Sec. 4 & 7
Lawful grounds
Personal data may be processed only for a lawful purpose, with consent or for a listed legitimate use.
India · Digital Personal Data Protection Act, 2023
Eighteen obligations, five penalty bands, and a Schedule that assesses per instance. This is the mapping from each obligation to the control that satisfies it.
₹250 Cr
Maximum penalty for failing to take reasonable security safeguards
₹200 Cr
For failing to intimate a breach — and separately for children's-data failures
₹150 Cr
For a Significant Data Fiduciary that misses its Sec. 10 obligations
Schedule penalties are assessed per instance.
The Act
The duties that attach to every Data Fiduciary, and the additional ones that attach once the Central Government notifies you as Significant.
Sec. 4 & 7
Personal data may be processed only for a lawful purpose, with consent or for a listed legitimate use.
Sec. 5
Itemised notice: what data, what purpose, how to exercise rights, how to complain to the Board — in English or any Eighth Schedule language.
Sec. 6
Free, specific, informed, unconditional, unambiguous, by clear affirmative action. Withdrawal as easy as giving.
Sec. 8
Accuracy, technical and organisational measures, reasonable security safeguards, erasure on withdrawal, published DPO contact — and liability for processors.
Sec. 9
Verifiable parental or guardian consent; no tracking or behavioural advertising directed at children.
Sec. 10
DPO based in India, independent data auditor, periodic DPIA and audit, algorithmic due diligence.
Sec. 11–14
Access summary, correction and erasure, grievance redressal, nomination.
Sec. 16
Transfer permitted except to countries restricted by the Central Government by notification.
Coverage
Eighteen obligations, eight products, no gap column — and no obligation that requires a second vendor to close.
Deployment
Phase 1
Weeks 1–6
Intelligent Data Mapper · Privacy Program Governance
Phase 2
Weeks 4–12
Data Anonymization & Masking · Data Breach Management
Phase 3
Weeks 8–18
Consent Management · Cookie Management
Phase 4
Weeks 14–26
DSAR Management · PIA / DPIA Assessment · Audit & Evidence Management
Discovery comes first because every other obligation is undeliverable without the catalogue. Masking and breach detection come second because Sec. 8(5) and 8(6) carry ₹250 Cr and ₹200 Cr — the largest exposure buys down earliest. Consent follows because it is the longest change-management effort and depends on knowing what is actually collected. Rights and audit come last because they consume what the first three phases built.
Enforcement timeline
The 2023 Act set the duties; the Rules notified on 13 November 2025 made them operative. Enterprise programmes typically need 9 to 12 months from gap assessment to audit readiness.
13 Nov 2025
The Rules were notified, turning the 2023 Act into operative obligations with detail on notice, consent, security safeguards and breach reporting.
From Nov 2025
The Board becomes operational and the complaint mechanism goes live, so a Data Principal has somewhere to take a grievance.
~Nov 2026
Consent Managers — registered intermediaries with a minimum net worth of ₹2 crore — can register with the Board. Fiduciaries that intend to interoperate need their consent artefacts in the right shape before this.
13 May 2027
Every organisation processing digital personal data in India must be fully compliant. Enterprise programmes typically run 9–12 months from gap assessment to audit readiness, so the window to start is now.
Hard deadline
Dates reflect the Rules as notified on 13 November 2025. Verify against the official notification before relying on them contractually.
Questions
The questions that come up in every readiness conversation.
Go deeper
Fifteen questions to put to any DPDP vendor, and what separates a demo answer from one that survives an inquiry.
Where the obligations actually bite in banking, healthcare, government, telecom, education and large groups.
Data Fiduciary, Data Principal, SDF, Consent Manager — the Act’s vocabulary in plain terms.
A readiness walkthrough maps your current controls onto the eighteen obligations and names the gaps, with the exposure attached to each.