Board ever writes to you.