The DPDP Act and Rules, in plain language
Twenty-three explainers on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Each one lists the sections and rules it relies on, checked against the official text between 5 and 7 Oct 2026.
- Scope
DPDP Act: does it apply to you? There is no size cutoff
Coverage turns on two questions about your data, then three exclusions. There is no size threshold.
- Timeline
DPDP Act dates: 13 Nov 2025, 13 Nov 2026, 13 May 2027. Which is yours?
Two instruments dated 13 November 2025 set three dates. Most duties on businesses start on the third.
- Penalties
DPDPA penalties: how big can one get? Up to ₹250 crore
The Schedule sets maximums. The Board fixes an amount only after an inquiry finds a significant breach, using seven factors set out in the Act.
- Breach
DPDP data breach under Rule 7: what to send the Board in 72 hours
Two filings to the Board and a notice to every affected person. What each must contain, and when it is due.
- Consent
DPDP consent notice: does yours meet Section 5 and Rule 3?
Every request for consent needs a notice that comes with it or before it. The Act and the Rules set the minimum contents.
- Rights
DPDP rights: what the 90-day limit really covers
The Act gives people four rights against a Data Fiduciary. The Rules cap the grievance response period at 90 days. It is not a deadline for every request.
- Vendors
DPDP processors: what goes in a DPA, and why you stay responsible
The Act keeps the duty with you whatever the contract says, and requires a valid contract for processors engaged to help you offer goods or services.
- Cross-border
Can you send personal data outside India? Section 16 and Rule 15
The Act allows transfers abroad unless the government restricts a country by notification. The Rules add requirements about foreign States, and stricter Indian law still applies.
- Privacy page
Privacy policy for an Indian website? The DPDP Act uses other words
The law does not use the words privacy policy. It asks for a notice, a contact, a way to make requests and a grievance period.
- Retention
How long can you keep customer data? Logs have a one-year minimum
Erase when the purpose ends unless a law says to keep it. Logs and related data are kept for at least one year for purposes the Rules list, then erased. Large platforms have a three-year limit.
- Consent Managers
DPDP Consent Managers: who can register from 13 November 2026?
Registration of Consent Managers starts on 13 November 2026. Data Fiduciary duties start later, on 13 May 2027.
- Definitions
Data Fiduciary, Data Processor, Data Principal: which one are you?
The three roles in the DPDP Act on one page, with the Act’s definitions in plain words and what each role owes.
- Clinics and hospitals
Clinics and hospitals under the DPDP Act: what about emergencies?
Patient records are personal data like any other. The Act lists medical emergencies as a use that needs no consent, and the Rules give clinics a limited exemption for children’s data.
- Children’s data
Children’s data, DPDP Act: who is a child and who must consent?
A child is anyone under 18. You need a parent’s verifiable consent first, and you may not track, behaviourally monitor or target ads at children unless an exemption applies.
- Small business
DPDP Act for small businesses: there is no size test
The law has no size test. These are the duties that start on 13 May 2027, with our own first steps for a shop, an app, a coaching institute or a salon, clearly labelled.
- Vendors
Zoho, Tally, Google Workspace, WhatsApp Business: a Data Processor?
Where a supplier stores or handles customer data for you, it is your Data Processor and you stay responsible. What the law asks, with Zoho, Tally, Google Workspace and WhatsApp Business as examples of where data sits.
- Erasure
Delete request vs invoices under the DPDP Act: which one wins?
Erase on request unless keeping the data is necessary for the purpose or to comply with a law. The Act and Rules name no invoice period, so the period comes from the other law.
- Registration
DPDP Act registration: only Consent Managers register
Only Consent Managers register with the Board; those rules come into force on 13 November 2026. Significant Data Fiduciaries are notified by the government. Other businesses meet the duties from 13 May 2027.
- Security safeguards
DPDP security safeguards: a checklist for small business
The Rules list seven minimum safeguards, from data security to keeping logs for a year. The duty starts on 13 May 2027.
- Other laws
DPDP Act vs IT Act 2000: does it override?
The DPDP Act adds to other laws and prevails only to the extent of a conflict. It amends the IT Act, including omitting 43A, from 13 May 2027.
- Significant Data Fiduciary
Do you need a DPO or a DPIA? Only if the government notifies you
Only a Significant Data Fiduciary, which the Central Government notifies, must appoint a DPO and run DPIAs. Those duties start on 13 May 2027.
- Startups
Are startups exempt from the DPDP Act? Only if notified
The Act has no startup test. The government may notify startups out of five named provisions. We have seen no such notification. Duties start on 13 May 2027.
- Data Protection Board
Complaint to the Data Protection Board: the steps and 60-day appeal
A person uses your grievance process first. The Board then checks, inquires and hears you, and an order can be appealed within 60 days.
A drafting aid. Get legal advice for your situation. These articles explain the published text.