In our previous guide to India’s Digital Personal Data Protection Act (DPDPA), we explored the high-level architecture of India’s first comprehensive privacy law. Since the act’s 2023 enactment, the landscape has shifted from legislative theory to operational reality.
While the 2023 act provided only the high-level framework, regulators have now implemented rules that inform what compliance must look like in practice. The most critical update in the rules is the timeline set for compliance, summarized below:
|
Timeline |
DPDPA Provisions |
DPDP Rules |
Affected Parties |
Explanation |
|
November 13th, 2025 |
Section 2, 18 to 26, 35, 38-44(1)(3) |
Rules 1, 2 and 17 to 21 |
Indian government |
Administrative features of the law become effective (e.g., Data Protection Board functions and rules). |
|
November 13th, 2026 |
Section 6(9), Section 27(1)(d) |
Rule 4 |
Indian government and consent manager SaaS companies |
The process to register as a consent manager begins. |
|
May 13th, 2027 |
3-5, 6(1)-(8), 6(10), 10-17, Section 27 (except 27(1)(d)), Sections 28-34, 36-37, 44(2) |
Rules 3, 5 to 16, 22 and 23 |
Everyone |
DPDPA compliance obligations come into effect. |
While India’s DPDPA uses some terms common to other data privacy laws, it also includes several unique terms. Here’s what you need to be familiar with:
The DPDPA applies to your organization if you:
However, one of the controversial aspects of the DPDPA is its broad set of exclusions. Many government agencies are exempt, and the central government has the power to regulate certain categories of organizations (such as startups) in the future. Other exempted activities include processing publicly available personal data, personal data for research purposes, and non-Indian citizens’ data under certain circumstances, which may make it easier to carry out targeted advertising.
By May 2027, notices must:
If you’re familiar with privacy notice requirements in other privacy laws, you’ll recognize that this is a lot more prescriptive and granular. For example, regulations like the GDPR only require you to list the categories of data types and the third parties that receive personal information; the DPDPA requires an itemized list of both.
This presents two challenges for businesses:
Businesses with a limited understanding of their website and data processing activities will struggle with listing out those details in the privacy policy. Meanwhile, many businesses will feel reluctant to disclose who they specifically transfer data to, especially if those vendors have a poor reputation or if the relationship is sensitive in some way.
The DPDPA’s definition of consent tracks with other privacy laws for the most part. However, its purpose limitation and right to withdraw consent at any time stand out.
The DPDPA limits businesses from processing data for purposes other than what the consumer consents to. Most data privacy laws also permit the use of data under other legal bases, but the DPDPA only permits data processing for purposes that the consumer explicitly consented to and a narrow list of certain legitimate uses (e.g., fulfilling a legal obligation or responding to a medical emergency).
Additionally, the moment a data principal withdraws consent, the data fiduciary is legally obligated to not only stop processing but also delete the data, unless retention is specifically mandated by another Indian law.
The DPDPA features a few terms that may be confusing for businesses seeking to comply with the law. The act uses the specific term “consent manager” to describe a new type of regulated legal entity, whereas most businesses just need a technical tool (a consent management platform, or CMP) to manage their own users.
|
Feature |
Standard CMP |
Registered Consent Manager (Rule 4) |
|
What It Is |
A software tool (like Osano) used by a company to manage its consumers’ consent preferences |
A licensed legal entity that acts as a single dashboard for a user across many companies |
|
Legal Status |
An extension of the data fiduciary (the company) |
An independent fiduciary registered with India’s Data Protection Board |
|
Scope of Service |
Handles consent specifically for your website/app only |
Allows users to manage, review, and withdraw consent for multiple different websites/apps in one place |
|
Obligations |
You are responsible for all records and compliance |
They take a more active role in compliance by holding a master record of consent and facilitating data portability |
|
Record Keeping |
You must maintain your own auditable logs |
They are legally mandated to keep immutable consent records for 7 years |
No. You do not need to register as a consent manager, nor are you forced to use one that is registered with the Indian government. Most companies will simply use their existing CMP to support the law’s notice and consent requirements.
The rights afforded to data subjects (or data principals), aside from the ability to consent to data collection and withdraw that consent, mirror the standard set of rights found in other data privacy laws. The right to consent is set aside from the normal set of rights to emphasize India’s adherence to an opt-in model of consent, rather than the opt-out model seen regularly in US state privacy laws.
Notably, however, the right to portability is absent.
The DPDPA’s data privacy rights are as follows:
Unlike certain data privacy laws like the CCPA, verification of requesters is allowed for all rights requests. Businesses only need to consider requests made in writing by a person who can be authenticated. Additionally, businesses must honor requests submitted by authorized agents for requesters who have a disability or are children.
You have a maximum of 90 days to complete a request, but this includes any appeals. Based on industry standards, it may make the most sense to set the default fulfillment timeline to 30 days–this should give you enough time to action the request and handle any appeals that may result.
Completing privacy assessments is an implicit necessity for meeting compliance obligations under the DPDPA. The only explicit requirement to conduct assessments is reserved for significant data fiduciaries, who must perform a data protection impact assessment (DPIA) when directed by the data protection authority (DPA). However, the precise definition and criteria for what constitutes a "significant data fiduciary" remain largely undefined beyond the general characteristics outlined in the legislation.
Unlike some laws where a vendor shares direct statutory liability for a breach, the DPDPA places the responsibility squarely with the fiduciary. The law doesn’t prescribe formal obligations for processors, which makes it even more important for fiduciaries to conduct their due diligence on vendors to ensure they are handling data responsibly and securely. Most businesses will likely align their India third-party risk management (TPRM) process with EU TPRM program processes.
As noted, the DPDPA is a consent-first framework with a strict purpose limitation. This requires rigorous data mapping to ensure that personal data is only processed for the purpose described to data subjects. Under Rule 8, data must be deleted the moment that purpose is deemed no longer served, making automated retention schedules a necessity.
The DPDP Board is a digital-first enforcement body with significant teeth. Penalties are tiered based on the violation.
|
Violation |
Fine Amount |
|
Breach of data fiduciary’s obligations |
Up to ₹250 crore (for significant data fiduciaries, or SDFs; ~$27M)/₹200 crores (non-SDF; ~$22M) |
|
Failure to comply with Board directions |
Up to ₹250 crore (SDF; ~$27M)/₹200 crores (non-SDF; ~$22M) |
|
Failure to protect data |
Up to ₹250 crore (~$27M) |
|
Failure to notify of a breach |
Up to ₹250 crore (~$27M) |
|
Failure to protect children's data |
Up to ₹200 crore (~$22M) |
|
Failure to publish contact information |
₹10,000 per day (~$110 per day), up to ₹10 lakh per default (~$11K) |
The on-ramp to DPDPA compliance in 2027 may feel long, but the operational requirements require immediate planning. Now is the time to transition from high-level policy to technical implementation.
Compliance with any data privacy law can be complicated, but given the unique provisions of the DPDPA and the sheer number of individuals it protects, businesses may struggle to get compliant quickly.
Fortunately, Osano can help with a number of DPDPA requirements. Businesses using the Osano platform will be able to:
Schedule a demo of Osano today to take your first steps toward DPDPA compliance.