QUICK ANSWER: The Digital Personal Data Protection Act, 2023, backed by DPDP Rules notified in November 2025, requires organisations processing personal data in India to implement consent mechanisms, publish plain language privacy notices, respond to data principal rights within 90 days, and report breaches within 72 hours. Full enforcement begins May 13, 2027. Penalties reach Rs. 250 crore. IndiSec Privacy Edge provides end-to-end DPDP compliance support.
What DPDP Compliance Actually Requires in 2026
The DPDP Act is not waiting for May 2027 to be relevant. The Data Protection Board was established in November 2025. Phase 2 of the DPDP Rules, beginning November 2026, brings Consent Manager registration and Significant Data Fiduciary obligations into force. The enforcement clock has started.
Building a consent framework, training teams, establishing breach response procedures, and mapping data flows takes time. Organisations that engage now will be structurally ready for May 2027. Those that wait until the final months will be scrambling. IndiSec Privacy Edge has been helping organisations navigate DPDP compliance since the Rules were notified in November 2025.
The Core Obligations
Consent as the Starting Point
Section 6 of the DPDP Act makes explicit, informed, and specific consent the primary legal basis for processing personal data. The consent request must be accompanied by a privacy notice in plain language explaining what data is collected, the purpose, and how individuals can withdraw consent and exercise their rights.
Withdrawal of consent must be as easy as giving it. Privacy notices must be available in English or any of the 22 languages listed in the Eighth Schedule. Organisations with pre-ticked boxes, vague purpose descriptions, or no functional withdrawal mechanism need to rebuild their consent flows before enforcement begins.
Data Principal Rights: The 90-Day Window
Every individual whose data is processed has the right to access what data is held, correct inaccuracies, request erasure once the purpose is served, withdraw consent, and raise a grievance. Organisations must respond within 90 days. which is the ceiling prescribed under Rule 14 of the DPDP Rules, 2025. Where a data principal is not satisfied, they can escalate to the Data Protection Board.
Building a functioning rights management process means creating a clear intake mechanism, a documented review and response procedure, and a system for tracking requests against the deadline. Organisations with no process for handling these requests when enforcement begins face both regulatory and reputational consequences.
Breach Notification: The 72-Hour Standard
Any personal data breach must be reported to the Data Protection Board and affected data principals. The operational standard is 72 hours from discovery. The penalty for failure to notify is up to Rs. 200 crore. Prompt notification also limits reputational damage in ways that delayed notification cannot.
A breach response programme requires detection capability, a trained response team, and a tested notification process. None of this can be built after a breach has already occurred.
Children’s Data
Processing personal data of anyone under 18 requires verifiable parental consent before collection. Age verification must be implemented before collecting any data from minors. Targeted advertising directed at children is prohibited entirely. The penalty for non-compliance is up to Rs. 200 crore per incident.
Significant Data Fiduciary Obligations
Organisations processing large volumes of personal data may be designated Significant Data Fiduciaries. SDF designation requires appointing a Data Protection Officer based in India, conducting annual DPIAs, and commissioning independent audits. Failure to meet SDF obligations attracts penalties of up to Rs. 150 crore. The criteria for designation have not been fully specified, meaning organisations processing high volumes should be preparing as if designation is possible.
The Penalty Framework
| Violation | Maximum Penalty |
| Failure to implement reasonable security safeguards | Rs. 250 crore |
| Failure to notify a personal data breach | Rs. 200 crore |
| Non-compliance with children’s data obligations | Rs. 200 crore |
| Breach of Significant Data Fiduciary obligations | Rs. 150 crore |
| Failure to honour data principal rights | Rs. 50 crore |
What Genuine DPDP Compliance Looks Like
Organisations building genuine DPDP compliance are starting with a data inventory to understand what personal data they hold. They are rebuilding consent mechanisms to meet the Act’s specificity and withdrawal requirements. They are establishing breach response procedures and testing them. They are reviewing vendor contracts against DPDP obligations.
Organisations treating this as a documentation exercise, updating privacy policies without changing underlying practices, are taking on regulatory risk that will materialise when the Data Protection Board begins enforcement in 2027. IndiSec Privacy Edge provides end-to-end DPDP compliance support from data inventory and gap assessment through consent framework design, breach response programme development, Virtual DPO services, and ongoing regulatory monitoring.
Frequently Asked Questions
Does the DPDP Act apply to foreign companies with Indian customers?
Yes. The Act has extraterritorial reach. It applies to any organisation processing personal data of individuals in India in connection with offering goods or services to them, regardless of where the organisation is based.
What is a Consent Manager under the DPDP Act?
A Consent Manager is an entity registered with the Data Protection Board that provides individuals a single platform to give, manage, and withdraw consent across multiple data fiduciaries. Consent Manager registration opens in November 2026 under Phase 2 of the DPDP Rules.
What is a DPIA and when is it required?
A Data Protection Impact Assessment is a structured assessment of privacy risks associated with a specific data processing activity. Annual DPIAs are mandatory for Significant Data Fiduciaries. For other organisations, DPIAs are best practice for high-risk processing activities.
What is the timeline for full DPDP enforcement?
Phase 1, November 2025: Data Protection Board established. Phase 2, November 2026: Consent Manager registration and SDF obligations including DPO requirement. Phase 3, May 13, 2027: All substantive obligations fully enforceable with penalties applying.
How can IndiSec help with DPDP compliance?
IndiSec Privacy Edge provides data inventory and gap assessment, consent framework design, privacy notice drafting, breach response programme development, Virtual DPO services, DPIA support, and ongoing regulatory monitoring. Contact IndiSec at business@indisec.com or +91 9311246497
IndiSec Privacy Edge | 207, Nilgiri Apartments, Barakhamba Road, New Delhi | business@indisec.com | +91 98100 22887

