Skip to content
SecuriFii

Regulation · India

Is the DPDP Act in force? What applies today, and the deadline that matters

If you arrived here after seeing a headline about ₹250 crore fines, the short answer is that you are not late — yet. India’s Digital Personal Data Protection Act is in force, its enforcement body exists, and almost none of the duties it places on your organisation are enforceable until 13 May 2027. That is a real runway, and it is shorter than it sounds.

Facts checked2026-09-11

The dates that actually matter

DateWhat changesStatus today
13 Nov 2025DPDP Rules notified. Definitions and the provisions constituting the Data Protection Board take effect.In force
13 Nov 2026Rule 4 — Consent Manager registration opens. This is a registration framework, not a compliance deadline for you.Pending
13 May 2027Notice, consent, security safeguards, breach reporting, data principal rights, children’s data and Significant Data Fiduciary duties become enforceable.The deadline

Verified against the notified Rules. Phase dates have moved before; re-check before relying on them for a board paper.

Is the DPDP Act in force?

Yes and no, and the distinction is the whole point. The Digital Personal Data Protection Act, 2023 received assent in August 2023 and is law. The Digital Personal Data Protection Rules were notified on 13 November 2025, which switched on the Act’s machinery — the definitions, and the provisions that allow the Data Protection Board of India to be constituted.

What has not switched on is the part that asks anything of you. Notice and consent, security safeguards, breach reporting, data principal rights, children’s data and the additional duties of Significant Data Fiduciaries commence on 13 May 2027, eighteen months after the Rules were notified. Nobody has been fined, because the obligations those fines attach to are not yet enforceable.

So if a vendor is telling you that you are already in breach, they are selling something. The honest position today is that you have a deadline and a runway.

What are the penalties under the DPDP Act?

The Schedule to the Act sets maximum penalties per violation, and they are large enough to explain why this is on your board’s agenda: up to ₹250 crore for failing to implement reasonable security safeguards, up to ₹200 crore for failing to notify a personal data breach to the Board and to affected individuals, and up to ₹200 crore for breaching the special provisions on children’s data.

These are ceilings rather than tariffs, and they are per violation — a single inquiry finding a security failure, an unreported breach and a consent problem can attach separate penalties to each. The Board is directed to consider the nature and gravity of the breach, the harm caused, whether it was repetitive, and what the organisation did about it.

That last factor is the one worth designing for. Self-disclosure, prompt remediation and a documented compliance programme are mitigating circumstances the Board weighs when it fixes an amount. The practical consequence is that the records you build before an incident are also what reduces your exposure after one.

Does it apply to us? Almost certainly yes

The Act reaches any organisation processing digital personal data in connection with offering goods or services in India, and it reaches processing outside India that relates to offering goods or services to people in India. There is no blanket exemption for small companies, no turnover threshold, and no carve-out for B2B — your own employees’ data is personal data.

The one threshold that does exist works the other way. A Significant Data Fiduciary is designated by the Central Government on the basis of factors including volume and sensitivity of data processed and risk to data principals, and carries extra duties: an India-based Data Protection Officer, an independent data auditor, and periodic Data Protection Impact Assessments. Most organisations will not be designated; all organisations are still in scope.

Why 13 May 2027 is closer than it reads

The obligations landing in 2027 are not ones you can implement in a quarter, and the sequence matters more than the start date.

A record of processing requires knowing where personal data actually lives — which, in most organisations, is a discovery project before it is a compliance one. Personal data accumulates in support tools, analytics, log files, spreadsheets and backups, and the first honest inventory is usually a surprise. Consent notice and withdrawal mechanics are product work with a release cycle attached, and they cannot be specified until the mapping is done. Breach reporting requires detection you may not currently have.

One provision deserves early attention because it can change what you build rather than how you document it: India sets the age of a child at eighteen and requires verifiable parental consent for their data. That is materially higher than most regimes, and if any part of your user base is under eighteen it is a product decision, not a policy one.

What to do in 2026

Map the personal data first. Nothing downstream — notice, consent, retention, rights handling, breach reporting — can be specified correctly until you know what you hold, where it came from, who it is shared with and where it goes. This is the long pole and it is almost always underestimated.

Second, determine controller and processor roles per processing activity. Most organisations are both, for different data, at the same time, and the role decides who owes what. Third, and only then, build the notice and consent mechanics — because the first two change what they have to say.

If you are already heading towards ISO/IEC 27701, most of this is the same work. A privacy information management system produces the records of processing, the rights-handling process and the retention decisions the Act will ask for, in a form an auditor already recognises. It is not a finding of compliance with the DPDP Act — no certificate is, and a legal question is answered against the law rather than against a standard — but it is the difference between demonstrating compliance and excavating it.

Common questions

Is the DPDP Act enforceable right now?

The Act is in force and the Data Protection Board can be constituted, but the obligations it places on organisations — notice, consent, security safeguards, breach reporting, data principal rights — become enforceable on 13 May 2027. No penalties have been levied to date.

What is the DPDP Act compliance deadline?

13 May 2027, eighteen months after the DPDP Rules were notified on 13 November 2025. The intermediate date of 13 November 2026 opens Consent Manager registration and is not a compliance deadline for data fiduciaries.

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore for failing to implement reasonable security safeguards. Failure to notify a personal data breach and breaches of the children’s data provisions each carry up to ₹200 crore. Penalties are per violation, so a single inquiry can attach more than one.

Does the DPDP Act apply to small companies and startups?

Yes. There is no turnover or headcount threshold and no blanket small-business exemption. Any organisation processing digital personal data while offering goods or services in India is in scope, including for its own employee data.

Do we need a Data Protection Officer?

Only if you are designated a Significant Data Fiduciary by the Central Government, in which case the DPO must be based in India and answerable to the board or equivalent. Other organisations must still publish a contact for answering data principals’ questions.

Does ISO 27701 make us DPDP compliant?

No certificate makes you compliant with a statute — that is a legal question decided against the law. ISO/IEC 27701 builds the records of processing, rights-handling process and retention decisions the Act requires, which makes demonstrating compliance straightforward rather than archaeological.

The bottom line

You are not late. The obligations commence on 13 May 2027 and penalties reach ₹250 crore per violation. Spend 2026 mapping where personal data actually lives — every other decision depends on it, and it is the one part that cannot be compressed into the final quarter.

Related insights