India compliance
The DPDP Act: what your website must do
India's Digital Personal Data Protection Act is now in force. Here is what it requires, what it costs to fix, and the deadline that matters.

TL;DR
- The Digital Personal Data Protection (DPDP) Act was passed in August 2023. Its procedural provisions came into force on 13 November 2025, and the substantive obligations phase in over the following 12 to 18 months, with full enforcement by mid-May 2027.
- The DPDP Act applies to any company processing digital personal data in India, and to companies outside India that offer goods or services to people in India, even without a local office.
- Every company in scope must give a clear, plain-language notice before collecting personal data and get specific consent recorded separately for each purpose.
- Significant Data Fiduciaries (companies handling large or sensitive volumes of data) face extra duties: a Data Protection Impact Assessment, an independent audit, and a Data Protection Officer based in India.
- A personal data breach must be reported to the Data Protection Board of India and to affected people within 72 hours of becoming aware of it.
- Penalties reach up to INR 250 crore per violation. Read how we audit technical compliance for teams handling personal data in or from India.
What changed and when
The DPDP Act is in force. The deadline that matters is May 2027.
India passed the Digital Personal Data Protection Act in August 2023, but a law needs rules before anyone can be held to it. The Government notified the DPDP Rules on 13 November 2025, which brought the procedural parts of the Act into effect immediately: definitions, the Data Protection Board of India, and the legal machinery the Act runs on. The substantive obligations, the notice, consent, breach reporting, and audit requirements that actually change how a website or company operates, phase in over roughly 12 to 18 months, with full enforcement due by mid-May 2027.
The Act has a wider reach than many Indian businesses expect. It applies to digital personal data processed inside India, and it applies extraterritorially: a company based in the US, UK, or anywhere else must comply if it offers goods or services to people located in India, even without an Indian office or server. A US SaaS company with Indian customers, or a UK retailer shipping to Indian addresses, is in scope the moment its website collects personal data from an Indian visitor.
Waiting until the 2027 deadline carries real risk. Consent flows, privacy notices, and data inventories take months to build properly, and the companies that start now avoid a scramble against a hard deadline shared with every other regulated company in the market.
A US, UK, or German company with Indian customers is in scope the moment its website collects personal data from a visitor in India.
DPDP Act obligations by company type
What the DPDP Act requires, and who carries the heavier duties.
| Obligation | Applies to | What it means in practice |
|---|---|---|
| Plain-language notice and consent | Every data fiduciary (any company processing personal data) | A clear notice in plain language before collecting data, with specific consent recorded separately for each purpose |
| Data Protection Impact Assessment | Significant Data Fiduciaries | A documented assessment of privacy risk before high-volume or high-sensitivity processing begins |
| Independent audit | Significant Data Fiduciaries | A periodic audit by an independent assessor, checking that stated practices match actual data handling |
| Data Protection Officer | Significant Data Fiduciaries | A person based in India who is the public point of contact for the Data Protection Board and for data principals |
| 72-hour breach notification | Every data fiduciary | Report a personal data breach to the Data Protection Board and to affected people within 72 hours of becoming aware of it |
| Consent Manager registration | Companies offering consent management as a service | Registration with the Data Protection Board before operating as a consent manager on behalf of other companies |
At a glance
- 13 Nov
- 2025: date the DPDP Rules were notified, bringing the Act's procedural provisions into force.
- 72hours
- Time limit to report a personal data breach to the Data Protection Board and to affected people.
- 250crore ₹
- Maximum penalty per violation under the DPDP Act, roughly $30 million USD.
Compliance next step
Get a compliance check on: DPDP Act India compliance
Send us where your site stands today. We reply with the risks that carry real exposure, not a generic checklist.
What to fix first
Four places DPDP gaps usually show up on a live website.
Consent banners that collect everything at once
A single "accept" checkbox covering analytics, marketing, and account data does not meet the DPDP standard of specific, purpose-linked consent. Each purpose needs its own clear consent, in plain language, that a person can withdraw as easily as they gave it.
Privacy notices too dense for an ordinary visitor
The DPDP Act requires a notice in clear, plain language describing what data is collected and why. A dense legal document that a non-technical visitor cannot parse in under a minute does not meet that bar, regardless of how thorough the legal drafting is.
No inventory of where Indian visitor data actually goes
Many companies cannot list, with confidence, every system and third-party tool that touches personal data from an Indian user. Without that inventory, a Data Protection Impact Assessment or a breach report cannot be produced quickly or accurately when the Board asks for one.
No breach response plan tested against a 72-hour clock
A written incident policy that has never been rehearsed usually fails the 72-hour window in practice: identifying the breach, assessing scope, and notifying the Board and affected people takes coordination that only works if someone has practised it.
Common questions
What companies ask when they start a DPDP compliance project.
When does the DPDP Act actually apply to my company?
The procedural provisions are already in force as of 13 November 2025. The substantive obligations, notice, consent, breach reporting, and audits, phase in over the following months, with full enforcement expected by mid-May 2027. Waiting for the deadline is risky: the consent and notice work takes months to build properly.
Does the DPDP Act apply to a US or UK company with Indian customers?
Yes. The Act applies extraterritorially to any company that offers goods or services to people in India, even without an Indian office. If your website collects personal data from visitors in India, you are in scope regardless of where your company is based.
What is a Significant Data Fiduciary?
A company designated by the Data Protection Board because of the volume or sensitivity of personal data it processes. Significant Data Fiduciaries carry extra duties: a Data Protection Impact Assessment, an independent audit, and a Data Protection Officer based in India.
What counts as valid consent under the DPDP Act?
Consent must be specific to a stated purpose, given freely, and as easy to withdraw as it was to give. A single checkbox covering multiple unrelated purposes, buried in a long policy document, does not meet the standard. Each purpose needs its own clear notice and its own consent.
What happens if we have a data breach?
You must notify the Data Protection Board of India and affected people within 72 hours of becoming aware of the breach. That timeline only works if your team has a rehearsed process for identifying scope and drafting notifications quickly. A policy document nobody has tested will not meet that clock.
What are the penalties for non-compliance?
Penalties under the DPDP Act can reach INR 250 crore per violation, roughly $30 million USD, with the amount set by the Data Protection Board based on the nature, duration, and impact of the failure. Consent and notice failures, and breach reporting failures, are among the most likely to be enforced early.
How we help with DPDP compliance
We start with a data inventory, then fix consent and notice.
We audit what personal data your site actually collects from Indian visitors, where it goes, and how consent is currently recorded. Most gaps we find are technical: consent banners that collect too much at once, notices that are legally accurate but unreadable, and no record of which third-party tool receives what data. We produce a gap list ranked by regulatory risk and fix the consent flow, notice language, and data flow documentation directly.
For companies that qualify as Significant Data Fiduciaries, we scope the audit and Data Protection Impact Assessment work alongside your legal counsel, who handles the parts of DPDP compliance that require an Indian-qualified lawyer. See our technical compliance services for scope, or read our guide to the EU GDPR audit cost if your company also handles EU personal data alongside Indian data.
Written by
Vineet Talwar
Co-founder, Tech & Operations at Some Tech Work. WordCamp speaker across Europe and Asia, and host of the WP Shoutout podcast.
Start here
Ready to talk.Book a short diagnostic.
Tell us what needs fixing
We read every brief and reply within one business day.
Prefer to talk first?or request a tech stack audit →or email us directly →
Not sure where to start? Send the stuck decision, workflow, or page. We will say whether you need a diagnostic call, a tech stack audit, or a different first step.