India’s Digital Personal Data Protection Act, 2023 (DPDP Act) becomes fully operational on May 13, 2027. That’s the date most of the law’s real obligations- consent, breach notification, data principal rights, security safeguards- stop being “future requirements” and start being enforceable, penalty-backed rules. It might sound far off, but the clock has already started. On November 13, 2025, the Ministry of Electronics and Information Technology (MeitY) officially notified the Digital Personal Data Protection Rules, 2025, kicking off a phased rollout that ends in May 2027. If you run a business in India, or handle the personal data of anyone in India, that date affects you, whether you’ve started preparing or not.
The DPDP Act – An Overview
The Digital Personal Data Protection Act, 2023 is India’s law governing how organisations collect, store, use, and share the personal digital data of individuals. Think of it as India’s answer to Europe’s GDPR.
It is a rulebook that says: if you’re collecting someone’s name, phone number, email, health data, or any other personal information, you owe that person transparency, security, and control over it.
Parliament passed the Act and published it in August 2023, but the government needed to establish detailed Rules before regulators could enforce its provisions. Those Rules finally arrived in November 2025.
Most Organizations Get It Wrong – The Real DPDP Timeline?
This is the part most businesses get wrong. The DPDP Act and Rules are rolling out in three phases, not overnight:
Phase 1: November 14, 2025 (already in effect): The date when the basic machinery of the law switched on – definitions and the setup of the Data Protection Board of India (DPBI), the body that will hear complaints and issue penalties.
Phase 2: November 13, 2026: Rules relating to “Consent Managers”, licensed platforms that help individuals manage their consents across services, come into force.
Phase 3: May 13, 2027: This is the key stage. Most major requirements, including consent, breach reporting, data rights, security safeguards, and Significant Data Fiduciary duties, become fully applicable on this date.
What’s the takeaway?
You have a runway, but it’s shorter than it sounds. Building proper consent flows, security controls, and internal processes takes most organisations several months. Waiting until early 2027 to start is too late!
Join our weekly newsletter and stay updated
Who Does the DPDP Act Apply To?
The Act uses three simple roles:
Data Principal: The person the data belongs to, such as your customer, employee, or app user.
Data Fiduciary: The organisation that decides why and how personal data is collected and used.
Data Processor: The organisation or person hired by the Data Fiduciary to process personal data, such as a cloud or payroll service provider.

The DPDP Act isn’t limited to Indian companies. It applies to any organisation, anywhere in the world, that processes the personal data of individuals in India, including foreign companies offering goods or services to Indian users. If you have Indian customers, this law is your problem too, regardless of where your servers sit.
What DPDP Actually Requires You to Do?
Here is what every Data Fiduciary needs to know:
- Give clear notice: Before or at the time of collecting data, tell people what you’re collecting and why.
- Get real consent. Consent has to be specific, informed, and freely given, and withdrawing it must be just as easy as giving it.
- Keep it secure. Implement reasonable security safeguards to protect personal data and prevent breaches. This is the one that connects data privacy directly to cybersecurity.
- Report breaches fast. If a personal data breach occurs, you must inform the Data Protection Board and affected individuals without delay, then submit a detailed report to the Board within 72 hours of discovering the breach.
- Delete data when it’s no longer needed. Once the purpose for collecting data is served, or if a user stops engaging with your service, the data must be erased.
- Protect children’s data. You need verifiable parental consent to process a child’s data, and you can’t run targeted ads or behavioural tracking aimed at children.
- Appoint a Grievance Officer. A designated Grievance Officer who handles users’ complaints about how the organisation manages their data.
Extra DPDP Rules for “Significant Data Fiduciaries”
If your organisation processes large volumes of sensitive personal data, like large social media platforms, fintechs, or healthcare data processors, the government can classify you as a Significant Data Fiduciary (SDF) that comes with additional homework:
- Appointing a Data Protection Officer based in India
- Getting an independent data auditor to review your practices periodically
- Running regular Data Protection Impact Assessments (DPIAs)
- In some cases, restrictions on moving certain sensitive categories of data outside India
What Happens If You Don’t Comply with DPDPA?
This is where the DPDP Act has real teeth. Under the Schedule to the Act, the Data Protection Board of India can impose penalties including:
- Up to Rs 250 crore for failing to implement reasonable security safeguards that lead to a data breach
- Up to Rs 200 crore for failing to notify a breach, or for violating children’s data protection rules
- Up to Rs 150 crore for a Significant Data Fiduciary failing its additional obligations (like skipping DPIAs or audits)
- Up to Rs 50 crore as a catch-all for any other violation not specifically listed
- Up to Rs 10,000 for a Data Principal misusing the grievance or complaint process
Book Your Free Cybersecurity Consultation Today!
How does Kratikal help with DPDP?
This is exactly the gap Kratikal’s DPDPA compliance services are built to close. As a CERT-In empanelled cybersecurity company, Kratikal combines regulatory expertise with hands-on security services, including data mapping, DPDP gap assessments, security audits, and vulnerability assessments, to test and verify your organisation’s reasonable security safeguards. If your organisation is still figuring out where it stands, Kratikal is a good place to start the conversation.
FAQs
- When does the DPDP Act come into full effect?
It’s phased. Basic provisions like the Data Protection Board took effect on November 14, 2025. Consent Manager rules follow around November 2026, and most substantive obligations like consent, breach notification, data principal rights, become enforceable around May 13, 2027.
- Does the DPDP Act apply to my company if we’re based outside India?
Yes. The Act applies to organisations that process the personal data of individuals in India or offer goods and services to them, regardless of where the organisation is based.
- What counts as “personal data” under the DPDP Act?
Any data about an individual that can identify them, in digital form or later digitised like names, phone numbers, emails, financial details, health records, and similar identifiers.
- What’s the difference between a Data Fiduciary and a Data Processor?
The Data Fiduciary determines why and how organisations process data and assumes legal responsibility for the processing. A Data Processor just processes data on the Fiduciary’s instructions, for example, a cloud storage provider.
- Can personal data be transferred outside India under the DPDP Act?
Generally yes. The Act takes a “negative list” approach like cross-border transfers are allowed by default unless the government specifically restricts transfers to a particular country.
- How is the DPDP Act different from GDPR?
They share similar goals like consent, transparency, breach notification, but the DPDP Act’s penalties are flat caps, up to Rs 250 crore, rather than GDPR’s turnover-based fines, and DPDP has fewer lawful bases for processing data, leaning heavily on consent.