Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
LIVE NOWDPDP Rules 2025 · full compliance 13 May 2027

Know the DPDP Act, and exactly what to do about it.

Every section in plain language, a clear picture of what is already in force, and one place to start instead of forty-four.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

Where the Act stands today
13 Nov 2025
Live now
The Data Protection Board is established. Definitions and its machinery are in force, and complaints can be filed.
13 Nov 2026
Next
Consent Manager registration opens; the penalty machinery begins to operate.
13 May 2027
Full compliance
Notice, consent, data-principal rights, breach reporting, children's data and SDF duties all apply.
Built from primary sources DPDP Act 2023 · DPDP Rules 2025 · Gazette notifications · MeitY releases · Data Protection Board updates
  • Independent, and cited to primary sources
  • A real person calls you first
  • Delivery partner introduced only after your consent
  • No details shared until you agree
  • Built from the Act, the Rules and Gazette notifications
  • Honest about certification: no official DPDP certificate exists
  • Free to read, in plain language

In short

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It sets out how organisations may collect, use and protect the personal data of people in India, and it is enforced by the Data Protection Board of India, with penalties up to ₹250 crore. The Rules took effect on 13 November 2025; full compliance is due by 13 May 2027.

Who is impacted?

Almost every organisation that handles the personal data of people in India, from a two-person startup to a multinational, including companies based abroad that offer goods or services to people in India.

Startups to enterprisesIndian & foreign companiesAny sector handling PIIGovernment, with carve-outs
From knowing to doing

Knowing the Act is step one. Operating it is the real work.

Most teams can read the law. Far fewer have mapped their data, wired consent and rights into live systems, and built the evidence a regulator will ask for. The implementation hub lays out the full path from readiness to operational compliance, and how partner-led delivery gets you there before 13 May 2027.

How long can you keep the data?

The Act sets a lifecycle, not a fixed number of years: keep personal data only while its purpose lives.

Collectwith consent, for a stated purpose
→
Keeponly while that purpose is served
→
Erasewhen the purpose ends or consent is withdrawn
Read the erasure rule, Section 8(7) →
The Rules

The DPDP Rules, 2025

The Act says what; the Rules say how. Notified and in force from 13 November 2025, they carry the operational detail behind every obligation.

Read the DPDP Rules 2025 →
Compliance certification

Turn your readiness into a credential.

DPDP Compliance Certification is an independent mark that shows customers, partners and regulators your organisation meets the Act's requirements, not just claims to.

  • Win trust and clear security reviews faster
  • Stand out in vendor and procurement checks
  • Lower your risk before the Board ever asks
Explore certification →

How it works

From "are we even compliant?" to a mark you can show, in four steps.

1

Assess

Take the free readiness check and see your gaps.

→
2

Remediate

Follow your prioritised roadmap to close them.

→
3

Verify

Have your controls and evidence reviewed.

→
4

Certify

Earn your certification and renew as you grow.

Knowledge base

Everything on the DPDP Act, in one place

23 guides, 6 articles, 12 tools and templates and a 38-term glossary.

Updated 7 Oct 2026
Browse the resource hub →

Common questions about the DPDP Act

Short, cite-able answers to what people ask most.

What is the DPDP Act, 2023?
The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It governs how organisations collect, use and protect the digital personal data of people in India, and it is enforced by the Data Protection Board of India.
When does the DPDP Act come into force?
The DPDP Rules, 2025 took effect on 13 November 2025, when the Data Protection Board was established. Most operational obligations, including notice, consent, data-principal rights and breach reporting, apply from 13 May 2027.
Who does the DPDP Act apply to?
It applies to any organisation, called a Data Fiduciary, that processes the digital personal data of people in India. It also reaches companies based outside India where they process such data in connection with offering goods or services to people in India.
What are the penalties under the DPDP Act?
The Schedule to the Act sets a maximum penalty for each type of breach, up to ₹250 crore for failing to take reasonable security safeguards. The Board decides the amount based on the gravity, duration and repetition of the breach.
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides why and how personal data is processed and carries the main obligations under the Act. A Data Processor only processes data on the Fiduciary's behalf, under a valid contract.
Does the DPDP Act apply to companies outside India?
Yes. The Act applies to the processing of digital personal data outside India where it is connected to offering goods or services to people within India.