DPDP Act Readiness & Compliance
India's Digital Personal Data Protection Act is now in force, and the Rules that operationalize it are notified — with the clock running on a phased compliance window. We get you ready: designing your notice, consent, rights and breach machinery with your teams, and validating your security safeguards the way an attacker would test them — so the protection you owe data principals is real, not just documented.
A law, not a certificate. CERT-In Empaneled. We don't just write the policy — we test that your safeguards actually hold.
India's data-protection law — and what it now asks of you
The Digital Personal Data Protection Act, 2023 is India's first comprehensive law dedicated to personal data.
It governs how organizations may process the digital personal data of individuals, recognizing both a person's right to protect their data and the need to process it for lawful purposes. The Act calls the individual a Data Principal, the organization that decides why and how data is processed a Data Fiduciary, and anyone processing on a fiduciary's behalf a Data Processor. Throughout, the burden sits with the fiduciary: you may process personal data only with consent or for a defined set of legitimate uses, you must tell people what you are doing and why, you must honour their rights, you must keep their data secure, and you must answer for a breach.
The Act was passed in 2023, but the part that turns it into a live obligation arrived later. The Digital Personal Data Protection Rules, 2025 were notified in November 2025, bringing a phased commencement: the Data Protection Board and the law's procedural machinery took effect on notification, Consent Manager registration follows after one year, and the core obligations of every Data Fiduciary — notice, consent, security safeguards, breach reporting, rights and grievance handling — become enforceable eighteen months from notification, in mid-2027. That window is not spare time; it is the runway to build consent, rights and breach processes that work, and to prove that the safeguards behind them do too. Organizations that wait until the deadline will be retrofitting privacy under pressure. The ones that start now build it properly.
"The Act doesn't ask whether you have a security policy. It asks whether your safeguards are reasonable — and the only honest way to answer that is to test them."
Who the DPDP Act applies to
The DPDP Act is not industry-specific. If you process the digital personal data of people in India, it reaches you — wherever you process it.
The Act applies to processing digital personal data within India, whether collected digitally or digitized afterwards — across every sector, public and private.
It also applies to processing outside India where that processing is connected to offering goods or services to Data Principals in India — so location offshore is not an exemption.
Whether you process on consent or on one of the Act’s "certain legitimate uses," you must be able to demonstrate the lawful basis for every purpose.
Processing a child’s data requires verifiable parental consent, and behavioural tracking or targeted advertising to children is prohibited — a high bar that needs real controls.
Organizations the government designates as Significant Data Fiduciaries — by data volume, sensitivity and risk — carry extra duties: DPIAs, an independent data audit, and a Data Protection Officer.
Non-compliance is adjudicated by the Data Protection Board of India, with financial penalties under the Act’s Schedule — making DPDP readiness a board-level assurance question, not just a legal one.
Who's who under the Act — and who owes what
The DPDP Act assigns clear roles, and the obligations follow the role. Getting the mapping right — which role you play, for which data, and therefore which duties bind you — is the first step of readiness.
The Data Principal holds rights; the Data Fiduciary carries the bulk of the duties; the Data Processor acts only under the fiduciary's contract; the Consent Manager is a registered intermediary that lets people manage consent in one place; and a Significant Data Fiduciary is a fiduciary the government designates for heightened obligations.
The individual the data is about. Holds the rights: access, correction & erasure, grievance redressal and nomination. (For a child, the parent or lawful guardian acts on their behalf.)
Determines the purpose and means of processing, and carries the obligations: lawful basis, notice, consent, security safeguards, breach intimation, erasure and grievance handling — responsible even when a Processor does the work.
Processes personal data only on behalf of a Data Fiduciary, and only under a valid contract. The fiduciary remains accountable for what its processors do.
A person registered with the Data Protection Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent — accountable to the Data Principal.
A fiduciary designated by the Central Government on volume, sensitivity and risk grounds — with extra duties: a Data Protection Officer, an independent data auditor, periodic Data Protection Impact Assessment and periodic audit.
From data discovery to sustained compliance
There is no DPDP certificate to obtain — readiness here means a working privacy programme and the evidence that it functions.
Our job is to build that with you and prove it: map where personal data lives, stand up notice, consent, rights and breach processes, and validate that the security safeguards the Act requires genuinely hold. We take you from a first data-mapping exercise to a programme that sustains itself as the Rules and your processing evolve.
FIG. 02 — DPDP readiness lifecycle · 7 steps · step 04 (Sec 8) is the offensive-edge, VAPT-backed step · step 06 applies to Significant Data Fiduciaries
Privacy on paper is a claim. A consent flow that works, a rights request that gets answered in time, and a safeguard that withstands a real test — that is compliance you can stand behind, to your board and to the Board.
What an engagement includes
We scope to your role and your risk — a first-time privacy programme, a GDPR programme being extended to India, or an SDF preparing for independent audit — and cover the work end to end.
Personal-data discovery and data-flow mapping
across systems, vendors and cross-border transfers
Records of processing
purpose, lawful basis (consent or legitimate use), retention and role (fiduciary vs processor) for each activity
Gap assessment against the DPDP Act, 2023 and the DPDP Rules, 2025
Notice and consent design aligned to Sec 5–6
plain-language notice, valid consent, easy withdrawal
Consent-record and consent-withdrawal handling
Consent Manager integration where applicable
Children's-data controls
verifiable parental consent and the prohibition on tracking and targeted advertising to children (Sec 9)
Data Principal rights workflows
access, correction, erasure and nomination (Sec 11–14)
Grievance-redressal mechanism
with prescribed response times (Sec 13)
Data-retention and erasure logic
erase when consent is withdrawn or the purpose is served (Sec 8)
Technical validation of the "reasonable security safeguards" required by Sec 8
penetration testing and configuration review that proves controls actually work
Evidence collection and an audit-ready artifact pack
Remediation retest after fixes
Breach-response process design
detection, severity assessment, escalation
Data Protection Board and Data Principal intimation playbooks (Sec 8)
in the prescribed form and manner
Tabletop exercises to rehearse the response before it is needed
Data Protection Impact Assessment (DPIA) for high-risk processing
(Sec 10)
Independent data audit of DPDP compliance (Sec 10)
a role for which CERT-In empanelment is well-suited
Data Protection Officer enablement
continuous-compliance support as the Rules phase in and processing evolves
"Reasonable security safeguards" have to actually be reasonable.
The Act doesn't ask whether you wrote a security policy. It requires reasonable security safeguards to prevent a personal data breach — and a safeguard you have never tested is a safeguard you are only hoping works.
The paper privacy programme
Most DPDP readiness work stops at documentation — a data map, a consent banner, a policy that says the right things and a security section that lists the controls you believe you have. It satisfies the letter of a gap assessment. But Section 8 puts the obligation on the outcome: prevent the breach. A documented encryption standard and an encryption control an attacker can route around are not the same thing — and the difference is exactly what surfaces in a breach you then have to report to the Board.
Safeguards proven by testing
Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the Act expects access control, encryption, logging and breach detection to be effective, our researchers test them — safely, the way an adversary would — and bring you evidence that the safeguard performs. You walk into the compliance window with controls that have already withstood a real probe, and a defensible answer to the one question the Act actually asks: were your safeguards reasonable?
A policy proves intent. A test proves the safeguard. When you have to account for a breach to the Data Protection Board, only one of those will help you.
PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the artefacts your privacy programme needs to operate — and the evidence pack that shows the Act's obligations are being met, not just described.
Data map & records of processing
Where personal data lives, why it is processed, on what lawful basis, and the role you play for each activity.
DPDP gap assessment report
Your current state mapped against the DPDP Act, 2023 and the DPDP Rules, 2025, with a prioritized roadmap to readiness.
Notice, consent & rights design
Notice templates, consent and withdrawal flows, and operational workflows for access, correction, erasure, nomination and grievance redressal.
Security-safeguards validation report
Pentest-backed evidence that the Section 8 safeguards genuinely work, with remediation guidance and retest.
Breach-response playbook
A rehearsed process for intimating the Data Protection Board and affected Data Principals, in the prescribed form and manner.
DPIA & independent data audit report (SDF)
Data Protection Impact Assessment and the independent data audit required of Significant Data Fiduciaries under Section 10.
Audit-ready evidence pack
Collected, organized artefacts that map cleanly to the Act's obligations and the Rules.
Why teams choose Intect for DPDP readiness
CERT-In Empaneled — A real, regulator-recognized credential under India's national cybersecurity authority — and the right profile to serve as the independent data auditor the Act requires of Significant Data Fiduciaries.
We build and we break — Most privacy consultancies only write policy. We design your DPDP programme and test the security safeguards behind it, so your Section 8 evidence is proven, not asserted.
Researcher-led, not template-led — Senior practitioners who understand both the law and the adversary — so your data map, rights workflows and safeguards reflect your real processing, not a copy-paste privacy kit.
Delhi-based, India-fluent — An India-based team that tracks the DPDP Rules as they phase in and speaks the language of the Data Protection Board — available to your team through the engagement.
Frequently asked questions
Is there a "DPDP certificate" we can get?
No. The DPDP Act is a law, not a certification scheme — there is no certificate any consultancy or government body issues to say you "have DPDP." What exists is compliance with the Act’s obligations, and the evidence that your processing meets them. Intect makes you ready: we build the consent, rights and breach machinery, validate your security safeguards by testing them, and — for Significant Data Fiduciaries — provide the independent data audit the Act requires. Beware anyone selling a "DPDP certificate."
When do we actually have to comply?
The Act was passed in 2023, and the DPDP Rules that operationalize it were notified in November 2025 with a phased commencement. The Data Protection Board and procedural provisions took effect on notification; Consent Manager registration follows after one year; and the core Data Fiduciary obligations — notice, consent, security safeguards, breach reporting, rights and grievance handling — become enforceable eighteen months from notification, in mid-2027. That window is the time to build readiness properly; we sequence the work to fit it.
Are we a "Significant Data Fiduciary"?
A Significant Data Fiduciary is a fiduciary the Central Government designates, based on factors including the volume and sensitivity of personal data you process and the risk to Data Principals, to electoral democracy, to the sovereignty of India, to the security of the State and to public order. If you are designated, you take on extra duties: a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments and audits. We help you assess whether you are likely in scope and prepare for those obligations either way.
How is DPDP different from GDPR?
They share DNA — both are consent-and-rights frameworks that put the burden on the organization — but DPDP is its own law with its own vocabulary (Data Principal, Data Fiduciary, Consent Manager, Significant Data Fiduciary), its own regulator (the Data Protection Board of India), and its own Rules and timelines. If you already run a GDPR programme, much of the foundation transfers; we map the delta to DPDP rather than starting over. See our GDPR and ISO 27701 pages for the adjacent work.
What happens if we have a breach?
The Act requires a Data Fiduciary, on a personal data breach, to give intimation to the Data Protection Board and to each affected Data Principal, in the form and manner prescribed by the Rules. The penalty for failing to take reasonable security safeguards to prevent a breach can extend to a very large sum under the Act’s Schedule — so breach prevention and a rehearsed breach response both matter. We prepare both: tested safeguards on the front end, and a playbook that makes the reporting obligation executable on the day.
Who enforces the Act, and what are the penalties?
Non-compliance is adjudicated by the Data Protection Board of India, which can impose monetary penalties set out in the Act’s Schedule. The Schedule scales the penalty to the breach — with the highest tier, for failing to take reasonable security safeguards to prevent a personal data breach, able to extend to ₹250 crore. We focus your effort where the obligation and the exposure are greatest.
Privacy is a programme, not a page
DPDP readiness rarely stands alone — it connects to your wider privacy and security posture.
Build privacy that's true — and prove it.
Tell us where you are — a first DPDP programme, a GDPR programme extending to India, or an SDF preparing for independent audit — and we'll scope a readiness assessment that fits, or connect you with an assessor.