Skip to main content
LiveIndia

DPDP

Digital Personal Data Protection Act 2023

India's data-protection law — consent, notice, data-principal rights and security — the DPDP Act 2023 + DPDP Rules 2025.

Overview

What is DPDP?

The Digital Personal Data Protection Act 2023 (DPDP), with the DPDP Rules 2025 notified in November 2025, is India's comprehensive personal-data law. It applies to anyone processing the digital personal data of individuals ("Data Principals") in India, and to processing outside India that offers goods or services to people in India.

It is a consent-and-notice regime enforced by the Data Protection Board of India (DPBI). A Data Fiduciary must have a lawful basis (consent or a listed legitimate use), give a clear itemised notice, honour rights (access, correction, erasure, grievance, nomination), keep data secure, and report breaches. Penalties reach ₹250 crore for failing to take reasonable security safeguards where that leads to a breach.

DPDP deliberately avoids blanket data-localisation: cross-border transfers are allowed to any country except those the government specifically restricts (none so far). Extra "localise specified data in India" duties apply only to Significant Data Fiduciaries, and only for data categories the government later notifies.

The core operational obligations bind from ~13 May 2027 (18 months after the Rules), so 2026 is a prepare-ahead window. Because DPDP is a GDPR-family privacy law, most of the website-level work — consent, cookie/tracker control, notice quality, transport security — overlaps heavily with a GDPR programme.

Applicability

Who must comply?

  • Any business processing the digital personal data of individuals located in India — whether the business is in India or abroad (the Act applies extraterritorially where goods/services are offered to people in India).
  • Data Processors handling personal data on behalf of an Indian-facing Data Fiduciary, under a valid contract.
  • Platforms handling children's (under-18) data, which carries extra verifiable-parental-consent and no-tracking duties.
  • Larger / higher-risk entities that the government designates as Significant Data Fiduciaries, which carry additional DPO, audit, DPIA and data-localisation duties.

Obligations

What you must maintain

A clear, itemised notice

A notice that itemises the personal data collected and the specific purposes, and gives clear routes to withdraw consent, exercise rights, and complain to the Data Protection Board — in plain language, available in English or a scheduled Indian language (s.5 / Rule 3).

Valid consent

Free, specific, informed, unconditional and unambiguous consent by clear affirmative action, limited to the data needed, with withdrawal as easy as giving it (s.6).

Data-principal rights + grievance redressal

Published means to request access, correction and erasure, and a grievance mechanism answered within 90 days (s.11–13 / Rule 14).

Reasonable security safeguards

Encryption/masking, access control, logging and monitoring, backups, and ≥1-year log retention for breach investigation (Rule 6).

Breach notification

Notify affected principals without delay, and the Data Protection Board — an initial intimation without delay plus a detailed report within 72 hours (Rule 7).

Retention & erasure

Erase when the purpose is served or consent is withdrawn; specified large platforms erase 3 years after last contact, with 48 hours' advance notice (s.8 / Rule 8).

Children & guardians

Verifiable parental consent before processing a child's (under-18) data, verifiable guardian consent for persons with disability, and no tracking or targeted advertising to children (s.9 / Rules 10–12).

Coverage

How Audulate covers DPDP

Automated scan

Automated website scans

The website-observable parts of DPDP are checked automatically — consent, cookies/trackers and transport security (largely shared with your GDPR scan) plus DPDP-native notice/rights/grievance/contact checks.

  • Consent (s.6): a genuine consent surface, reject as easy as accept, granular categories, no pre-ticked boxes or cookie walls, and detection of trackers/storage firing before consent.
  • Notice & disclosure (s.5 / Rule 3): the privacy notice references a route to complain to the Data Protection Board, a published rights-request mechanism, a grievance channel, and a data-processing contact / DPO.
  • Children (s.9 / Rule 10): where a sign-up collects personal data, an age-assurance / age-declaration signal is present.
  • Security safeguards (Rule 6): HTTPS, modern TLS, security headers and no mixed content.
AI-assessed

AI-assessed checks

Notice and consent quality is a judgement call, so AI reads the actual notice and consent copy against DPDP's requirements.

  • Privacy-notice completeness — itemised data, specified purposes, and routes to withdraw consent, exercise rights and complain to the Board.
  • Consent-request quality — plain language, tied to a specific purpose, not deceptive, with a multi-language access option and DPO contact.
  • Notice language options — whether the notice is offered in English plus a scheduled Indian language.
Attested

Organisational controls (attested)

The off-site DPDP duties — lawful basis, breach process, retention, children's verifiable consent, and Significant-Data-Fiduciary duties — are provided as attestation controls with evidence surfaces, and we are candid that these are attested, not scanned.

  • Lawful basis, records of processing, and reasonable-security TOMs with ≥1-year log retention.
  • Breach runbook (principal + Board notification within 72 hours), retention/erasure with 48-hour notice, and processor erasure.
  • Rights fulfilment, grievance SLA (≤90 days), nomination support, and DPO/contact in every response.
  • Children & guardian verifiable consent, no-tracking / no-targeted-ads to children — plus the conditional Significant-Data-Fiduciary set (India-based DPO, annual DPIA + audit, algorithmic due diligence, specified-data localisation).

DPDP findings roll into the same compliance score and reports as your other frameworks, so your India posture sits alongside the rest.

Get started

Up and running in 3 steps

1

Run a free scan

Add your website URL — your first scan is free and runs in minutes.

2

Review your findings

See every gap with severity, plain-English explanation and fix guidance.

3

Fix & evidence

Resolve issues, track them over time, and export audit-ready reports.

FAQ

DPDP questions

Who does the DPDP Act apply to?

Anyone processing the digital personal data of individuals in India — including businesses outside India that offer goods or services to people in India. It is enforced by the Data Protection Board of India.

When does DPDP compliance become mandatory?

The DPDP Rules 2025 were notified in November 2025. The core operational obligations (notice, consent, rights, security, breach, retention, children, Significant-Data-Fiduciary duties) commence about 18 months later — around 13 May 2027 — so 2026 is a prepare-ahead window.

Does DPDP require my data to be stored in India?

No, not generally. DPDP uses a negative-list model — transfers are allowed to any country except those the government specifically restricts, and none have been restricted so far. Only Significant Data Fiduciaries face localisation, and only for data categories the government later specifies.

What are the penalties?

Up to ₹250 crore for failing to take reasonable security safeguards where that leads to a personal-data breach, with other tiers for other violations — imposed by the Data Protection Board of India.

Does Audulate cover the children's-data and Significant-Data-Fiduciary rules?

Yes, as attestation controls with evidence surfaces — verifiable parental/guardian consent, no tracking/targeted-ads to children, and the SDF duties (India-based DPO, annual DPIA + audit, algorithmic due diligence, specified-data localisation). We are upfront that these are attested, not scanned; the consent, notice and security checks are automated.

Is this legal advice?

No. Audulate audits, flags and provides evidence surfaces for DPDP; it is informational and not a substitute for advice from qualified Indian data-protection counsel.

This page is informational and not legal advice. Coverage describes Audulate’s current capabilities; your compliance obligations depend on your specific circumstances.

Get started today

Your compliance changes
every time you ship.

Audulate keeps up. Free to start.

2 free scans / monthNo credit card5-minute setup