Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Free brief for fintech teams

Where fintech teams are most exposed under the DPDP Act

Two pages on the duties that matter first, the dates that apply, and five questions to test your readiness.

Request the brief

Free. Two pages. Request it below and we will email it to you.

Last updated

Three figures to know

  • 13 May 2027Most DPDP Rules duties apply from this date
  • ₹250 croreMaximum penalty for failing security safeguards
  • 72 hoursTo file a detailed breach report with the Board

The short answer

Fintechs are most exposed on five duties under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: security safeguards, breach notice, notice and consent, vendor control and children’s data. Security failures carry the highest maximum penalty, up to ₹250 crore, and most Rules duties apply from 13 May 2027.

What is inside the brief

  • The dates that applyRules notified on 13 November 2025, Consent Manager rules from 13 November 2026, and most other duties from 13 May 2027.
  • Five places fintechs are most exposedSecurity safeguards, breach notice, notice and consent, vendors, and children’s data, each with its maximum penalty.
  • How the Act sits alongside RBI rulesSection 38 on overlap with other laws, and the Section 8(7) retention rule.
  • Significant Data FiduciariesWhat changes if the government notifies a fintech.
  • Five self-check questions and a first 90 daysA short test of your readiness and a plan to close the gaps.

Request the brief

Tell us where to send it. We review each request and email the brief to you personally.

Blurred preview of page 1 of the Fintech DPDP Act Exposure Brief: title, key figures and the five exposure points
Blurred preview of page 2 of the brief: RBI overlap, Significant Data Fiduciaries, five self-check questions and a 90-day plan
Request the brief to read both pages
Page 1 covers the dates and the five exposure points. Page 2 covers RBI overlap, Significant Data Fiduciaries, five self-check questions and a first 90 days.
  • Two A4 pages in plain language
  • The five duties with their maximum penalties
  • Five questions to test your readiness
  • A suggested first 90 days
Which best describes you?
Team size (optional)

Want to talk it through? A person from our team may call to walk you through your brief.

Who it is for

Written for compliance, product and engineering leads at:

  • LendersLoan files hold identity, income and bank data. Security safeguards and breach notice apply to all of it.
  • Payment companiesTransaction trails that link to a person are personal data, and each partner needs clear processor terms.
  • KYC providersYou are often a processor. The fintech that hires you stays responsible, so contracts must cover security and deletion.
  • InsurtechsPolicy and claims files hold a lot of personal detail. Every partner you share them with needs a clear contract.
  • Wealth platformsInvestor profiles and holdings call for strong access controls and a record of what each person agreed to.

Frequently asked questions

How do I get the Fintech DPDP Act Exposure Brief?

Fill in the short form on this page with your name, work email, company and role. We review each request and email the two-page PDF to you.

When do the DPDP Rules apply to fintechs?

The DPDP Rules, 2025 were notified on 13 November 2025. Rules 1, 2 and 17 to 21 applied from publication. Rule 4, which covers Consent Managers, applies from 13 November 2026. Most other duties, including notice, security safeguards, breach notice, retention and Significant Data Fiduciary duties, apply from 13 May 2027.

What is the maximum penalty for a fintech under the DPDP Act?

The Schedule to the Digital Personal Data Protection Act, 2023 sets maximum penalties, imposed after a Data Protection Board inquiry. The highest is up to ₹250 crore for failing to take reasonable security safeguards. Failing to notify a personal data breach, or breaching the duties on children’s data, carries up to ₹200 crore each. Significant Data Fiduciary duties carry up to ₹150 crore, and other provisions up to ₹50 crore.

How quickly must a fintech report a personal data breach?

Under Rule 7, tell each affected person and the Data Protection Board without delay. Then send the Board a detailed report within 72 hours, or within a longer period the Board allows.

Does the DPDP Act replace RBI rules for fintechs?

No. Section 38 says the Act applies in addition to other laws, and prevails only to the extent of a conflict. RBI directions and the DPDP Act both apply, so a fintech has to meet both.

Is my fintech a Significant Data Fiduciary?

A Significant Data Fiduciary is notified by the government, which weighs the volume and sensitivity of the personal data processed, the risk to people’s rights and other factors. As of 5 October 2026 we found no notification designating one, so check the current position. A notified fintech needs a Data Protection Officer based in India, an independent data auditor, and an annual impact assessment and audit under Rule 13.

Is this brief legal advice?

No. The brief is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Please take advice on your own situation.

Check where you stand

Take the DPDP Readiness Assessment to see which of these duties you are ready for and where the gaps are.

Take the readiness assessment

Prefer to talk it through? Write to us and a member of our team will get back to you.

For information only, not legal advice. Please take advice on your own situation.

Sources: Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025 (Ministry of Electronics and Information Technology).