India’s DPDPA compliance, enforcement timelines, and potential director exposure

IFLR is part of Legal Benchmarking Limited, 1-2 Paris Garden, London, SE1 8ND

Copyright © Legal Benchmarking Limited and its affiliated companies 2026

Accessibility | Terms of Use | Privacy Policy | Modern Slavery Statement


India’s DPDPA compliance, enforcement timelines, and potential director exposure

Sponsored by

TWL Square Logo 2026 (Bold x2) new.png
Digital illustration representing the Indian economy and financial markets
Shutterstock

India’s new data protection regime is now taking shape through a phased implementation. Niharika Sinha and Yashas Gowda C D of TWL Law Group examine the key compliance obligations, penalties, and potential implications for directors

1 What is the DPDPA and its implementation timeline?

The Digital Personal Data Protection Act, 2023 (DPDPA) marks India’s shift from a fragmented data protection framework under the Information Technology Act, 2000 towards a comprehensive statutory regime for digital personal data protection.

The Digital Personal Data Protection Rules, 2025, notified in November 2025, set out the phased implementation of the DPDPA. The first phase, establishing the institutional framework, including the Data Protection Board of India, is already in force. Provisions relating to consent managers take effect in November 2026, while most substantive compliance obligations, data principal rights, enforcement provisions, and related rules take effect in May 2027.

2 Who is responsible for compliance under the DPDPA?

Data principals are individuals to whom the personal data relates, with statutory rights including access, correction, erasure, grievance redressal, and nomination. The data fiduciary determines the purpose and means of processing such personal data and remains responsible for compliance, including processing undertaken on its behalf by a data processor. Key responsibilities include:

  • Implementing appropriate technical and organisational measures and reasonable security safeguards;

  • Notifying personal data breaches;

  • Ensuring required erasure of personal data;

  • Providing accessible contact information; and

  • Establishing an effective grievance redressal mechanism.

Data processors may be engaged only under a valid contract; however, the responsibility remains with the data fiduciary.

3 What are the lawful grounds for processing personal data?

The DPDPA permits processing on two principal grounds:

  • Consent – must be free, specific, informed, unconditional and unambiguous, involve clear affirmative action, and be limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent, and the data fiduciary must be able to demonstrate valid notice and consent.

  • Legitimate uses processing without consent is permitted in specified circumstances, including voluntarily provided data, certain state functions, legal obligations, emergencies, and employment-related purposes.

4 Can personal data be transferred outside India?

Yes, the DPDPA permits cross-border transfers unless the government restricts transfers to notified countries or territories, subject to stricter requirements under other Indian laws. This framework takes effect in May 2027, and no restricted jurisdictions have yet been notified. Businesses should therefore map cross-border data flows, monitor notifications, and maintain safeguards consistent with the highest applicable standards.

5 What are the penalties for non-compliance?

The DPDPA principally imposes monetary penalties rather than imprisonment. Penalties can be as high as INR 2.5 billion (approximately $26 million) for failure to maintain reasonable security safeguards and INR 2 billion for breach-notification failures. Other contraventions may attract penalties of up to INR 500 million.

6 Can directors be held personally liable?

The DPDPA does not automatically impose corporate liability on directors. However, directors remain subject to their fiduciary duties under the Companies Act, 2013, including duties of due care, skill, and diligence, and oversight of compliance with applicable laws. Serious data protection failures could raise broader questions of board oversight. However, personal liability remains fact-specific. Indian courts have generally rejected liability based solely on directorship without a statutory basis and facts linking the director to the relevant misconduct or negligence.

7 What should companies do to prepare for compliance?

Companies should use the transition period to:

  • Map personal data processing activities and identify data fiduciary and data processor roles;

  • Identify and document the lawful basis for processing;

  • Implement compliant notices and consent mechanisms;

  • Review processor contracts and security safeguards;

  • Adopt purpose-based retention and erasure procedures;

  • Establish grievance-redressal and data-breach response protocols; and

  • Integrate data protection into existing governance and risk-management structures.

The transition period provides an important opportunity to implement and test these measures before the substantive obligations take effect.

Gift this article