India’s privacy framework has moved from policy discussion to a fixed implementation schedule. The Digital Personal Data Protection Act received assent in 2023, and the final rules were notified in November 2025. For most businesses, 2026 is the year to prepare systems and processes before many key duties start on 13 May 2027. The Consent Manager provisions begin earlier, on 13 November 2026. The current position is explained in the EY DPDP guide, Which also covers how the Act and Rules affect organisations operating in India.
Waiting until 2027 creates a practical risk. Personal information may sit across customer platforms, HR tools, cloud systems, support applications, analytics platforms, and vendor environments. Mapping these systems takes time. So do changes to notices, consent flows, deletion rules, contracts, access controls, breach procedures, and security monitoring. DPDPA Compliance should therefore be treated as a business programme rather than a last-minute legal review. Calance’s Cybersecurity Services can support the technical side of this work through security assessment, monitoring, protection controls, and incident-response support.
The Digital Personal Data Protection Act applies to digital personal data processed in India when it was collected digitally or collected offline and later digitised. It may also apply to processing outside India when that activity is linked to offering goods or services to people in India. DPDPA 2023 can therefore affect Indian businesses as well as foreign companies serving Indian customers. The real question isn’t only where a company is registered. Businesses also need to know where personal information enters their systems, who uses it, which vendors receive it, why it is processed, and when it is removed.
TL;DR
The Digital Personal Data Protection Act is India’s central law governing digital personal data. It gives individuals rights over their information and places duties on organisations that decide why and how that information is processed. The DPDP Rules 2025 add operating detail around notices, consent, security safeguards, breaches, rights requests, children’s information, retention, Consent Managers, and Significant Data Fiduciaries. The official DPDP Rules 2025 are therefore a key reference for companies building their 2026 preparation plans.
Most major business duties don’t start until 13 May 2027, but that doesn’t make 2026 a waiting period. A company may need months to identify personal information, review processors, update privacy notices, change application workflows, create rights procedures, test deletion, improve security controls, and prepare for breach reporting. Data Protection Compliance in India depends on whether these requirements work inside real systems rather than whether a policy exists on paper.
Technology teams have a large role because many requirements depend on working system connections. A consent withdrawal may need to reach a CRM, marketing application, customer portal, and vendor platform. A correction request may affect several connected systems. Calance’s Integration Solutions cover APIs, authentication, access controls, encryption, logging, and system connections that can help companies pass privacy instructions between applications without relying on manual updates.
Businesses with GDPR programmes already have a useful starting point, but they shouldn’t assume that GDPR work automatically satisfies DPDPA Compliance. DPDPA 2023 uses different terminology, a different approach to certain lawful processing situations, a different child threshold, different penalty ceilings, and a different international-transfer framework. Existing policies and controls should therefore be mapped against Indian requirements one by one.
What Is the Digital Personal Data Protection Act?
The Digital Personal Data Protection Act is India’s law for processing digital personal data. It applies when personal information exists in digital form or when information collected offline is later digitised. The Act identifies the individual as the Data Principal and the organisation deciding why and how processing happens as the Data Fiduciary. A Data Processor handles information on behalf of a Data Fiduciary.
The Act applies to processing within India and can also reach some processing outside India when it is connected with offering goods or services to people in India. This means foreign SaaS providers, ecommerce businesses, mobile apps, consulting companies, online marketplaces, and other organisations may need to examine whether their Indian activities fall within scope. The IAPP scope analysis gives useful context on cross-border processing and how the Indian model differs from some global privacy frameworks.
Not every processing activity is treated in the same way. The law contains exemptions and specific situations where different rules may apply. Processing for personal or domestic purposes can fall outside the law. Certain activities connected with courts, legal claims, state functions, research, or other statutory cases can also receive special treatment where the legal conditions are met.
Data Protection Compliance in India should therefore begin with an activity-level review. Businesses need to identify what personal information they hold, where it comes from, why it is required, which systems hold it, who can access it, whether another organisation receives it, how long it remains available, and how it is removed. That creates the working foundation for every later decision.
The technical part becomes harder when information exists across many devices and platforms. Calance’s Endpoint Management Services cover device policies, endpoint protection, patch controls, Microsoft Intune, Defender for Endpoint, conditional access, and related controls. These measures can help businesses control which devices and users can reach systems that contain personal information.
Why 2026 Matters for DPDPA Compliance
The implementation dates are central to understanding DPDPA 2023. The government brought selected provisions into force in November 2025. Consent Manager provisions are scheduled to begin on 13 November 2026. Most business-facing duties follow on 13 May 2027. That creates a preparation period in which businesses can identify gaps and fix them before the main requirements start.
Companies shouldn’t confuse notification of the Rules with immediate application of every duty. The legal framework now exists, but many obligations follow the phased schedule. This distinction matters for board reporting, budgets, compliance plans, vendor work, and implementation projects. It also helps businesses avoid exaggerated statements that every requirement is already under full enforcement.
The penalty levels explain why preparation deserves attention. Government material on DPDP penalty provisions describes maximum statutory amounts including up to ₹250 crore for failure to take reasonable security safeguards and up to ₹200 crore for specified breach-notification failures. These figures are maximum ceilings rather than automatic fines for every incident.
The practical challenge is that security and privacy changes rarely happen in one department. Security teams may need new monitoring. Product teams may need to change consent screens. Procurement teams may need new processor clauses. HR may need to review employee information. Application owners may need to support correction and deletion. Each area has its own release schedules and dependencies.
Calance’s Managed Detection Services can support the security side by monitoring environments, investigating events, collecting security signals, and supporting incident response. Early detection matters because a company can’t meet a short reporting deadline if it takes days to discover or understand an incident.
Who Must Follow DPDPA 2023?
The Digital Personal Data Protection Act can affect companies of many sizes and sectors. Banks, software firms, retailers, employers, healthcare providers, manufacturers, professional-services companies, online platforms, insurers, and other organisations may process digital personal information. Size alone doesn’t decide whether the law applies. The type of processing and its connection with India matter more.
A useful first step is to create a processing inventory. It should state what information is collected, which Data Principal group it relates to, where it comes from, why the organisation needs it, where it is stored, who can use it, whether a processor receives it, where processing occurs, how long it is retained, and how deletion happens.
This inventory often reveals hidden copies. Information may exist in exported spreadsheets, testing systems, support tickets, CRM records, employee laptops, cloud backups, or analytics platforms. Those copies matter because a rights request or deletion request can fail if the business only updates the main application.
Cross-border flows require particular attention. A customer may enter information in India while the main application runs in a foreign cloud region. Support teams may operate from another country. Backups may sit elsewhere. Analytics vendors may process the same information again. The business should map the full path rather than stop at the first system.
The Digital Personal Data Protection Act gives the Central Government power to restrict transfers to specified countries or territories. Other Indian sector rules may also impose separate limits. Businesses in regulated industries should therefore check DPDPA Compliance together with requirements issued by bodies such as RBI, SEBI, IRDAI, or other regulators that apply to their sector.
What Roles and Consent Rules Matter?
The main statutory role is the Data Fiduciary. This is the organisation or person that decides why personal information will be processed and how that processing will happen. A Data Processor acts on behalf of the Data Fiduciary. A Data Principal is the person to whom the information relates. A Consent Manager allows a Data Principal to give, manage, review, or withdraw consent through a registered service.
A Significant Data Fiduciary is different. A large company doesn’t automatically become one. The Central Government must notify a Data Fiduciary or class of Data Fiduciaries based on factors listed in the Act. This distinction matters because Significant Data Fiduciaries face extra duties.
Consent is one route for processing, but it isn’t the only route under DPDPA 2023. Section 7 describes certain legitimate uses in specified situations. These can involve voluntary provision of information, employment, state functions, medical emergencies, compliance with legal duties, or other situations named in the Act.
A business should identify the correct basis for every important purpose. Using consent for everything can create problems. If the organisation says processing depends on consent, it must also be able to deal with withdrawal. That withdrawal may need to move through every connected application that relies on the same permission.
DPDPA Compliance should therefore connect legal decisions with application behaviour. Privacy teams can state why processing is permitted, but product and technology teams need to make the decision work inside applications.
What Do the DPDP Rules 2025 Require?
The DPDP Rules 2025 explain how several duties in the Digital Personal Data Protection Act are expected to work. They cover notices, consent, security safeguards, breach procedures, Data Principal rights, retention, children, Consent Managers, and additional duties for Significant Data Fiduciaries.
The table below gives 7 areas that deserve early attention.
| Requirement | What Businesses Need |
| Notice | Clear purpose, information description, rights path, and complaint route |
| Consent | Consent record, withdrawal flow, and downstream update |
| Security | Access control, encryption or masking, monitoring, logs, and backups |
| Breaches | Detection, investigation, notices, reporting, and evidence |
| Rights | Access, correction, erasure, grievance, and nomination processes |
| Retention | Defined retention periods, exceptions, and tested deletion |
| Children and SDFs | Parent checks where needed and extra controls after SDF notification |
Processor contracts also matter. A Data Fiduciary can’t assume that using a vendor removes its responsibility. Contracts should address processing scope, permitted access, security duties, breach support, deletion, subprocessors, and evidence. A processor inventory should show which vendor handles each type of personal information and which contract covers that activity.
The technical controls named in the DPDP Rules 2025 also need to exist in practice. Encryption, masking, access control, logging, monitoring, backups, and contract safeguards may all form part of the evidence a company keeps. Policies should match the real system state.
For AI systems, the same principle applies. The official Act doesn’t create a separate general AI law, but personal information used by AI can still fall within its scope. Companies should examine input information, model access, retrieval systems, prompt logs, outputs, and storage. The government text on child data duties also matters where AI products or digital services may be used by people under 18.
Calance’s Generative AI Solutions include private deployment options, role-based access, encryption, identity integration, and audit logs. These measures can support organisations that need tighter control over personal information used in AI environments.
How Should Businesses Handle Security and Breaches?
Security is one of the most important technical parts of the Digital Personal Data Protection Act. Written policies aren’t enough if systems still allow unnecessary access, weak authentication, poor logging, or untracked exports. DPDPA Compliance should therefore include both preventive controls and evidence that those controls operate as expected.
The DPDP Rules 2025 refer to measures such as encryption, masking or similar techniques, access controls, monitoring, backups, and measures that help detect unauthorised access. Processor contracts also need security terms that fit the type of processing involved.
Breach handling creates another challenge. Data Principals must be notified without delay where the rules require it. The Board must also receive an initial intimation without delay. Further specified details are then expected within 72 hours unless a longer period is allowed.
Businesses also need to consider CERT-In. Its cyber incident directions require covered cyber incidents to be reported within 6 hours of noticing the incident or being informed of it. DPDPA Compliance and CERT-In reporting are separate questions, so one event may trigger more than one process.
An incident playbook should therefore identify who detects the event, who gathers technical facts, who decides whether personal information is involved, who checks reporting duties, who contacts affected individuals, and who preserves records. The sequence should be tested before an actual breach.
Calance’s Microsoft 365 Services support technologies such as Defender, Purview, conditional access, and other Microsoft security capabilities. These controls can help companies restrict access, identify risky activity, and keep information-governance evidence in Microsoft environments.
How Should Businesses Manage Children and Significant Data Fiduciaries?
The Digital Personal Data Protection Act defines a child as an individual who hasn’t completed 18 years of age. Businesses that process children’s information need to examine whether verifiable parental consent is required and whether an exemption under the Act or Rules applies.
This is particularly important for online services that don’t already know the age of their users. Registration screens, gaming services, education platforms, healthcare applications, social services, and other digital products may need age-related controls. The business also needs to examine tracking and targeted advertising because the Act places restrictions on processing connected with children.
Significant Data Fiduciaries face further requirements after government notification. These can include the appointment of a Data Protection Officer and recurring duties such as Data Protection Impact Assessments and audits. The DPDP Rules 2025 also add checks related to technical measures and algorithmic software.
A company shouldn’t state that it is an SDF merely because it has many customers or large revenue. The legal designation comes from the Central Government. Businesses that believe they may later fall into this category can still prepare in advance by documenting higher-risk processing, governance roles, system controls, and assessment methods.
AI systems deserve attention in this area because an algorithm may use personal information without privacy teams having a clear view of every input. Product teams should record what personal information is used, why it is needed, who can access it, whether the output creates new personal information, and how logs are retained.
How Should Retention and Deletion Work?
Retention is one of the hardest parts of Data Protection Compliance in India because information rarely sits in only one place. A customer record may appear in a CRM, billing tool, support platform, reporting environment, warehouse, backup, export, and third-party system.
The Digital Personal Data Protection Act requires erasure in applicable situations when consent is withdrawn or when the purpose is no longer being served, unless retention is needed to comply with law. Businesses therefore need to know why each major category of information is kept and what rule controls deletion.
A useful retention schedule should identify the information category, business purpose, system owner, legal requirement, retention period where applicable, deletion trigger, exception route, and deletion method. That schedule should match actual system settings.
Testing matters because a policy may say that information is deleted after a fixed period while a backup keeps it for much longer. The same problem may occur where a vendor retains its own copy after the primary application removes the record.
Calance’s Application Support Services cover access reviews, audit records, log retention, masking, backup checks, and recovery testing. These activities can help businesses keep operational evidence around the systems that process personal information.
DPDPA 2023 also needs to be read with other Indian requirements. Tax, employment, banking, cybersecurity, healthcare, or sector rules may require certain records to remain available for a specific period. A deletion request therefore doesn’t always mean immediate deletion of every related record.
How Is DPDPA Different From GDPR?
The Digital Personal Data Protection Act shares several privacy concepts with GDPR, but the 2 frameworks aren’t identical. Businesses with GDPR programmes can reuse useful controls, but they need to map those controls against Indian requirements before treating them as sufficient.
The GDPR provides several legal bases for processing. DPDPA 2023 uses consent together with specified legitimate uses described in the Act. Processor obligations are also structured differently. GDPR places several direct statutory duties on processors, while the Indian framework places much of the main responsibility on the Data Fiduciary.
Children are another difference. The Indian Act defines a child as a person under 18. GDPR Article 8 uses 16 as the default age for certain consent situations involving information-society services, while EU Member States can set a lower threshold within the permitted range.
Cross-border transfers also work differently. GDPR uses mechanisms such as adequacy decisions and Standard Contractual Clauses. India’s framework allows the Central Government to restrict transfers to specified countries or territories. The IAPP GDPR comparison provides a useful point-by-point discussion for global privacy teams.
Penalty structures also differ. GDPR can calculate major administrative fines by reference to worldwide turnover. The Indian Act uses rupee-denominated maximum amounts for specified violations.
Existing GDPR work can still save time. A company may already have a processing inventory, rights workflow, vendor review process, access-control model, incident plan, or retention schedule. DPDPA Compliance should test each of these against the Indian framework instead of rebuilding everything from zero.
Calance’s Zero Trust Services focus on identity checks, least-privilege access, segmentation, and monitoring. These controls can support organisations that need to reduce unnecessary access to personal information while keeping stronger evidence of who can reach important systems.
What Should a 2026 DPDPA Compliance Roadmap Include?
A 2026 programme should begin with discovery. The company needs to identify in-scope entities, systems, Data Principal groups, processors, international transfers, collection points, purposes, retention periods, and deletion methods. This creates a factual record of how personal information moves through the organisation.
The next stage is legal and process mapping. Each processing purpose should be linked to consent, a certain legitimate use, or an applicable exemption. Privacy notices should then be checked against actual system behaviour. If a notice says information is used for one purpose while teams use it for something else, the gap needs to be fixed.
Rights workflows should also be tested. A customer may ask what information is being processed, request a correction, seek erasure, raise a grievance, or use another right under the Act. The business needs to know which team receives the request, how identity is checked, which systems are searched, which vendors must act, and how completion is recorded.
Vendor reviews should follow. A company should know which processors handle important personal information, where those vendors operate, which subprocessors they use, how they protect information, how quickly they report incidents, and how they delete information after the service ends.
Security testing should happen before 2027. Access rights need review. Logging needs to work. Backups need recovery tests. Endpoint security needs current policies. Privileged accounts need stronger controls. Incident-response teams should run exercises based on a realistic breach scenario.
The company should then test deletion and retention. Select a small set of customer or employee records and trace what happens across connected systems when deletion is required. This often uncovers forgotten exports, old application copies, test records, or vendor-held information.
The last stage is evidence. Data Protection Compliance in India needs records that show what the organisation did and why. Evidence can include processing maps, consent records, access reviews, vendor contracts, incident exercises, deletion tests, audit logs, policy approvals, and assessment results.
Why Calance Fits the Technical Side of DPDPA Readiness
The Digital Personal Data Protection Act creates legal obligations, so companies should involve qualified privacy or legal counsel for interpretation. Calance fits most clearly on the technical side, where privacy requirements need to become working controls in applications, cloud environments, devices, security tools, and operating processes.
A legal team may state that access must be restricted. Technology teams then need to identify users, groups, permissions, service accounts, and systems that require changes. A retention policy may define when information should be removed. Application teams then need to make deletion work across databases and connected systems.
The same gap appears in incident response. A processor contract may say a vendor must report an event quickly, but the organisation still needs monitoring that can detect the event. A privacy team may create a 72-hour workflow, but security teams need enough technical information to decide whether a breach has occurred.
Calance’s service portfolio covers cybersecurity, endpoint management, application support, cloud operations, Microsoft environments, MDR, system integration, and enterprise AI. These areas align with many technical requirements that companies will need to review during DPDPA Compliance.
The best starting point isn’t a generic compliance checklist. It is a requirement-to-control map. For each important DPDPA 2023 requirement, the business should record the system owner, technical control, operating process, evidence source, and current test result.
That approach gives leadership a clearer view of what remains unfinished before 13 May 2027. It also keeps the work tied to real systems rather than policy language alone.
Frequently Asked Questions
What Is DPDPA in Simple Terms?
The Digital Personal Data Protection Act is India’s law for processing digital personal information. It gives people rights over their information and places duties on organisations that decide why and how that information is processed. The law covers consent, certain legitimate uses, security, breach reporting, rights requests, retention, children’s information, and processor use.For a business, DPDPA Compliance means being able to explain what personal information it collects, why it needs that information, who can access it, which vendors receive it, how long it is kept, and how it is protected.
Is DPDPA Fully Applicable in 2026?
No. The law uses phased commencement. Some provisions started in November 2025. Specified Consent Manager provisions begin on 13 November 2026. Most major business-facing provisions are scheduled to begin on 13 May 2027.Businesses should still prepare during 2026 because system changes, contract reviews, consent work, rights processes, retention changes, security tests, and vendor reviews can take months.
What Is a Data Fiduciary?
A Data Fiduciary decides why personal information is processed and how the processing takes place. This role carries much of the main responsibility under the Digital Personal Data Protection Act.A Data Processor acts on behalf of the Data Fiduciary. Using a processor doesn’t remove the Data Fiduciary’s responsibility for the processing activity.
Does DPDPA Apply to Foreign Companies?
It can. DPDPA 2023 may apply to processing outside India when that processing is connected with offering goods or services to Data Principals in India.A foreign company should therefore examine its Indian customer activity, personal information flows, processing purposes, cloud systems, processors, and service locations before deciding that the law doesn’t apply.
What Rights Do Data Principals Have?
The framework provides rights connected with access to information about processing, correction, updating, erasure in applicable cases, grievance redressal, and nomination.Companies need a working process behind these rights. Teams should know how identity will be checked, which systems must be searched, which processors need instructions, what exceptions apply, and how the final action will be recorded.
What Are the Main DPDPA Penalties?
The Act sets different maximum penalty amounts for different violations. Failure to take reasonable security safeguards can carry a maximum penalty of ₹250 crore. Certain failures connected with breach notification can carry a maximum penalty of ₹200 crore.These amounts are statutory ceilings rather than automatic penalties for every incident. The actual outcome depends on the violation and the legal process.
Does DPDPA Replace CERT-In Rules?
No. DPDPA Compliance and CERT-In cyber reporting can apply to the same incident.CERT-In has reporting requirements for specified cyber incidents, while the DPDP framework creates personal-data breach duties involving the Board and affected Data Principals. Incident-response teams should test both requirements during breach planning.
What Should Businesses Do First? Start with the processing inventory. Identify what personal information is collected, where it enters the organisation, where it is stored, which teams use it, which processors receive it, why it is required, how long it remains available, and how deletion works.Once that information is clear, the company can review consent, legal routes, privacy notices, vendor contracts, rights handling, retention, security safeguards, child-data processing, cross-border activity, and breach procedures. That sequence gives Data Protection Compliance in India a clear technical and operating base.
