DPDP Act, Section 8(5)
DPDP Act, any breach = report
DPDP Rules 2025
Ministry of Electronics & IT
What Is the DPDP Act, and Why Does It Matter Now?
India had been debating a dedicated data protection law for nearly a decade. The Digital Personal Data Protection Act, 2023 was signed into law on 11 August 2023. It sat quietly for two years while rules were drafted and consulted upon. On 14 November 2025, the DPDP Rules 2025 were formally notified by the Ministry of Electronics and Information Technology, turning the law from a document into an enforceable reality.
What makes it significant isn't just that India now has a law, it's what the law requires. The DPDP Act is grounded in consent, transparency, purpose limitation, and individual rights. It mirrors the spirit of GDPR, with its own structure and some distinctly Indian characteristics. And crucially, it has teeth: fines that go up to ₹250 crore per violation.
The DPDP Act doesn't just apply to Indian companies. Any foreign business offering goods or services to individuals in India, and processing their personal data, is covered. This includes SaaS platforms, global HR systems, and e-commerce companies with Indian customers, regardless of where servers are located.
Who Does It Apply To?
If your business collects, stores, processes, shares, or derives value from personal data of Indian residents in digital form, you need to comply. This isn't limited to large enterprises, it applies to startups, MSMEs, fintech apps, healthcare platforms, HR software, and outsourcing companies alike.
Data Fiduciary
The entity that determines the purpose and means of processing personal data. This is typically your organisation. You carry the primary compliance responsibility.
Data Processor
An entity that processes data on behalf of a Data Fiduciary, such as a cloud provider, payroll vendor, or analytics firm. The Fiduciary remains liable for the Processor's compliance.
Data Principal
The individual whose personal data is being processed. Under DPDP, they hold rights to access, correct, and erase their data, and raise grievances, all of which you must operationalise.
Significant Data Fiduciary (SDF)
Entities processing large volumes of sensitive data. SDFs face additional obligations: a resident DPO, annual DPIAs, and independent audits.
The DPDP Timeline: Where We Are and What's Coming
"2026 is a build year. Businesses that use this window to get their consent systems, data inventories, and breach protocols in place will face May 2027 with confidence. Those that don't will face it with a fine."
Five Core Obligations Every Business Must Address
- 1Consent, and It Has to Be RealUnlike GDPR which offers 'legitimate interests' as a processing ground, the DPDP Act makes consent the primary basis for most processing. Consent must be free, specific, informed, and unambiguous, it cannot be buried in a 47-page privacy policy. Users must have a visible, easy mechanism to withdraw consent, and withdrawal must be as simple as giving it.
- 2Data Security, The Highest-Stakes ObligationSection 8(5) requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches. 'Reasonable' is widely expected to align with ISO 27001, NIST, or CERT-In guidelines. This is the provision that carries the largest penalty: up to ₹250 crore. An unencrypted backup, a misconfigured cloud bucket, an unsecured API endpoint, none require malicious intent to attract the maximum fine.
- 3Breach Notification, Zero ThresholdUnlike breach reporting frameworks in the EU, UK, and Australia, which typically require notification only above a threshold of likely harm, the DPDP Act has no threshold. Any personal data breach must be reported to both the Data Protection Board and affected individuals. Required disclosures include the nature of the breach, consequences, mitigation steps, and safety guidance. Delays carry a fine of up to ₹200 crore.
- 4Data Retention, Erasure Is MandatoryRule 8 requires businesses to erase personal data once the specified purpose is achieved, unless another law requires retention. There's also an inactivity-based deletion requirement: if a user doesn't engage for a defined period, the business must auto-erase data after giving 48 hours' prior notice. This has direct implications for CRM systems, marketing databases, and app user records.
- 5Data Principal Rights, 90-Day Response ObligationUsers in India now have GDPR-equivalent rights: access to their data, correction of inaccuracies, erasure, and the right to nominate someone to exercise these rights on their behalf. Grievances must be responded to within 90 days. If users exhaust your redressal mechanism without resolution, they can file complaints directly with the Data Protection Board through an online portal.
A fintech startup stores sensitive KYC data in plain text on a cloud server with poor access controls. A security researcher flags the vulnerability publicly. No data is stolen, but the Data Protection Board launches an investigation and imposes a penalty for lack of adequate safeguards. Under DPDP, you don't need a breach to face a fine. You just need inadequate security.
The Penalty Schedule: What's at Stake
The DPDP Act establishes a graduated penalty framework. Crucially, penalties are per violation, not per incident. A single data breach can simultaneously trigger the inadequate security penalty and the failure-to-notify penalty.
| Violation | Maximum Penalty |
|---|---|
| Inadequate security safeguards leading to a data breach | Up to ₹250 Crore |
| Failure to notify the Board and Data Principals of a breach | Up to ₹200 Crore |
| Non-compliance with children's data obligations | Up to ₹200 Crore |
| Failure to meet Significant Data Fiduciary obligations (DPO, DPIA, audits) | Up to ₹150 Crore |
| Breach of consent obligations, notice requirements, or Data Principal rights | Up to ₹50 Crore |
| Data Principal misuse or filing false complaints | Up to ₹10,000 |
Penalties are assessed per violation, not per incident. An organisation facing a data breach that also failed to notify could face ₹250 crore + ₹200 crore = ₹450 crore in combined penalties for a single incident. The Data Protection Board has discretion to reduce penalties for swift remediation and demonstrated good faith, but documentation of your compliance actions is your primary defence.
Your DPDP Readiness Roadmap
You have until May 2027. That sounds distant but it isn't, building consent infrastructure, completing data inventories, and training teams takes time.
- Map your data. Understand what personal data you collect, where it lives, how it flows, and who processes it on your behalf. You cannot manage what you cannot see.
- Audit your consent flows. Review every touchpoint where personal data is collected, app onboarding, contact forms, marketing sign-ups, and assess whether your notices are DPDP-compliant.
- Assess your security posture against reasonable safeguard standards (ISO 27001, CERT-In). The ₹250 crore provision is your highest financial risk, treat it accordingly.
- Build a breach response protocol. Establish who does what in the first 24 hours after a breach is detected. Notification obligations are immediate under DPDP, you cannot improvise.
- Designate a data protection lead. Even if you're not an SDF, someone needs to own DPDP compliance internally, with resources, authority, and a direct line to the board.
- Operationalise Data Principal rights. Build workflows for access, correction, erasure, and grievance requests. 90-day response windows require structured processes, not inbox monitoring.
- Review your vendor contracts. Your Data Processor relationships must include appropriate security provisions under the DPDP Rules. Audit your agreements, especially cloud and HR vendors.
SecComply maps your existing controls, endpoint encryption, access management, breach detection, data retention policies, directly to DPDP obligations and generates audit-ready evidence automatically. Rather than a once-a-year gap assessment, you see your compliance posture in real time with prioritised actions for any drift. This is how organisations reach May 2027 with confidence rather than a last-minute scramble.
"The DPDP Act isn't just a legal requirement, it's a signal to your customers, partners, and investors that you take data seriously. In India's growing digital economy, compliance is competitive advantage."
Frequently Asked Questions
The Digital Personal Data Protection Act, 2023 was signed into law on 11 August 2023. The DPDP Rules 2025 were notified on 14 November 2025, making the law enforceable. Full enforcement, when all compliance obligations become active, is 13 May 2027. The Consent Manager Framework becomes operational from November 2026.
The DPDP Act applies to any business that collects, stores, processes, shares, or derives value from personal data of Indian residents in digital form. This includes Indian startups, MSMEs, SaaS companies, fintech platforms, healthcare apps, HR software, and outsourcing companies. Crucially, it also applies to foreign businesses offering goods or services to individuals in India, regardless of where servers are located.
The DPDP Act has a graduated penalty framework: up to ₹250 crore for inadequate security safeguards leading to a breach; up to ₹200 crore for failure to notify a breach; up to ₹200 crore for non-compliance with children's data obligations; up to ₹150 crore for Significant Data Fiduciary obligation failures; and up to ₹50 crore for consent or Data Principal rights violations. Penalties are assessed per violation, a single breach can trigger multiple penalties simultaneously.
The DPDP Act has a zero-threshold breach notification requirement. Unlike GDPR which requires notification only above a certain harm threshold, DPDP requires notification of any personal data breach to both the Data Protection Board and affected individuals. Required disclosures include the nature of the breach, its consequences, mitigation steps, and safety guidance. Delays or omissions can attract a fine of up to ₹200 crore.
Significant Data Fiduciaries (SDFs) are entities processing large volumes of sensitive personal data, likely major platforms, fintech players, and healthcare systems. They face additional obligations beyond standard Data Fiduciaries, including: a resident Data Protection Officer (DPO), annual Data Protection Impact Assessments (DPIAs), independent audits, and enhanced security requirements.
SecComply maps your existing controls, endpoint encryption, access management, breach detection, data retention policies, directly to DPDP obligations and generates audit-ready evidence automatically. Rather than a once-a-year gap assessment, you see your DPDP compliance posture in real time with prioritised actions for any drift. This is how organisations reach the May 2027 deadline with confidence rather than a last-minute scramble.
