Adv. (Dr.) Prashant Mali advises Indian and global companies on Digital Personal Data Protection Act, 2023 (DPDP Act / DPDPA) compliance, the DPDP Rules 2025, GDPR, CCPA data-breach response, consent and notice design, and data-principal rights - and is the creator of DPDPA.com, India's DPDPA knowledge hub.
India's data protection regime has moved from theory to enforcement. The Digital Personal Data Protection Act, 2023 (DPDP Act, or "DPDPA") is the country's first standalone privacy law, and the DPDP Rules, 2025 - notified by the Ministry of Electronics and Information Technology (MeitY) on 14 November 2025 -turn its principles into concrete, audited obligations with penalties running up to ₹250 crore. This page explains who must comply, what the law requires, and how organisations prepare. It is information, not legal advice.
Privacy is a fundamental right in India. In the landmark nine-judge decision Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the Supreme Court held that the right to informational privacy flows from Article 21 of the Constitution. The DPDP Act is the legislative answer to Puttaswamy and with the 2025 Rules now in force, the grace period for "we'll deal with privacy later" is over. Every business that handles the personal data of Indian residents, whether a startup, a hospital, an e-commerce platform or a multinational, now has statutory duties.
The Act uses three core roles:
Data Principal - the individual whose personal data is processed (you and me).
Data Fiduciary - any person or organisation that decides the purpose and means of processing personal data (most businesses).
Data Processor - a party that processes data on a fiduciary's behalf (e.g., a cloud vendor or SaaS provider).
The Act applies to processing of digital personal data within India, and - importantly - has extra-territorial reach: it also covers processing outside India where it relates to offering goods or services to Data Principals in India. A company in Singapore or the US selling to Indian users is squarely within its scope.
Larger or higher-risk entities may be notified as Significant Data Fiduciaries (SDFs) under Section 10, attracting heavier duties (a Data Protection Officer based in India, independent data audits, and Data Protection Impact Assessments).
Consent must be free, specific, informed, unconditional and unambiguous, sought through a clear notice (available in English and the languages of the Eighth Schedule). Bundled or pre-ticked consent will not do. Consent must be as easy to withdraw as to give.
Personal data may be processed only for the lawful purpose for which consent was given, and only the data actually needed for that purpose.
Processing the data of anyone under 18 requires verifiable parental/guardian consent, and behavioural tracking or targeted advertising directed at children is prohibited. This is one of the most operationally demanding parts of the law for ed-tech, gaming and social platforms.
Data Fiduciaries must implement reasonable security safeguards and must report every personal data breach to the Data Protection Board and to affected Data Principals, in the manner and timelines set by the 2025 Rules. Documented chain of custody and incident-response playbooks are now compliance essentials, not nice-to-haves.
Individuals have the right to access their data, to correction and erasure, to grievance redressal, and to nominate another person to exercise their rights. Businesses must build channels to honour these rights within prescribed timelines.
The DPDPA permits transfer of personal data outside India except to countries restricted by the Central Government (a "negative list" model) — a lighter touch than the GDPR's, but one that still requires mapping data flows and monitoring notifications.
The Schedule to the Act prescribes graded financial penalties imposed by the Data Protection Board of India, including up to ₹250 crore for failure to take reasonable security safeguards to prevent a breach, and up to ₹200 crore for breaches of obligations relating to children's data. Unlike the GDPR, the DPDPA has no percentage-of-turnover cap - the rupee figures are the ceiling, and they are large enough to make privacy a board-level risk.
For companies already GDPR-compliant, the DPDPA is familiar but not identical. Key contrasts:
Legal bases: GDPR has six lawful bases; the DPDPA runs primarily on consent plus certain "legitimate uses" - narrower than GDPR's "legitimate interests."
Data categories: the DPDPA does not create a separate "sensitive personal data" category (unlike GDPR and the old SPDI Rules).
Penalties: fixed rupee ceilings vs GDPR's 4%-of-global-turnover model.
Transfers: negative-list model vs GDPR's adequacy/SCC framework.
A GDPR programme is a strong head-start, but a gap assessment is essential — copy-pasting EU documents into an Indian context is a common and costly mistake.
DPDP gap assessment & readiness audits - where you stand today vs the Act and 2025 Rules.
Privacy notices, consent flows and policies - drafted to be legally sound and usable.
Data Processing Agreements (DPAs) and vendor/processor contracts.
Data Protection Impact Assessments (DPIAs) and SDF-specific obligations.
Data-breach response - notification strategy, regulator liaison, and evidence preservation.
DPO advisory and staff training.
Representation before the Data Protection Board of India and in privacy disputes and writ matters.
Cross-border transfer mapping and GDPR ↔ DPDPA harmonisation for multinationals.
Very likely yes. The Act applies to any Data Fiduciary processing digital personal data of individuals in India, with no blanket small-business exemption (though some obligations are eased for certain notified classes). If you collect emails, phone numbers, KYC or customer data, you are in scope.
The DPDP Rules 2025 provide a phased implementation, with certain obligations (especially for Significant Data Fiduciaries) taking effect over a defined runway after notification. The prudent course is to start your gap assessment now, because building consent, notice and breach-response systems takes months, not days.
A DPO based in India is mandatory for Significant Data Fiduciaries. Other businesses must at minimum designate a contactable person to answer data-principal queries. Whether you are likely to be classed as an SDF is itself worth assessing.
You must notify the Data Protection Board and affected individuals per the Rules, and be able to show the safeguards you had in place. Failure to maintain reasonable security safeguards is the single most heavily penalised failing (up to ₹250 crore) - so preparation and documentation are everything.
Partly. GDPR compliance is a strong foundation, but the DPDPA differs on legal bases, consent, children's data, transfers and penalties. A targeted gap assessment closes the delta.
Adv. (Dr.) Prashant Mali is the creator of DPDPA.com, India's dedicated DPDPA knowledge hub, and writes regularly on data protection developments. Read the cyber law blog → www.dpdpa.com/blog.html · Visit DPDPA.com → www.dpdpa.com
For DPDP Act readiness, breach response, or a data-protection dispute, contact Adv. (Dr.) Prashant Mali - consultations available online and in person at the Andheri and Bandra (Mumbai) offices, for clients across India and internationally.
Disclaimer: This page is for general information only and does not constitute legal advice or solicitation, nor does it create a lawyer–client relationship. Statutory provisions and Rules are summarised and may be updated; please consult a qualified advocate about your specific situation. Last updated: July 2026.