Skip to content
FaceOff Technologies

India · Digital Personal Data Protection Act, 2023

What the Act actually demands

Eighteen obligations, five penalty bands, and a Schedule that assesses per instance. This is the mapping from each obligation to the control that satisfies it.

Act
DPDP Act, 2023
Obligations
18 mapped to products
Max penalty
₹250 Cr, per instance
Applies to
Every Data Fiduciary
Maximum penalty for failing to take reasonable security safeguards

₹250 Cr

Maximum penalty for failing to take reasonable security safeguards

For failing to intimate a breach — and separately for children's-data failures

₹200 Cr

For failing to intimate a breach — and separately for children's-data failures

For a Significant Data Fiduciary that misses its Sec. 10 obligations

₹150 Cr

For a Significant Data Fiduciary that misses its Sec. 10 obligations

Schedule penalties are assessed per instance.

The Act

Obligation by obligation

The duties that attach to every Data Fiduciary, and the additional ones that attach once the Central Government notifies you as Significant.

Sec. 4 & 7

Lawful grounds

Personal data may be processed only for a lawful purpose, with consent or for a listed legitimate use.

Sec. 5

Notice

Itemised notice: what data, what purpose, how to exercise rights, how to complain to the Board — in English or any Eighth Schedule language.

Sec. 6

Consent

Free, specific, informed, unconditional, unambiguous, by clear affirmative action. Withdrawal as easy as giving.

Sec. 8

Fiduciary duties

Accuracy, technical and organisational measures, reasonable security safeguards, erasure on withdrawal, published DPO contact — and liability for processors.

Sec. 9

Children

Verifiable parental or guardian consent; no tracking or behavioural advertising directed at children.

Sec. 10

Significant Data Fiduciary

DPO based in India, independent data auditor, periodic DPIA and audit, algorithmic due diligence.

Sec. 11–14

Principal rights

Access summary, correction and erasure, grievance redressal, nomination.

Sec. 16

Cross-border

Transfer permitted except to countries restricted by the Central Government by notification.

Coverage

Every obligation has an owner

Eighteen obligations, eight products, no gap column — and no obligation that requires a second vendor to close.

DPDP obligationSectionPrimary productSupporting
Lawful purpose & legitimate uses4, 7Privacy Program GovernanceConsent Management
Itemised notice, multi-language5Consent ManagementIntelligent Data Mapper · Privacy Program Governance
Consent: specific, informed, affirmative6(1)Consent ManagementPrivacy Program Governance
Withdrawal parity & cessation6(4)–(6)Consent ManagementIntelligent Data Mapper · Privacy Program Governance
Consent Manager interoperability6(7)–(9)Consent Management
Processor accountability8(1)–(2)Privacy Program GovernanceData Anonymization & Masking · Audit & Evidence Management
Accuracy where used for decisions8(3)Intelligent Data MapperPrivacy Program Governance
Technical & organisational measures8(4)Data Anonymization & MaskingPIA / DPIA Assessment · Audit & Evidence Management
Reasonable security safeguards8(5)Data Anonymization & MaskingData Breach Management · Audit & Evidence Management
Breach intimation to Board & Principals8(6)Data Breach ManagementIntelligent Data Mapper · Audit & Evidence Management
Erasure on withdrawal / purpose expiry8(7)–(8)Intelligent Data MapperDSAR Management · Consent Management
Published DPO contact & grievance8(9)–(10)Audit & Evidence ManagementDSAR Management
Children's data & parental consent9Consent ManagementPIA / DPIA Assessment · Intelligent Data Mapper
SDF: DPO, auditor, DPIA, algorithms10PIA / DPIA AssessmentAudit & Evidence Management · Privacy Program Governance
Access summary & sharing lineage11DSAR ManagementIntelligent Data Mapper · Data Anonymization & Masking
Correction, completion & erasure12DSAR ManagementIntelligent Data Mapper
Grievance redressal & nomination13, 14DSAR ManagementAudit & Evidence Management
Cross-border transfer restrictions16Privacy Program GovernanceIntelligent Data Mapper

Deployment

A readiness sequence that de-risks the biggest exposure first

  1. Phase 1

    Weeks 1–6

    See the estate

    • Deploy Discovery across priority systems
    • Build the identity-resolved catalogue
    • Reconcile collected data against notice
    • Stand up the processor register

    Intelligent Data Mapper · Privacy Program Governance

  2. Phase 2

    Weeks 4–12

    Stop the bleeding

    • Mask non-production and analytics estates
    • Deploy breach detection and playbooks
    • Wire intimation to the catalogue
    • Evidence safeguards continuously

    Data Anonymization & Masking · Data Breach Management

  3. Phase 3

    Weeks 8–18

    Fix the basis

    • Roll out purpose-level consent and notice
    • Enforce withdrawal parity and cessation
    • Turn on children's age-band gating
    • Migrate legacy consent where valid

    Consent Management · Cookie Management

  4. Phase 4

    Weeks 14–26

    Prove it

    • Automate DSAR intake and fulfilment
    • Run DPIA cadence for SDF duties
    • Open the auditor workspace
    • Report posture to the board

    DSAR Management · PIA / DPIA Assessment · Audit & Evidence Management

Why this order

Discovery comes first because every other obligation is undeliverable without the catalogue. Masking and breach detection come second because Sec. 8(5) and 8(6) carry ₹250 Cr and ₹200 Cr — the largest exposure buys down earliest. Consent follows because it is the longest change-management effort and depends on knowing what is actually collected. Rights and audit come last because they consume what the first three phases built.

Enforcement timeline

The Rules are notified. The deadline is 13 May 2027.

The 2023 Act set the duties; the Rules notified on 13 November 2025 made them operative. Enterprise programmes typically need 9 to 12 months from gap assessment to audit readiness.

  1. 13 Nov 2025

    DPDP Rules notified

    The Rules were notified, turning the 2023 Act into operative obligations with detail on notice, consent, security safeguards and breach reporting.

  2. From Nov 2025

    Data Protection Board stands up

    The Board becomes operational and the complaint mechanism goes live, so a Data Principal has somewhere to take a grievance.

  3. ~Nov 2026

    Consent Manager registration opens

    Consent Managers — registered intermediaries with a minimum net worth of ₹2 crore — can register with the Board. Fiduciaries that intend to interoperate need their consent artefacts in the right shape before this.

  4. 13 May 2027

    Full compliance required

    Every organisation processing digital personal data in India must be fully compliant. Enterprise programmes typically run 9–12 months from gap assessment to audit readiness, so the window to start is now.

    Hard deadline

Dates reflect the Rules as notified on 13 November 2025. Verify against the official notification before relying on them contractually.

Questions

DPDP, answered

The questions that come up in every readiness conversation.

What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 is India's data protection law. It governs how organisations — Data Fiduciaries — may process the digital personal data of individuals, called Data Principals. It requires a lawful purpose, itemised notice, specific and informed consent, security safeguards, breach intimation, and a defined set of rights including access, correction, erasure and grievance redressal.
When is the DPDP compliance deadline?
The DPDP Rules were notified on 13 November 2025, and full compliance is required by 13 May 2027. The Data Protection Board and its complaint mechanism are already operational, and Consent Manager registration is expected to open around November 2026. Most enterprise programmes take 9 to 12 months from gap assessment to audit readiness.
What are the penalties under the DPDP Act?
The Schedule sets penalties of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to intimate a personal data breach, up to ₹200 crore for children's-data failures, up to ₹150 crore for a Significant Data Fiduciary that misses its Section 10 duties, and up to ₹50 crore for other contraventions. Penalties are assessed per instance.
Who is a Significant Data Fiduciary?
The Central Government may notify any Data Fiduciary, or a class of them, as Significant based on the volume and sensitivity of the data processed and the risk to Data Principals. An SDF must appoint a Data Protection Officer based in India who is answerable to the board, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments, audits and due diligence of algorithmic software. An enterprise can become an SDF without changing anything it does.
What is a Consent Manager under the DPDP Act?
A Consent Manager is a registered intermediary that gives a Data Principal a single accessible, transparent and interoperable point to give, review and withdraw consent across multiple Data Fiduciaries. Registration is with the Data Protection Board and carries a minimum net-worth requirement. It is distinct from a Consent Management Platform, which is the software an organisation runs internally to capture and enforce consent.
Does the DPDP Act require consent for cookies?
The Act requires consent by clear affirmative action before processing begins. In practice that means non-essential cookies and trackers must not fire until the visitor has opted in — prior blocking — with rejection as easy as acceptance and no pre-ticked boxes. A tag that fires before the affirmative action is unlawful processing from the first pageview, and no consent receipt recorded afterwards can retrofit it.
How long do we have to respond to a DSAR?
The Act gives Data Principals rights of access, correction, completion, updating, erasure, grievance redressal and nomination, and requires a response within the prescribed period. Meeting that clock at volume depends on being able to locate every store holding a given individual's data, which is why a live data catalogue is a prerequisite rather than a nice-to-have.
How does DPDP compare to GDPR?
Both require a lawful basis, notice, security safeguards, breach reporting and individual rights, so a mature GDPR programme covers much of the ground. DPDP differs in important ways: consent is the primary basis with a narrower set of legitimate uses, notice must be available in English or any of the 22 Eighth Schedule languages, verifiable parental consent is required for children with a ban on behavioural advertising directed at them, and the Consent Manager is a registered intermediary with no direct GDPR equivalent.

Find out which obligations you already meet.

A readiness walkthrough maps your current controls onto the eighteen obligations and names the gaps, with the exposure attached to each.