India’s Digital Personal Data Protection Act requires covered businesses to process digital personal data for lawful purposes, explain consent-based processing clearly, protect data, respond to rights requests and grievances, and erase data when retention is no longer justified. Extra safeguards apply to children’s data and to businesses formally notified as Significant Data Fiduciaries (SDFs). The Act and its 2025 Rules have staged commencement dates, so businesses should prepare against the requirements while checking the latest government notifications for the applicable dates.
Does India’s DPDP Act apply to your business?
The Act covers digital personal data processed in India if it was collected digitally or was collected in non-digital form and later digitized. It can also cover processing outside India when that processing is connected with offering goods or services to people in India. The Act has exclusions, so assess the particular data, processing and any applicable exemption rather than assuming the law covers every organization or dataset. See the Digital Personal Data Protection Act, 2023.
The organization that determines the purpose and means of processing is the Data Fiduciary; the individual the data relates to is the Data Principal. A business may use a Data Processor, but the Data Fiduciary remains responsible for its statutory duties for processing it performs itself or through a processor.
What should a business put in place?
Start with a map of personal data, purposes, recipients and processors. Then use that map to build notices, consent records, security controls, retention decisions and request-handling procedures. These workstreams connect: for example, a request to erase data cannot be handled reliably without knowing where the data is held and whether a legal retention requirement applies.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
1. Record the data, purpose and processing roles
- Identify the personal data the business processes and the specified purpose or purposes for each use.
- Record who receives the data, which processors handle it, and the relevant retention period or legal requirement.
- Use the inventory to support notices, security, rights responses and deletion decisions.
The Rules require notices to itemize the personal data and describe the specified purposes. The Act ties processing to a lawful basis and specified purpose. Consult the Digital Personal Data Protection Rules, 2025 alongside the Act.
2. Give clear notice and manage consent
When consent is the basis for processing, give the person a notice that is clear, specific, informed and understandable on its own, rather than buried in unrelated information. The Rules call for an itemized description of the personal data, the specified purposes, and the goods, services or uses enabled by processing. The notice must also explain how to withdraw consent, exercise rights and complain to the Board.
Make withdrawal as easy as giving consent, and retain evidence of the notice and consent. If the question arises in proceedings, the Act places the burden on the Data Fiduciary to prove that notice was given and consent obtained when consent is the basis.
Consent is not the Act’s only permitted basis. The Act also allows specified “legitimate uses,” including certain cases where a person voluntarily provides data for a specified purpose and has not indicated non-consent. That is not blanket permission for unrelated or indefinite reuse: confirm that the particular use meets the Act’s conditions.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
3. Protect data and prepare for breaches
Put reasonable security safeguards in place to prevent personal data breaches, including when a processor handles data on the business’s behalf. If a breach occurs, the Act requires notification to the Board and affected Data Principals in the form and manner prescribed by the Rules.
A workable incident process should identify affected data and people, coordinate with processors, escalate the incident and support the required notifications. Notification details and timing depend on the applicable Rules and circumstances; do not assume a universal deadline without checking the final text.
4. Set retention and erasure rules
Erase personal data when its purpose is no longer served or consent is withdrawn, unless retaining it remains necessary for the specified purpose or another law requires retention. Do not apply a single deletion rule across all data: the Act’s purpose-based approach interacts with specific retention requirements in the Rules and other laws.
The Rules generally require preserving personal data and related processing logs for at least one year for specified security and legal purposes, then erasing them unless another law or government requirement calls for longer retention. They also provide inactivity-based periods for certain large e-commerce, online gaming and social-media entities, subject to stated exceptions:
Rank #3
| Entity category | Threshold specified in the Rules | Inactivity period |
|---|---|---|
| Certain e-commerce entities | At least two crore registered users in India | Three years |
| Certain online gaming intermediaries | At least fifty lakh users | Three years |
| Certain social-media intermediaries | At least two crore users | Three years |
These are requirements in the Government of India’s 2025 Rules, not independently measured statistics. The Rules specify exceptions, so check the relevant category and conditions before applying a period.
5. Handle rights requests and grievances
Data Principals have rights to access information about processing and sharing, seek correction, completion and updating, request erasure, obtain grievance redressal and nominate another person. Publish contact information for the Data Protection Officer (DPO), if applicable, or another person able to answer questions about processing.
Make the grievance mechanism readily available and track requests and responses. A person generally must first use the organization’s grievance mechanism before approaching the Board.
Which businesses need additional safeguards?
Businesses processing children’s data
Before processing a child’s personal data—or personal data of a person with disability who has a lawful guardian—obtain verifiable consent from the parent or lawful guardian, as applicable. The Act also bars processing likely to harm a child’s well-being, tracking or behavioural monitoring of children, and targeted advertising directed at children, subject to prescribed exemptions and government notifications. Check the final Rules and any relevant notifications for the service; do not assume an age threshold or exemption.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Businesses notified as Significant Data Fiduciaries
The Central Government may notify an organization or class as an SDF, considering factors that include the volume and sensitivity of data, risks to individuals, and impacts on national interests and public order. An SDF has additional duties, including an India-based DPO responsible to its governing body, an independent data auditor, and periodic data protection impact assessments and audits. Size alone does not make a business an SDF: check official notifications.
What should businesses check about processors and overseas transfers?
Processor contracts and operating controls should enable the Data Fiduciary to meet its duties when a processor handles personal data. Map processor access and responsibilities as part of the data inventory and incident process.
The Act permits transfers outside India subject to restrictions the Central Government may specify, including requirements about making data available to a foreign state or its entities. The Act and Rules reviewed here do not establish a blanket localization rule. Check current government orders and any sector-specific requirements that apply to each transfer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When do the DPDP Rules come into force?
The final Rules were notified on 13 November 2025. Their published commencement clause stages the start dates as follows:
| Rules | Commencement stated in the published Rules |
|---|---|
| Rules 1, 2 and 17–21 | On publication: 13 November 2025 |
| Rule 4 | One year after publication |
| Rules 3, 5–16, 22 and 23 | Eighteen months after publication |
The broad notice, security, breach, retention, rights and transfer duties are in provisions with staged commencement. MeitY’s document listing identifies a corrigendum dated 16 December 2025 and an enforcement timeline. Because the corrigendum text is not reflected in the cited commencement summary, check the MeitY Rules listing and any later notifications before relying on a date as the complete current schedule. These dates describe the published Rules’ commencement clause, not a verified account of subsequent changes.
How to choose an implementation approach
The Act and Rules do not mandate a particular compliance product. Whether a business uses internal processes, an adviser or a software platform, assess the approach against its actual obligations:
- Does it fit the business’s data, purposes and processing roles?
- Can it preserve evidence of consent and make withdrawal accessible?
- Does it cover processors and support a breach workflow?
- Can it handle retention, deletion and legal holds?
- Does it support rights requests and grievances?
- Can it adapt to India-specific legal requirements and changing notifications?
- What integration effort and total cost will it involve?
These are practical evaluation questions, not a government-endorsed vendor scorecard. A specialist adviser or privacy operations platform may help, but neither is mandated by the cited sources.

