DPDP Readiness Check

A plain-language self-assessment against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Current as of July 2026.

Is your business ready for India's data protection law?

The DPDP Rules were notified on 13 November 2025. There is no turnover threshold and no small-business exemption: if you collect a customer's name, phone number or email through any digital channel, this law applies to you. Penalties reach ₹250 crore for failing to keep personal data secure.

November 2025
Rules notified. Data Protection Board constituted. Soft-enforcement phase begins.
November 2026
Consent Manager framework becomes operational. Four months from now.
13 May 2027
Hard deadline. Full compliance enforceable, penalty regime live.

This check takes about ten minutes. You answer questions about how your business actually works. Nothing is uploaded and no customer data is asked for; your answers stay in this browser tab. You get a readiness score, a gap list in plain words, a roadmap against the real deadlines, and starter documents with your business name already in them.

This tool gives guidance, not legal advice. Its question bank and outputs are designed for review by a qualified data-protection lawyer before you rely on them. Treat the result as a map of your gaps, not a certificate of compliance.
Before we begin

Your business, briefly

Result

Prepared with the DPDP Act, 2023 and DPDP Rules, 2025 as notified on 13 November 2025, and the enforcement timeline as understood in July 2026. Guidance only; not legal advice. Have the output reviewed by a qualified data-protection lawyer.
Reference library

The DPDP Act, the Rules, and everything notified so far

The full law, chapter by chapter, in the plain words this tool uses everywhere else. This is a working digest for business owners, current as of July 2026. It is faithful to the statute but it is not the statute; the official full text is linked at the bottom and always prevails.

The Act at a glance

The Digital Personal Data Protection Act, 2023 is India's first standalone law on personal data. It received Presidential assent on 11 August 2023 and came to life operationally when the DPDP Rules were notified on 13 November 2025.

Three roles run through the whole law. The Data Principal is the person the data is about: your customer, your student, your patient, your employee. The Data Fiduciary is whoever decides why and how that data is used: your business. The Data Processor handles data on the fiduciary's behalf: your billing software, your marketing agency, your accountant.

The obligations sit on the fiduciary. There is no turnover threshold and no small-business exemption from the core duties. If you collect a name and a phone number in digital form, you are a Data Fiduciary.

Chapter I · Preliminary (Sections 1 to 3)

Section 1 gives the short title and lets the government bring different provisions into force on different dates, which is why the law is arriving in phases rather than on one day.

Section 2 defines the terms. The ones that matter daily: personal data is any data about an identifiable individual; processing covers collection, storage, use, sharing and even deletion; a child is anyone under 18; a Consent Manager is a registered platform through which a person can give, manage and withdraw consent.

Section 3 sets the reach. The Act applies to digital personal data processed within India, whether collected digitally or collected on paper and digitised later. It also applies to processing outside India if it is connected to offering goods or services to people in India. It does not apply to purely personal or domestic use, or to data the individual has themselves made publicly available or that is public under a legal obligation.

Chapter II · Obligations of the Data Fiduciary (Sections 4 to 10)

Section 4: personal data may be processed only for a lawful purpose, and only with the person's consent or for a listed "legitimate use".

Section 5: before or while asking for consent, you must give a notice stating what data you collect, the purpose, how the person can exercise their rights, and how to complain to the Data Protection Board. The notice must be available in English or any of the 22 languages in the Eighth Schedule of the Constitution.

Section 6: consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the stated purpose. Withdrawing consent must be as easy as giving it. Consent can also flow through a registered Consent Manager.

Section 7: the "legitimate uses" that permit processing without fresh consent, including data a person volunteers for a specified purpose, employment purposes, medical emergencies, disasters, and specified State functions.

Section 8: the general duties. Ensure accuracy where data feeds decisions about the person, put reasonable security safeguards in place, report breaches to the Board and to affected individuals, erase data once the purpose is served (unless another law requires retention), publish a grievance contact, and answer for your processors: their failure is your failure.

Section 9: children. Verifiable consent of a parent or lawful guardian is required before processing a child's data. Processing likely to cause a child detrimental effect is prohibited, as are tracking, behavioural monitoring and targeted advertising directed at children.

Section 10: the government may notify certain businesses as Significant Data Fiduciaries based on volume and sensitivity of data, risk, and similar factors. An SDF must appoint a Data Protection Officer based in India, appoint an independent data auditor, and conduct periodic Data Protection Impact Assessments and audits.

Chapter III · Rights and duties of the Data Principal (Sections 11 to 15)

Section 11: right to a summary of what data you hold about the person, what processing you have done, and who it has been shared with.

Section 12: right to correction, completion, updating and erasure. Erasure follows unless retention is needed for the stated purpose or required by law.

Section 13: right to grievance redressal. The person must first come to your grievance channel; only after that can they escalate to the Board. This is why a working, published grievance contact protects you.

Section 14: right to nominate another person to exercise these rights in case of death or incapacity.

Section 15: duties of the Data Principal: no impersonation, no suppression of material information, no false or frivolous complaints. Breach of these duties carries a penalty up to ₹10,000.

Chapter IV · Cross-border transfer and exemptions (Sections 16 and 17)

Section 16: personal data may be transferred outside India except to countries the government specifically restricts by notification. This is a blacklist approach, the reverse of Europe's whitelist. Sector regulators (such as RBI rules on payments data) can still impose stricter localisation on top.

Section 17: exemptions. Processing for enforcing legal rights, by courts, for prevention and investigation of offences, and certain research or statistical purposes sits outside parts of the Act. The government may exempt notified startups from some notice and accuracy obligations, and may exempt State instrumentalities on grounds such as sovereignty and public order.

Chapters V and VI · The Data Protection Board (Sections 18 to 28)

These chapters establish the Data Protection Board of India, a digital-first adjudicating body, and set its powers and procedure. The Board inquires into breaches on complaint, reference or its own motion, can summon and examine, inspect documents, direct urgent remedial measures during a breach, and impose the monetary penalties in the Schedule. It functions as a digital office: complaints, hearings and orders are designed to move electronically. The Board was constituted following the November 2025 notifications.

Chapter VII · Appeals, mediation and voluntary undertakings (Sections 29 to 32)

Orders of the Board are appealable to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), generally within 60 days. The Board may refer disputes to mediation. It may also accept a voluntary undertaking: a business admits the gap, commits to fix it within a timeline, and proceedings on that matter are dropped. For a small business caught mid-remediation, the voluntary undertaking route is likely to matter more than any other section in this chapter.

Chapter VIII · Penalties (Sections 33 and 34, with the Schedule)

Penalties are civil monetary penalties imposed by the Board after inquiry, scaled to the nature, gravity, duration and repetitiveness of the breach, the gain made or loss averted, and mitigation efforts. The ceilings per instance:

FailureMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failure to notify the Board or affected individuals of a personal data breach₹200 crore
Breach of obligations relating to children₹200 crore
Breach of Significant Data Fiduciary obligations₹150 crore
Breach of any other provision of the Act or Rules₹50 crore
Breach of duties by a Data Principal₹10,000

Note the shape of the table: the two highest ceilings sit on security and breach reporting. That is why this tool weights those modules the way it does.

Chapter IX · Miscellaneous, and what the Act changed in other laws (Sections 35 to 44)

The closing chapter covers protection for action taken in good faith, the government's power to call for information and to block repeat-offender platforms in specified circumstances, rule-making powers, and consequential amendments.

Two amendments to other laws matter in practice. The Right to Information Act, Section 8(1)(j) was amended so that personal information is exempt from RTI disclosure. And the Information Technology Act lost Section 43A (the old compensation route for negligent handling of sensitive personal data), since this Act replaces that regime.

The DPDP Rules, 2025 · what they added to the Act

The Act sets the duties; the Rules, notified 13 November 2025, set the mechanics. The parts a business feels directly:

  • Notice mechanics. The notice must stand on its own, in clear plain language, itemising the personal data and the purpose, with links to withdraw consent, exercise rights, and complain to the Board.
  • Reasonable security safeguards, spelled out. Minimum expectations include encryption or equivalent protection, access control, monitoring and logging, backups, and retention of logs and related traffic data for at least one year.
  • Breach reporting mechanics. On becoming aware of a breach: intimate the Board without delay, follow with a detailed report within 72 hours (extendable on request), and inform each affected individual plainly: what happened, the likely consequences, what you have done, and what they can do.
  • Consent Managers. A registration framework for Consent Manager platforms, with net-worth and governance conditions, becoming operational from November 2026.
  • Children. Mechanics for verifiable parental consent, including verification against identity or age details already held or issued by law.
  • Retention for large platforms. Specified classes such as large e-commerce, social media and online gaming platforms must erase personal data after a defined period of user inactivity (three years), with advance notice to the user.
  • Significant Data Fiduciaries. Annual Data Protection Impact Assessment and audit, with findings reported to the Board.
  • Phased commencement. The Rules themselves stagger obligations, which produces the timeline below.
Timeline · notifications and changes so far (as of July 2026)
11 August 2023
DPDP Act, 2023 receives Presidential assent. The Act is on the books but dormant without Rules.
3 January 2025
Draft DPDP Rules released by MeitY for public consultation.
13 to 14 November 2025
Final DPDP Rules, 2025 notified in the Gazette. Phased commencement begins; Data Protection Board constituted; soft-enforcement period opens.
January 2026
MeitY floats a proposal to compress the compliance window for Significant Data Fiduciaries toward November 2026. As of July 2026 this remains a proposal, not a notified change.
November 2026
Consent Manager registration framework becomes operational. Consent, notice and related obligations tighten as the phased schedule matures.
13 May 2027
End of the transition. Full obligations enforceable; the penalty Schedule applies with the Board fully in play.

No amendment to the text of the Act itself has been notified as of July 2026. Change so far has come through the Rules and the phased commencement notifications. Check the official sources below for anything after this date.

Read the official full text

This digest is for orientation. For the authoritative text, use the government sources directly:

  • meity.gov.in · Ministry of Electronics and IT: the Act, the DPDP Rules 2025, and all related notifications and FAQs.
  • indiacode.nic.in · India Code: the consolidated statute text of the DPDP Act, 2023.
  • egazette.gov.in · The e-Gazette: original Gazette notifications, including the November 2025 Rules and commencement notifications.
  • prsindia.org · PRS Legislative Research: neutral clause-by-clause summaries and legislative history.

If any statement in this digest and the Gazette text ever differ, the Gazette text wins.

Plain-language digest prepared for orientation, current as of July 2026. It is not the statute and not legal advice. Verify against the official text linked above, and have decisions reviewed by a qualified data-protection lawyer.