Compliance · DPDP Act Digital Personal Data Protection Act, 2023 · Rules 2025

DPDP Act Readiness & Compliance

India's Digital Personal Data Protection Act is now in force, and the Rules that operationalize it are notified — with the clock running on a phased compliance window. We get you ready: designing your notice, consent, rights and breach machinery with your teams, and validating your security safeguards the way an attacker would test them — so the protection you owe data principals is real, not just documented.

A law, not a certificate. CERT-In Empaneled. We don't just write the policy — we test that your safeguards actually hold.

DPDP Act, 2023 (Act No. 22 of 2023) DPDP Rules, 2025 Data Protection Board of India CERT-In Empaneled
Law
DPDP Act, 2023 (Act No. 22 of 2023)
Rules
DPDP Rules, 2025 — notified · phased to mid-2027
Role
Readiness & advisory — a law, not a certificate
Validation
Section 8 safeguards proven by VAPT
02

India's data-protection law — and what it now asks of you

The Digital Personal Data Protection Act, 2023 is India's first comprehensive law dedicated to personal data.

It governs how organizations may process the digital personal data of individuals, recognizing both a person's right to protect their data and the need to process it for lawful purposes. The Act calls the individual a Data Principal, the organization that decides why and how data is processed a Data Fiduciary, and anyone processing on a fiduciary's behalf a Data Processor. Throughout, the burden sits with the fiduciary: you may process personal data only with consent or for a defined set of legitimate uses, you must tell people what you are doing and why, you must honour their rights, you must keep their data secure, and you must answer for a breach.

The Act was passed in 2023, but the part that turns it into a live obligation arrived later. The Digital Personal Data Protection Rules, 2025 were notified in November 2025, bringing a phased commencement: the Data Protection Board and the law's procedural machinery took effect on notification, Consent Manager registration follows after one year, and the core obligations of every Data Fiduciary — notice, consent, security safeguards, breach reporting, rights and grievance handling — become enforceable eighteen months from notification, in mid-2027. That window is not spare time; it is the runway to build consent, rights and breach processes that work, and to prove that the safeguards behind them do too. Organizations that wait until the deadline will be retrofitting privacy under pressure. The ones that start now build it properly.

"The Act doesn't ask whether you have a security policy. It asks whether your safeguards are reasonable — and the only honest way to answer that is to test them."
03

Who the DPDP Act applies to

The DPDP Act is not industry-specific. If you process the digital personal data of people in India, it reaches you — wherever you process it.

You process personal data of people in India

The Act applies to processing digital personal data within India, whether collected digitally or digitized afterwards — across every sector, public and private.

You serve Indian users from outside India

It also applies to processing outside India where that processing is connected to offering goods or services to Data Principals in India — so location offshore is not an exemption.

You rely on consent or legitimate uses

Whether you process on consent or on one of the Act’s "certain legitimate uses," you must be able to demonstrate the lawful basis for every purpose.

You handle children's or guardians' data

Processing a child’s data requires verifiable parental consent, and behavioural tracking or targeted advertising to children is prohibited — a high bar that needs real controls.

You may be a Significant Data Fiduciary

Organizations the government designates as Significant Data Fiduciaries — by data volume, sensitivity and risk — carry extra duties: DPIAs, an independent data audit, and a Data Protection Officer.

You answer to a board and to regulators

Non-compliance is adjudicated by the Data Protection Board of India, with financial penalties under the Act’s Schedule — making DPDP readiness a board-level assurance question, not just a legal one.

04

Who's who under the Act — and who owes what

The DPDP Act assigns clear roles, and the obligations follow the role. Getting the mapping right — which role you play, for which data, and therefore which duties bind you — is the first step of readiness.

The Data Principal holds rights; the Data Fiduciary carries the bulk of the duties; the Data Processor acts only under the fiduciary's contract; the Consent Manager is a registered intermediary that lets people manage consent in one place; and a Significant Data Fiduciary is a fiduciary the government designates for heightened obligations.

05

From data discovery to sustained compliance

There is no DPDP certificate to obtain — readiness here means a working privacy programme and the evidence that it functions.

Our job is to build that with you and prove it: map where personal data lives, stand up notice, consent, rights and breach processes, and validate that the security safeguards the Act requires genuinely hold. We take you from a first data-mapping exercise to a programme that sustains itself as the Rules and your processing evolve.

01
Data Discovery & Mapping
We find the personal data you actually hold — where it is collected, stored, shared and sent — and map every processing activity to its purpose, lawful basis and the role you play. You cannot protect or account for what you have not mapped.
02
Notice & Consent (Sec 5–6)
We design the notice and consent flows the Act requires (Sec 5–6): clear and plain-language notice of what and why, free, specific, informed and unambiguous consent, easy withdrawal, and — where relevant — integration with a registered Consent Manager.
03
Rights & Grievance Workflows (Sec 11–14)
We build the workflows that honour Data Principal rights (Sec 11–14): access, correction and erasure, nomination, and a grievance-redressal mechanism that responds within the prescribed time — operational processes, not just policy statements.
04
Security Safeguards Validation (Sec 8)
We assess the "reasonable security safeguards" the Act demands to prevent a personal data breach — and we validate them by testing. This is the offensive edge: safeguards proven against a real probe, not signed off on a checklist.
05
Breach Readiness
We prepare your breach-response process so that, in the event of a personal data breach, you can intimate the Data Protection Board and each affected Data Principal in the prescribed form and manner — with the detection, escalation and reporting machinery rehearsed before you need it.
06
SDF Obligations: DPIA + Independent Audit (Sec 10)
For Significant Data Fiduciaries, we run periodic Data Protection Impact Assessments and the independent data audit the Act requires (Sec 10), and support the Data Protection Officer function — independent, evidence-based assurance over your highest-risk processing.
07
Sustain
DPDP compliance is continuous. We help you keep the programme current as the Rules phase in, as your processing changes, and as the Data Protection Board issues guidance — re-mapping, re-testing and re-auditing on a defensible cadence.

FIG. 02 — DPDP readiness lifecycle · 7 steps · step 04 (Sec 8) is the offensive-edge, VAPT-backed step · step 06 applies to Significant Data Fiduciaries

Privacy on paper is a claim. A consent flow that works, a rights request that gets answered in time, and a safeguard that withstands a real test — that is compliance you can stand behind, to your board and to the Board.

06

What an engagement includes

We scope to your role and your risk — a first-time privacy programme, a GDPR programme being extended to India, or an SDF preparing for independent audit — and cover the work end to end.

Discover & map
01

Personal-data discovery and data-flow mapping

across systems, vendors and cross-border transfers

02

Records of processing

purpose, lawful basis (consent or legitimate use), retention and role (fiduciary vs processor) for each activity

03

Gap assessment against the DPDP Act, 2023 and the DPDP Rules, 2025

Govern consent & notice
04

Notice and consent design aligned to Sec 5–6

plain-language notice, valid consent, easy withdrawal

05

Consent-record and consent-withdrawal handling

Consent Manager integration where applicable

06

Children's-data controls

verifiable parental consent and the prohibition on tracking and targeted advertising to children (Sec 9)

Operationalize rights
07

Data Principal rights workflows

access, correction, erasure and nomination (Sec 11–14)

08

Grievance-redressal mechanism

with prescribed response times (Sec 13)

09

Data-retention and erasure logic

erase when consent is withdrawn or the purpose is served (Sec 8)

Validate safeguards (the offensive edge)
10

Technical validation of the "reasonable security safeguards" required by Sec 8

penetration testing and configuration review that proves controls actually work

11

Evidence collection and an audit-ready artifact pack

12

Remediation retest after fixes

Breach readiness
13

Breach-response process design

detection, severity assessment, escalation

14

Data Protection Board and Data Principal intimation playbooks (Sec 8)

in the prescribed form and manner

15

Tabletop exercises to rehearse the response before it is needed

SDF obligations & sustain
16

Data Protection Impact Assessment (DPIA) for high-risk processing

(Sec 10)

17

Independent data audit of DPDP compliance (Sec 10)

a role for which CERT-In empanelment is well-suited

18

Data Protection Officer enablement

continuous-compliance support as the Rules phase in and processing evolves

07

"Reasonable security safeguards" have to actually be reasonable.

The Act doesn't ask whether you wrote a security policy. It requires reasonable security safeguards to prevent a personal data breach — and a safeguard you have never tested is a safeguard you are only hoping works.

Safeguards on paper

The paper privacy programme

Most DPDP readiness work stops at documentation — a data map, a consent banner, a policy that says the right things and a security section that lists the controls you believe you have. It satisfies the letter of a gap assessment. But Section 8 puts the obligation on the outcome: prevent the breach. A documented encryption standard and an encryption control an attacker can route around are not the same thing — and the difference is exactly what surfaces in a breach you then have to report to the Board.

Safeguards that have been proven

Safeguards proven by testing

Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the Act expects access control, encryption, logging and breach detection to be effective, our researchers test them — safely, the way an adversary would — and bring you evidence that the safeguard performs. You walk into the compliance window with controls that have already withstood a real probe, and a defensible answer to the one question the Act actually asks: were your safeguards reasonable?

A policy proves intent. A test proves the safeguard. When you have to account for a breach to the Data Protection Board, only one of those will help you.

PENTEST-BACKED EVIDENCE
08

What you receive

Every engagement produces the artefacts your privacy programme needs to operate — and the evidence pack that shows the Act's obligations are being met, not just described.

01

Data map & records of processing

Where personal data lives, why it is processed, on what lawful basis, and the role you play for each activity.

02

DPDP gap assessment report

Your current state mapped against the DPDP Act, 2023 and the DPDP Rules, 2025, with a prioritized roadmap to readiness.

03

Notice, consent & rights design

Notice templates, consent and withdrawal flows, and operational workflows for access, correction, erasure, nomination and grievance redressal.

04

Security-safeguards validation report

Pentest-backed evidence that the Section 8 safeguards genuinely work, with remediation guidance and retest.

VAPT-BACKED
05

Breach-response playbook

A rehearsed process for intimating the Data Protection Board and affected Data Principals, in the prescribed form and manner.

06

DPIA & independent data audit report (SDF)

Data Protection Impact Assessment and the independent data audit required of Significant Data Fiduciaries under Section 10.

07

Audit-ready evidence pack

Collected, organized artefacts that map cleanly to the Act's obligations and the Rules.

DPDP Act, 2023 DPDP Rules, 2025 CERT-In Empaneled SDF independent data auditor VAPT-backed validation Supports GDPR & ISO 27701 readiness
09

Why teams choose Intect for DPDP readiness

CERT-In Empaneled Delhi-based · India-fluent

CERT-In Empaneled — A real, regulator-recognized credential under India's national cybersecurity authority — and the right profile to serve as the independent data auditor the Act requires of Significant Data Fiduciaries.

We build and we break — Most privacy consultancies only write policy. We design your DPDP programme and test the security safeguards behind it, so your Section 8 evidence is proven, not asserted.

Researcher-led, not template-led — Senior practitioners who understand both the law and the adversary — so your data map, rights workflows and safeguards reflect your real processing, not a copy-paste privacy kit.

Delhi-based, India-fluent — An India-based team that tracks the DPDP Rules as they phase in and speaks the language of the Data Protection Board — available to your team through the engagement.

10

Frequently asked questions

Is there a "DPDP certificate" we can get?

No. The DPDP Act is a law, not a certification scheme — there is no certificate any consultancy or government body issues to say you "have DPDP." What exists is compliance with the Act’s obligations, and the evidence that your processing meets them. Intect makes you ready: we build the consent, rights and breach machinery, validate your security safeguards by testing them, and — for Significant Data Fiduciaries — provide the independent data audit the Act requires. Beware anyone selling a "DPDP certificate."

When do we actually have to comply?

The Act was passed in 2023, and the DPDP Rules that operationalize it were notified in November 2025 with a phased commencement. The Data Protection Board and procedural provisions took effect on notification; Consent Manager registration follows after one year; and the core Data Fiduciary obligations — notice, consent, security safeguards, breach reporting, rights and grievance handling — become enforceable eighteen months from notification, in mid-2027. That window is the time to build readiness properly; we sequence the work to fit it.

Are we a "Significant Data Fiduciary"?

A Significant Data Fiduciary is a fiduciary the Central Government designates, based on factors including the volume and sensitivity of personal data you process and the risk to Data Principals, to electoral democracy, to the sovereignty of India, to the security of the State and to public order. If you are designated, you take on extra duties: a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments and audits. We help you assess whether you are likely in scope and prepare for those obligations either way.

How is DPDP different from GDPR?

They share DNA — both are consent-and-rights frameworks that put the burden on the organization — but DPDP is its own law with its own vocabulary (Data Principal, Data Fiduciary, Consent Manager, Significant Data Fiduciary), its own regulator (the Data Protection Board of India), and its own Rules and timelines. If you already run a GDPR programme, much of the foundation transfers; we map the delta to DPDP rather than starting over. See our GDPR and ISO 27701 pages for the adjacent work.

What happens if we have a breach?

The Act requires a Data Fiduciary, on a personal data breach, to give intimation to the Data Protection Board and to each affected Data Principal, in the form and manner prescribed by the Rules. The penalty for failing to take reasonable security safeguards to prevent a breach can extend to a very large sum under the Act’s Schedule — so breach prevention and a rehearsed breach response both matter. We prepare both: tested safeguards on the front end, and a playbook that makes the reporting obligation executable on the day.

Who enforces the Act, and what are the penalties?

Non-compliance is adjudicated by the Data Protection Board of India, which can impose monetary penalties set out in the Act’s Schedule. The Schedule scales the penalty to the breach — with the highest tier, for failing to take reasonable security safeguards to prevent a personal data breach, able to extend to ₹250 crore. We focus your effort where the obligation and the exposure are greatest.

11

Privacy is a programme, not a page

DPDP readiness rarely stands alone — it connects to your wider privacy and security posture.

Scope an engagement

Build privacy that's true — and prove it.

Tell us where you are — a first DPDP programme, a GDPR programme extending to India, or an SDF preparing for independent audit — and we'll scope a readiness assessment that fits, or connect you with an assessor.