Readiness assessment
LIVE NOWDPDP Rules 2025 · full compliance 13 May 2027

Know the DPDP Act, and exactly what to do about it.

Every section in plain language, a clear picture of what is already in force, and one place to start instead of forty-four.

Where the Act stands today
13 Nov 2025
Live now
The Data Protection Board is established. Definitions and its machinery are in force, and complaints can be filed.
13 Nov 2026
Next
Consent Manager registration opens; the penalty machinery begins to operate.
13 May 2027
Full compliance
Notice, consent, data-principal rights, breach reporting, children's data and SDF duties all apply.
Built from primary sources DPDP Act 2023 · DPDP Rules 2025 · Gazette notifications · MeitY releases · Data Protection Board updates

In short

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It sets out how organisations may collect, use and protect the personal data of people in India, and it is enforced by the Data Protection Board of India, with penalties up to ₹250 crore. The Rules took effect on 13 November 2025; full compliance is due by 13 May 2027.

Who is impacted?

Almost every organisation that handles the personal data of people in India, from a two-person startup to a multinational, including companies based abroad that offer goods or services to people in India.

Startups to enterprisesIndian & foreign companiesAny sector handling PIIGovernment, with carve-outs
From knowing to doing

Knowing the Act is step one. Operating it is the real work.

Most teams can read the law. Far fewer have mapped their data, wired consent and rights into live systems, and built the evidence a regulator will ask for. The implementation hub lays out the full path from readiness to operational compliance, and how partner-led delivery gets you there before 13 May 2027.

How long can you keep the data?

The Act sets a lifecycle, not a fixed number of years: keep personal data only while its purpose lives.

Collectwith consent, for a stated purpose
Keeponly while that purpose is served
Erasewhen the purpose ends or consent is withdrawn
Read the erasure rule, Section 8(7)
The Rules

The DPDP Rules, 2025

The Act says what; the Rules say how. Notified and in force from 13 November 2025, they carry the operational detail behind every obligation.

Read the DPDP Rules 2025
Compliance certification

Turn your readiness into a credential.

DPDP Compliance Certification is an independent mark that shows customers, partners and regulators your organisation meets the Act's requirements, not just claims to.

  • Win trust and clear security reviews faster
  • Stand out in vendor and procurement checks
  • Lower your risk before the Board ever asks
Explore certification

How it works

From "are we even compliant?" to a mark you can show, in four steps.

1

Assess

Take the free readiness check and see your gaps.

2

Remediate

Follow your prioritised roadmap to close them.

3

Verify

Have your controls and evidence reviewed.

4

Certify

Earn your certification and renew as you grow.

Common questions about the DPDP Act

Short, cite-able answers to what people ask most.

What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It governs how organisations collect, use and protect the digital personal data of people in India, and it is enforced by the Data Protection Board of India.
When does the DPDP Act come into force?
The DPDP Rules, 2025 took effect on 13 November 2025, when the Data Protection Board was established. Most operational obligations, including notice, consent, data-principal rights and breach reporting, apply from 13 May 2027.
Who does the DPDP Act apply to?
It applies to any organisation, called a Data Fiduciary, that processes the digital personal data of people in India. It also reaches companies based outside India where they process such data in connection with offering goods or services to people in India.
What are the penalties under the DPDP Act?
The Schedule to the Act sets a maximum penalty for each type of breach, up to ₹250 crore for failing to take reasonable security safeguards. The Board decides the amount based on the gravity, duration and repetition of the breach.
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides why and how personal data is processed and carries the main obligations under the Act. A Data Processor only processes data on the Fiduciary's behalf, under a valid contract.
Does the DPDP Act apply to companies outside India?
Yes. The Act applies to the processing of digital personal data outside India where it is connected to offering goods or services to people within India.