Home / FAQ
38 questions · DPDP Act 2023 + Rules 2025

Frequently asked DPDP questions

Questions we've heard often enough to write down. Answers are short and quote the section or rule they come from, so you can check us against MeitY if you're feeling suspicious. Last verified against the primary sources on 8 September 2026.

Verified 8 Sep 2026 Primary sources cited on every claim Schema.org FAQPage

01Enforcement

When were the DPDP Rules 2025 notified?

The Ministry of Electronics and Information Technology notified the final DPDP Rules 2025 on 13 November 2025 via Gazette Notification G.S.R. 846(E). The draft was released ten months earlier, on 3 January 2025.

When does the DPDP Act enforcement actually begin?

Enforcement is phased. Rules 1, 2 and 17 to 21 took effect on 13 November 2025. Rule 4 (Consent Manager registration) takes effect on 14 November 2026. The substantive core (Rules 3, 5 to 16, 22 and 23) takes effect on 14 May 2027, 18 months after notification. MeitY has floated a proposal to shorten the 18-month clock to 12 months, moving the last date to 13 November 2026, but the proposal has not been notified.

Is the Data Protection Board of India operational?

Not yet. MeitY invited applications for the Chairperson and four Members on 6 May 2026. A follow-up notification issued on 6 June 2026. The Cabinet Secretary heads the search-cum-selection committee. As of August 2026, no appointments had been announced.

Where can I read the primary source?

DPDP Act 2023 in the Gazette of India dated 11 August 2023. DPDP Rules 2025 via G.S.R. 846(E) dated 13 November 2025 on meity.gov.in. Full text mirrored at dpdpa.com.

02Coverage

Who has to comply with the DPDP Act?

Any organisation of any size that processes the digital personal data of individuals located in India. This includes Indian companies and foreign companies offering goods or services in India. There is no revenue floor and no headcount floor.

Does DPDP apply to personal data collected on paper?

Not directly. DPDP covers only digital personal data (Section 3). Paper records that are later digitised come within scope from the point of digitisation.

Does DPDP apply outside India?

Yes, extraterritorially, when the processing is in connection with an offering of goods or services to Data Principals within India (Section 3(b)). Physical presence in India is not required.

What is not covered by DPDP?

Personal data processed for personal or domestic purposes and personal data made publicly available by the Data Principal themselves are outside the Act (Section 3(c)). State processing under Section 7 and Section 17 exemptions is treated differently.

What makes consent valid under DPDP?

Section 6(1) requires consent to be free, specific, informed, unconditional and unambiguous, with a clear affirmative action. Pre-ticked boxes, bundled purposes, and silence do not qualify.

How easy must withdrawal be?

As easy as giving consent. Section 6(4) sets an equivalent-ease standard. If you offered a one-tap consent, you cannot bury withdrawal three menus deep.

What does the Rule 3 notice have to contain?

The notice must be understandable on its own, in clear and plain language, with an itemised description of the personal data collected, the specified purposes, and a specific link for the Data Principal to withdraw consent, exercise other rights, and complain to the Board. It must be available in English by default and in any of the 22 Eighth Schedule languages on request.

What is a Consent Manager?

A Consent Manager is a Data Protection Board-registered platform through which a Data Principal gives, manages, reviews and withdraws consent across multiple Data Fiduciaries via a single interface (Sec. 2(g), Sec. 6(3)). Rule 4 sets registration standards. Rule 4 takes effect on 14 November 2026.

04Penalties

What are the DPDP penalty caps?

The Schedule sets four caps per breach. Rs. 250 crore for failure to implement reasonable security safeguards (Sec. 8(5)). Rs. 200 crore for failure to notify a personal data breach (Sec. 8(6)) or for a breach of children's data obligations (Sec. 9). Rs. 150 crore for a breach of Significant Data Fiduciary obligations (Sec. 10). Rs. 50 crore for any other violation.

Are there penalties on Data Principals?

Yes. Section 15 imposes duties on Data Principals not to file frivolous complaints, not to impersonate, not to suppress material information, and to comply with applicable law. Breach attracts up to Rs. 10,000 under the Schedule.

Can multiple caps apply to the same incident?

Yes. A single incident that both breaches security (Sec. 8(5)) and results in an unreported breach (Sec. 8(6)) can attract both the Rs. 250 crore and Rs. 200 crore caps. There is no lifetime or annual cap.

How does the Board decide the amount within a cap?

Section 33(2) requires the Board to weigh the nature and gravity of the breach, the type and volume of personal data affected, the repetitive nature, whether the breach yielded gain or avoided loss, mitigation steps, and the proportionality of the penalty.

05Cross-border

Can I transfer personal data outside India?

Yes, by default. Section 16 uses a negative-list model. The Central Government may restrict transfers to specific countries by notification. As of September 2026 no country has been so notified.

Does DPDP require data localisation?

Not by default. Rule 12(4) reserves a targeted lever: the Central Government may notify specific data categories that Significant Data Fiduciaries must keep in India. Sectoral regulators (RBI, IRDAI, SEBI, DoT) already impose their own localisation on specific data categories.

Is DPDP like GDPR on transfers?

Opposite. GDPR uses a whitelist and adequacy model: transfers prohibited unless an adequacy decision or a safeguard (SCC, BCR) covers the transfer. DPDP uses a negative-list model: transfers permitted unless specifically restricted.

06SDF

What is a Significant Data Fiduciary?

A Data Fiduciary designated by the Central Government under Section 10, individually or as part of a class. SDFs take on extra obligations under Rules 12 and 13, including an India-resident DPO, annual DPIA, annual independent audit, and algorithm due-diligence.

What six factors trigger SDF designation?

Volume and sensitivity of personal data processed, risk to Data Principals' rights, potential impact on India's sovereignty and integrity, risk to electoral democracy, risk to State security, risk to public order (Section 10(1)).

Have any SDFs been designated?

No public designation has been issued as of September 2026. Industry expectation is that the first designations will follow the Data Protection Board being seated.

Do I need a DPO under DPDP?

A formal DPO is mandatory only for designated SDFs (Rule 12). Every Data Fiduciary must publish contact information of the DPO or an authorised person for grievance handling under Sec. 8(9).

07Children

What is the age of consent under DPDP?

18. The Act defines a child as any person under 18 (Section 2(f)). Stricter than GDPR (13 to 16) and COPPA (13).

What is verifiable parental consent?

Before processing any personal data of a child, obtain consent from the parent or lawful guardian in a manner that verifies both the parent's identity and the parent-child link. Rule 10 permits verification via DigiLocker and equivalent Central Government-designated identity services.

Can I show targeted ads to children with parental consent?

No. Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children, regardless of consent. Contextual advertising (based on the page or app screen) is permitted.

08Rights

What rights does a Data Principal have?

Four rights under Sections 11 to 14: right to access a summary of personal data being processed (Sec. 11), right to correction, completion, updating and erasure (Sec. 12), right to grievance redressal (Sec. 13), right to nominate a person to exercise rights on death or incapacity (Sec. 14).

How long do I have to respond to a Data Principal request?

Rule 14 gives you seven days to acknowledge a valid request, 90 days to complete an erasure or a grievance. Access and correction requests must be completed within a reasonable time.

What if I ignore a Data Principal request?

The Data Principal can escalate to the Data Protection Board under Section 27. The Board can impose a Sec. 33 penalty (up to Rs. 50 crore under the residual cap) and direct you to comply.

09Breach

What is a personal data breach under DPDP?

Any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of the data (Sec. 2(u)).

Who do I notify after a breach?

The Data Protection Board and every affected Data Principal. Under Rule 7, notification must be without delay. A comprehensive report to the Board is due within 72 hours. This is separate from and additional to CERT-In's 6-hour cyber incident reporting under the 28 April 2022 Directions.

What if I don't know the full impact within 72 hours?

File the initial report with what you know. Rule 7 contemplates supplementary reports as investigation progresses. Delayed notification because you are still investigating is not a defence.

10Board

What is the Data Protection Board of India?

A digital-by-design adjudicatory body constituted under Section 18 of the DPDP Act. It has a Chairperson and up to four Members appointed by the Central Government. It hears complaints, opens inquiries, and imposes penalties. Appeals go to TDSAT under Section 29.

Where do Board appeals go?

To the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days of the Board's order (Sec. 29 read with Rule 21). Further appeal to the Supreme Court on questions of law.

Can the Board direct me to take specific action?

Yes, under Section 32. Directions can require you to take specific technical or organisational steps, cease specific processing, or publish notices. Non-compliance with a direction is itself a further Sec. 33 breach.

11GDPR

How does DPDP compare with GDPR?

Both protect personal data but differ on scope (DPDP is digital-only), legal bases (DPDP relies primarily on consent and legitimate uses), penalty design (fixed rupee caps vs turnover-based fines), cross-border transfer (negative-list vs whitelist), and DPO requirement (SDF-only vs broader). See our full DPDP vs GDPR side-by-side.

If I am GDPR compliant, am I DPDP compliant?

Partly. The consent hygiene, ROPA, breach response, and rights-handling structures translate. India-specific gaps: 22-language notice format, nomination right under Sec. 14, verifiable parental consent under Rule 10 (with DigiLocker), Consent Manager route, and any Sec. 16 restricted-country notifications. Also expect stricter penalties for security failures.

Do GDPR Standard Contractual Clauses satisfy DPDP?

DPDP does not require SCCs. The negative-list model makes SCCs unnecessary in most cases. However, if you are a Data Fiduciary using a foreign processor for personal data of Indian Data Principals, a valid Section 8(4) processor contract is required.

Question not answered here? Ask the DPDP AI Advisor, dcomply's RAG-grounded assistant that cites the underlying section or rule on every answer.