Home All services
Start a project → Call Now

DPDP Act compliance consultant in India

Know which DPDP Act duties apply to you — and from when.

India's Digital Personal Data Protection (DPDP) Act is only partly in force. Its duties to the people whose data you hold start in May 2027. We plan your readiness around those dates.

  • Scoped to the Act's three start dates
  • A signed opinion, because no DPDP certificate exists
  • We reply within one working day.
  • DPDP Act, 2023
  • DPDP Rules, 2025
  • G.S.R. 843(E)
Illustration: three doors in a row, one open and glowing and two still closed, with three blank personal data cards standing in a row in front of them and a clock beside the cards

In brief

What it is
Readiness work for the DPDP Act, 2023 and DPDP Rules, 2025: what personal data you hold, why, and what the Act asks for each use.
Why it matters
Nothing you owe individuals under the DPDP Act is enforceable yet. From May 2027 it all is, penalties included. The SPDI Rules on sensitive personal data and CERT-In's six-hour direction bind you today.
What you get
A readiness assessment signed in our own name, plus the documents the Act needs, each with a named owner on your side.

In force today

What applies now, and what starts in May 2027.

Four notifications on 13 November 2025 switched on the Act's institutional half. No duty a Data Fiduciary (the organization deciding how data is used) owes a Data Principal (the person it is about) is live yet.

Commencement by tranche, per G.S.R. 843(E) and Rule 1.
TrancheWhat commencesFrom
(a) On publicationDefinitions, the Board's constitution, its digital-office functioning, rule-making powers and the Right to Information (RTI) amendment. (Act sections 1(2), 2, 18 to 26, 35, 38 to 43, 44(1) and 44(3), plus Rules 1, 2 and 17 to 21.)November 2025. In force.
(b) One year after publicationConsent Manager registration, and the Board's function of dealing with Consent Manager breaches. (Rule 4 and Act sections 6(9) and 27(1)(d) only.)November 2026.
(c) Eighteen months after publicationNotice, consent, Rule 6 safeguards, Rule 7 breach reporting, children's data, Significant Data Fiduciary duties, rights, transfer, section 33 penalties and the Schedule, and the repeal of IT Act section 43A. (Act sections 3 to 5, 6(1) to (8) and (10), 7 to 17, 27 other than 27(1)(d), 28 to 34, 36, 37 and 44(2), plus Rules 3, 5 to 16, 22 and 23.)May 2027.
The four notifications of 13 November 2025

G.S.R. 843(E) commenced the Act in three tranches. G.S.R. 844(E) established the Data Protection Board of India, with its head office in the National Capital Region, and G.S.R. 845(E) fixed its strength at one Chairperson and four Members. G.S.R. 846(E) made the DPDP Rules, 2025: twenty-three rules and seven Schedules, final after 6,915 public inputs on the draft of 3 January 2025, whose consultation MeitY (the Ministry of Electronics and Information Technology) extended to 5 March 2025.

Why we give a month, not a day

Rule 1(3) and Rule 1(4) count the future tranches from the publication date, and official sources disagree on it. The notification line says 13 November 2025; the e-Gazette code, the Controller of Publications' digital signature and the Press Information Bureau backgrounder of 17 November 2025 say 14 November. Practitioners are split, so we plan to the earlier reading and give months only.

Public authorities: the RTI amendment is under challenge

Section 44(3), which rewrote section 8(1)(j) of the RTI Act, is live and under constitutional challenge. In February 2026 the Supreme Court issued notice in The Reporters Collective Trust v. Union of India, referred the questions to a larger bench and declined an interim stay, so the framework operates as notified.

How DPDP works

Six DPDP rules that shape your compliance work.

If you run a GDPR program, these are the parts to rebuild. For EU data, see GDPR compliance.

Digital personal data only

Section 3(a) covers data collected digitally, or on paper and later digitized. No special category exists for health, biometrics, religion or caste, unlike GDPR Article 9.

Consent, or a closed list

Consent under section 6, or a legitimate use listed in section 7. No balancing test: a use neither consented nor listed is unlawful, so consent has to be redesigned.

A Consent Manager, with no EU equivalent

A registered intermediary under Rule 4 and the First Schedule: a company incorporated in India, net worth not less than Rs 2 crore, articles it can amend only with the Board's prior approval. It runs an interoperable platform it cannot itself read, independently certified against a standards and assurance framework the Board publishes on its website. Registration, from November 2026, is a license, and nobody can promise you a date for one.

Two breach clocks, no threshold

Rule 7 runs one clock to each affected Data Principal and one to the Board, both without delay. Seventy-two hours applies only to the six-part follow-up report. No materiality test: every personal data breach is notifiable.

Transfer runs the other way

DPDP permits transfer unless the Central Government restricts it under section 16; GDPR forbids it without a mechanism. No adequacy list, standard contractual clauses (SCCs), binding corporate rules or transfer impact assessment. Rule 13(4), a hook for keeping data in India, targets only Significant Data Fiduciaries, and nothing has been specified under it.

Fewer rights, and duties for individuals

Access, correction, erasure, grievance redressal and a section 14 right to nominate someone to act for you. No portability, right to object or rules on solely automated decisions. Section 15 puts duties on individuals, with a penalty of up to Rs 10,000 for a false or frivolous grievance.

How an engagement runs

What must exist by May 2027, and who signs it.

Finding your data takes longest. Budget eight to twelve weeks for an honest inventory. Against a six to twelve month workload, starting now is uncomfortable but workable.

  1. Data inventory and flow map

    Where your data lives and flows, separating section 3(a) digital personal data from anonymized, non-personal and never-digitized records.

  2. Purpose and lawful-basis register

    Most organizations have no purpose list, so consent has nothing to attach to. We map each processing activity to consent under section 6 or a named limb of section 7.

  3. Notices, in up to 23 languages

    A standalone Rule 3 notice itemizing each item of personal data against each purpose, with withdrawal as easy as the grant. Section 5(3) gives each person the option of English or any of the 22 Eighth Schedule languages, so a consumer product needs 23 versions of every consent string, with a translation control log.

  4. Security safeguards

    Mapped clause by clause against Rule 6(1)(a) to (g). The one-year log retention in Rule 6(1)(e) is built, not just claimed, through our log analysis and detection work.

  5. Breach runbook

    Both Rule 7 clocks, with the five-item notice to individuals and the six-item Board report drafted in advance. CERT-In's six-hour direction sits above both: it binds you today; DPDP's does not. See incident response.

  6. Retention and erasure schedule

    We reconcile three rules. The Third Schedule's three-year inactivity trigger binds only three named classes of platform. Rule 8(2) requires a warning forty-eight hours before erasure and Rule 8(3) sets a one-year minimum; those two pull against each other.

  7. Retro-notice plan and today's rules

    A section 5(2) retro-notice plan for everyone who consented before commencement. Plus a gap assessment against today's rules: IT Act section 43A and the SPDI Rules, 2011, which stay operative until section 44(2) repeals section 43A in tranche (c).

What we sign

There is no DPDP certificate. We sign an opinion instead.

Nobody can issue an organization a DPDP certificate or compliance seal: not a consultancy, not an auditor, not a government body. We sign a DPDP readiness assessment against the Act and the Rules instead, with a stated scope and basis, in our own name.

If a customer's procurement team wants a certificate, the honest route is ISO 27701 privacy information management certification from an accredited certification body. The current edition, ISO/IEC 27701:2025, published on 14 October 2025, no longer requires ISO 27001 certification first, unlike the 2019 edition. A standalone certificate still depends on your certification body having transitioned to ISO/IEC 27706:2025.

We also won't declare you a Significant Data Fiduciary, or say you aren't one: designation under section 10(1), which brings extra duties, is the Central Government's call, and no entity or class has been notified. Our signed readiness memo gives a likelihood view instead. Nor will we tell you that you face DPDP penalties today: none can lawfully be imposed before tranche (c).

What this work does not include. An audit or a certificate: we hold no accreditation to audit anyone against anything, and no certificate of our own. We work remotely from India.

Related: third-party risk, compliance as a service, all compliance work.

FAQ

Questions Indian buyers ask about DPDP.

Partly. Tranche (a) of G.S.R. 843(E) commenced on publication: definitions, the Data Protection Board, the rule-making powers and the RTI amendment. Nothing there creates a duty you owe an individual. Those duties, the Rule 6 safeguards, the Rule 7 breach clocks and the penalties all sit in tranche (c), which lands in May 2027.

No. November 2025 brought only the institutional provisions and the Rules. G.S.R. 843(E) lists sections 3 to 17 in clause (c), the eighteen-month tranche, and sections 6(9) and 27(1)(d) alone in clause (b). Rule 1(4) says the same for Rules 3 and 5 to 16.

No. The Act creates no certification scheme, no accreditation body, no approved code of conduct and no seal. The single certification in the Rules is First Schedule Part A item 9, which applies to a company applying to register as a Consent Manager. It is a precondition to registration, not a market badge. What you can hold is a readiness assessment with a defined scope, signed by SecWiz in our own name.

Less than you would like. The record of processing and the security work transfer reasonably well. The lawful bases do not: with no legitimate-interests balancing test, anything resting on legitimate interests has to be rebuilt or dropped. Your SCC package does nothing here, because transfer runs on a restriction model under section 16 rather than an authorization model. A data protection officer (DPO) is mandatory only for a Significant Data Fiduciary.

MeitY floated the idea at a stakeholder meeting in January 2026, at least for Significant Data Fiduciaries. So far no amending notification has been gazetted, so the tranches in G.S.R. 843(E) and Rule 1 stand as notified and we scope to those. If you are a plausible Significant Data Fiduciary, the proposal still argues for starting discovery now rather than in early 2027.

Not under the DPDP Act, and it cannot yet. The Board exists, but section 27, which carries its functions, sits in tranche (c), apart from section 27(1)(d) on Consent Manager breaches, which arrives with the one-year tranche in November 2026. Section 33, the power to impose penalties, is also in tranche (c). Until then there is no DPDP complaint to file and no DPDP penalty that can lawfully be imposed on anyone.

Almost certainly not. There is no revenue, headcount or volume threshold anywhere in the Act. Employee records, contractor data and the named individuals at your customer accounts are all personal data, and for most B2B firms the HR system is the largest DPDP exposure in the building. Section 3(b) also reaches a foreign company with no Indian entity where the processing connects to offering goods or services to people in India. What is genuinely out: paper records never digitized, and data an individual has made public herself.

Not as a standalone claim. DPDP puts its duties on the Data Fiduciary, not directly on the processor, so a compliant-processor badge is a category error Indian IT services and BPO firms make constantly. What you can be is a well-contracted processor: the Rule 6(1)(f) clause in every agreement, flow-down obligations to your own subprocessors, log retention that supports your client's Rule 6(1)(e) duty, and a breach path that gets your client to both Rule 7 clocks on time.

Let's talk

Find out where you stand before May 2027.

Send us a system list, your current privacy notice and whatever passes for a data map. You get back a scope and a schedule built around the Act's start dates, not a round number of weeks. We reply within one working day.