1 What is the DPDPA and its implementation timeline?
The Digital Personal Data Protection Act, 2023 (DPDPA) marks India’s shift from a fragmented data protection framework under the Information Technology Act, 2000 towards a comprehensive statutory regime for digital personal data protection.
The Digital Personal Data Protection Rules, 2025, notified in November 2025, set out the phased implementation of the DPDPA. The first phase, establishing the institutional framework, including the Data Protection Board of India, is already in force. Provisions relating to consent managers take effect in November 2026, while most substantive compliance obligations, data principal rights, enforcement provisions, and related rules take effect in May 2027.
2 Who is responsible for compliance under the DPDPA?
Data principals are individuals to whom the personal data relates, with statutory rights including access, correction, erasure, grievance redressal, and nomination. The data fiduciary determines the purpose and means of processing such personal data and remains responsible for compliance, including processing undertaken on its behalf by a data processor. Key responsibilities include:
Implementing appropriate technical and organisational measures and reasonable security safeguards;
Notifying personal data breaches;
Ensuring required erasure of personal data;
Providing accessible contact information; and
Establishing an effective grievance redressal mechanism.
Data processors may be engaged only under a valid contract; however, the responsibility remains with the data fiduciary.
3 What are the lawful grounds for processing personal data?
The DPDPA permits processing on two principal grounds:
Consent – must be free, specific, informed, unconditional and unambiguous, involve clear affirmative action, and be limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent, and the data fiduciary must be able to demonstrate valid notice and consent.
Legitimate uses – processing without consent is permitted in specified circumstances, including voluntarily provided data, certain state functions, legal obligations, emergencies, and employment-related purposes.
4 Can personal data be transferred outside India?
Yes, the DPDPA permits cross-border transfers unless the government restricts transfers to notified countries or territories, subject to stricter requirements under other Indian laws. This framework takes effect in May 2027, and no restricted jurisdictions have yet been notified. Businesses should therefore map cross-border data flows, monitor notifications, and maintain safeguards consistent with the highest applicable standards.
5 What are the penalties for non-compliance?
The DPDPA principally imposes monetary penalties rather than imprisonment. Penalties can be as high as INR 2.5 billion (approximately $26 million) for failure to maintain reasonable security safeguards and INR 2 billion for breach-notification failures. Other contraventions may attract penalties of up to INR 500 million.
6 Can directors be held personally liable?
The DPDPA does not automatically impose corporate liability on directors. However, directors remain subject to their fiduciary duties under the Companies Act, 2013, including duties of due care, skill, and diligence, and oversight of compliance with applicable laws. Serious data protection failures could raise broader questions of board oversight. However, personal liability remains fact-specific. Indian courts have generally rejected liability based solely on directorship without a statutory basis and facts linking the director to the relevant misconduct or negligence.
7 What should companies do to prepare for compliance?
Companies should use the transition period to:
Map personal data processing activities and identify data fiduciary and data processor roles;
Identify and document the lawful basis for processing;
Implement compliant notices and consent mechanisms;
Review processor contracts and security safeguards;
Adopt purpose-based retention and erasure procedures;
Establish grievance-redressal and data-breach response protocols; and
Integrate data protection into existing governance and risk-management structures.
The transition period provides an important opportunity to implement and test these measures before the substantive obligations take effect.