DPDP Act Complete Guide
India’s Digital Personal Data Protection Act, explained the way you’d explain it to someone who actually has to comply with it.
What Is the DPDP Act?
India’s first comprehensive data protection law, now fully in force.
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s federal law governing how organisations collect, process, store, and share the digital personal data of individuals in India. It received Presidential assent in August 2023, and the DPDP Rules, 2025 – notified on 13 November 2025 – supply the operational detail needed to actually comply with it. Together, the Act and Rules form India’s equivalent of the GDPR.
Compliance is being phased in over 18 months rather than switched on overnight. The Data Protection Board of India was established immediately when the Rules were notified. Registration for Consent Managers opens 12 months later, in November 2026. Full compliance – notice requirements, breach reporting, Data Principal rights, and Significant Data Fiduciary obligations – becomes mandatory at the 18-month mark, in May 2027.
HOW TO IMPLEMENT & COMPLY WITH
DPDPA FROM SCRATCH KNOW FROM THE BELOW VIDEO:
KEY TERMS TO KNOW
|

The Act applies broadly: any organisation processing digital personal data connected to India, regardless of where that organisation is physically located. A US company with no Indian office can still be a Data Fiduciary under this law if it offers goods or services to people in India.
Related reading: Who Needs DPDP Compliance? · Data Principal Rights · Significant Data Fiduciaries
How GCAI helps: GCAI maps your data flows against the DPDP Act’s definitions before anything else, so you know with certainty whether you’re a Data Fiduciary, a Data Processor, or both.
Who Needs DPDP Compliance?
The territorial reach is wider than most organisations outside India expect.
The DPDP Act applies to any entity processing digital personal data in connection with offering goods or services to individuals in India – a test that mirrors the GDPR’s extraterritorial reach rather than tying jurisdiction to physical presence. It also covers data collected offline and later digitised, which catches paper-based businesses that scan records into a database.
Two carve-outs are worth knowing early. Personal data an individual has voluntarily made public – a public social media profile, for instance – falls outside the consent requirement. And organisations that process data of individuals located outside India, under contract with an Indian entity, may be exempt from certain obligations under the outsourcing exemption.

LARGE-SCALE DATA FIDUCIARIES FACE EXTRA RULES
|
Separately, Significant Data Fiduciaries (SDFs) – designated by the government based on data volume, sensitivity, and risk – face the heaviest obligations: appointing a Data Protection Officer based in India, conducting Data Protection Impact Assessments, and undergoing periodic independent audits.
Related reading: What Is the DPDP Act? · Significant Data Fiduciaries · Penalties Under the DPDP Act
How GCAI helps: GCAI determines your fiduciary classification – ordinary, large-scale, or significant – and scopes the compliance programme to match, rather than over-building controls you don’t need.
Core Obligations of a Data Fiduciary
Consent, purpose limitation, and security sit at the centre of every requirement.
The DPDP Act is consent-centric: outside a short list of “legitimate uses,” a Data Fiduciary needs clear, specific, informed consent before processing personal data, and that consent must be as easy to withdraw as it was to give. Everything else in the Act builds on top of that single requirement.
| Obligation | What it requires |
| Notice | Plain-language notice at or before collection, stating purpose and data collected |
| Purpose limitation | Data used only for the purpose consented to, not repurposed silently |
| Data minimisation | Collect only what the stated purpose actually needs |
| Security safeguards | Reasonable technical and organisational measures against breach |
| Breach notification | Notify the Board and affected individuals without delay |
| Erasure | Delete data once its purpose is served, per Rule 8 retention timelines |
| Grievance redressal | Provide an accessible mechanism for Data Principal complaints |
Retention isn’t open-ended even with consent in hand. The Third Schedule sets default erasure timelines for specific sectors – three years from last login or transaction for large e-commerce, gaming, and social media platforms – and Rule 8 requires a 48-hour notice to the individual before scheduled erasure goes ahead.
Related reading: Data Principal Rights · Penalties Under the DPDP Act · Children’s Data Under DPDP
How GCAI helps: GCAI builds your consent and notice flows directly against Rule 3 and Rule 8 language, so the notice your users actually see matches what the law requires them to be told.
Data Principal Rights
Simpler than the GDPR’s rights framework, but still enforceable in plain terms.
The Act deliberately uses plain language over an exhaustive rights catalogue. A Data Principal can access information about what data is held and how it’s processed, request correction or updating of inaccurate data, request erasure once the purpose is served, nominate another individual to exercise these rights on their behalf, and lodge a grievance directly with the Data Fiduciary before escalating to the Board.
Erasure requests carry a firm clock: Rule 14 requires a response within 90 days. A Data Fiduciary acting only as a controller of the relationship still has to ensure its Data Processors erase the same data – the obligation doesn’t stop at the Fiduciary’s own systems.
Related reading: Core Obligations of a Data Fiduciary · Children’s Data Under DPDP · Penalties Under the DPDP Act
How GCAI helps: GCAI sets up a request-handling workflow that tracks the 90-day erasure clock automatically, so rights requests don’t slip past the deadline.
Children’s Data Under DPDP
Verifiable parental consent, with no behavioural targeting permitted at all.
Section 9 of the Act and Rule 10 of the Rules impose the strictest obligations in the entire framework on processing the personal data of children – defined as anyone under 18 – and of persons with disabilities who have a lawful guardian. Verifiable parental or guardian consent is required before any processing begins.

WHAT’S PROHIBITED OUTRIGHT
|
Rule 10 names DigiLocker – India’s government-backed digital document wallet – as an approved verification method for confirming a parent’s identity and their relationship to the child. A narrow set of purposes is exempt from the consent requirement, including child-protection functions, statutory benefit or subsidy delivery, and basic email account creation.
Related reading: Core Obligations of a Data Fiduciary · Data Principal Rights · Significant Data Fiduciaries
How GCAI helps: GCAI designs the age-gate and parental verification flow to Rule 10’s specific standard, including DigiLocker integration where that fits the product.
Significant Data Fiduciaries
The government can designate any organisation an SDF based on risk, not just size.
Significant Data Fiduciary status is assigned by the central government, considering factors such as the volume and sensitivity of data processed, risk to Data Principal rights, potential impact on India’s sovereignty and electoral integrity, and risk to public order. It is not purely a revenue or headcount test – a smaller organisation handling sensitive enough data can still be designated an SDF.
| SDF obligation | What it means in practice |
| Data Protection Officer | Must be based in India and report to the board or governing body |
| Independent data auditor | Periodic audits of processing activities and compliance posture |
| Data Protection Impact Assessment | Formal risk assessment before high-risk processing begins |
| Algorithmic accountability | Verification that algorithmic tools don’t risk Data Principal rights |
Failing to meet SDF-specific obligations carries its own dedicated penalty under the Act’s Schedule – separate from, and in addition to, the general security-safeguard penalty that applies to every Data Fiduciary regardless of size.
Related reading: Who Needs DPDP Compliance? · Penalties Under the DPDP Act · What Is the DPDP Act?
How GCAI helps: GCAI runs the SDF designation criteria against your actual data footprint early, so a DPO appointment and DPIA process are in place before the government makes the determination for you.
Penalties Under the DPDP Act
The Schedule sets some of the steepest data-protection fines in the world.
The DPDP Act’s Schedule sets maximum penalties by violation type, with the Data Protection Board determining the actual amount based on the nature, gravity, and duration of the breach, the number of individuals affected, and the Fiduciary’s compliance history.
| Violation | Maximum penalty |
| Failure to implement reasonable security safeguards (S.8(5)) | ₹250 crore (~USD 30 million) |
| Failure to notify the Board or Data Principals of a breach (S.8(6)) | ₹200 crore |
| Non-compliance with special provisions for children (S.9) | ₹200 crore |
| Failure to fulfil additional SDF obligations (S.10) | ₹150 crore |
| Breach of duty by a Data Principal (S.15) | ₹10,000 |

Appeals against Board decisions go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). The Board itself operates as a fully digital body – complaints are filed and tracked through an online portal and mobile app, which is a deliberate departure from the paper-based grievance processes common under older Indian regulatory bodies.
Related reading: Significant Data Fiduciaries · Core Obligations of a Data Fiduciary · DPDP FAQ
How GCAI helps: GCAI prioritises remediation against the highest-penalty provisions first – security safeguards and breach notification – so the biggest exposure closes earliest.
DPDP FAQ
The questions that come up most once the basics are out of the way.
Is the DPDP Act in force yet? Yes. The Act received assent in 2023, and the Rules notified in November 2025 operationalise it on an 18-month phased timeline, with full compliance required by May 2027.
Does it apply to companies outside India? Yes, if they process the personal data of individuals located in India in connection with offering goods or services to them – physical presence in India is not required for the law to apply.
How is this different from the GDPR? DPDP is consent-centric with a narrow set of legitimate uses, rather than the GDPR’s six lawful bases. It uses simpler, plainer language, and it doesn’t include a GDPR-style set of Standard Contractual Clauses for vendor contracts – organisations have to negotiate their own Rule 6 terms with processors.
What’s a Consent Manager, and is using one mandatory? A Consent Manager is a registered third party that lets individuals manage consent across multiple services from one place. Using one is optional for organisations, but registration for Consent Managers themselves opens in November 2026, and any Data Principal who chooses to use one adds another layer of obligation for the Fiduciary.
What should we be doing right now? Inventory where personal data is processed, classify whether you’re a Data Fiduciary, Processor, or both, and review vendor contracts for Rule 6 security obligations – 2026 is widely described as the practical build year ahead of the May 2027 deadline.
Related reading: What Is the DPDP Act? · Who Needs DPDP Compliance? · Penalties Under the DPDP Act
How GCAI helps: GCAI’s DPDP readiness review can answer most of the questions above for your specific business in a single working session, including whether you qualify as a Significant Data Fiduciary.