Skip to main content
AIZZENTEC - DPDP, Privacy & Cybersecurity Advisory — page loaded
All articles

What Is the DPDP Act 2025? Key Rules, Compliance Requirements, and Business Impact

By Praveen Kumar, Practice Leader — Risk, Cyber and AnalyticsCA, CISA, CEH, CDPSE, CFEPublished
A DPDP Act 2023 shield beside a DPDP Rules 2025 book, over a dotted map of India
ShareLinkedInX

If you’ve been wondering what the DPDP Act is — and hearing the term “DPDP Act 2025” a lot lately while feeling slightly out of the loop — you’re not alone. Almost every business owner, IT head, and compliance manager in India is asking some version of the same question right now: do I need to do something about this, and if so, what?

Here’s the short version before we get into the details: yes, you probably do need to act, and the clock is already running. This guide is for anyone responsible for a business that collects personal data in India — founders, compliance leads, IT and security teams — and it walks through what the DPDP Act actually is, why it exists, who it applies to, and most importantly what your business needs to do to stay on the right side of it.

Let’s unpack the digital personal data protection act, its 2025 Rules, the compliance requirements, and the penalties — step by step.

What Is the DPDP Act 2025?

First, a small but important clarification. India didn’t pass a brand-new law in 2025. The Digital Personal Data Protection Act was actually enacted back in 2023. What happened in 2025 is that the Ministry of Electronics and Information Technology (MeitY) finally notified the Digital Personal Data Protection Rules, 2025 — the detailed, operational playbook that tells organizations exactly how to comply with the 2023 law.

So when people say “DPDP Act 2025,” they really mean the DPDP Act, 2023 as it has now come alive through the DPDP Rules, 2025, notified in mid-November 2025.

In plain terms, the DPDP Act is India’s first comprehensive data privacy law. It governs how organizations collect, store, process, share, and delete the personal data of individuals in India — everything from your name and phone number to your location data, health records, and browsing behavior.

The law is built around a few simple ideas:

  • People (called Data Principals) have the right to know what data of theirs is being collected and why.
  • Organizations (called Data Fiduciaries) can only use that data with clear, informed consent, and only for the purpose it was collected for.
  • Data must be kept secure, retained only as long as necessary, and deleted once its purpose is served.
  • If something goes wrong — a breach, a leak, a misuse — there are strict timelines for reporting it and real financial consequences for getting it wrong.

Organizations have an 18-month runway from the Rules’ notification to get fully compliant, which puts the final deadline at May 13, 2027. Some provisions, like the constitution of the Data Protection Board of India, are already in effect. The rest is being rolled out in phases, but 18 months disappears faster than most compliance teams expect, especially if your data infrastructure isn’t mature yet. For a month-by-month plan to hit that date, see our DPDP Act compliance deadline roadmap.

Why Was the DPDP Act Introduced?

For years, India relied on a fairly thin legal framework — largely the IT Act, 2000 and its associated rules — to deal with something as sensitive as personal data protection. That framework was written for a very different internet than the one we use today, one without smartphones in every pocket, UPI transactions happening by the second, or AI models trained on massive datasets.

A few things pushed India toward a dedicated data protection law:

  • The Puttaswamy judgment (2017): The Supreme Court of India declared privacy a fundamental right under Article 21 of the Constitution. That ruling more or less obligated the government to build a legal framework that actually protects this right in the digital world.
  • Explosive growth in digital services: From fintech apps to e-commerce platforms to healthtech, Indian businesses now routinely collect and process personal data at massive scale, often with very little transparency about what happens to it afterward.
  • Rising data breaches and misuse: High-profile data leaks and the growing sophistication of cyberattacks made it clear that “we’ll be careful” wasn’t a real strategy for protecting citizens’ data.
  • Alignment with global standards: Regulations like the EU’s GDPR reshaped how the world thinks about data rights. India needed its own version, one suited to its scale and digital economy — so that Indian businesses could operate confidently in global markets too.

The result is a law designed to shift organizations away from loosely governed data collection and toward a consent-first, accountability-driven approach to handling personal data.

Who Needs to Comply With the DPDP Act?

This is where a lot of businesses get caught off guard: the DPDP Act casts a very wide net.

You need to comply if you are:

  • Any organization processing the digital personal data of individuals in India: Regardless of your size, sector, or revenue.
  • A foreign company: Any company that processes personal data in connection with offering goods or services to people in India, even if you have no physical office here.
  • A start-up, an SME, or a large enterprise: There’s no small-business exemption for the core obligations under the Act.
  • A “Consent Manager”: A new category of entity that helps individuals manage and withdraw their consent across platforms.

There is one tier that carries heavier obligations: Significant Data Fiduciaries (SDFs). These are organizations designated by the government based on factors like the volume and sensitivity of personal data they handle, and the potential risk to individuals’ rights. If you’re classified as an SDF, expect additional requirements like mandatory Data Protection Impact Assessments (DPIAs), independent audits, and appointing a dedicated Data Protection Officer (DPO).

Bottom line: if your business collects a customer’s name, email, phone number, payment details, location, or any other personal data online, this law almost certainly applies to you.

What Are the Key DPDP Act Compliance Requirements for Businesses?

This is the part that actually matters for your day-to-day operations. Here’s what the DPDP Rules 2025 expect from Data Fiduciaries:

1. Clear, Itemized Consent Notices

Gone are the days of vague, 40-page privacy policies nobody reads. Consent must be free, specific, informed, unconditional, and based on a clear affirmative action — think a genuine opt-in, not a pre-ticked checkbox. Notices need to itemize exactly what data is being collected and why, in plain language the average user can actually understand.

2. Purpose Limitation and Data Minimization

You can only collect data for a specific, lawful purpose — and you can’t quietly repurpose it later for something else without fresh consent.

3. Defined Retention and Erasure Timelines

Personal data can’t just sit in your systems indefinitely. Once its purpose is served — consent is withdrawn, the transaction is complete, or the user goes inactive for a defined period — it needs to be erased. The Rules even set default retention periods for specific sectors, such as e-commerce platforms with large user bases. Individuals generally need to be notified before their data is erased.

4. Data Breach Notification Within 72 Hours

This is a big one. If a breach occurs, affected individuals must be notified within 72 hours of the breach being reported to the Data Protection Board. The notification has to include what happened, what data was exposed, what protective steps people can take, and who to contact. There’s no room here for a “we’ll get to it eventually” approach.

5. Verifiable Parental Consent for Children’s Data

Any platform processing the personal data of children (under 18) needs verifiable parental or guardian consent before proceeding, along with restrictions on tracking, behavioral monitoring, and targeted advertising aimed at minors.

6. Reasonable Security Safeguards

Organizations are expected to implement technical and organizational security measures — think encryption, access controls, monitoring, and incident response readiness — appropriate to the sensitivity of the data they hold. This is arguably the single biggest reason cybersecurity and data protection tools are no longer optional line items; they’re compliance essentials.

7. Enhanced Obligations for Significant Data Fiduciaries

If you’re designated an SDF, layer on annual DPIAs, independent audits, algorithmic fairness assessments, and a formally appointed DPO who reports to the board.

8. Cross-Border Data Transfer Rules

The Rules follow a “negative list” approach — data can generally be transferred outside India unless the government specifically restricts transfers to a particular country.

9. Recordkeeping and Governance

Maintain logs, contracts with third-party processors, and internal governance documentation that can demonstrate compliance if the Data Protection Board comes calling.

What Are the DPDP Act Penalties for Non-Compliance?

This is the part that tends to get everyone’s attention — and rightly so. The DPDP Act doesn’t impose criminal liability, but the financial penalties are substantial and are levied by the Data Protection Board of India (DPBI) under Section 33 of the Act. (We break these down in detail in our guide to data breach penalties under the DPDP Act.)

Type of Violation Maximum Penalty
Failure to implement reasonable security safeguards, leading to a data breach Up to ₹250 crore
Failure to notify the Board and affected individuals of a data breach Up to ₹200 crore
Non-fulfilment of additional obligations related to children’s data Up to ₹200 crore
Non-compliance by a Significant Data Fiduciary (e.g., failing mandatory audits) Up to ₹150 crore
Breach of other specified obligations Varies, up to ₹50 crore
Individual (Data Principal) filing false or frivolous complaints Up to ₹10,000

A few important nuances worth remembering:

  • Penalties are assessed per violation, per instance — a single incident that breaches multiple provisions (say, poor security and delayed breach notification) can trigger overlapping penalties that add up fast.
  • The Board weighs mitigating factors like self-disclosure, how quickly you responded, cooperation during the inquiry, and whether you had a genuine compliance program in place — so being proactive genuinely helps reduce exposure.
  • Only Data Fiduciaries are directly penalized for most violations; however, a Fiduciary remains liable for violations committed by its data processors or vendors.
  • Decisions by the Board can be appealed before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

In short: the cost of ignoring DPDP compliance is significantly higher than the cost of getting ahead of it.

Best Practices for DPDP Act Compliance

Given the 18-month runway, here’s a practical starting point for businesses that want to move from “we know we need to do something” to “we’re actually compliant.” For a fuller, step-by-step version, use our DPDP Act compliance checklist for Indian businesses.

1. Map your data first. You can’t protect what you can’t see. Run a data discovery and classification exercise across your systems to understand what personal data you hold, where it lives, who has access, and why you’re collecting it in the first place.

2. Rebuild your consent architecture. Move away from bundled, vague consent forms. Implement itemized, purpose-specific consent flows with easy withdrawal options — and keep an auditable record of every consent given or revoked.

3. Put a real breach response plan in place. With a 72-hour notification window, you don’t have time to figure things out after an incident happens. Build an incident response playbook, define your escalation team in advance, and run tabletop exercises so your team knows exactly what to do when (not if) something goes wrong.

4. Strengthen your technical security posture. This is where cybersecurity solutions genuinely earn their keep. Endpoint protection, network security, data loss prevention, encryption, and continuous threat monitoring aren’t just “nice to have” anymore — they’re the backbone of demonstrating “reasonable security safeguards” under the law.

5. Set data retention and erasure policies — and automate them. Define how long different categories of data should be kept, and build automated deletion workflows so data doesn’t linger past its purpose by accident.

6. Review every third-party and vendor contract. Since you remain liable for your processors’ mistakes, make sure vendor agreements clearly define data handling responsibilities, security standards, and breach notification obligations.

7. Assign clear ownership. Even if you’re not classified as an SDF (and therefore don’t need a formal DPO), designate a privacy point of contact internally who owns compliance, tracks regulatory updates, and coordinates across legal, IT, and security teams.

8. Start now, not later. 18 months sounds like a long runway until you’re three months away from a security audit with half your data map still incomplete. Organizations that treat this as a strategic priority — rather than a last-minute scramble — will spend far less on remediation and carry far less regulatory risk.

Final Thoughts

The DPDP Act 2025 isn’t just another compliance checkbox — it’s a fundamental shift in how Indian businesses are expected to treat personal data. Consent has to be real, security has to be demonstrable, and accountability has to be built into your systems, not bolted on after the fact.

The good news? None of this needs to be overwhelming if you start early. A strong cybersecurity foundation, clear data governance, and the right monitoring tools can take you a long way toward not just DPDP compliance, but genuinely better data hygiene across your organization.

Frequently Asked Questions

What is the DPDP Act in simple terms?

The DPDP Act is India’s first comprehensive data privacy law, enacted in 2023 and operationalized through the DPDP Rules, 2025 notified in mid-November 2025. It governs how organizations collect, store, process, share, and delete the personal data of individuals in India, built around consent, purpose limitation, security, and timely deletion.

Is the DPDP Act 2025 a new law?

No — India didn’t pass a brand-new law in 2025. The Digital Personal Data Protection Act was enacted in 2023; in 2025, MeitY notified the DPDP Rules, 2025, the detailed operational playbook explaining how to comply with the 2023 law. “DPDP Act 2025” refers to the 2023 Act as brought to life by those Rules.

What is the deadline for DPDP Act compliance?

The final compliance deadline is May 13, 2027 — an 18-month runway from the notification of the DPDP Rules, 2025. Some provisions, like the constitution of the Data Protection Board of India, are already in effect, with the rest rolling out in phases.

What is the penalty for a data breach under the DPDP Act?

Failing to implement reasonable security safeguards that leads to a data breach can attract a penalty of up to ₹250 crore, and failing to notify the Board and affected individuals can add up to ₹200 crore more. Penalties are assessed per violation, per instance, so one incident can trigger overlapping fines.

Who has to comply with the DPDP Act?

Any organization processing the digital personal data of individuals in India — regardless of size, sector, or revenue — plus foreign companies offering goods or services to people in India, even without an Indian office. There is no small-business exemption for the core obligations, and Significant Data Fiduciaries face additional requirements.

What is the 72-hour breach notification rule?

If a breach occurs, affected individuals must be notified within 72 hours of the breach being reported to the Data Protection Board. The notification must cover what happened, what data was exposed, what protective steps people can take, and who to contact.

Key Takeaways

  • The “DPDP Act 2025” is the DPDP Act, 2023 made operational by the DPDP Rules, 2025, notified in mid-November 2025.
  • The final compliance deadline is May 13, 2027 — an 18-month window that runs out faster than most teams expect.
  • The Act applies to virtually every organization handling digital personal data of individuals in India, including foreign companies serving Indian users.
  • Core obligations include itemized consent, purpose limitation, retention and erasure timelines, 72-hour breach notification, parental consent for children’s data, and reasonable security safeguards.
  • Penalties reach up to ₹250 crore per violation, assessed per instance, with fiduciaries also liable for their processors’ failures.
  • Start with data mapping, consent redesign, and a breach response plan now — proactive compliance is dramatically cheaper than remediation.
All articles