Every section in plain language, a clear picture of what is already in force, and one place to start instead of forty-four.
In short
The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It sets out how organisations may collect, use and protect the personal data of people in India, and it is enforced by the Data Protection Board of India, with penalties up to ₹250 crore. The Rules took effect on 13 November 2025; full compliance is due by 13 May 2027.
Almost every organisation that handles the personal data of people in India, from a two-person startup to a multinational, including companies based abroad that offer goods or services to people in India.
Wherever you are in the journey, start there. Each stage links to the guidance, tools and sections that fit.
Understand the Act in plain language.
Start guide →See where you stand and find your gaps.
Readiness check →Map data, write notices, fix consent.
The roadmap →Put controls and safeguards in place.
Tools & partners →Review and stay compliant over time.
Stay updated →Most teams can read the law. Far fewer have mapped their data, wired consent and rights into live systems, and built the evidence a regulator will ask for. The implementation hub lays out the full path from readiness to operational compliance, and how partner-led delivery gets you there before 13 May 2027.
Six roles the whole law turns on. Knowing which one you are is the first compliance decision.
The Act sets a lifecycle, not a fixed number of years: keep personal data only while its purpose lives.
All nine chapters and 44 sections, each in plain language with the statutory citation underneath.
The Act says what; the Rules say how. Notified and in force from 13 November 2025, they carry the operational detail behind every obligation.
Read the DPDP Rules 2025 →Same Act, different data. See what the DPDP Act means for your sector.
A hand-picked few to get you moving. Everything else lives in the resource hub.
Answer a short set of questions and get a personalised gap report, private and with no sign-up.
Start the check →Board and Data Principal notice templates, ready to adapt before an incident.
Get the pack →How to build notice, consent capture and withdrawal that actually meet Sections 5 and 6.
Read the guide →What the Rules add on top of the Act, and what they change for you.
Read the guide →Fintech, health, edtech, SaaS and more, each with its own data-stream map.
Find yours →Vetted consultants and tools, matched to your size and sector.
Browse partners →DPDP Compliance Certification is an independent mark that shows customers, partners and regulators your organisation meets the Act's requirements, not just claims to.
From "are we even compliant?" to a mark you can show, in four steps.
Take the free readiness check and see your gaps.
Follow your prioritised roadmap to close them.
Have your controls and evidence reviewed.
Earn your certification and renew as you grow.
Plain-language guides and updates on the DPDP Act.
How the government designates a Significant Data Fiduciary, the extra Section 10 duties (India-based DPO, independent auditor, DPIAs) and how to…
Read guide →What counts as a personal data breach under the DPDP Act, who you must notify and how fast, the penalty band, and a first-hours…
Read guide →What a DPDP Act Section 5 consent notice must contain under Rule 3, the plain-language standard, and a copy-paste skeleton you can…
Read guide →A plain-English, 10-point DPDP Act checklist for Indian websites and startups, ordered by the penalty exposure each item…
Read guide →Short, cite-able answers to what people ask most.