Skip to content
Offer of the Day Free Billing Software with Company Registration. Valid today only Claim on WhatsApp
TaxhintAdvisors
Data protection · DPDP Act 2023

DPDP Compliance: Digital Personal Data Protection Act Readiness

DPDP compliance is the work of bringing how your business collects, stores and shares personal data in line with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The main obligations start on 13 May 2027, so the preparation window is open now. We map your data, draft the notices and policies, and prepare the paperwork.

Main duties from 13 May 2027Data mapping & gap reviewNotices, consent & policiesBreach response plan
5000+ businesses served10+ years of practice · Pan-India
Get a free consultationWe reply within one working day

What it is

The Digital Personal Data Protection Act, 2023 governs any digital personal data you handle in India, and data of people in India handled for offering them goods or services. If you decide why and how that data is used, the Act calls you a Data Fiduciary. The person the data is about is the Data Principal.

The Act gives the Data Principal rights and gives you duties. Ask for consent. Say what you collect and why. Keep the data safe, report breaches, and delete it when the purpose ends. The DPDP Rules, 2025 were notified on 13 November 2025 and fill in the detail. The Data Protection Board of India enforces both. A privacy policy page alone does not cover it. The duties reach your forms, vendors, HR files and customer records.

Who it applies to

Businesses that collect customer data

An online store, a clinic, a school, a lender or a coaching institute that takes names, phone numbers, addresses or ID details through forms, apps or a website.

Employers and service firms

Payroll files, attendance data, KYC copies and candidate CVs are personal data. A Faridabad manufacturer with 150 employees is a Data Fiduciary for every one of those files.

Companies that hand data to vendors

If a CRM provider, cloud host or marketing agency processes data for you, you stay responsible. You need a written contract with each processor and a clear idea of what they hold.

Why it matters

The penalties are large

The Schedule to the Act allows up to ₹250 crore for failing to keep reasonable security safeguards and up to ₹200 crore for failing to report a breach or for breaching duties about children’s data. Lesser breaches can still attract up to ₹50 crore.

Customers and partners now ask

Larger buyers and banks are adding data-protection clauses to contracts, and DPDP compliance is becoming a tender question. A clear notice, a consent record and a breach plan answer their questions quickly.

It forces tidy data habits

Mapping often turns up old files, unused tools and shared passwords. Fixing them cuts risk early.

Documents required

Information we need from you

  • List of systems, apps and forms that collect personal data
  • Vendors and processors that touch the data
  • Current privacy policy, terms and consent wording
  • Retention practice for customer and employee records

Business papers

  • Certificate of incorporation or registration
  • Website and app details
  • Standard contracts with customers, staff and vendors
  • Past incident or complaint history, if any

What we prepare

  • Data inventory and gap report
  • Privacy notice and consent text
  • Processor contract clauses
  • Breach response and rights-request procedures

Key dates under the DPDP Rules at a glance

DateWhat starts
13 November 2025Rules notified; Data Protection Board and definitions provisions in force
13 November 2026Consent Manager registration provisions
13 May 2027Core duties of Data Fiduciaries: notice, consent, security, breach reporting, rights, erasure

Your timeline is the May 2027 one unless you plan to register as a Consent Manager. We re-check the notified text when we begin your assignment.

How it works

1

Map the personal data you hold

We list every place personal data comes in, where it sits, who sees it and how long it stays. Say a Faridabad coaching centre keeps enquiry details in a shared sheet and a WhatsApp group: that is the first thing we trace.

2

Review the gap against the Act and Rules

We compare that map with the Act and Rules: notice, consent, security safeguards, breach reporting, children’s data and retention. You get a plain list of gaps, ranked by risk.

3

Draft the notices, consent wording and contracts

We write the privacy notice, consent text for your forms and apps, processor clauses and an internal data policy. They are drafted for your review and approval.

4

Set up breach and rights procedures

We prepare a breach response plan, a rights-request tracker and a grievance contact, so your team knows who does what on day one of an incident.

5

Keep it current each year

We diarise reviews, vendor changes and staff briefings, and fold them into your ongoing compliance calendar.

Timelines

13 May 2027: main duties begin

DPDP compliance is tested from this date: notice, consent, safeguards, breach reporting, rights and erasure all apply to Data Fiduciaries. Here is the catch: fixing vendor contracts takes months, so start mapping well before it.

72 hours: breach report to the Board

After a personal data breach, the Rules require an intimation to affected people without delay and a detailed report to the Board within 72 hours.

One year: logs

Processing logs and related personal data must be retained for at least one year for the purposes set out in the Rules.

What happens if you do not comply

Up to ₹250 crore

The ceiling for failing to take reasonable security safeguards when a breach follows. The Board sets the actual amount after an inquiry, so these are limits, not price tags.

Up to ₹200 crore

The maximum for not notifying the Board and affected people of a breach, or for breaching the duties on children’s data.

Up to ₹50 crore and more

Other violations of the Act or Rules carry up to ₹50 crore. Significant Data Fiduciaries who miss their extra duties face up to ₹150 crore.

Frequently asked questions

When do the DPDP Rules actually apply to my business?

Most duties start on 13 May 2027, which is 18 months after the Rules were notified on 13 November 2025. The Board provisions are already in force, and Consent Manager provisions begin on 13 November 2026. Unless you are a Consent Manager, May 2027 is your date. Use the months before it to map data and fix gaps, and the deadline stays comfortable.

Does a small business or startup have to comply?

Yes, the Act applies by what you do with personal data, not by your size. We check which provisions apply to your case. A small clinic or online seller that collects customer details is covered.

What is a Significant Data Fiduciary?

It is a Data Fiduciary the Central Government notifies because of the volume and sensitivity of data it handles, risk to people’s rights, or risk to the country’s security and public order. Such entities must appoint a Data Protection Officer based in India, get an independent data auditor and run periodic impact assessments.

Do I need a Data Protection Officer?

Only a Significant Data Fiduciary must appoint a Data Protection Officer. Every Data Fiduciary, however, must publish contact details of a person who can answer questions about processing, so people know where to complain. In practice, name one responsible person and put their details in your notice.

How fast must we report a data breach?

Tell affected people without delay, and send the Board a detailed report within 72 hours of becoming aware, as the Rules provide. Failing to report can cost up to ₹200 crore. A ready breach plan makes the 72 hours manageable.

What counts as valid consent under the Act?

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The notice must list the data collected and the purpose, and withdrawing consent must be as easy as giving it. Pre-ticked boxes do not meet that standard. We redraft your forms so each purpose gets its own choice.

Are there special rules for children’s data?

Yes. For anyone under 18, you need verifiable consent from a parent or lawful guardian before processing, and you cannot track, monitor behaviour or target advertising at children. Breaches of these duties can cost up to ₹200 crore, so schools and ed-tech firms should review early.

Do the IT Act rules on sensitive personal data still apply?

They continue until the DPDP provisions replacing Section 43A of the IT Act commence, expected with the May 2027 phase. Until then, the 2011 SPDI Rules, with their privacy policy and security requirements, stay in force. Aligning with the DPDP Act now means you are covered both before and after the switch.

What does Taxhint do, and what do I still need from IT?

We map data, review gaps, draft notices, consent wording, policies and contracts, and prepare breach and rights procedures. Technical controls such as encryption, access control and logging are set up by your IT team or vendor, and legal opinions or Board proceedings need a practising advocate. We coordinate all three so one plan covers the full job.

Pricing

What it costs

Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.

The Act does not charge a registration fee for ordinary Data Fiduciaries, so there is no government filing fee on this route. A Consent Manager must register with the Board, and the Rules set the fee and conditions for that route. Your cost is the effort of mapping, drafting and training. It grows with the number of systems and vendors you use, which is why a one-shop business and a 300-person firm get different quotes.

Ready to begin?

Tell us which systems collect personal data in your business, and we will give you a clear DPDP compliance gap list well before May 2027.