Free brief for fintech teams
Two pages on the duties that matter first, the dates that apply, and five questions to test your readiness.
Free. Two pages. Request it below and we will email it to you.
Last updated
Fintechs are most exposed on five duties under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: security safeguards, breach notice, notice and consent, vendor control and children’s data. Security failures carry the highest maximum penalty, up to ₹250 crore, and most Rules duties apply from 13 May 2027.
Tell us where to send it. We review each request and email the brief to you personally.


An independent resource. Not affiliated with or endorsed by these bodies.
Thank you. We review each request and will email your brief to the address you gave.
A member of our team may also call you on the number you gave.
This brief is written for teams that have to comply, so we keep it for them. If you are learning or researching, start with our free DPDP guides and the Act explained in plain language.
Written for compliance, product and engineering leads at:
Fill in the short form on this page with your name, work email, company and role. We review each request and email the two-page PDF to you.
The DPDP Rules, 2025 were notified on 13 November 2025. Rules 1, 2 and 17 to 21 applied from publication. Rule 4, which covers Consent Managers, applies from 13 November 2026. Most other duties, including notice, security safeguards, breach notice, retention and Significant Data Fiduciary duties, apply from 13 May 2027.
The Schedule to the Digital Personal Data Protection Act, 2023 sets maximum penalties, imposed after a Data Protection Board inquiry. The highest is up to ₹250 crore for failing to take reasonable security safeguards. Failing to notify a personal data breach, or breaching the duties on children’s data, carries up to ₹200 crore each. Significant Data Fiduciary duties carry up to ₹150 crore, and other provisions up to ₹50 crore.
Under Rule 7, tell each affected person and the Data Protection Board without delay. Then send the Board a detailed report within 72 hours, or within a longer period the Board allows.
No. Section 38 says the Act applies in addition to other laws, and prevails only to the extent of a conflict. RBI directions and the DPDP Act both apply, so a fintech has to meet both.
A Significant Data Fiduciary is notified by the government, which weighs the volume and sensitivity of the personal data processed, the risk to people’s rights and other factors. As of 5 October 2026 we found no notification designating one, so check the current position. A notified fintech needs a Data Protection Officer based in India, an independent data auditor, and an annual impact assessment and audit under Rule 13.
No. The brief is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Please take advice on your own situation.
Take the DPDP Readiness Assessment to see which of these duties you are ready for and where the gaps are.
Take the readiness assessmentPrefer to talk it through? Write to us and a member of our team will get back to you.
For information only, not legal advice. Please take advice on your own situation.
Sources: Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025 (Ministry of Electronics and Information Technology).
Consultant-led and partner-backed.