India compliance

The DPDP Act: what your website must do

India's Digital Personal Data Protection Act is now in force. Here is what it requires, what it costs to fix, and the deadline that matters.

Website design work
On this page
  1. TL;DR
  2. What changed and when
  3. DPDP Act obligations by company type
  4. What to fix first
  5. Common questions
  6. How we help with DPDP compliance
Technical review of consent and data flows for DPDP Act compliance in India
TL;DR
  • The Digital Personal Data Protection (DPDP) Act was passed in August 2023. Its procedural provisions came into force on 13 November 2025, and the substantive obligations phase in over the following 12 to 18 months, with full enforcement by mid-May 2027.
  • The DPDP Act applies to any company processing digital personal data in India, and to companies outside India that offer goods or services to people in India, even without a local office.
  • Every company in scope must give a clear, plain-language notice before collecting personal data and get specific consent recorded separately for each purpose.
  • Significant Data Fiduciaries (companies handling large or sensitive volumes of data) face extra duties: a Data Protection Impact Assessment, an independent audit, and a Data Protection Officer based in India.
  • A personal data breach must be reported to the Data Protection Board of India and to affected people within 72 hours of becoming aware of it.
  • Penalties reach up to INR 250 crore per violation. Read how we audit technical compliance for teams handling personal data in or from India.
What changed and when

The DPDP Act is in force. The deadline that matters is May 2027.

India passed the Digital Personal Data Protection Act in August 2023, but a law needs rules before anyone can be held to it. The Government notified the DPDP Rules on 13 November 2025, which brought the procedural parts of the Act into effect immediately: definitions, the Data Protection Board of India, and the legal machinery the Act runs on. The substantive obligations, the notice, consent, breach reporting, and audit requirements that actually change how a website or company operates, phase in over roughly 12 to 18 months, with full enforcement due by mid-May 2027.

The Act has a wider reach than many Indian businesses expect. It applies to digital personal data processed inside India, and it applies extraterritorially: a company based in the US, UK, or anywhere else must comply if it offers goods or services to people located in India, even without an Indian office or server. A US SaaS company with Indian customers, or a UK retailer shipping to Indian addresses, is in scope the moment its website collects personal data from an Indian visitor.

Waiting until the 2027 deadline carries real risk. Consent flows, privacy notices, and data inventories take months to build properly, and the companies that start now avoid a scramble against a hard deadline shared with every other regulated company in the market.

A US, UK, or German company with Indian customers is in scope the moment its website collects personal data from a visitor in India.
DPDP Act obligations by company type

What the DPDP Act requires, and who carries the heavier duties.

Significant Data Fiduciary status depends on the volume and sensitivity of data a company processes, decided by the Data Protection Board.
ObligationApplies toWhat it means in practice
Plain-language notice and consentEvery data fiduciary (any company processing personal data)A clear notice in plain language before collecting data, with specific consent recorded separately for each purpose
Data Protection Impact AssessmentSignificant Data FiduciariesA documented assessment of privacy risk before high-volume or high-sensitivity processing begins
Independent auditSignificant Data FiduciariesA periodic audit by an independent assessor, checking that stated practices match actual data handling
Data Protection OfficerSignificant Data FiduciariesA person based in India who is the public point of contact for the Data Protection Board and for data principals
72-hour breach notificationEvery data fiduciaryReport a personal data breach to the Data Protection Board and to affected people within 72 hours of becoming aware of it
Consent Manager registrationCompanies offering consent management as a serviceRegistration with the Data Protection Board before operating as a consent manager on behalf of other companies
At a glance
13 Nov
2025: date the DPDP Rules were notified, bringing the Act's procedural provisions into force.
72hours
Time limit to report a personal data breach to the Data Protection Board and to affected people.
250crore ₹
Maximum penalty per violation under the DPDP Act, roughly $30 million USD.
Compliance next step

Get a compliance check on: DPDP Act India compliance

Send us where your site stands today. We reply with the risks that carry real exposure, not a generic checklist.

Name the regulation, the page, or the deadline you are working against.

By submitting you agree to our privacy policy.

What to fix first

Four places DPDP gaps usually show up on a live website.

Consent banner redesign for purpose-specific data collection

Consent banners that collect everything at once

A single "accept" checkbox covering analytics, marketing, and account data does not meet the DPDP standard of specific, purpose-linked consent. Each purpose needs its own clear consent, in plain language, that a person can withdraw as easily as they gave it.

Plain-language privacy notice review

Privacy notices too dense for an ordinary visitor

The DPDP Act requires a notice in clear, plain language describing what data is collected and why. A dense legal document that a non-technical visitor cannot parse in under a minute does not meet that bar, regardless of how thorough the legal drafting is.

Data flow mapping for Indian visitor personal data

No inventory of where Indian visitor data actually goes

Many companies cannot list, with confidence, every system and third-party tool that touches personal data from an Indian user. Without that inventory, a Data Protection Impact Assessment or a breach report cannot be produced quickly or accurately when the Board asks for one.

Breach response plan rehearsal against a 72-hour reporting deadline

No breach response plan tested against a 72-hour clock

A written incident policy that has never been rehearsed usually fails the 72-hour window in practice: identifying the breach, assessing scope, and notifying the Board and affected people takes coordination that only works if someone has practised it.

Common questions

What companies ask when they start a DPDP compliance project.

When does the DPDP Act actually apply to my company?

The procedural provisions are already in force as of 13 November 2025. The substantive obligations, notice, consent, breach reporting, and audits, phase in over the following months, with full enforcement expected by mid-May 2027. Waiting for the deadline is risky: the consent and notice work takes months to build properly.

Does the DPDP Act apply to a US or UK company with Indian customers?

Yes. The Act applies extraterritorially to any company that offers goods or services to people in India, even without an Indian office. If your website collects personal data from visitors in India, you are in scope regardless of where your company is based.

What is a Significant Data Fiduciary?

A company designated by the Data Protection Board because of the volume or sensitivity of personal data it processes. Significant Data Fiduciaries carry extra duties: a Data Protection Impact Assessment, an independent audit, and a Data Protection Officer based in India.

What counts as valid consent under the DPDP Act?

Consent must be specific to a stated purpose, given freely, and as easy to withdraw as it was to give. A single checkbox covering multiple unrelated purposes, buried in a long policy document, does not meet the standard. Each purpose needs its own clear notice and its own consent.

What happens if we have a data breach?

You must notify the Data Protection Board of India and affected people within 72 hours of becoming aware of the breach. That timeline only works if your team has a rehearsed process for identifying scope and drafting notifications quickly. A policy document nobody has tested will not meet that clock.

What are the penalties for non-compliance?

Penalties under the DPDP Act can reach INR 250 crore per violation, roughly $30 million USD, with the amount set by the Data Protection Board based on the nature, duration, and impact of the failure. Consent and notice failures, and breach reporting failures, are among the most likely to be enforced early.

How we help with DPDP compliance

We start with a data inventory, then fix consent and notice.

We audit what personal data your site actually collects from Indian visitors, where it goes, and how consent is currently recorded. Most gaps we find are technical: consent banners that collect too much at once, notices that are legally accurate but unreadable, and no record of which third-party tool receives what data. We produce a gap list ranked by regulatory risk and fix the consent flow, notice language, and data flow documentation directly.

For companies that qualify as Significant Data Fiduciaries, we scope the audit and Data Protection Impact Assessment work alongside your legal counsel, who handles the parts of DPDP compliance that require an Indian-qualified lawyer. See our technical compliance services for scope, or read our guide to the EU GDPR audit cost if your company also handles EU personal data alongside Indian data.

Start here

Ready to talk.Book a short diagnostic.

Tell us what needs fixing

A process, a tool, a decision that's stuck. One sentence is fine.

By submitting you agree to our privacy policy.

We read every brief and reply within one business day.

Prefer to talk first?or request a tech stack audit or email us directly

Not sure where to start? Send the stuck decision, workflow, or page. We will say whether you need a diagnostic call, a tech stack audit, or a different first step.