If you are trying to work out what your organisation actually has to do and by when, the deadlines and the obligation list are below, along with the contract clauses most companies have not yet added.
DPDP Act compliance means meeting the obligations of the Digital Personal Data Protection Act, 2023 as operationalised by the DPDP Rules, 2025, notified in November 2025. Implementation is phased. The Data Protection Board of India is already functioning, Consent Manager registration opens in November 2026, and the substantive obligations together with penalties of up to Rs 250 crore take effect in May 2027.
Key points
- Three dates matter: November 2025 (Board established), November 2026 (Consent Manager registration), May 2027 (full obligations and penalties).
- Penalties reach Rs 250 crore per violation category and stack, so a single incident can produce cumulative exposure across several heads.
- Rule 6 requires written contracts with every data processor. An EY survey found more than 81 percent of organisations had not updated or drafted DPDP-aligned contracts.
- The Act applies extraterritorially where personal data of individuals in India is processed in connection with offering goods or services to them.
- 2026 is the build year. Enforcement through this period is expected to focus on guidance rather than penalties, which is exactly why the work should happen now.
This guide covers the timeline, the obligations by role, the contract clauses Rule 6 requires, the breach notification rules, penalties, and a practical sequence for getting ready.
Download the free DPDP compliance checklist in Word or PDF. The phased timeline, a 46 point obligation tracker across four sections, a contract audit sheet, and a model data processing clause you can drop straight into vendor agreements.
What Is the DPDP Act and When Does It Apply?
The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023 and is India’s first comprehensive data protection legislation. It gives statutory effect to the right to informational privacy recognised by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), where a nine judge bench held privacy to be a fundamental right traceable to Articles 14, 19 and 21.
The Act applies to the processing of digital personal data within India, whether collected digitally or digitised afterwards. It also applies outside India where the processing relates to offering goods or services to individuals in India, which brings a large number of foreign companies within scope.
It does not apply to personal data made publicly available by the individual themselves, or by a person under a legal obligation to publish it, and it does not cover data processed for purely personal or domestic purposes.
Three roles run through the whole framework:
- Data Principal: the individual the data relates to.
- Data Fiduciary: whoever determines the purpose and means of processing. This is the party carrying most of the obligations.
- Data Processor: whoever processes data on behalf of a fiduciary. Processors have no direct statutory obligations, which is precisely why the contract matters.
The wider constitutional framework and the shape of Indian online privacy and security sit behind all of this, and the Act interacts with the developing law on personality rights and data protection where identity rather than mere information is at stake.
The DPDP Compliance Timeline
The Rules were notified in November 2025 with staggered commencement, so nothing happened all at once and a good deal has not happened yet.
| Basis | Date | What takes effect |
|---|---|---|
| Phase 1 | November 2025 | Data Protection Board of India constituted. Definitions and rule-making provisions in force. Penalty framework established |
| Phase 2 | November 2026 | Consent Manager registration regime opens. Interoperable platforms for individuals to give, review and withdraw consent |
| Phase 3 | May 2027 | Notice and consent obligations, security safeguards, data principal rights, breach notification, Significant Data Fiduciary duties, and penalties all bite |
Where that leaves you today. Consent Manager registration is a few months away. Full enforcement is roughly twenty one months away. Regulatory posture through 2026 is expected to be guidance and awareness rather than penalties, which is why this is the build year rather than a period to wait out.
The transition period exists because compliance is not a document exercise. It requires knowing what data you hold, why you hold it, who you share it with and how you delete it, and most organisations do not currently know.
What Must a Data Fiduciary Actually Do?
Ten obligations. The first four are where most programmes start.
Give notice in clear language
Every data fiduciary must issue a notice, separate from any other document, explaining the specific personal data being collected, the purpose of processing, how the individual may exercise their rights, and how to complain to the Board. It must be available in English and in the languages listed in the Eighth Schedule to the Constitution.
Burying this in terms of service does not satisfy the requirement. The notice must stand alone and be intelligible.
Obtain free, specific, informed consent
Consent must be a clear affirmative action, limited to the data necessary for the stated purpose. Bundled consent, pre-ticked boxes and consent obtained as a condition of unrelated service do not work.
Certain processing may proceed on legitimate uses rather than consent, including where the individual voluntarily provides data for a specific purpose, employment purposes, medical emergencies and specified State functions. The position on regulating AI in India remains separate and less settled, which matters where automated processing is involved.
Enable withdrawal of consent
Withdrawal must be as easy as giving consent. Once withdrawn, processing must stop and the data must be erased unless retention is legally required.
Honour data principal rights
Individuals have the right to access a summary of their data and the identities of those it has been shared with, to correction and completion, to erasure, and to grievance redressal. Build a request handling process before the requests arrive.
Implement reasonable security safeguards
Encryption, access controls, logging and monitoring, and measures to detect and address breaches. The Rules expect these to be demonstrable rather than asserted.
Notify breaches
Notification to affected individuals and to the Data Protection Board, on the timelines the Rules prescribe. Build the detection and escalation path now, because the window is short and a process invented during an incident will fail.
Delete data when the purpose is served
Retention only for as long as necessary. This requires automated deletion workflows in most organisations, and it is the obligation most often postponed because it is genuinely difficult.
Protect children’s data
Verifiable parental consent for anyone under eighteen, and a prohibition on tracking, behavioural monitoring and targeted advertising directed at children.
Appoint the right people
Significant Data Fiduciaries, designated by the government on volume and risk criteria, must appoint a Data Protection Officer based in India, conduct periodic Data Protection Impact Assessments and independent audits. Every fiduciary must publish contact details for grievances.
Contract properly with processors
Covered in the next section, because it is the obligation lawyers own and the one least addressed.
The Part Nobody Is Doing: DPDP Is a Contract Problem
This is where the compliance gap is widest and where legal teams add the most value.
The Rules require a data fiduciary to engage a data processor only under a valid contract. A processor has no direct statutory obligations under the Act. The entire mechanism for controlling processor behaviour is contractual. If the contract is silent, the fiduciary carries the risk and has no recourse.
An EY survey of more than 150 professionals found that over 81 percent had not updated or drafted DPDP-aligned contracts, and close to 70 percent were not very familiar with the Act and Rules. The obligation is clear, the deadline is fixed, and the work has largely not started.
What every processor contract now needs
- Purpose limitation. The processor may process only on the fiduciary’s documented instructions and only for the stated purpose. This sits alongside the essential clauses every commercial contract must contain rather than replacing any of them.
- Security obligations. Specific safeguards rather than a general promise to be careful.
- Sub-processing controls. No sub-processor without prior written consent, and flow-down of equivalent obligations.
- Breach notification. The processor must notify the fiduciary without undue delay and within a period short enough for the fiduciary to meet its own deadline.
- Assistance with data principal rights. The processor must help the fiduciary respond to access, correction and erasure requests.
- Deletion or return on termination. With written confirmation.
- Audit rights. The fiduciary’s right to verify compliance.
- Termination consequences. What happens to the data on exit. A termination clause that states a right without addressing data return leaves the fiduciary exposed at the worst moment.
- Indemnity. For losses arising from the processor’s breach, including regulatory penalties. Note that a contract of indemnity creates primary liability, and this indemnity should sit outside any general liability cap or it is worthless against a penalty of this scale.
Which contracts need reviewing
Almost more than people expect:
- Vendor and supplier agreements where the vendor handles employee or customer data. The data protection clause in a vendor agreement is no longer optional.
- Consultancy and professional services agreements, since a consultancy agreement frequently involves access to personal data.
- SaaS and cloud contracts, which are usually on the provider’s paper and rarely DPDP aligned.
- Employment contracts, which involve processing employee data as a matter of course. Any employment agreement drafted before November 2025 predates the Rules entirely.
- Marketing and analytics agreements, the highest risk category and the most frequently overlooked.
- Confidentiality agreements, since confidentiality and data protection are different obligations. An NDA restricts disclosure, while DPDP governs processing, and one does not substitute for the other.
- AI tool subscriptions. Where staff paste client or employee data into a consumer AI tool, the organisation is transferring personal data to a third party, often outside India, frequently with no contract at all. The data privacy concerns with AI in law apply to every business function, not only to legal, and the broader framework of AI and law is developing faster than most internal policies.
The practical starting point is a contract audit. Work through the register, identify every agreement involving personal data, and triage. The discipline is the same as any contract review, with data protection added as a pass of its own, and the failures follow the familiar pattern of omissions rather than badly worded clauses.
What Are the Penalties Under the DPDP Act?
The Schedule to the Act sets maximum penalties by category of failure. The headline figure is up to Rs 250 crore, and the categories stack, so a single incident that involves both a security failure and a notification failure can attract penalties under both heads.
The Data Protection Board is a digital, quasi-judicial body that investigates complaints and imposes penalties. It is already constituted and operating. Organisations that have been through a POSH compliance exercise will recognise the shape of the obligation: a committee or officer, a written policy, records, and an annual rhythm.
Three points worth understanding about exposure:
- Penalties attach to the fiduciary, not the processor. Your vendor’s failure becomes your penalty, which is the whole argument for the indemnity clause above.
- The Board can act on complaint or on reference. A single disgruntled employee or customer can start the process.
- Cumulative exposure is the real risk, not the headline number. Modelling a worst case across several categories produces figures well beyond Rs 250 crore.
A Practical DPDP Compliance Sequence
Twenty one months sounds long and is not, because the first phase takes longer than anyone budgets for.
Months 1 to 3: Know what you hold
Build a data inventory. What personal data does the organisation hold, where does it sit, why was it collected, who has access, who is it shared with, and how long is it kept?
Most organisations discover at this stage that they do not know, and that the answer differs by team. This phase cannot be shortened by buying software.
Months 4 to 9: Fix the paperwork
Privacy notice, consent architecture, retention schedule, breach response plan, and the processor contract programme. This is the phase legal teams own.
Months 10 to 15: Build the systems
Consent capture and withdrawal, data principal request handling, automated deletion, access controls, logging.
Months 16 to 21: Test
Run a simulated breach. Run a simulated access request. Find out what fails while failure is still cheap.
Learning to Advise on DPDP Compliance
DPDP work is unusual in that most of it is not privacy law. It is data mapping, process design and contract drafting, and the contract drafting is the part that falls squarely on lawyers.
That is also where the commercial opportunity sits for anyone building a practice. Thousands of Indian companies have twenty one months to update every agreement under which a third party touches personal data, and more than eight in ten have not started. The work is drafting processor clauses, allocating liability, and negotiating with vendors whose standard terms predate the Rules entirely. Anyone who can do that competently will not be short of instructions, which is one reason technology law has become a serious career path rather than a niche.
Doing it well requires the same instinct as any commercial drafting: work out what breaks, then draft for it. That is the substance of the basic principles of legal drafting applied to a new statute, and it builds on the foundation in contract drafting, where the recurring lesson is that the clause nobody negotiated is the clause that decides the outcome.
LawMento’s Practical Training in Drafting of Contracts covers vendor, consultancy and services agreements and the risk allocation clauses that DPDP compliance now depends on, across 30+ contract types and 26 hours of instruction.
DPDP Act Compliance FAQs
When does the DPDP Act come into force?
In phases. The Data Protection Board was constituted in November 2025, Consent Manager registration opens in November 2026, and the substantive obligations together with penalties take effect in May 2027.
Who does the DPDP Act apply to?
Any person processing digital personal data in India, and any person outside India processing personal data of individuals in India in connection with offering goods or services to them. It does not cover purely personal or domestic processing, or data the individual has made publicly available.
What is the difference between a data fiduciary and a data processor?
A data fiduciary determines the purpose and means of processing and carries the statutory obligations. A processor processes on the fiduciary’s behalf and has no direct statutory duties, which is why its obligations must be imposed by contract.
What is the maximum penalty under the DPDP Act?
Up to Rs 250 crore, set by category of failure in the Schedule to the Act. Categories stack, so a single incident can attract penalties under more than one head.
Do we need a Data Protection Officer?
Significant Data Fiduciaries, designated by the government on volume and risk criteria, must appoint a DPO based in India. Other fiduciaries must publish contact details for grievance redressal but are not required to appoint a DPO.
Does the DPDP Act require consent for employee data?
Not always. Processing for employment purposes is among the legitimate uses that may proceed without consent, though notice and security obligations still apply. Employment contracts and HR processes still need review.
What contracts need updating for DPDP compliance?
Every agreement under which a third party handles personal data on your behalf. Vendor and supplier contracts, SaaS and cloud agreements, consultancy agreements, marketing and analytics contracts, and employment contracts.
Is the DPDP Act the same as the GDPR?
No. The structure is similar but the DPDP Act is narrower in several respects, has different lawful bases, does not contain an express right to data portability or a right to be forgotten in the GDPR sense, and provides broader State exemptions.
This guide describes the general framework and is not legal advice on any specific organisation’s obligations. The DPDP Rules are being implemented in phases and guidance continues to develop. Verify the current position and take advice on your own facts before relying on any compliance position.




