DPDP Rules 2025: Key Changes, Obligations & Implementation Guide
Read here
Consolidated FAQ Page

DPDP Act FAQ: What Every Data Fiduciary Needs to Know, Prepare, and Do

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's law governing how organisations collect, use, and protect personal data. If you process the personal data of individuals in India — as a bank, hospital, e-commerce platform, insurer, university, or any other organisation — you are very likely a "Data Fiduciary" under the Act, with legal obligations that are now being phased into force. This page answers the questions we hear most often, in three parts: what the law actually says, what a Data Fiduciary needs to do to prepare, and how IndiaConsent's platform helps you get there.

Part 1 — Understanding the DPDP Act, 2023

Fundamental definitions, scope, rights, penalties, and legal foundations

The Digital Personal Data Protection Act, 2023 is India's dedicated law on processing digital personal data, passed by Parliament in August 2023. It sets out the rights individuals ("Data Principals") have over their personal data, the obligations organisations ("Data Fiduciaries") must meet when processing that data, and the penalties the Data Protection Board of India can impose for non-compliance.

Yes, in a phased manner. The DPDP Rules, 2025 were notified on 13 November 2025, which started an 18-month implementation runway. Provisions relating to Consent Managers and the Data Protection Board's establishment take effect earliest, while the core operative obligations on Data Fiduciaries — consent, notice, breach reporting, and Significant Data Fiduciary duties — become fully enforceable on 13 May 2027. Being "not yet fully enforced" is not the same as "not applicable" — organisations are expected to use this window to become compliant, not to wait.

Section 2 of the Act defines a Data Fiduciary as "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data." In practice, this is almost any organisation that decides why and how it collects personal data — a bank opening accounts, a hospital maintaining patient records, an e-commerce site processing orders, or an insurer underwriting a policy.

Section 2 defines personal data broadly as "any data about an individual who is identifiable by or in relation to such data." Unlike the EU's GDPR, the DPDP Act does not create a separate legal category of "sensitive personal data" (such as health or financial data) with heightened rules — all personal data is governed by the same obligations, though sector regulators like the RBI or IRDAI may impose additional sector-specific safeguards over categories like financial or health data.

Yes. Under Section 5(2), if you are already processing personal data that was collected before the Act commenced, you must still give the Data Principal a notice covering what data you hold, why, and how they can exercise their rights — "as soon as it is reasonably practicable." You may keep processing that data while consent has not been withdrawn, but the notice obligation is not avoided just because the data predates the law.

It applies to personal data that is in digital form, or non-digital personal data that is subsequently digitised. A paper KYC form filed in 2019 falls within scope the moment it is scanned, imaged, or entered into a digital system — which is exactly what most organisations do as a matter of course during audits, onboarding, or system migrations.

Section 6(1) requires consent to be free, specific, informed, unconditional, and unambiguous, "expressed by way of any clear affirmative action and not by mere inaction or disengagement." A single pre-ticked box bundled into general terms and conditions does not meet this standard — each purpose needs its own clear, affirmative opt-in, and withdrawing consent must be at least as easy as giving it.

A Consent Manager is an entity registered with the Data Protection Board under Section 6(7)-(9) and Rule 4, acting as a single point of contact through which a Data Principal can give, manage, review, and withdraw consent across multiple organisations. Consent Managers must be interoperable and accountable to the Data Principal, not to the businesses they serve.

No. Section 7 recognises certain "legitimate uses" where personal data can be processed without separate consent — for example, when a Data Principal voluntarily provides data for a specified purpose, for compliance with a court order or judgment, for medical emergencies, or for certain employment purposes. Legitimate uses are specific, limited grounds set out in the Act — they are not a general substitute for consent, and each ground has its own conditions that must genuinely be met.

Section 10(1) allows the Central Government to notify certain Data Fiduciaries as Significant Data Fiduciaries based on factors including the volume and sensitivity of personal data processed, risk to Data Principals' rights, and potential impact on India's sovereignty, electoral democracy, or public order. As of this writing, the Central Government has not yet published a notified list of SDFs — but organisations handling large volumes of data (large banks, telecom operators, major platforms) should reasonably expect to be considered.

Under Section 10(2) and Rule 13, an SDF must: appoint a Data Protection Officer based in India who reports to its Board of Directors; appoint an independent data auditor; carry out a Data Protection Impact Assessment (DPIA) and a data audit once every 12 months from the date of notification; and ensure the auditor/assessor reports "significant observations" to the Data Protection Board. Some categories of SDF-processed data may also be required to stay localised within India.

Generally yes. Section 16 takes a "restriction list" approach rather than the EU's "approved list" (adequacy) approach — cross-border transfer is permitted by default, unless the Central Government specifically notifies a country or territory as restricted. Section 16(2) also preserves any stricter sectoral law (for example, RBI data-localisation requirements for certain payment data) that already applies.

Under Section 8(6), a Data Fiduciary must intimate both the Data Protection Board and each affected Data Principal in the prescribed form and manner. Rule 7 sets the actual clock: affected individuals must be notified "without delay," with a description of the breach, its likely consequences, mitigation steps taken, and what they can do to protect themselves. The Board must also be notified without delay, followed by a detailed report within 72 hours of the fiduciary becoming aware of the breach (or such longer period as the Board allows).

Penalties are set out in the Schedule to the Act and can reach up to ₹250 crore for a single instance, depending on the nature of the failure: up to ₹250 crore for failing to take reasonable security safeguards against a breach (Section 8(5)); up to ₹200 crore for failing to notify a breach (Section 8(6)); up to ₹200 crore for breaching children's-data obligations (Section 9); up to ₹150 crore for breaching Significant Data Fiduciary obligations (Section 10); and up to ₹50 crore for any other breach of the Act or Rules not separately specified. A Data Principal who breaches their own duties under Section 15 faces a comparatively small penalty of up to ₹10,000.

Yes. Section 9 requires verifiable parental or guardian consent before processing a child's (under-18) personal data, prohibits any processing likely to cause a detrimental effect on a child's well-being, and bans tracking, behavioural monitoring, and targeted advertising directed at children outright — this particular prohibition has no general exemption. Rule 12 does carve out limited, conditional exemptions for specified classes of fiduciaries (such as healthcare and educational institutions) and specified purposes under the Fourth Schedule.

Not broadly. The exemption under Section 17 is narrow and applies to specific notified instrumentalities of the State for defined purposes (such as sovereignty, security, and public order), not to the public sector as a whole. A government-owned bank, university, or hospital carrying out ordinary commercial or service functions is not automatically exempt merely because of its ownership.

Under Section 13, if a Data Principal is unsatisfied with a Data Fiduciary's response — or receives no response within the prescribed period — they may escalate the complaint directly to the Data Protection Board. Rule 14(3) requires every Data Fiduciary and Consent Manager to publish a grievance redressal system that responds within a reasonable period not exceeding 90 days.

Part 2 — What Every Data Fiduciary Needs to Prepare

Technical architecture, multi-language notices, DSR, processors, and KYC conflicts

With a data inventory: what personal data you hold, where it lives (which systems, which vendors, which paper archives), why you collect it, and who it flows to next. Almost every other obligation — consent notices, breach response, retention, vendor contracts — depends on first knowing what data you actually have and where it moves.

Per Section 5(1), every consent request must be accompanied by a notice stating: the personal data being collected and the purpose of processing; how the Data Principal can exercise their rights (including withdrawal); and how to complain to the Data Protection Board. Section 5(3) also requires that the Data Principal be given the option to access this notice in English or any language listed in the Eighth Schedule of the Constitution — not just in whatever language the organisation happens to publish in.

No. That kind of bundled, implied consent does not meet Section 6(1)'s "clear affirmative action" standard, and it typically fails to separate consent from unrelated contractual terms — a bundling practice the Act's "unconditional" requirement is specifically aimed at. Each distinct purpose of processing generally needs its own clear opt-in, capable of being withdrawn independently.

Review them against Section 8(2), which requires that a Data Processor be engaged only "under a valid contract" for any activity related to offering goods or services to Data Principals. Contracts with IT vendors, marketing agencies, collection agents, business correspondents, or cloud providers that don't currently specify data-processing terms, security obligations, and breach-notification duties need to be updated — this is not optional paperwork, it's a named statutory obligation.

Build (and rehearse) a breach response playbook mapped to Rule 7's actual timeline: immediate internal escalation, a "without delay" notification to affected individuals and the Board with the prescribed content, and a detailed report to the Board within 72 hours of becoming aware. Waiting to design this process after a breach has already happened means missing the clock the Rules set.

Section 8(7) requires a Data Fiduciary to erase personal data once the Data Principal withdraws consent or once it is reasonable to assume the specified purpose is no longer being served — whichever comes first — unless retention is required under some other law. This means "we might need it someday" is not, on its own, a lawful basis to keep data indefinitely; retention needs a specific legal basis, tied to a specific timeframe.

Only Significant Data Fiduciaries are required by Section 10(2)(a) to appoint an India-based Data Protection Officer reporting to the Board of Directors. Every Data Fiduciary, however — SDF or not — must publish, under Section 8(9), the business contact details of a DPO (if one exists) or of some person able to answer questions about personal data processing on the organisation's behalf.

Section 8(10) requires every Data Fiduciary to establish an effective mechanism to redress Data Principal grievances, and Rule 14(3) requires this mechanism, and its response-time commitment (up to 90 days), to be published on the organisation's website or app. A generic customer-service inbox with no defined DPDP process and no published timeline does not satisfy this.

The Act only mandates a Data Protection Impact Assessment for Significant Data Fiduciaries under Section 10(2)(c) and Rule 13. That said, given how narrow the SDF-notification criteria are expected to be applied and how significant the compliance lift is once notified, most mid-sized and large organisations handling meaningful volumes of personal data run a DPIA-style risk assessment proactively — to find and close gaps well before regulatory notification (or a Data Protection Board inquiry) forces the pace.

Roughly: (1) map your data and vendor flows, (2) fix your consent notices and collection points to meet Section 6, (3) put a valid-contract review in place for every processor under Section 8(2), (4) stand up and publish a grievance redressal mechanism under Section 8(10)/Rule 14, (5) build and rehearse a breach-notification playbook against Rule 7's timeline, and (6) if you are, or expect to be, an SDF, get your DPO, auditor, and DPIA cadence in place well ahead of the annual cycle Rule 13 requires.
Compliance Timeline at a Glance
Milestones and key dates under the DPDP Act & Rules
DateMilestone
11 August 2023DPDP Act, 2023 enacted
13 November 2025DPDP Rules, 2025 notified; 18-month transition window begins
13 November 2026Consent Manager registration and related provisions come into force
13 May 2027Core operative obligations (consent, notice, breach reporting, Significant Data Fiduciary duties) become fully enforceable; Data Protection Board's full powers activate

Part 3 — How IndiaConsent Helps You Get and Stay Compliant

Automated solutions, SDKs, DSR portal, and enterprise retention management

It runs the full consent lifecycle — capturing consent through a clear affirmative-action interface (not a pre-checked box), issuing a compliant Section 5 notice at the point of collection, recording a tamper-evident consent artifact, propagating withdrawal instantly across connected systems, and giving Data Principals a dashboard to review and revoke consent at any time — the same standard a registered Consent Manager is expected to meet.

It scans a website or app to detect every cookie and tracking script in use, classifies them by purpose, blocks non-essential trackers until a Data Principal has given clear affirmative consent, automatically enforces the Section 9(3) prohibition on tracking or targeted advertising to users identified as children, and keeps an auditable log of what consent was given, when, and for what.

DPIA/TPRM is the formal, structured assessment required of (or recommended in preparation for) Significant Data Fiduciary status — covering processing purpose, risk to Data Principal rights, and mitigation measures, mapped against Rule 13's requirements, and extending into third-party/vendor risk (TPRM) so that Section 8(2) processor obligations are actually verified, not just contractually promised. The Fiduciary Self Risk Assessment is a lighter-weight, faster diagnostic — a structured self-assessment any organisation can run today to find its biggest compliance gaps and prioritise remediation, without waiting for SDF notification to force the issue.

It gives a Data Fiduciary a ready-made, published grievance system that logs every Data Principal request, tracks it against the Rule 14(3) response window, escalates internally before the clock runs out, and keeps a complete audit trail — the exact record a Data Fiduciary would need to show the Data Protection Board if a complaint under Section 13 were ever escalated.

PII Discovery scans structured and unstructured systems — databases, file shares, SaaS tools, even legacy archives — to find where personal data actually lives, much of which organisations underestimate or have simply lost track of over time. Lineage Mapping then traces how that data flows between systems, vendors, and business units. Because Section 8(7) erasure decisions, Section 8(2) vendor contracts, and breach-scoping under Rule 7 all depend on knowing where data is and where it goes, this is usually the first solution a new IndiaConsent customer implements — everything else is more accurate once this foundation exists.

No, and it isn't meant to. IndiaConsent operationalises DPDP compliance in software — consent capture, breach workflows, grievance tracking, data mapping — but legal interpretation of ambiguous provisions, sector-specific regulatory overlap (RBI, IRDAI, SEBI, healthcare regulations), and formal legal opinions should come from qualified counsel. Many of IndiaConsent's customers use it precisely to implement what their law firm or compliance consultant has already advised.

Individually. Consent Management, Cookie Management, DPIA/TPRM, Fiduciary Self Risk Assessment, Grievance Redressal, and PII Discovery & Lineage Mapping are each usable on their own, so an organisation can start with its most urgent gap — commonly consent management or PII discovery — and add other modules as its compliance programme matures.

Organisations with high-volume, high-sensitivity personal data processing and multiple regulatory overlays — banks, NBFCs and fintechs, insurers, hospitals and healthcare providers, universities, e-commerce and quick-commerce platforms, travel companies, and metro/transit and cab operators — where DPDP compliance intersects with sector regulators like the RBI, IRDAI, or healthcare data rules.
IndiaConsent Solutions Mapping
Mapping IndiaConsent modules to specific DPDP Act & Rules obligations
IndiaConsent SolutionDPDP Obligation It Addresses
Consent ManagementSection 5 (notice), Section 6 (valid consent, withdrawal), Section 6(7)-(9)/Rule 4 (Consent Manager interoperability)
Cookie ManagementSection 6 (consent for tracking technologies), Section 9(3) (no tracking/targeted ads to children)
DPIA / TPRMSection 10(2)(c) and Rule 13 (DPIA for SDFs), Section 8(2) (vendor/processor risk)
Fiduciary Self Risk AssessmentSection 8 general obligations, readiness ahead of SDF notification
Grievance RedressalSection 8(10), Section 13, Rule 14(3) (published mechanism, response timelines)
PII Discovery & Lineage MappingThe data inventory every other obligation depends on; Section 8(7) retention/erasure decisions

Ready to Get SDF-Ready & Fully DPDP Compliant?

See how IndiaConsent's Consent & Privacy Management Platform automates 22-language notices, DSR workflows, and audit receipts.