AMLEGALS — Strategic Lawyering
India data privacy regulatory landscape with corporate skyline representing DPDPA compliance transformation
AMLEGALS Advisory Publication

A 12-month DPDPA
implementation programme
for Data Fiduciaries

A structured, 12-month compliance programme for the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, designed for General Counsel, CISOs, and Board-level decision makers.

44
Statutory Sections
23
Rules (2025)
10
Programme Phases
₹250 Cr
Maximum Penalty (Schedule)
Executive Summary

India's data protection regime has shifted from principle to prescription

With the DPDP Rules published on 13 November 2025 and full enforcement set for 13 May 2027, every organisation processing personal data in India faces a hard deadline. The Act introduces a consent-first architecture, mandatory breach reporting, and a penalty framework under the Schedule with the highest listed maximum of ₹250 crore for a specified contravention. Compliance is no longer discretionary. It is an infrastructure requirement.

13 May 2027
Compliance Deadline
12 Months
Programme Duration
72 Hours
Breach Notification Window
₹250 Cr
Maximum Under Schedule
01

Why This Matters Now

The DPDPA is not a generic privacy law. It is a techno-legal specification that demands operational proof, not paper commitments.

Digital data flow mapping and infrastructure visualization representing DPDPA data audit requirements

The Digital Personal Data Protection Act introduces obligations that require changes across technology, governance, and vendor relationships simultaneously. Consent management under Section 6 demands granular, revocable, and machine-readable artifacts. Breach reporting under Rule 7 requires notification to the Data Protection Board without delay, with detailed information to follow within 72 hours, and notification to affected Data Principals without undue delay. Significant Data Fiduciaries face additional requirements, including resident DPO appointment, periodic Data Protection Impact Assessments, and independent annual audits.

Organisations that treat this as a documentation exercise will find themselves exposed. The Act demands operational readiness, meaning systems, processes, and people that function under scrutiny.

02

Core Statutory Obligations

Six pillars that every Data Fiduciary must address to achieve and sustain DPDPA compliance.

Consent Architecture

Section 6 | Rule 3

Implement granular, purpose-specific consent collection with machine-readable artifacts. Consent must be freely given, informed, unconditional, unambiguous, and specific to each processing purpose. Withdrawal must be as simple as the act of giving consent.

Privacy Notice

Section 5 | Rule 3

Deploy clear privacy notices before or at the time of data collection. Each notice must identify the Data Fiduciary, specify every processing purpose, and inform Data Principals of their rights, including the right to access, correction, erasure, and grievance redressal.

Security Safeguards

Section 8 | Rule 6

Implement reasonable technical and organisational security measures. This includes encryption, access controls, data minimisation, retention policies, and documented procedures for regular testing of security architecture.

Breach Notification

Section 8(6) | Rule 7

Establish a breach response protocol with the capability to notify the Data Protection Board and affected Data Principals without undue delay. The notification must include the nature of the breach, its potential consequences, and mitigation measures undertaken.

Data Principal Rights

Sections 11-14

Build operational workflows for responding to rights requests, including the right to access information, correction, erasure, and the right to nominate. Each request must be addressed within the timelines prescribed under Rule 8.

SDF Compliance Tier

Section 10 | Rule 12-14

Significant Data Fiduciaries must appoint a resident Data Protection Officer, conduct periodic impact assessments, commission independent annual audits, and maintain algorithmic transparency where automated decision-making applies.

03

The Significant Data Fiduciary Standard

Section 10 empowers the Central Government to notify certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data processed, the risk to the rights of Data Principals, and the potential impact on sovereignty, public order, and electoral democracy. SDF status triggers the highest compliance tier.

Resident DPO
Physically based in India, reporting directly to the Board of Directors
Independent Audit
Annual external audit by a DPBI-empanelled auditor under Rule 13
Periodic DPIA
Data Protection Impact Assessments for high-risk processing, including AI-driven profiling
Algorithmic Disclosure
Transparency obligations where decisions materially affecting Data Principals are automated
Executive boardroom setting representing board-level governance and strategic decision-making for DPDPA compliance
“The DPDPA does not ask whether you have a policy. It asks whether your policy worked when it was tested.”
04

The Consent Artifact

Section 6 requires consent to be specific, informed, unconditional, and unambiguous. Rule 3 prescribes the operational format.

Digital consent and privacy controls framework representing DPDPA Section 6 consent architecture
Granular
Specific to each distinct processing purpose
Revocable
Withdrawal as simple as the act of giving consent
Verifiable
Auditable record of when and how consent was obtained
Interoperable
Compatible with Consent Manager infrastructure
05

The 72-Hour Breach Protocol

Rule 7 mandates breach notification to the Board and affected Data Principals without undue delay from the point of awareness.

Cybersecurity operations centre representing DPDPA breach response and incident management protocol
Critical Timeline

The notification must include the nature and extent of the breach, the categories of personal data affected, the measures taken to mitigate the breach, and the recommended steps Data Principals should take to protect themselves. Delayed reporting is itself a basis for penalty proceedings under the Schedule.

What should a 12-month DPDPA implementation programme contain?

It should contain programme governance, a defensible data and processing inventory, legal-basis decisions, notice and consent redesign, Data Principal rights workflows, processor controls, retention, security and breach protocols, special-risk workstreams, training, testing and a Board-ready evidence repository. A shorter statutory runway requires parallel execution, not omission of controls.

06

Open 12-Month Implementation Roadmap

A sequenced, dependency-aware programme that moves from governance through operationalisation to Board-ready evidence.

Current Runway Control — as at 27 July 2026

An organisation targeting 13 May 2027 now has less than a full twelve-month runway. Run discovery, legal analysis, contracting and technical design in parallel, while preserving evidence gates and decision ownership. A shorter statutory runway requires parallel execution, not omission of controls.

1

Governance and Programme Charter

Month 0–1
  • Secure Board mandate and programme sponsorship
  • Define programme charter, scope, owners, source register and change control
  • Evidence gate: approved charter, RACI, decision log
2

Data Discovery and Inventory

Months 1–2
  • Inventory data, systems, purposes, Data Principals, processors, transfers and retention
  • Map data flows across departments and vendor relationships
  • Evidence gate: inventory and flow-map validation
3

Applicability, Legal Basis and Gap Assessment

Months 2–3
  • Determine applicability, consent and Section 7 decisions for each processing purpose
  • Conduct statutory gap assessment against all 44 sections and 23 Rules
  • Evidence gate: legal-basis and gap registers
4

Notice and Consent Architecture

Months 3–5
  • Design Section 5 notices, consent journeys, withdrawal mechanisms and record architecture
  • Implement product changes for consent collection and management
  • Evidence gate: approved notices, UX decisions, consent evidence
5

Rights and Grievance Workflow

Months 4–6
  • Build rights and grievance intake, identity checks, routing, response and nomination workflows
  • Configure response tracking against prescribed timelines under Rule 8 and Rule 14
  • Evidence gate: tested request register and response proof
6

Processor Governance and Contracting

Months 4–7
  • Conduct processor inventory, valid contracts, due diligence, instructions, breach and deletion controls
  • Remediate existing processor agreements to Section 8(2) requirements
  • Evidence gate: contract remediation and monitoring evidence
7

Security Safeguards and Breach Response

Months 5–8
  • Implement security safeguards, incident classification, breach response and notification decisioning
  • Conduct tabletop exercises and test 72-hour notification capability
  • Evidence gate: control evidence and tabletop record
8

Special Risk Workstreams

Months 6–9
  • Address children, SDF readiness, algorithm risks, cross-border and sector overlays where applicable
  • Map additional SDF obligations to Section 10 read with Rule 13
  • Evidence gate: special-risk assessment and approvals
9

Policies, Training and Testing

Months 8–10
  • Finalise policies, deliver training, run operational pilots and control testing
  • Remediate findings and close gaps before evidence assembly
  • Evidence gate: training records, test scripts, findings and closure
10

Assurance, Evidence and Board Readiness

Months 10–12
  • Commission assurance review and assemble Board report
  • Compile evidence index, BAU metrics and legal-change process
  • Evidence gate: Board pack, evidence catalogue and review calendar
Strategic compliance roadmap visualization representing phased DPDPA implementation milestones
07

Anonymisation and Technical Boundaries

The line between regulatory liability and data utility runs through anonymisation. Getting it wrong is expensive.

Under Section 2(t), data ceases to be personal data when it has been anonymised such that the Data Principal is no longer identifiable. However, the test is irreversibility. Pseudonymisation alone does not meet this threshold.

Organisations relying on anonymised datasets for analytics, research, or AI training must demonstrate that re-identification is computationally impractical. Differential privacy, K-Anonymity, and L-Diversity are established benchmarks that can withstand regulatory scrutiny.

Technical Standard

Engineering teams should implement K-Anonymity and L-Diversity benchmarks for datasets subject to the Rule 13 SDF Independent Audit. Anonymisation methodology must be documented and defensible.

Request the Guide

Get the Complete DPDPA Implementation Guide

This guide distils the statutory requirements of the DPDPA and DPDP Rules into a structured, actionable programme. It is designed for organisations that need to move from assessment to implementation with clarity on what needs to be done, in what sequence, and to what standard.

Phase-wise implementation roadmap with statutory cross-references
Consent architecture and breach response protocol templates
SDF compliance tier requirements and audit preparation checklist
Vendor governance framework with Data Processor Agreement guidance
The Path Forward

Compliance as Infrastructure

The organisations that will thrive under the DPDPA are those that treat compliance not as a cost centre, but as foundational infrastructure. Privacy-by-design is no longer aspirational. It is the regulatory baseline.

Source and legal review basis: AMLEGALS DPDPA Implementation Centre | Digital Personal Data Protection Act, 2023 | DPDP Rules, 2025 (23 Rules, 7 Schedules) and applicable corrigendum/commencement notification | Legally reviewed by AMLEGALS Data Privacy Practice on 27 July 2026

DPDPA implementation: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA implementation?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA implementation under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA implementation under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA implementation?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA implementation rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA implementation?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA implementation · DPDPA Exposure Assessment