July 6, 2026

DPDPA Act Explained: Everything Businesses Need to Know in 2026

By digitechmediaa07
DPDP Act Complete Guide

India’s Digital Personal Data Protection Act, explained the way you’d explain it to someone who actually has to comply with it.

What Is the DPDP Act?

India’s first comprehensive data protection law, now fully in force.

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s federal law governing how organisations collect, process, store, and share the digital personal data of individuals in India. It received Presidential assent in August 2023, and the DPDP Rules, 2025 – notified on 13 November 2025 – supply the operational detail needed to actually comply with it. Together, the Act and Rules form India’s equivalent of the GDPR.

Compliance is being phased in over 18 months rather than switched on overnight. The Data Protection Board of India was established immediately when the Rules were notified. Registration for Consent Managers opens 12 months later, in November 2026. Full compliance – notice requirements, breach reporting, Data Principal rights, and Significant Data Fiduciary obligations – becomes mandatory at the 18-month mark, in May 2027.

HOW TO IMPLEMENT & COMPLY WITH
DPDPA FROM SCRATCH KNOW FROM THE BELOW VIDEO:

KEY TERMS TO KNOW

  • Data Fiduciary – the organisation that decides why and how personal data is processed; carries the compliance burden.
  • Data Principal – the individual the data belongs to; holds rights to access, correct, and erase it.
  • Data Processor – any entity processing data on a Fiduciary’s behalf, under contract.
  • Consent Manager – a registered intermediary individuals can use to manage consent across services.
Illustration showing key roles in data privacy under the DPDP Act, including Data Fiduciary, Data Principal, Data Processor, and Consent Manager working together to ensure personal data protection.
Understanding the key roles in the DPDP Act: Data Fiduciaries, Data Principals, Data Processors, and Consent Managers each play a vital role in protecting personal data.

The Act applies broadly: any organisation processing digital personal data connected to India, regardless of where that organisation is physically located. A US company with no Indian office can still be a Data Fiduciary under this law if it offers goods or services to people in India.

Related reading: Who Needs DPDP Compliance?  ·  Data Principal Rights  ·  Significant Data Fiduciaries

How GCAI helps: GCAI maps your data flows against the DPDP Act’s definitions before anything else, so you know with certainty whether you’re a Data Fiduciary, a Data Processor, or both.

Who Needs DPDP Compliance?

The territorial reach is wider than most organisations outside India expect.

The DPDP Act applies to any entity processing digital personal data in connection with offering goods or services to individuals in India – a test that mirrors the GDPR’s extraterritorial reach rather than tying jurisdiction to physical presence. It also covers data collected offline and later digitised, which catches paper-based businesses that scan records into a database.

Two carve-outs are worth knowing early. Personal data an individual has voluntarily made public – a public social media profile, for instance – falls outside the consent requirement. And organisations that process data of individuals located outside India, under contract with an Indian entity, may be exempt from certain obligations under the outsourcing exemption.

Concentric circle diagram illustrating data fiduciary obligations across digital platforms, including social media, online gaming, and e-commerce platforms under India's DPDP Act.
The DPDP Act applies to a wide range of digital platforms, with data fiduciary responsibilities extending from social media to online gaming and e-commerce services.
LARGE-SCALE DATA FIDUCIARIES FACE EXTRA RULES

  • E-commerce platforms with more than 20 million Indian users
  • Online gaming platforms with 5 million or more Indian users
  • Social media platforms with more than 20 million Indian users
  • These carry sector-specific retention periods and stricter erasure duties

 

Separately, Significant Data Fiduciaries (SDFs) – designated by the government based on data volume, sensitivity, and risk – face the heaviest obligations: appointing a Data Protection Officer based in India, conducting Data Protection Impact Assessments, and undergoing periodic independent audits.

Related reading: What Is the DPDP Act?  ·  Significant Data Fiduciaries  ·  Penalties Under the DPDP Act

How GCAI helps: GCAI determines your fiduciary classification – ordinary, large-scale, or significant – and scopes the compliance programme to match, rather than over-building controls you don’t need.

Core Obligations of a Data Fiduciary

Consent, purpose limitation, and security sit at the centre of every requirement.

The DPDP Act is consent-centric: outside a short list of “legitimate uses,” a Data Fiduciary needs clear, specific, informed consent before processing personal data, and that consent must be as easy to withdraw as it was to give. Everything else in the Act builds on top of that single requirement.

Obligation What it requires
Notice Plain-language notice at or before collection, stating purpose and data collected
Purpose limitation Data used only for the purpose consented to, not repurposed silently
Data minimisation Collect only what the stated purpose actually needs
Security safeguards Reasonable technical and organisational measures against breach
Breach notification Notify the Board and affected individuals without delay
Erasure Delete data once its purpose is served, per Rule 8 retention timelines
Grievance redressal Provide an accessible mechanism for Data Principal complaints

 

Retention isn’t open-ended even with consent in hand. The Third Schedule sets default erasure timelines for specific sectors – three years from last login or transaction for large e-commerce, gaming, and social media platforms – and Rule 8 requires a 48-hour notice to the individual before scheduled erasure goes ahead.

Related reading: Data Principal Rights  ·  Penalties Under the DPDP Act  ·  Children’s Data Under DPDP

How GCAI helps: GCAI builds your consent and notice flows directly against Rule 3 and Rule 8 language, so the notice your users actually see matches what the law requires them to be told.

Data Principal Rights

Simpler than the GDPR’s rights framework, but still enforceable in plain terms.

The Act deliberately uses plain language over an exhaustive rights catalogue. A Data Principal can access information about what data is held and how it’s processed, request correction or updating of inaccurate data, request erasure once the purpose is served, nominate another individual to exercise these rights on their behalf, and lodge a grievance directly with the Data Fiduciary before escalating to the Board.

Erasure requests carry a firm clock: Rule 14 requires a response within 90 days. A Data Fiduciary acting only as a controller of the relationship still has to ensure its Data Processors erase the same data – the obligation doesn’t stop at the Fiduciary’s own systems.

Related reading: Core Obligations of a Data Fiduciary  ·  Children’s Data Under DPDP  ·  Penalties Under the DPDP Act

How GCAI helps: GCAI sets up a request-handling workflow that tracks the 90-day erasure clock automatically, so rights requests don’t slip past the deadline.

Children’s Data Under DPDP

Verifiable parental consent, with no behavioural targeting permitted at all.

Section 9 of the Act and Rule 10 of the Rules impose the strictest obligations in the entire framework on processing the personal data of children – defined as anyone under 18 – and of persons with disabilities who have a lawful guardian. Verifiable parental or guardian consent is required before any processing begins.

Infographic highlighting prohibited children's data practices under the DPDP Act, including behavioural monitoring, targeted advertising, harmful processing, and unverified parent-child relationships.
The DPDP Act strengthens children’s privacy by prohibiting behavioural tracking, targeted advertising, harmful data processing, and unverified parental consent practices.
WHAT’S PROHIBITED OUTRIGHT

  • Behavioural monitoring or profiling of children
  • Targeted or personalised advertising directed at children
  • Any processing likely to cause harm to a child
  • Processing without a verified parent-child relationship on file

 

Rule 10 names DigiLocker – India’s government-backed digital document wallet – as an approved verification method for confirming a parent’s identity and their relationship to the child. A narrow set of purposes is exempt from the consent requirement, including child-protection functions, statutory benefit or subsidy delivery, and basic email account creation.

Related reading: Core Obligations of a Data Fiduciary  ·  Data Principal Rights  ·  Significant Data Fiduciaries

How GCAI helps: GCAI designs the age-gate and parental verification flow to Rule 10’s specific standard, including DigiLocker integration where that fits the product.

Significant Data Fiduciaries

The government can designate any organisation an SDF based on risk, not just size.

Significant Data Fiduciary status is assigned by the central government, considering factors such as the volume and sensitivity of data processed, risk to Data Principal rights, potential impact on India’s sovereignty and electoral integrity, and risk to public order. It is not purely a revenue or headcount test – a smaller organisation handling sensitive enough data can still be designated an SDF.

SDF obligation What it means in practice
Data Protection Officer Must be based in India and report to the board or governing body
Independent data auditor Periodic audits of processing activities and compliance posture
Data Protection Impact Assessment Formal risk assessment before high-risk processing begins
Algorithmic accountability Verification that algorithmic tools don’t risk Data Principal rights

 

Failing to meet SDF-specific obligations carries its own dedicated penalty under the Act’s Schedule – separate from, and in addition to, the general security-safeguard penalty that applies to every Data Fiduciary regardless of size.

Related reading: Who Needs DPDP Compliance?  ·  Penalties Under the DPDP Act  ·  What Is the DPDP Act?

How GCAI helps: GCAI runs the SDF designation criteria against your actual data footprint early, so a DPO appointment and DPIA process are in place before the government makes the determination for you.

Penalties Under the DPDP Act

The Schedule sets some of the steepest data-protection fines in the world.

The DPDP Act’s Schedule sets maximum penalties by violation type, with the Data Protection Board determining the actual amount based on the nature, gravity, and duration of the breach, the number of individuals affected, and the Fiduciary’s compliance history.

Violation Maximum penalty
Failure to implement reasonable security safeguards (S.8(5)) ₹250 crore (~USD 30 million)
Failure to notify the Board or Data Principals of a breach (S.8(6)) ₹200 crore
Non-compliance with special provisions for children (S.9) ₹200 crore
Failure to fulfil additional SDF obligations (S.10) ₹150 crore
Breach of duty by a Data Principal (S.15) ₹10,000
Thermometer-style infographic showing DPDP Act penalties, including fines of up to ₹250 crore for security safeguard failures and penalties for breach notification, children's data violations, and Significant Data Fiduciary non-compliance.
Non-compliance with the DPDP Act can result in substantial financial penalties, making strong data governance and security practices essential for every organization.

Appeals against Board decisions go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). The Board itself operates as a fully digital body – complaints are filed and tracked through an online portal and mobile app, which is a deliberate departure from the paper-based grievance processes common under older Indian regulatory bodies.

Related reading: Significant Data Fiduciaries  ·  Core Obligations of a Data Fiduciary  ·  DPDP FAQ

How GCAI helps: GCAI prioritises remediation against the highest-penalty provisions first – security safeguards and breach notification – so the biggest exposure closes earliest.

 

DPDP FAQ

The questions that come up most once the basics are out of the way.

Is the DPDP Act in force yet? Yes. The Act received assent in 2023, and the Rules notified in November 2025 operationalise it on an 18-month phased timeline, with full compliance required by May 2027.

Does it apply to companies outside India? Yes, if they process the personal data of individuals located in India in connection with offering goods or services to them – physical presence in India is not required for the law to apply.

How is this different from the GDPR? DPDP is consent-centric with a narrow set of legitimate uses, rather than the GDPR’s six lawful bases. It uses simpler, plainer language, and it doesn’t include a GDPR-style set of Standard Contractual Clauses for vendor contracts – organisations have to negotiate their own Rule 6 terms with processors.

What’s a Consent Manager, and is using one mandatory? A Consent Manager is a registered third party that lets individuals manage consent across multiple services from one place. Using one is optional for organisations, but registration for Consent Managers themselves opens in November 2026, and any Data Principal who chooses to use one adds another layer of obligation for the Fiduciary.

What should we be doing right now? Inventory where personal data is processed, classify whether you’re a Data Fiduciary, Processor, or both, and review vendor contracts for Rule 6 security obligations – 2026 is widely described as the practical build year ahead of the May 2027 deadline.

Related reading: What Is the DPDP Act?  ·  Who Needs DPDP Compliance?  ·  Penalties Under the DPDP Act

How GCAI helps: GCAI’s DPDP readiness review can answer most of the questions above for your specific business in a single working session, including whether you qualify as a Significant Data Fiduciary.

Get the latest posts in your email

Related Posts

About GCAI

GCAI is an independent, internationally accredited certification body helping fast-growing organizations demonstrate trust across security, privacy and AI.
By combining impartial audits with expert guidance, GCAI delivers transparent timelines, clear scoping and globally recognized credentials — so teams reach certification with confidence.
From HIPAA and SOC 2 to ISO 27001, ISO 42001, GDPR, PCI and beyond; GCAI helps teams achieve multi-framework certification with ease.
Newsletter

Join 10K+ compliance and security leaders and be the first to know about new guides, framework updates and audit insights that help you get certified faster.

Scroll to Top