DPDP Act 2023: The Complete 2026 Compliance Guide for Data Fiduciaries and Processors

DPDP Act

Last updated on August 8th, 2026 at 07:35 pm

TL;DR: The Digital Personal Data Protection Act, 2023 governs how anyone, anywhere, handles the digital personal data of people in India. Its Rules were notified on 14 November 2025, and full compliance is due by 13 May 2027. The Act covers not just Indian companies but any business in the world that processes an Indian resident’s personal data in connection with offering them goods or services, even with no office, server, or employee in India. There is no small-business exemption. This guide starts with the basic vocabulary the Act uses, explains exactly who is covered and who is genuinely exempt, and then gives a step-by-step implementation plan split for small businesses and larger companies.

Quick overview: Before applicability or compliance makes sense, the terms need to be clear, because most confusion about this law comes from people not knowing what a “Data Principal” or “Data Fiduciary” actually means, or assuming the Act is only about Indian companies. This guide is built in that order: what the words mean, who is covered (including businesses outside India), what is genuinely exempt, what you must build, and how to build it depending on the size of your operation.

The basic vocabulary: who is who under the Act

The Act uses a specific, deliberate set of terms, and understanding them is the foundation for everything else.

Data Principal. The individual to whom the personal data belongs, the person the data is about. If a company holds your name, phone number, and purchase history, you are the Data Principal for that data. For a child under 18, or a person with a disability who has a lawful guardian, the parent or guardian exercises rights on their behalf as the Data Principal’s representative.

Personal Data. Any data about an individual who is identifiable by or in relation to that data. This is broad by design: a name, phone number, email address, physical address, photograph, device or location data, or any combination of data points that identifies a specific person, all count. It covers digital personal data specifically, meaning data collected in digital form, or non-digital data that is subsequently digitised (a paper form later scanned or entered into a database, for instance).

Data Fiduciary. Any person or entity, alone or with others, that determines the purpose and means of processing personal data. In plain terms: whoever decides why the data is collected and how it will be used is the Data Fiduciary. This includes companies, LLPs, partnerships, sole proprietors, and government bodies. If your business decides to collect customer emails to send order updates, you are the Data Fiduciary for that data, regardless of your size.

Data Processor. Any person or entity that processes personal data on behalf of a Data Fiduciary, under its instructions, rather than for its own independent purposes. A payment gateway, an email delivery service, a cloud hosting provider, or an outsourced customer-support vendor is typically a Data Processor when it handles data strictly as instructed by the Data Fiduciary that engaged it. The Act places the primary compliance responsibility on the Data Fiduciary, but Processors are drawn in through the contracts between them, covered further below.

Significant Data Fiduciary (SDF). A Data Fiduciary the government formally designates as significant, based on factors such as the volume and sensitivity of the data it processes and the risk to individuals’ rights. SDFs carry materially heavier obligations, explained later in this guide.

Data Protection Board of India. The body established under the Act to receive complaints, investigate breaches and non-compliance, and impose penalties. It is now operational, following the Rules notified in November 2025.

With these terms in place, the rest of the Act reads far more clearly: it is a law that governs what Data Fiduciaries and their Processors must do with the personal data of Data Principals, enforced by the Data Protection Board.

Who the Act covers: territorial reach, including businesses outside India

This is the part most guides underexplain, and it matters more than most businesses realise.

Inside India. The Act applies to the processing of digital personal data within India, regardless of the nationality of the Data Principal or the Data Fiduciary. An Indian company processing an Indian customer’s data is squarely covered. So, in fact, is an Indian company processing the data of a foreign tourist while they are in India.

Outside India, extraterritorial reach. This is the provision businesses most often miss. The Act also applies to the processing of digital personal data outside India, wherever the entity doing the processing is located, if that processing is connected with offering goods or services to individuals within India. There is no requirement for the business to have an office, server, or employee in India. The test is functional: is the business offering goods or services directed at people in India, not merely whether an Indian user happens to stumble onto a global website.

What this looks like in practice: a software-as-a-service company based entirely in the United States, with no Indian office or infrastructure, that lets Indian customers sign up and pay for its product, is a Data Fiduciary under the DPDP Act for the data of those Indian users. So is a UK-based e-commerce site that ships to Indian addresses and stores Indian customers’ names and delivery details. So is a global advertising-technology company serving ads to devices located in India. None of these businesses need a physical presence in India to be covered; what brings them into scope is that they are processing the personal data of people in India in connection with offering those people something. The trigger is the Data Principal’s location and where the data is processed, not their nationality. An Indian citizen living in the US whose data is handled entirely by US companies, a US employer, a local bank, a US shopping app, falls outside the Act for that data; Indian citizenship alone does not pull it in. The same person’s data is covered the moment it is processed ‘within the territory of India’, for example when they manage an NRE/NRO account with an Indian bank, invest through an Indian stockbroker, or buy from an Indian e-commerce platform while abroad. It is also covered if a foreign platform explicitly targets users located in India and they sign up as such a user. Conversely, a foreign tourist or expatriate physically in India is protected by the Act for data collected during their time there, regardless of their nationality.

For any business operating across borders, our guide on why having international users means having international legal obligations and our comparison of data protection laws around the world put this extraterritorial reach in context alongside GDPR and other regimes, since the DPDP Act’s approach here deliberately mirrors GDPR’s own extraterritorial provision.

A direct applicability test

Given the definitions and scope above, ask two questions.

Question 1: Do you collect, store, or use any personal data of an identifiable individual, in digital form? This includes names, phone numbers, email addresses, addresses, employee records, customer databases, even a simple spreadsheet or CRM with contact details.

Question 2: Is the personal data itself processed within India, or are you offering goods or services to individuals located in India, regardless of their nationality and wherever your own business is based? If the answer to both is yes, you are a Data Fiduciary and the Act applies to you in full, whether you are an Indian sole proprietor or a foreign company with no presence in the country.

There is no size-based exemption anywhere in this test. A three-person startup storing customer data in a spreadsheet is a Data Fiduciary in exactly the same legal sense as a large enterprise. What differs between them is not whether the law applies, but how much needs to be built to comply, covered in the steps below.

What is genuinely exempt

The real exemptions are narrow, and knowing them precisely avoids both over-compliance and, more commonly, the mistaken assumption of an exemption that does not exist.

Personal or domestic use. Processing purely for personal or domestic purposes, your own phone contacts, for example, falls outside the Act.

Data the individual has made publicly available themselves. If a person has voluntarily made their own personal data public, or a person legally required to make it public has done so, processing that specific data is exempt.

Enforcing a legal right or claim. Processing necessary to establish, exercise, or defend a legal right or claim is exempt.

Journalistic, academic, artistic, or literary purposes. Processing carried out in the course of journalistic activity, or for academic, artistic, or literary purposes, has a specific carve-out.

Government functions. Processing necessary for India’s sovereignty and integrity, national security, and certain state functions is exempt or subject to a separate standard.

Research and archiving. Processing for research, archiving, or statistical purposes, carried out with safeguards, has a specific exemption.

Corporate restructuring. Processing connected with court- or tribunal-approved mergers, acquisitions, or similar restructuring has specific carve-outs.

What is not a real exemption: being a small business, not selling data, only using data internally, or being based outside India. None of these remove your obligations. If your data footprint is small, the practical compliance burden is lighter, but the legal duty is not zero, and if you offer goods or services to people in India, your location outside the country does not exempt you either.

What every data fiduciary must actually have in place

Six obligations apply to every Data Fiduciary regardless of size or location. Here is what each means in practice.

1. Valid consent, with no legitimate-interest fallback. This is a critical difference from GDPR that trips up businesses assuming familiarity. The DPDP Act does not recognise “legitimate interest” as a lawful basis for processing. Consent is the primary basis, and it must be free, specific, informed, unconditional, and unambiguous, collected through a clear affirmative action, no pre-ticked boxes, no consent walls, no bundled consent covering unrelated purposes. In practice: your signup forms, cookie banners, and any point where you collect data need a genuine opt-in, not an assumed one.

2. Itemised, plain-language notice. At the point you collect data, you must tell the Data Principal, in plain language, exactly what categories of data you are collecting and why, for each purpose separately. A vague “we collect data to improve our services” notice does not meet this standard. In practice: this is your privacy policy and your in-app or on-form notices, and they need to itemise, not generalise.

3. Reasonable security safeguards. Appropriate technical and organisational measures to prevent breaches, proportionate to what you handle. Critically, the penalty for failing to maintain reasonable safeguards can be triggered by the absence of adequate measures alone; an actual breach is not required to attract liability of up to Rs 250 crore. In practice: access controls, basic encryption where relevant, and a documented, even if simple, security policy.

4. Dual breach notification capability. If a breach happens, you must inform the affected Data Principals without delay, in plain language, and separately report to the Data Protection Board within 72 hours. In practice: you need a plan for this before a breach happens, who does what, in what order, within what hours, not something improvised under pressure.

5. Data Principal rights fulfilment. Working mechanisms for a Data Principal to request access to their data, ask for a correction, ask for erasure, raise a grievance, or nominate someone to act for them if they die or become incapacitated. In practice: an email address or process that actually gets a response, not just a clause in your privacy policy that nobody monitors.

6. A clear contact point. Every Data Fiduciary must display contact details for data-related queries. Only Significant Data Fiduciaries need a formal, India-based Data Protection Officer; everyone else needs a real, working contact point, which can be as simple as a monitored email address.

Our guide on what a privacy policy must cover, our DPDP-compliant privacy policy drafting service, and our consent management guide cover building obligations 1, 2, and 5 correctly. For processing a child’s data specifically: verifiable parental consent is required, and behavioural monitoring, tracking, and targeted advertising directed at children is prohibited outright, regardless of consent.

The three-phase compliance timeline

The Rules operate on an 18-month phased rollout from their notification date.

Phase 1: Immediate (from 14 November 2025). The Data Protection Board of India was constituted and its procedural rules came into force. Complaint and enforcement mechanisms are operational.

Phase 2: 12 months (around 13 November 2026). The Consent Manager framework opens for registration, a regulated entity that lets a Data Principal manage consent across multiple Data Fiduciaries from one interface.

Phase 3: 18 months (13 May 2027). Full substantive compliance becomes mandatory, notice, consent, security safeguards, breach notification, and Data Principal rights, all operational, with no announced grace period.

A caution worth building into any plan: officials have discussed compressing this window from 18 to 12 months, which would move the deadline earlier. Treat May 2027 as the latest possible date to be ready, not a comfortable target.

Step by step: what to do, by the size of your business

If you are a small business, startup, or solo operator

You have the same legal obligations as a large company, but a far smaller build. Do these in order.

Step 1: List where you collect personal data. Every form, every signup, every spreadsheet where you store a customer’s or employee’s name, contact details, or similar. Most small businesses are surprised how many places this actually is.

Step 2: Write or update your privacy policy to itemise what you collect and why, in plain language, for each purpose. This is usually the fastest win and the most commonly missing piece.

Step 3: Fix your consent points. Check every signup form, checkout, and cookie banner for pre-ticked boxes or bundled consent, and fix them to require a genuine opt-in per purpose.

Step 4: Set up one real contact point for data requests and grievances, monitored by an actual person, and note it in your privacy policy.

Step 5: Write a one-page breach response plan. Who gets notified internally, who tells affected users, who reports to the Board, and within what timeframe. It does not need to be elaborate; it needs to exist and be followed.

Step 6: Check your vendor contracts (payment processors, email tools, cloud storage) for basic data-handling and breach-cooperation language.

This is achievable without a large budget or a dedicated compliance team, and it should be complete well before the May 2027 deadline, not started close to it.

If you are a larger company, platform, or handle sensitive or high-volume data

Do everything above, at a more rigorous standard, and add the following.

Step 1: Map data flows across every system and every vendor, not just customer-facing forms, including internal tools, analytics, marketing platforms, and outsourced processors.

Step 2: Assess whether you are likely to be designated a Significant Data Fiduciary. The government designates SDFs based on six factors under the Act: the volume and sensitivity of personal data processed, the risk to Data Principals’ rights, the potential impact on India’s sovereignty and integrity, the risk to electoral democracy, the security of the state, and public order. If you process data at meaningful scale, particularly sensitive categories such as financial, health, or biometric data, or run a large consumer platform, budget for SDF-level obligations now rather than waiting for formal designation.

Step 3: If SDF criteria plausibly apply, build the enhanced layer: an India-based Data Protection Officer, a programme for periodic independent data audits, Data Protection Impact Assessments for high-risk processing activities, and stricter due diligence before deploying new or sensitive technologies, including certain AI systems.

Step 4: Formalise consent architecture for scale, including preparing to integrate with registered Consent Managers once that framework opens in November 2026.

Step 5: Update every vendor and processor contract with DPDP-compliant data processing terms, security standards, breach-cooperation clauses, sub-processing restrictions, and data-return or deletion obligations at the end of the engagement. Our DPA template and technology lawyers can help here.

Step 6: Build breach response at scale, with a tested internal escalation path that satisfies both the 72-hour Board reporting window and, where applicable, CERT-In’s six-hour rule, without the two contradicting each other.

If you are a foreign business with Indian users and no India presence, the same six steps apply, plus one addition: consider appointing an India-based point of contact or representative. It is not universally mandated for every fiduciary, but it meaningfully reduces enforcement friction and demonstrates good-faith compliance to the Data Protection Board.

For a general overview of website and platform legal requirements alongside DPDP, see legal documents your website cannot ignore and legal documents every SaaS startup needs, and check your current position with our free DPDP compliance checker.

Penalties: what non-compliance actually costs

The Act’s penalty structure is steep, and penalties can stack across multiple violations arising from the same conduct. Failing to maintain reasonable security safeguards can attract penalties up to Rs 250 crore. Breach-notification failures and violations involving children’s data can each attract penalties up to Rs 200 crore. Failures specific to Significant Data Fiduciary obligations can attract penalties up to Rs 150 crore. General non-compliance carries penalties up to Rs 50 crore. These are ceilings per contravention, not a single aggregate cap, which is why a gap analysis now is materially cheaper than remediation after an enforcement action, and this applies equally to a foreign company with Indian users as to a company incorporated in India.

The bottom line

There is no deadline for “starting to think about DPDP.” The deadline is 13 May 2027 for having it actually built and working, and businesses that leave it late will be doing rushed, expensive compliance under a compressed timeline. Whether you are a two-person startup, a listed company, or a business based entirely outside India with Indian customers, the steps above are the same shape, scoped to your size: know where your data is, tell people what you do with it honestly, get real consent, be ready if something goes wrong, and hold your vendors to the same standard. Our legal compliance checklist for startups in India is a useful companion for founders building this alongside their other statutory obligations, and our contract drafting and contract review services can update your vendor and customer contracts to reflect DPDP requirements.

Frequently asked questions

What is a Data Principal under the DPDP Act?

A Data Principal is the individual to whom personal data relates, the person the data is about. If a business holds someone’s name, contact details, or purchase history, that person is the Data Principal for that data. For a child under 18, or a person with a disability who has a lawful guardian, the parent or guardian acts as the Data Principal’s representative in exercising rights under the Act.

What is the difference between a Data Fiduciary and a Data Processor?

A Data Fiduciary is the entity that determines the purpose and means of processing personal data, essentially whoever decides why data is collected and how it will be used. A Data Processor processes personal data on behalf of a Data Fiduciary, under its instructions, rather than for its own independent purposes, such as a payment gateway or cloud hosting provider. The Data Fiduciary carries the primary legal responsibility under the Act, and is expected to bind its Processors to the same standards through contract.

Does the DPDP Act apply to businesses based outside India?

Yes. The Act has extraterritorial reach: it applies to the processing of digital personal data outside India whenever that processing is connected with offering goods or services to individuals within India, regardless of whether the business has an office, server, or employee in India. A foreign SaaS company, e-commerce site, or app that lets Indian users sign up or buy from it is a Data Fiduciary under the Act for the data of those Indian users, in the same way as an Indian company would be.

Does the DPDP Act apply to small businesses and startups?

Yes. There is no small-business exemption under the DPDP Act. Any entity, including a sole proprietor, partnership, LLP, or private limited company, that determines the purpose and means of processing personal data of individuals in India is a Data Fiduciary and subject to the Act, regardless of size. What differs by size is the scale of what you need to build to comply, not whether the law applies.

What is genuinely exempt from the DPDP Act?

The real exemptions are narrow: processing purely for personal or domestic purposes, data an individual has voluntarily made publicly available themselves, processing necessary to enforce a legal right or claim, journalistic, academic, artistic, or literary purposes, certain government functions related to sovereignty and security, research and archiving carried out with safeguards, and processing connected to court-approved corporate restructuring. Being a small business, not selling data, only using data internally, or being based outside India are not recognised exemptions.

What are the penalties for DPDP non-compliance?

Penalties can reach up to Rs 250 crore for failing to maintain reasonable security safeguards, up to Rs 200 crore each for breach-notification failures and violations involving children’s data, up to Rs 150 crore for Significant Data Fiduciary obligation failures, and up to Rs 50 crore for general non-compliance. These are ceilings per violation and can stack, so a single incident touching multiple obligations can attract several penalties simultaneously, whether the fiduciary is based in India or abroad.

If I am an Indian citizen living abroad, does the DPDP Act protect my data?

Not automatically. The DPDP Act runs on territory and the location of processing, not citizenship. If you are physically abroad and your data is processed entirely by foreign companies, a foreign employer, a foreign bank, a local shopping app, in that country, the Act does not apply, regardless of your Indian passport. However, your data is covered the moment it is processed within India, for example when you operate an NRE/NRO account with an Indian bank, invest through an Indian broker, or use an Indian e-commerce platform while living abroad. It is also covered if a foreign platform is specifically targeting users located in India and you sign up as such a user.


Authored and reviewed by Prakhar Rai, Advocate, founder of My Legal Pal. Prakhar is enrolled with the Bar Council of India and has over ten years of experience advising businesses on data protection, technology, and regulatory compliance in India and cross-border. He is an alumnus of the National Law School of India University, Bangalore, where he completed his Master of Business Laws, and of La Martiniere. Connect on LinkedIn.

This article is general information, not legal advice. DPDP compliance requirements are technical and the regulatory timeline may change. For advice on your organisation’s specific obligations as a data fiduciary or processor, speak to a qualified lawyer.

If you need your privacy policy, consent flows, or vendor contracts brought in line with the DPDP Rules, our team can help. Start with our DPDP-compliant privacy policy drafting service, check your current position with our free DPDP compliance checker, or speak to our technology lawyers about a full compliance gap assessment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha