What is the DPDP Act? Complete Guide for Indian Businesses (2026)
Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.
Read articleUnderstand the DPDP Rules 2025 with this practical guide for Indian startups and businesses. Learn key requirements, compliance steps, FAQs, and best practices.
The Digital Personal Data Protection (DPDP) Act, 2023 established India's legal framework for protecting digital personal data. The DPDP Rules, 2025 — notified on 13 November 2025 — provide operational detail on how organisations implement the Act's requirements in practice.
If you're a startup founder, product manager, compliance officer, HR leader, or business owner, understanding these Rules will help you prepare for responsible data governance before the 13 May 2027 full compliance deadline.
Act vs Rules: The Act defines what the law requires. The notified Rules explain how many of those requirements operate day to day — notices, consent mechanics, breach reporting timelines, and more. An earlier draft of the Rules circulated in January 2025; the notified Rules of 13 November 2025 are what you should implement against.
Related guides: What is the DPDP Act? · DPDP compliance checklist · Ultimate compliance guide (2026) · Free readiness check · DPDPKit
The DPDP Act establishes the legal framework. The DPDP Rules, 2025 explain how certain provisions of the Act operate in practice — including implementation expectations, operational procedures, and compliance-related processes.
Think of it this way:
DPDP Act → Defines what the law requires.
DPDP Rules, 2025 → Explain how organisations implement those requirements.
The Rules cover areas such as:
| Milestone | Date |
|---|---|
| DPDP Act passed | August 2023 |
| Draft Rules circulated | January 2025 |
| DPDP Rules, 2025 notified | 13 November 2025 |
| Data Protection Board operational | From 13 November 2025 |
| Full compliance mandatory | 13 May 2027 |
Phase 1 provisions — including the Board and penalty framework — are already live. Complaints can be filed today. Full operational compliance must be in place by May 2027.
| DPDP Act, 2023 | DPDP Rules, 2025 | |
|---|---|---|
| Nature | Primary legislation | Subordinate rules under the Act |
| Passed / issued by | Parliament | Government notification |
| Scope | Legal principles and obligations | Operational implementation detail |
| Examples | Data Fiduciary duties, penalties, Board powers | Notice format, breach reporting steps, retention expectations |
| Status | In force | Notified 13 November 2025 |
Businesses should understand both together. Your policies and SOPs should reference the Act for legal basis and align operational steps to the notified Rules.
The Rules are relevant to organisations that process digital personal data, including:
If your organization collects personal information digitally — including B2B customer and employee data — you should understand how the notified Rules apply to you.
The following sections summarise the practical areas founders most often need to operationalise. Rule numbers refer to the notified DPDP Rules, 2025.
Individuals should receive a clear notice before or at the time their personal data is collected. Under the Rules, notices must be itemised — not buried in Terms of Service.
A good notice typically explains:
Avoid legal jargon, hidden disclosures, and ambiguous wording. Notices should also be available in English and a scheduled Indian language where required.
Where consent is the lawful basis, it should be:
Good practices:
Maintain versioned consent records — who consented, to what, and when.
Individuals must have a straightforward way to withdraw consent. Businesses should establish documented workflows so withdrawal requests are handled consistently, logged, and result in cessation of the relevant processing (subject to lawful exceptions).
The Act and Rules require Data Fiduciaries to appoint a Grievance Officer — a named internal contact for Data Principal complaints. Contact details must be published in your privacy policy. This is one of the most commonly missed requirements in readiness checks.
Organisations must implement reasonable security safeguards appropriate to the nature of personal data processed.
Examples include:
Security is an ongoing process, not a one-time project.
The Rules operationalise the Act's breach obligations. In summary:
Maintain a Breach Register — log every incident including near-misses. Run a tabletop drill before you need the plan for real.
Organisations should avoid keeping personal information indefinitely. Create documented retention schedules defining:
Regular reviews reduce unnecessary data accumulation and simplify rights requests.
Prepare internal processes for access, correction, erasure, and consent withdrawal requests.
Practical preparation includes:
Many businesses rely on external providers for cloud hosting, email, payments, analytics, CRM, and customer support. The Rules expect Data Fiduciaries to govern processors through DPAs and due diligence.
Maintain a Vendor Register and review cross-border storage locations.
Employees play a critical role in protecting personal data. Training should cover password security, phishing awareness, incident reporting, data handling practices, and privacy responsibilities.
Good compliance depends on internal governance — policies, registers, and a workbook that tracks gap assessment progress.
Use this quick assessment. For the full 13-section version, see our DPDP compliance checklist.
A focused starting point aligned to the notified Rules. For a fuller plan, see the 90-day roadmap in DPDPKit.
Many organizations:
A structured implementation plan reduces these risks. Take the free readiness check to see which gaps apply to you.
Yes. The Act establishes the legal framework; the notified Rules provide operational guidance for implementing various provisions.
No. They were formally notified on 13 November 2025. Implement against the notified Rules, not the earlier January 2025 draft.
Organizations that process digital personal data should understand how the Rules apply to their activities — regardless of company size.
Building good privacy practices early is easier than retrofitting them later. The Board is already accepting complaints, and the 13 May 2027 deadline is fixed.
Common documents include a Privacy Policy, consent notices, data inventory, vendor register, rights request register, retention schedule, breach SOP, and Grievance Officer appointment. See the full document list in our pillar guide.
Many early-stage startups begin with structured spreadsheets. DPDPKit's 8-tab workbook is built for this stage and aligned to the notified Rules.
Not sure how prepared your business is?
Take our free DPDP readiness check — 50 questions, about 2 minutes, instant score with your top three gaps. No signup required.
Instead of creating every document from scratch, DPDPKit includes templates and a workbook drafted against the DPDP Rules notified 13 November 2025 — not the January 2025 draft:
₹4,999 — instant download after payment.
The DPDP Rules, 2025 translate the principles of the DPDP Act into practical, day-to-day operations. Rather than treating compliance as a one-time legal project, view it as ongoing governance that evolves with your products and services.
Start with the basics: understand what personal data you process, align your documents to the notified Rules, establish clear internal procedures, and review them regularly. For startups, embedding privacy early improves customer trust, strengthens security, and reduces future compliance effort.
Next steps:
This guide is for informational purposes only and does not constitute legal advice. Have your counsel or CA review your customised documents before you rely on them.
Written by
Founder, UXLaunch Lab
11+ years across fintech, Web3, and SaaS. Shipped RoleGrowth — an AI-powered career platform — end-to-end in 8 weeks.
Frequently asked questions
Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.
Read articleLearn about DPDP Act penalties, how financial penalties are determined, common compliance mistakes, and practical steps businesses can take to reduce privacy risks.
Read articleLearn a practical DPDP compliance timeline for startups and businesses. Follow this 90-day roadmap to prepare your organization for India's data protection law.
Read article