dpdpactindia.in

Category: Guides

  • DPDP compliance checklist for Indian businesses (2026)

    Share this article

    DPDP compliance checklist for Indian businesses (2026)

    A plain-English, 10-point DPDP Act checklist for Indian websites and startups, ordered by the penalty exposure each item closes, with the deadline that matters.

    If you run an Indian business that collects any personal data, even just names and emails through a contact form, the Digital Personal Data Protection Act, 2023 applies to you. This checklist turns the Act into a short list of things to actually do, ordered by how much penalty exposure each one closes. It is the same ground the free readiness assessment walks you through, in list form.

    The 10-point DPDP checklist

    Where to start

    Do not try to do all ten at once. Start with the two that carry the highest penalty band, security safeguards and breach reporting sit against the ₹250 crore ceiling, and the two that are cheapest to fix, the notice and the grievance officer. That order gives you the largest risk reduction for the least effort.

    The deadline

    The DPDP Rules, 2025 were notified in November 2025 with an 18-month rollout, so most organisations are planning to be defensible by 13 May 2027. That is runway, not a reason to wait, see Section 1 on how the Act commences in stages.

    Frequently asked questions

    Does the DPDP Act apply to a small Indian startup?
    Yes. The Act applies to any Data Fiduciary processing personal data in India, regardless of size or revenue. There is no small-business exemption in the penalty schedule.
    What is the DPDP compliance deadline?
    Most organisations are planning around 13 May 2027, based on the 18-month rollout that followed the November 2025 notification of the Rules.
    What should I fix first?
    Start with security safeguards and breach response (highest penalty band) plus the notice and grievance officer (cheapest to close).

    Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.

  • How to write a DPDP-compliant privacy notice (Section 5 and Rule 3)

    Share this article

    How to write a DPDP-compliant privacy notice (Section 5 and Rule 3)

    What a DPDP Act Section 5 consent notice must contain under Rule 3, the plain-language standard, and a copy-paste skeleton you can adapt for your Indian website.

    Under Section 5 of the DPDP Act, before or when you collect someone's personal data you must give them a clear notice. It is separate from your long privacy policy, and it is one of the cheapest, highest-value things you can fix. Here is what it must contain and a skeleton you can adapt.

    What a Section 5 notice must include

    Rule 3 of the DPDP Rules, 2025 itemises the mandatory parts: the categories of personal data collected, the specific purpose for each, how to withdraw consent, how to exercise rights, the grievance officer contact, and the right to complain to the Data Protection Board. Plain language is itself a requirement, not a nicety.

    A skeleton you can adapt

    Section 5 notice skeleton
    PRIVACY NOTICE: [Your Organisation]
    Issued under Section 5, DPDP Act 2023 and Rule 3, DPDP Rules 2025.
    
    1. WHAT WE COLLECT: [list the categories of personal data].
    2. WHY: [state each specific purpose].
    3. HOW TO WITHDRAW CONSENT: [link/email, as easy as giving it].
    4. YOUR RIGHTS: access, correction, erasure, nomination, grievance.
    5. GRIEVANCE OFFICER: [name], [email], response within 30 days.
    6. COMPLAIN TO THE BOARD: you may escalate to the Data Protection Board.

    Swap the brackets for your real details, keep it in plain language, and serve it at the point of collection, not buried three clicks deep. When you are ready to build the full version, the build-a-consent-notice workflow walks through it step by step.

    Common mistakes

    • Relying on the long privacy policy instead of a notice at the point of collection.
    • Listing vague purposes like "business purposes" instead of specific ones.
    • No withdrawal path, or one that is harder than giving consent.
    • No named grievance officer or response timeline.

    Frequently asked questions

    Is a Section 5 notice the same as my privacy policy?
    No. The DPDP notice is served at the moment of collection and lists categories, purposes, withdrawal, rights and grievance contact. Your longer privacy policy complements it.
    What must the notice contain?
    Per Rule 3: data categories, specific purpose for each, how to withdraw consent, how to exercise rights, the grievance officer contact, and the right to complain to the Data Protection Board, in plain language.
    Does this replace legal review?
    No. The skeleton is a starting point. Have a qualified lawyer review it, especially if you are a Significant Data Fiduciary or in a regulated sector.

    Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.

  • The DPDP data breach notification rule, explained (Section 8, Rule 7)

    Share this article

    The DPDP data breach notification rule, explained (Section 8, Rule 7)

    What counts as a personal data breach under the DPDP Act, who you must notify and how fast, the ₹200 crore penalty band, and a first-hours response checklist.

    A personal data breach under the DPDP Act is not only a hack, it includes any unauthorised access, disclosure, or loss of personal data. Section 8 obligations and Rule 7 of the DPDP Rules, 2025 require you to notify both the affected people and the Data Protection Board, and there is a tight reporting window. Here is the shape of a plan that meets it.

    What the rule requires

    On becoming aware of a breach, a Data Fiduciary must inform each affected Data Principal in plain language, what happened, likely consequences, and what you are doing, and report to the Board, with a detailed follow-up report inside the prescribed window. The penalty band for failing to report a breach reaches ₹200 crore, which is why this is a board-level plan, not an afterthought.

    A first-hours checklist

    Breach response, first hours
    BREACH RESPONSE: first hours
    [ ] Detect & contain; freeze affected systems.
    [ ] Assess scope: what data, how many principals.
    [ ] Notify each affected Data Principal (plain language).
    [ ] Notify the Data Protection Board without delay.
    [ ] File the detailed report within the required window.
    [ ] Log everything: timeline, decisions, comms.

    The single biggest determinant of how a breach goes is whether this plan existed before the breach. Write it, name an owner, and rehearse it once. The report-a-data-breach workflow has the full sequence.

    What good preparation looks like

    • A named incident owner and an escalation path.
    • Pre-drafted notification templates for principals and the Board.
    • Logging that lets you reconstruct the timeline afterwards.

    Frequently asked questions

    What counts as a data breach under DPDP?
    Any unauthorised processing, accidental disclosure, acquisition, sharing, loss, or destruction of personal data that compromises its confidentiality, integrity, or availability.
    Who do I have to notify?
    Both the affected Data Principals, in plain language, and the Data Protection Board, with a detailed report within the prescribed window under Rule 7.
    What is the penalty for not reporting a breach?
    The Schedule to the Act sets a maximum penalty of up to ₹200 crore for failure to notify a personal data breach.

    Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.

  • Significant Data Fiduciary under the DPDP Act: who qualifies and what changes (Section 10)

    Share this article

    Significant Data Fiduciary under the DPDP Act: who qualifies and what changes (Section 10)

    How the government designates a Significant Data Fiduciary, the extra Section 10 duties (India-based DPO, independent auditor, DPIAs) and how to prepare if you might qualify.

    Most organisations under the DPDP Act are ordinary Data Fiduciaries. A smaller group carries a heavier set of duties: Significant Data Fiduciaries (SDFs). If you might be one, the extra obligations change your compliance plan materially, so it is worth knowing early.

    Who becomes an SDF

    The Central Government notifies a Data Fiduciary, or a class of them, as significant based on factors set out in Section 10: the volume and sensitivity of personal data processed, the risk to Data Principals, potential effects on the sovereignty and integrity of India, risks to electoral democracy, and security of the state. There is no single number, it is a risk-and-impact judgement the government makes.

    What changes if you are one

    What to do if you might qualify

    If your data volume is large or you handle sensitive categories, plan as if you may be notified: the DPO and audit functions take time to stand up. The readiness assessment flags the SDF track when your answers suggest it, and a DPO or consultant can help you build the governance layer.

    Frequently asked questions

    Who decides if I am a Significant Data Fiduciary?
    The Central Government notifies a Data Fiduciary or class as significant, based on Section 10 factors like data volume and sensitivity, risk to principals, and effects on state security and electoral democracy.
    What extra duties does an SDF have?
    An India-based Data Protection Officer, an independent Data Auditor, and periodic Data Protection Impact Assessments and audits, plus any further measures the government prescribes.
    Is there a fixed data-volume threshold?
    No single published number. It is a risk-and-impact assessment, so organisations with large volumes or sensitive data should prepare in case they are notified.

    Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.