[{"data":1,"prerenderedAt":1970},["ShallowReactive",2],{"dpdp-hub":3},[4,467,707,928,1197,1438,1684],{"id":5,"title":6,"author":7,"body":8,"category":435,"date":436,"description":437,"draft":438,"extension":439,"eyebrow":440,"faq":441,"h1":448,"keywords":449,"meta":453,"navigation":39,"ogTitle":454,"path":455,"readingTime":456,"relatedArticles":457,"relatedServices":459,"seo":462,"stem":463,"tags":464,"updated":465,"__hash__":466},"dpdp\u002Fdpdp-act\u002Fcompliance-checklist.md","DPDP Compliance Checklist (2026)","DreamyHook Consultancy Services",{"type":9,"value":10,"toc":421},"minimark",[11,21,26,79,87,91,148,156,160,198,204,208,259,265,269,298,302,359,363,393,396,401,415],[12,13,14,15,20],"p",{},"DPDP compliance can feel overwhelming. It needn't be. This checklist breaks it into clear stages — roughly the order we work through with clients. Treat it as a map, then ",[16,17,19],"a",{"href":18},"\u002Fquick-scan","scan your readiness"," to see where you actually stand.",[22,23,25],"h2",{"id":24},"stage-1-discover","Stage 1 — Discover",[27,28,31,47,56,65],"ul",{"className":29},[30],"contains-task-list",[32,33,36,41,42,46],"li",{"className":34},[35],"task-list-item",[37,38],"input",{"disabled":39,"type":40},true,"checkbox"," ",[43,44,45],"strong",{},"Map your personal data."," What do you collect, where does it live, who can access it, where does it flow?",[32,48,50,41,52,55],{"className":49},[35],[37,51],{"disabled":39,"type":40},[43,53,54],{},"Build a record of processing (ROPA)."," Purposes, categories, retention, recipients.",[32,57,59,41,61,64],{"className":58},[35],[37,60],{"disabled":39,"type":40},[43,62,63],{},"List your processors."," Every vendor and tool that touches personal data.",[32,66,68,41,70,73,74,78],{"className":67},[35],[37,69],{"disabled":39,"type":40},[43,71,72],{},"Check your SDF likelihood."," Could you be notified a ",[16,75,77],{"href":76},"\u002Fdpdp-act\u002Fsignificant-data-fiduciary","Significant Data Fiduciary","?",[12,80,81,82,86],{},"A ",[16,83,85],{"href":84},"\u002Fservices\u002Freadiness-audit","readiness audit"," does all of this systematically.",[22,88,90],{"id":89},"stage-2-notice-consent","Stage 2 — Notice & consent",[27,92,94,103,112,121,130,139],{"className":93},[30],[32,95,97,41,99,102],{"className":96},[35],[37,98],{"disabled":39,"type":40},[43,100,101],{},"Rewrite your notices"," to be clear, itemized, and specific.",[32,104,106,41,108,111],{"className":105},[35],[37,107],{"disabled":39,"type":40},[43,109,110],{},"Offer notices in the user's language"," (English + Eighth Schedule languages).",[32,113,115,41,117,120],{"className":114},[35],[37,116],{"disabled":39,"type":40},[43,118,119],{},"Capture consent properly"," — free, specific, informed, unconditional, unambiguous.",[32,122,124,41,126,129],{"className":123},[35],[37,125],{"disabled":39,"type":40},[43,127,128],{},"Make withdrawal as easy as consent",", and stop downstream processing when it's withdrawn.",[32,131,133,41,135,138],{"className":132},[35],[37,134],{"disabled":39,"type":40},[43,136,137],{},"Keep a consent ledger"," — tamper-evident evidence of who agreed to what, when.",[32,140,142,41,144,147],{"className":141},[35],[37,143],{"disabled":39,"type":40},[43,145,146],{},"Plan for Consent Managers."," Architect so you can integrate when they go live.",[12,149,150,151,155],{},"See ",[16,152,154],{"href":153},"\u002Fservices\u002Fconsent-management","Consent & Notice Management",".",[22,157,159],{"id":158},"stage-3-data-principal-rights","Stage 3 — Data Principal rights",[27,161,163,172,181,189],{"className":162},[30],[32,164,166,41,168,171],{"className":165},[35],[37,167],{"disabled":39,"type":40},[43,169,170],{},"Stand up a rights workflow"," for access, correction, completion, updating, and erasure.",[32,173,175,41,177,180],{"className":174},[35],[37,176],{"disabled":39,"type":40},[43,178,179],{},"Add grievance redressal"," that's readily available.",[32,182,184,41,186],{"className":183},[35],[37,185],{"disabled":39,"type":40},[43,187,188],{},"Support nomination.",[32,190,192,41,194,197],{"className":191},[35],[37,193],{"disabled":39,"type":40},[43,195,196],{},"Track SLAs"," so you respond within the required timelines.",[12,199,150,200,155],{},[16,201,203],{"href":202},"\u002Fservices\u002Fdata-principal-rights","Data Principal Rights Automation",[22,205,207],{"id":206},"stage-4-security-retention","Stage 4 — Security & retention",[27,209,211,220,229,238,250],{"className":210},[30],[32,212,214,41,216,219],{"className":213},[35],[37,215],{"disabled":39,"type":40},[43,217,218],{},"Encrypt"," personal data in transit and at rest.",[32,221,223,41,225,228],{"className":222},[35],[37,224],{"disabled":39,"type":40},[43,226,227],{},"Lock down access"," with role-based controls.",[32,230,232,41,234,237],{"className":231},[35],[37,233],{"disabled":39,"type":40},[43,235,236],{},"Log processing"," and retain logs as required.",[32,239,241,41,243,246,247,155],{"className":240},[35],[37,242],{"disabled":39,"type":40},[43,244,245],{},"Set retention rules"," by purpose, and ",[43,248,249],{},"automate deletion",[32,251,253,41,255,258],{"className":252},[35],[37,254],{"disabled":39,"type":40},[43,256,257],{},"Back up"," safely, with a defensible deletion approach.",[12,260,150,261,155],{},[16,262,264],{"href":263},"\u002Fservices\u002Ftechnical-implementation","Technical Implementation",[22,266,268],{"id":267},"stage-5-breach-readiness","Stage 5 — Breach readiness",[27,270,272,280,289],{"className":271},[30],[32,273,275,41,277],{"className":274},[35],[37,276],{"disabled":39,"type":40},[43,278,279],{},"Deploy breach detection \u002F monitoring.",[32,281,283,41,285,288],{"className":282},[35],[37,284],{"disabled":39,"type":40},[43,286,287],{},"Write a notification runbook"," for the Board and affected users.",[32,290,292,41,294,297],{"className":291},[35],[37,293],{"disabled":39,"type":40},[43,295,296],{},"Run a drill"," so the process is tested, not theoretical.",[22,299,301],{"id":300},"stage-6-governance","Stage 6 — Governance",[27,303,305,319,333,346],{"className":304},[30],[32,306,308,41,310,313,314,318],{"className":307},[35],[37,309],{"disabled":39,"type":40},[43,311,312],{},"Appoint a grievance officer"," (and a ",[16,315,317],{"href":316},"\u002Fservices\u002Fdpo-as-a-service","DPO"," if you're an SDF or your customers require one).",[32,320,322,41,324,327,328,332],{"className":321},[35],[37,323],{"disabled":39,"type":40},[43,325,326],{},"Draft your policies and DPAs"," (via ",[16,329,331],{"href":330},"\u002Fservices\u002Flegal-and-policy","legal partners",").",[32,334,336,41,338,341,342,155],{"className":335},[35],[37,337],{"disabled":39,"type":40},[43,339,340],{},"Train your team"," — ",[16,343,345],{"href":344},"\u002Fservices\u002Ftraining","awareness and engineering workshops",[32,347,349,41,351,354,355,155],{"className":348},[35],[37,350],{"disabled":39,"type":40},[43,352,353],{},"Schedule ongoing reviews"," with ",[16,356,358],{"href":357},"\u002Fservices\u002Fmanaged-compliance","Managed Compliance",[22,360,362],{"id":361},"stage-7-special-cases","Stage 7 — Special cases",[27,364,366,375,384],{"className":365},[30],[32,367,369,41,371,374],{"className":368},[35],[37,370],{"disabled":39,"type":40},[43,372,373],{},"Children's data:"," verifiable parental consent; no tracking or targeting of minors.",[32,376,378,41,380,383],{"className":377},[35],[37,379],{"disabled":39,"type":40},[43,381,382],{},"Large-platform retention:"," inactivity-based deletion if you cross notified thresholds.",[32,385,387,41,389,392],{"className":386},[35],[37,388],{"disabled":39,"type":40},[43,390,391],{},"Cross-border transfers:"," documentation in line with the framework.",[394,395],"hr",{},[397,398,400],"h3",{"id":399},"your-fastest-first-step","Your fastest first step",[12,402,403,404,407,408,410,411,155],{},"Don't guess which of these you've missed. The free ",[16,405,406],{"href":18},"DPDP Quick Scan"," turns this checklist into a personalized scorecard in five minutes — then a ",[16,409,85],{"href":84}," turns that into a costed plan to the ",[16,412,414],{"href":413},"\u002Fdpdp-act\u002Ftimeline-deadlines","deadline",[416,417,418],"blockquote",{},[12,419,420],{},"General information, not legal advice. Confirm specifics against the notified DPDP Rules.",{"title":422,"searchDepth":423,"depth":423,"links":424},"",3,[425,427,428,429,430,431,432],{"id":24,"depth":426,"text":25},2,{"id":89,"depth":426,"text":90},{"id":158,"depth":426,"text":159},{"id":206,"depth":426,"text":207},{"id":267,"depth":426,"text":268},{"id":300,"depth":426,"text":301},{"id":361,"depth":426,"text":362,"children":433},[434],{"id":399,"depth":423,"text":400},"Practical","2026-03-01","A practical, step-by-step DPDP Act compliance checklist for Indian businesses — what to do, in what order, to be ready before the deadline.",false,"md","Checklist",[442,445],{"q":443,"a":444},"Is this checklist enough to be compliant?","It's a strong starting framework, but real compliance depends on your specific data and systems. Use it to orient, then validate with a readiness audit and, where needed, legal advice.",{"q":446,"a":447},"Where should we start?","Start by mapping your data — you can't protect or govern what you haven't found. A readiness audit does this systematically.","The DPDP compliance checklist (2026)",[450,451,452],"DPDP compliance checklist","how to comply with DPDP Act","DPDP checklist India",{},null,"\u002Fdpdp-act\u002Fcompliance-checklist","7 min read",[458,413],"\u002Fdpdp-act\u002Fwhat-is-dpdp-act",[460,461],"readiness-audit","technical-implementation",{"title":6,"description":437},"dpdp-act\u002Fcompliance-checklist",[],"2026-05-25","asMKA9Y5ap2Vj3Zqw1_41SQ8OF0eyolqUp0y-WTcZPk",{"id":468,"title":469,"author":7,"body":470,"category":681,"date":682,"description":683,"draft":438,"extension":439,"eyebrow":681,"faq":684,"h1":691,"keywords":692,"meta":696,"navigation":39,"ogTitle":454,"path":697,"readingTime":698,"relatedArticles":699,"relatedServices":700,"seo":702,"stem":703,"tags":704,"updated":705,"__hash__":706},"dpdp\u002Fdpdp-act\u002Fdpdp-rules-2025.md","DPDP Rules 2025, Explained",{"type":9,"value":471,"toc":668},[472,479,495,499,511,515,519,532,536,541,545,554,558,563,567,588,592,610,614,621,625,658,663],[12,473,474,475,478],{},"The DPDP Act, 2023 sets the principles. The ",[43,476,477],{},"DPDP Rules"," turn those principles into operational requirements — the practical detail your systems and processes actually have to meet. This guide explains what the Rules cover and what to do about them.",[416,480,481],{},[12,482,483,486,487,490,491,494],{},[43,484,485],{},"Status note (dated):"," Draft DPDP Rules were published for consultation in ",[43,488,489],{},"January 2025",". The Government has signalled finalization and phased notification since. Because exact figures and dates can change between draft and final text, treat specific numbers below as drawn from the draft and ",[43,492,493],{},"confirm them against the official notified Rules"," before relying on them.",[22,496,498],{"id":497},"why-the-rules-matter-more-than-the-act-day-to-day","Why the Rules matter more than the Act, day to day",[12,500,501,502,506,507,510],{},"The Act tells you ",[503,504,505],"em",{},"what"," (get valid consent, protect data, honor rights). The Rules tell you ",[503,508,509],{},"how"," — the format of notices, the timelines for responding to requests, what counts as \"reasonable\" security, and the precise duties of Significant Data Fiduciaries. Compliance work lives in the Rules.",[22,512,514],{"id":513},"what-the-rules-address","What the Rules address",[397,516,518],{"id":517},"consent-and-notice-mechanics","Consent and notice mechanics",[12,520,521,522,525,526,529,530,155],{},"The Rules detail how notices must be presented — clear, itemized, available in English and the languages of the Eighth Schedule — and how consent and ",[43,523,524],{},"withdrawal"," must work. They also set the framework for ",[43,527,528],{},"Consent Managers",", the registered intermediaries who will let people manage consents in one place. We design for this in ",[16,531,154],{"href":153},[397,533,535],{"id":534},"security-safeguards","Security safeguards",[12,537,538,539,155],{},"The Rules describe the kind of reasonable security measures expected — including encryption, access control, logging, and the retention of processing logs for a defined period — so that \"reasonable safeguards\" isn't left to guesswork. We build these in ",[16,540,264],{"href":263},[397,542,544],{"id":543},"breach-notification","Breach notification",[12,546,547,548,551,552,155],{},"The Rules set out how and when to notify the ",[43,549,550],{},"Data Protection Board of India"," and affected Data Principals after a personal data breach, including the information your notification must contain. A tested runbook is essential — see our breach-readiness work in ",[16,553,358],{"href":357},[397,555,557],{"id":556},"data-principal-rights","Data Principal rights",[12,559,560,561,155],{},"The Rules specify how Data Fiduciaries must enable and respond to rights requests — access, correction, erasure, grievance — within defined timelines. Automating this is the only way to stay reliable at scale: see ",[16,562,203],{"href":202},[397,564,566],{"id":565},"childrens-data","Children's data",[12,568,569,570,573,574,578,579,583,584,155],{},"The Rules address ",[43,571,572],{},"verifiable parental consent"," and the mechanics of age assurance, alongside the Act's prohibition on tracking, behavioural monitoring, and targeted advertising directed at children. This is especially important for ",[16,575,577],{"href":576},"\u002Findustries\u002Fedtech","edtech",", ",[16,580,582],{"href":581},"\u002Findustries\u002Fhealthtech","healthtech",", and ",[16,585,587],{"href":586},"\u002Findustries\u002Fonline-gaming","online gaming",[397,589,591],{"id":590},"significant-data-fiduciaries","Significant Data Fiduciaries",[12,593,594,595,598,599,602,603,606,607,155],{},"For organizations notified as SDFs, the Rules detail the added duties — appointing a ",[43,596,597],{},"DPO based in India",", conducting an ",[43,600,601],{},"annual Data Protection Impact Assessment",", and undergoing an ",[43,604,605],{},"annual independent audit",". See ",[16,608,609],{"href":76},"What is a Significant Data Fiduciary?",[397,611,613],{"id":612},"retention-and-erasure","Retention and erasure",[12,615,616,617,620],{},"The draft Rules introduced ",[43,618,619],{},"default retention limits for large platforms"," — for example, erasing personal data after roughly three years of user inactivity (with advance notice) for large e-commerce, online gaming, and social-media intermediaries above notified user thresholds. Confirm the thresholds and periods against the final text.",[22,622,624],{"id":623},"what-to-do-now","What to do now",[626,627,628,636,647],"ol",{},[32,629,630,633,634,155],{},[43,631,632],{},"Map your obligations to the Rules",", not just the Act — that's where the work is. Start with a ",[16,635,85],{"href":84},[32,637,638,41,641,646],{},[43,639,640],{},"Prioritize by the",[16,642,643],{"href":413},[43,644,645],{},"timeline"," — build the deadline-critical controls first.",[32,648,649,41,652,657],{},[43,650,651],{},"Use the",[16,653,654],{"href":455},[43,655,656],{},"compliance checklist"," to track progress.",[12,659,660,661,155],{},"Want a personalized read on which Rule obligations bite hardest for you? Take the free ",[16,662,406],{"href":18},[416,664,665],{},[12,666,667],{},"General information, not legal advice. Always confirm against the official notified Rules.",{"title":422,"searchDepth":423,"depth":423,"links":669},[670,671,680],{"id":497,"depth":426,"text":498},{"id":513,"depth":426,"text":514,"children":672},[673,674,675,676,677,678,679],{"id":517,"depth":423,"text":518},{"id":534,"depth":423,"text":535},{"id":543,"depth":423,"text":544},{"id":556,"depth":423,"text":557},{"id":565,"depth":423,"text":566},{"id":590,"depth":423,"text":591},{"id":612,"depth":423,"text":613},{"id":623,"depth":426,"text":624},"Rules","2026-01-20","What the DPDP Rules mean for your business — the operational detail behind the Act, the phased timeline, and the obligations you need to act on.",[685,688],{"q":686,"a":687},"When were the DPDP Rules released?","Draft DPDP Rules were released for public consultation in January 2025. The government has indicated the Rules are being finalized and notified on a phased basis — confirm the current status of any provision against the official notification.",{"q":689,"a":690},"Do the Rules change what the Act requires?","The Rules don't change the Act's principles — they add the operational detail: how consent notices should work, breach-notification timelines, SDF obligations, children's-data mechanics, and more.","DPDP Rules 2025, explained",[693,694,695],"DPDP Rules 2025","DPDP Rules explained","DPDP implementation",{},"\u002Fdpdp-act\u002Fdpdp-rules-2025","8 min read",[413,455],[461,701],"consent-management",{"title":469,"description":683},"dpdp-act\u002Fdpdp-rules-2025",[],"2026-05-22","uZTzEmpF7zdOOaHxAM9GmUtRNBc8gl8JOYIBdD3Z9ME",{"id":708,"title":709,"author":7,"body":710,"category":908,"date":909,"description":910,"draft":438,"extension":439,"eyebrow":911,"faq":912,"h1":913,"keywords":914,"meta":918,"navigation":39,"ogTitle":454,"path":919,"readingTime":920,"relatedArticles":921,"relatedServices":922,"seo":923,"stem":924,"tags":925,"updated":926,"__hash__":927},"dpdp\u002Fdpdp-act\u002Fglossary.md","DPDP Act Glossary of Terms",{"type":9,"value":711,"toc":901},[712,718,722,728,738,748,757,763,772,776,782,788,794,800,804,814,820,829,835,839,845,851,857,863,867,876,882,888,890,896],[12,713,714,715,155],{},"The DPDP Act uses specific terms with precise meanings. Here they are in plain English. For the full picture, start with ",[16,716,717],{"href":458},"What is the DPDP Act?",[22,719,721],{"id":720},"core-roles","Core roles",[12,723,724,727],{},[43,725,726],{},"Data Principal"," — The individual whom the personal data is about. If it's a child, the parent or lawful guardian; if a person with disability, their lawful guardian.",[12,729,730,733,734,737],{},[43,731,732],{},"Data Fiduciary"," — The person or organization that, alone or with others, determines the ",[43,735,736],{},"purpose and means"," of processing personal data. Most businesses are Data Fiduciaries.",[12,739,740,743,744,747],{},[43,741,742],{},"Data Processor"," — Anyone who processes personal data ",[43,745,746],{},"on behalf of"," a Data Fiduciary (for example, a cloud host or analytics vendor).",[12,749,750,753,754,155],{},[43,751,752],{},"Significant Data Fiduciary (SDF)"," — A Data Fiduciary notified by the government as higher-risk, with extra duties. See ",[16,755,756],{"href":76},"the SDF guide",[12,758,759,762],{},[43,760,761],{},"Consent Manager"," — A registered intermediary, accountable to the Data Principal, that provides a single interface to give, manage, review, and withdraw consent.",[12,764,765,768,769,155],{},[43,766,767],{},"Data Protection Officer (DPO)"," — The individual an SDF must appoint, based in India, as the point of contact for data-protection grievances. Available as a service via ",[16,770,771],{"href":316},"DPO-as-a-Service",[22,773,775],{"id":774},"data-processing","Data & processing",[12,777,778,781],{},[43,779,780],{},"Personal data"," — Any data about an individual who is identifiable by or in relation to such data.",[12,783,784,787],{},[43,785,786],{},"Digital personal data"," — Personal data in digital form — what the Act governs.",[12,789,790,793],{},[43,791,792],{},"Processing"," — Any operation on personal data: collection, storage, use, sharing, erasure, and more.",[12,795,796,799],{},[43,797,798],{},"Purpose"," — The specific reason for which personal data is processed, which must be lawful and stated to the Data Principal.",[22,801,803],{"id":802},"consent-notice","Consent & notice",[12,805,806,809,810,813],{},[43,807,808],{},"Consent"," — Agreement that is ",[43,811,812],{},"free, specific, informed, unconditional, and unambiguous",", given by a clear affirmative action, and limited to the stated purpose.",[12,815,816,819],{},[43,817,818],{},"Notice"," — The clear, itemized information a Data Fiduciary must give a Data Principal about what data is collected and why, and how to withdraw consent and complain.",[12,821,822,825,826,155],{},[43,823,824],{},"Withdrawal of consent"," — The right to take back consent, which must be ",[43,827,828],{},"as easy to do as it was to give",[12,830,831,834],{},[43,832,833],{},"Legitimate uses"," — Certain situations where personal data may be processed without fresh consent (for example, where a Data Principal has voluntarily provided data for a specified purpose, or for certain state functions).",[22,836,838],{"id":837},"rights-duties","Rights & duties",[12,840,841,844],{},[43,842,843],{},"Right to access"," — A Data Principal's right to a summary of their personal data and the recipients it's shared with.",[12,846,847,850],{},[43,848,849],{},"Right to correction and erasure"," — The right to have personal data corrected, completed, updated, or erased.",[12,852,853,856],{},[43,854,855],{},"Right to grievance redressal"," — The right to a readily available means of complaint.",[12,858,859,862],{},[43,860,861],{},"Right to nominate"," — The right to nominate another person to exercise one's rights in case of death or incapacity.",[22,864,866],{"id":865},"enforcement","Enforcement",[12,868,869,871,872,155],{},[43,870,550],{}," — The independent regulator that investigates breaches and complaints and can impose ",[16,873,875],{"href":874},"\u002Fdpdp-act\u002Fpenalties","penalties",[12,877,878,881],{},[43,879,880],{},"Personal data breach"," — Any unauthorized processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises its confidentiality, integrity, or availability.",[12,883,884,887],{},[43,885,886],{},"Data Protection Impact Assessment (DPIA)"," — A structured assessment of the risks processing poses to Data Principals and the measures to manage them; required (annually) for SDFs.",[394,889],{},[12,891,892,893,895],{},"Not sure how these apply to your business? The free ",[16,894,406],{"href":18}," translates the terms into your specific situation.",[416,897,898],{},[12,899,900],{},"General information, not legal advice. Definitions are simplified — confirm against the official Act.",{"title":422,"searchDepth":423,"depth":423,"links":902},[903,904,905,906,907],{"id":720,"depth":426,"text":721},{"id":774,"depth":426,"text":775},{"id":802,"depth":426,"text":803},{"id":837,"depth":426,"text":838},{"id":865,"depth":426,"text":866},"Reference","2026-03-15","A plain-English glossary of DPDP Act terms — Data Fiduciary, Data Principal, Consent Manager, SDF, and more, defined simply.","Glossary",[],"DPDP Act glossary of terms",[915,916,917],"DPDP Act terms","DPDP glossary","DPDP definitions",{},"\u002Fdpdp-act\u002Fglossary","5 min read",[458,697],[460,701],{"title":709,"description":910},"dpdp-act\u002Fglossary",[],"2026-05-20","oc5pzQ42c5eYcOQWJOud9DHARQ0cKNLTtszxlm74K-Q",{"id":929,"title":930,"author":7,"body":931,"category":866,"date":1173,"description":1174,"draft":438,"extension":439,"eyebrow":1175,"faq":1176,"h1":1183,"keywords":1184,"meta":1187,"navigation":39,"ogTitle":454,"path":874,"readingTime":1188,"relatedArticles":1189,"relatedServices":1190,"seo":1192,"stem":1193,"tags":1194,"updated":1195,"__hash__":1196},"dpdp\u002Fdpdp-act\u002Fpenalties.md","DPDP Act Penalties & Enforcement",{"type":9,"value":932,"toc":1166},[933,944,948,954,958,961,1037,1040,1044,1067,1074,1078,1081,1108,1112,1119,1153,1156,1161],[12,934,935,936,939,940,943],{},"The DPDP Act has teeth. Financial penalties run up to ",[43,937,938],{},"₹250 crore",", and enforcement sits with a dedicated regulator. This guide explains the penalties, who imposes them, and — more usefully — how to keep your exposure low. We do this ",[43,941,942],{},"without fear-mongering",": the point isn't the scary number, it's that good engineering makes the number irrelevant.",[22,945,947],{"id":946},"who-enforces-it-the-data-protection-board","Who enforces it: the Data Protection Board",[12,949,950,951,953],{},"The ",[43,952,550],{}," is the independent regulator created by the Act. It investigates complaints from Data Principals and reports of breaches, gives organizations a chance to be heard, and can impose financial penalties for non-compliance. Its decisions are appealable.",[22,955,957],{"id":956},"the-penalties","The penalties",[12,959,960],{},"Penalties are graded to the nature and gravity of the failure. The headline figures (per the Act's schedule) include:",[962,963,964,977],"table",{},[965,966,967],"thead",{},[968,969,970,974],"tr",{},[971,972,973],"th",{},"Failure",[971,975,976],{},"Penalty up to",[978,979,980,990,1000,1009,1019,1029],"tbody",{},[968,981,982,986],{},[983,984,985],"td",{},"Failure to take reasonable security safeguards to prevent a breach",[983,987,988],{},[43,989,938],{},[968,991,992,995],{},[983,993,994],{},"Failure to notify the Board \u002F affected persons of a breach",[983,996,997],{},[43,998,999],{},"₹200 crore",[968,1001,1002,1005],{},[983,1003,1004],{},"Breach of additional obligations relating to children",[983,1006,1007],{},[43,1008,999],{},[968,1010,1011,1014],{},[983,1012,1013],{},"Breach of additional obligations of Significant Data Fiduciaries",[983,1015,1016],{},[43,1017,1018],{},"₹150 crore",[968,1020,1021,1024],{},[983,1022,1023],{},"Breach of other provisions \u002F duties",[983,1025,1026],{},[43,1027,1028],{},"₹50 crore",[968,1030,1031,1034],{},[983,1032,1033],{},"Breach of a voluntary undertaking",[983,1035,1036],{},"up to the applicable amount",[12,1038,1039],{},"Data Principals also have duties, and there are smaller penalties for frivolous or false complaints.",[22,1041,1043],{"id":1042},"how-penalties-are-decided","How penalties are decided",[12,1045,1046,1047,1050,1051,1054,1055,1058,1059,1062,1063,1066],{},"The Board considers factors such as the ",[43,1048,1049],{},"nature and gravity"," of the breach, its ",[43,1052,1053],{},"duration",", the ",[43,1056,1057],{},"type of data"," affected, whether it was ",[43,1060,1061],{},"repetitive",", and what the organization did to ",[43,1064,1065],{},"mitigate",". In other words: an organization that took compliance seriously and responded well is treated very differently from one that ignored its duties.",[12,1068,1069,1070,1073],{},"That's the key insight — ",[43,1071,1072],{},"demonstrable good-faith effort matters",". Mapping your data, building real controls, and having a tested breach runbook aren't just risk reduction; they're evidence in your favor.",[22,1075,1077],{"id":1076},"the-real-cost-is-bigger-than-the-fine","The real cost is bigger than the fine",[12,1079,1080],{},"A penalty is only part of the bill. A breach also brings:",[27,1082,1083,1089,1095,1101],{},[32,1084,1085,1088],{},[43,1086,1087],{},"Reputational damage"," and lost customer trust,",[32,1090,1091,1094],{},[43,1092,1093],{},"Lost enterprise deals"," (your buyers' due diligence will find the gap),",[32,1096,1097,1100],{},[43,1098,1099],{},"Operational disruption"," while you firefight,",[32,1102,1103,1104,1107],{},"and ",[43,1105,1106],{},"management distraction"," from the actual business.",[22,1109,1111],{"id":1110},"how-to-keep-your-exposure-low","How to keep your exposure low",[12,1113,1114,1115,1118],{},"The single biggest penalty attaches to ",[43,1116,1117],{},"failing to take reasonable security safeguards",". So the highest-leverage work is exactly the engineering we specialize in:",[27,1120,1121,1129,1137,1145],{},[32,1122,1123,1126,1127,155],{},[43,1124,1125],{},"Encryption, access control, and audit logging"," — see ",[16,1128,264],{"href":263},[32,1130,1131,1134,1135,155],{},[43,1132,1133],{},"A tested breach-notification runbook"," — part of ",[16,1136,358],{"href":357},[32,1138,1139,1142,1143,155],{},[43,1140,1141],{},"Knowing your gaps before the Board does"," — a ",[16,1144,85],{"href":84},[32,1146,1147,1150,1151,155],{},[43,1148,1149],{},"SDF duties handled"," if they apply — ",[16,1152,771],{"href":316},[12,1154,1155],{},"The cheapest way to avoid a ₹250 crore problem is to spend a small fraction of that, early, on getting the controls right.",[12,1157,1158,1159,155],{},"See your current exposure in five minutes with the free ",[16,1160,406],{"href":18},[416,1162,1163],{},[12,1164,1165],{},"General information, not legal advice. Penalty amounts are from the Act's schedule; confirm against the official text.",{"title":422,"searchDepth":423,"depth":423,"links":1167},[1168,1169,1170,1171,1172],{"id":946,"depth":426,"text":947},{"id":956,"depth":426,"text":957},{"id":1042,"depth":426,"text":1043},{"id":1076,"depth":426,"text":1077},{"id":1110,"depth":426,"text":1111},"2026-02-25","What it costs to get DPDP wrong — penalties up to ₹250 crore, how the Data Protection Board enforces them, and how to reduce your exposure.","Penalties",[1177,1180],{"q":1178,"a":1179},"What's the maximum DPDP penalty?","Up to ₹250 crore for certain failures — most notably, failing to take reasonable security safeguards to prevent a personal data breach. Penalties are decided by the Data Protection Board after due process.",{"q":1181,"a":1182},"Who enforces the DPDP Act?","The Data Protection Board of India — an independent body that investigates complaints and breaches and can impose financial penalties.","DPDP Act penalties & enforcement",[1185,1186,550],"DPDP Act penalties","DPDP fines",{},"6 min read",[413,76],[461,1191],"managed-compliance",{"title":930,"description":1174},"dpdp-act\u002Fpenalties",[],"2026-05-24","1zUcrI-Oj9V8SY66tVrGL_Oru6o_SYe_UUKpZdECI10",{"id":1198,"title":1199,"author":7,"body":1200,"category":1414,"date":1415,"description":1416,"draft":438,"extension":439,"eyebrow":1417,"faq":1418,"h1":1425,"keywords":1426,"meta":1429,"navigation":39,"ogTitle":454,"path":76,"readingTime":1188,"relatedArticles":1430,"relatedServices":1431,"seo":1433,"stem":1434,"tags":1435,"updated":1436,"__hash__":1437},"dpdp\u002Fdpdp-act\u002Fsignificant-data-fiduciary.md","What Is a Significant Data Fiduciary?",{"type":9,"value":1201,"toc":1402},[1202,1213,1217,1220,1254,1260,1264,1267,1306,1309,1313,1316,1320,1329,1333,1339,1343,1350,1354,1357,1361,1364,1384,1388,1397],[12,1203,1204,1205,1208,1209,1212],{},"Most organizations under the DPDP Act are ",[43,1206,1207],{},"Data Fiduciaries",". A subset — those that handle data at higher volume or higher risk — can be notified as ",[43,1210,1211],{},"Significant Data Fiduciaries (SDFs)",", and they carry extra duties. This guide explains who's likely an SDF and what it means.",[22,1214,1216],{"id":1215},"what-makes-a-data-fiduciary-significant","What makes a Data Fiduciary \"significant\"",[12,1218,1219],{},"The government can notify an organization (or a class of them) as an SDF based on an assessment of relevant factors, including:",[27,1221,1222,1229,1235,1242],{},[32,1223,1224,1225,1228],{},"the ",[43,1226,1227],{},"volume and sensitivity"," of personal data processed,",[32,1230,1224,1231,1234],{},[43,1232,1233],{},"risk to the rights"," of Data Principals,",[32,1236,1237,1238,1241],{},"potential impact on ",[43,1239,1240],{},"the sovereignty and integrity of India",",",[32,1243,1244,1245,578,1248,583,1251,155],{},"risks to ",[43,1246,1247],{},"electoral democracy",[43,1249,1250],{},"state security",[43,1252,1253],{},"public order",[12,1255,1256,1257],{},"There's no single magic number — it's a risk-based judgment. But as a rule of thumb, ",[43,1258,1259],{},"large user bases and sensitive data push you toward SDF territory.",[22,1261,1263],{"id":1262},"whos-likely-an-sdf","Who's likely an SDF",[12,1265,1266],{},"Strong candidates include:",[27,1268,1269,1278,1286],{},[32,1270,1271,1277],{},[43,1272,1273],{},[16,1274,1276],{"href":1275},"\u002Findustries\u002Ffintech","Fintech"," — sensitive financial and KYC data.",[32,1279,1280,1285],{},[43,1281,1282],{},[16,1283,1284],{"href":581},"Healthtech"," — health records, often children's data.",[32,1287,1288,1289,578,1295,583,1299,1305],{},"Large ",[43,1290,1291],{},[16,1292,1294],{"href":1293},"\u002Findustries\u002Fecommerce","e-commerce",[43,1296,1297],{},[16,1298,587],{"href":586},[43,1300,1301],{},[16,1302,1304],{"href":1303},"\u002Findustries\u002Fmedia-adtech","media & social platforms"," — high volume, profiling, behavioural data.",[12,1307,1308],{},"If that sounds like you, plan as if you'll be notified.",[22,1310,1312],{"id":1311},"the-extra-duties-of-an-sdf","The extra duties of an SDF",[12,1314,1315],{},"Being an SDF adds specific, ongoing obligations:",[397,1317,1319],{"id":1318},"_1-appoint-a-data-protection-officer-dpo","1. Appoint a Data Protection Officer (DPO)",[12,1321,1322,1323,1325,1326,1328],{},"You must appoint a ",[43,1324,597],{}," who reports to your board\u002Fgoverning body and acts as the point of contact for grievances. A senior in-house DPO can cost ₹20–40 lakh a year — which is why many organizations use ",[16,1327,771],{"href":316}," instead.",[397,1330,1332],{"id":1331},"_2-conduct-an-annual-dpia","2. Conduct an annual DPIA",[12,1334,81,1335,1338],{},[43,1336,1337],{},"Data Protection Impact Assessment"," — a structured review of the risks your processing poses to Data Principals and how you mitigate them — must be carried out periodically (annually).",[397,1340,1342],{"id":1341},"_3-undergo-an-annual-independent-audit","3. Undergo an annual independent audit",[12,1344,1345,1346,1349],{},"An ",[43,1347,1348],{},"independent data auditor"," must assess your compliance each year. Your DPO coordinates this and manages the evidence.",[397,1351,1353],{"id":1352},"_4-other-measures","4. Other measures",[12,1355,1356],{},"The government may specify additional measures, which can include obligations around algorithmic processing and data flows.",[22,1358,1360],{"id":1359},"why-this-matters-even-if-youre-not-sure","Why this matters even if you're not sure",[12,1362,1363],{},"Two reasons:",[626,1365,1366,1372],{},[32,1367,1368,1371],{},[43,1369,1370],{},"The duties are continuous."," A DPO, an annual DPIA, and an annual audit are a standing program, not a one-off — so it pays to design for them early.",[32,1373,1374,1377,1378,1380,1381,155],{},[43,1375,1376],{},"The penalties are higher."," Breaching SDF-specific obligations carries penalties up to ",[43,1379,1018],{},", on top of the general regime. See ",[16,1382,1383],{"href":874},"Penalties & Enforcement",[22,1385,1387],{"id":1386},"find-out-where-you-stand","Find out where you stand",[12,1389,1390,1391,1393,1394,1396],{},"Don't wait for a notification to start preparing. A ",[16,1392,85],{"href":84}," gives you a likely SDF determination and a plan; the free ",[16,1395,406],{"href":18}," gives you an instant first read.",[416,1398,1399],{},[12,1400,1401],{},"General information, not legal advice. SDF status is determined by government notification — confirm your position with qualified advice.",{"title":422,"searchDepth":423,"depth":423,"links":1403},[1404,1405,1406,1412,1413],{"id":1215,"depth":426,"text":1216},{"id":1262,"depth":426,"text":1263},{"id":1311,"depth":426,"text":1312,"children":1407},[1408,1409,1410,1411],{"id":1318,"depth":423,"text":1319},{"id":1331,"depth":423,"text":1332},{"id":1341,"depth":423,"text":1342},{"id":1352,"depth":423,"text":1353},{"id":1359,"depth":426,"text":1360},{"id":1386,"depth":426,"text":1387},"Obligations","2026-03-10","Significant Data Fiduciaries face extra DPDP duties — a DPO in India, annual DPIAs, and audits. Find out if you're likely one, and what it means.","SDF",[1419,1422],{"q":1420,"a":1421},"How do I know if we're an SDF?","The government notifies SDFs based on factors like the volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security, and public order. There's no single number — but high volume or sensitive data makes it more likely. Our readiness audit assesses your likelihood.",{"q":1423,"a":1424},"What extra duties do SDFs have?","Appointing a Data Protection Officer based in India, conducting an annual Data Protection Impact Assessment, undergoing an annual independent data audit, and other additional measures the government may specify.","What is a Significant Data Fiduciary (SDF)?",[77,1427,1428],"SDF DPDP","DPDP DPO requirement",{},[458,874],[1432,460],"dpo-as-a-service",{"title":1199,"description":1416},"dpdp-act\u002Fsignificant-data-fiduciary",[],"2026-05-23","H0597BdZs1pl2hmRWpbe-qmQS9twdSZWET3CmT0yDa0",{"id":1439,"title":1440,"author":7,"body":1441,"category":1661,"date":1662,"description":1663,"draft":438,"extension":439,"eyebrow":1661,"faq":1664,"h1":1671,"keywords":1672,"meta":1676,"navigation":39,"ogTitle":454,"path":413,"readingTime":1188,"relatedArticles":1677,"relatedServices":1678,"seo":1679,"stem":1680,"tags":1681,"updated":1682,"__hash__":1683},"dpdp\u002Fdpdp-act\u002Ftimeline-deadlines.md","DPDP Compliance Deadlines & Timeline",{"type":9,"value":1442,"toc":1651},[1443,1450,1474,1478,1482,1491,1495,1504,1508,1519,1523,1579,1583,1590,1593,1614,1616,1641,1646],[12,1444,1445,1446,1449],{},"The DPDP Act doesn't switch on all at once. It rolls out in ",[43,1447,1448],{},"phases",", giving organizations a transition period to get ready. This guide lays out the timeline and the key dates — and why starting early is the only sensible strategy.",[416,1451,1452],{},[12,1453,1454,1457,1458,1461,1462,1465,1466,1469,1470,1473],{},[43,1455,1456],{},"Accuracy note (dated):"," Dates below reflect the phased rollout as understood in ",[43,1459,1460],{},"May 2026",". The headline date for full compliance is ",[43,1463,1464],{},"13 May 2027",". In ",[43,1467,1468],{},"January 2026"," there was public discussion of compressing the transition window (from 18 months to 12). That was ",[43,1471,1472],{},"proposed and unconfirmed"," at the time of writing — we'll update this page if it's formalized. Always confirm against the official notifications.",[22,1475,1477],{"id":1476},"the-phased-rollout","The phased rollout",[397,1479,1481],{"id":1480},"phase-1-foundations-from-notification-late-2025","Phase 1 — Foundations (from notification, late 2025)",[12,1483,1484,1485,1487,1488,1490],{},"The provisions needed to stand up the regime commence first: establishing the ",[43,1486,550],{},", and the framework for ",[43,1489,761],{}," registration. This is the machinery, not yet the obligations on your business.",[397,1492,1494],{"id":1493},"phase-2-build-period-2026","Phase 2 — Build period (~2026)",[12,1496,1497,1498,1500,1501,332],{},"The transition window where organizations are expected to get ready: mapping data, fixing consent, building rights workflows, and putting security and retention in place. The ",[43,1499,761],{}," framework is expected to become operational during this period (around ",[43,1502,1503],{},"November 2026",[397,1505,1507],{"id":1506},"phase-3-full-compliance-13-may-2027","Phase 3 — Full compliance (13 May 2027)",[12,1509,1510,1511,1514,1515,606,1517,155],{},"The core obligations on Data Fiduciaries become ",[43,1512,1513],{},"enforceable",". From this date, the Data Protection Board can act on non-compliance, including the penalties of up to ",[43,1516,938],{},[16,1518,1383],{"href":874},[22,1520,1522],{"id":1521},"the-dates-at-a-glance","The dates at a glance",[962,1524,1525,1535],{},[965,1526,1527],{},[968,1528,1529,1532],{},[971,1530,1531],{},"When",[971,1533,1534],{},"What",[978,1536,1537,1545,1552,1560,1568],{},[968,1538,1539,1542],{},[983,1540,1541],{},"11 August 2023",[983,1543,1544],{},"DPDP Act received Presidential assent",[968,1546,1547,1549],{},[983,1548,489],{},[983,1550,1551],{},"Draft DPDP Rules released for consultation",[968,1553,1554,1557],{},[983,1555,1556],{},"Late 2025",[983,1558,1559],{},"Phased notification begins; Board & Consent Manager framework commence",[968,1561,1562,1565],{},[983,1563,1564],{},"~November 2026",[983,1566,1567],{},"Consent Manager framework expected operational",[968,1569,1570,1574],{},[983,1571,1572],{},[43,1573,1464],{},[983,1575,1576],{},[43,1577,1578],{},"Core compliance obligations enforceable",[22,1580,1582],{"id":1581},"why-we-have-until-2027-is-the-wrong-way-to-think","Why \"we have until 2027\" is the wrong way to think",[12,1584,1585,1586,1589],{},"Eighteen months sounds like plenty. It isn't, because compliance is ",[43,1587,1588],{},"sequential",": you can't build consent flows before you've mapped your data, you can't automate erasure before retention rules exist, and you can't prove security without controls in place. Each stage depends on the last.",[12,1591,1592],{},"The organizations that struggle are the ones that wait. The earlier you start:",[27,1594,1595,1601,1607],{},[32,1596,1224,1597,1600],{},[43,1598,1599],{},"cheaper"," it is (no rushed, premium-priced scramble),",[32,1602,1224,1603,1606],{},[43,1604,1605],{},"calmer"," it is (no firefighting against a hard date),",[32,1608,1609,1610,1613],{},"and the ",[43,1611,1612],{},"stronger"," your position if the timeline accelerates.",[22,1615,624],{"id":623},[626,1617,1618,1626,1632],{},[32,1619,1620,1623,1624,155],{},[43,1621,1622],{},"Baseline today"," with a ",[16,1625,85],{"href":84},[32,1627,1628,1631],{},[43,1629,1630],{},"Sequence the work"," to the timeline — deadline-critical items first.",[32,1633,1634,1637,1638,1640],{},[43,1635,1636],{},"Keep watching"," the Rules with ",[16,1639,358],{"href":357},", so a change in dates never catches you out.",[12,1642,1643,1644,155],{},"See where you stand in five minutes with the free ",[16,1645,406],{"href":18},[416,1647,1648],{},[12,1649,1650],{},"General information, not legal advice. Dates are subject to official notification.",{"title":422,"searchDepth":423,"depth":423,"links":1652},[1653,1658,1659,1660],{"id":1476,"depth":426,"text":1477,"children":1654},[1655,1656,1657],{"id":1480,"depth":423,"text":1481},{"id":1493,"depth":423,"text":1494},{"id":1506,"depth":423,"text":1507},{"id":1521,"depth":426,"text":1522},{"id":1581,"depth":426,"text":1582},{"id":623,"depth":426,"text":624},"Timeline","2026-02-18","The DPDP Act compliance timeline explained — the phased rollout, the key dates, and the 13 May 2027 deadline for core obligations.",[1665,1668],{"q":1666,"a":1667},"What is the main DPDP deadline?","Core obligations are set to become enforceable on 13 May 2027, following a phased rollout that began after the Rules were notified. Some provisions (like setting up the Board and Consent Manager registration) commence earlier.",{"q":1669,"a":1670},"Could the deadline change?","It's possible. In early 2026 there was discussion about accelerating the transition period. We treat 13 May 2027 as the working deadline and flag any change as it's confirmed — start early either way.","DPDP compliance deadlines & timeline",[1673,1674,1675],"DPDP compliance deadline","DPDP Act timeline","DPDP 2027 deadline",{},[697,455],[460,1191],{"title":1440,"description":1663},"dpdp-act\u002Ftimeline-deadlines",[],"2026-05-26","F_heL0vR6OvIUQvkrfFQNa_Tw6rmObHls8WYeTivNbM",{"id":1685,"title":1686,"author":7,"body":1687,"category":1943,"date":1944,"description":1945,"draft":438,"extension":439,"eyebrow":1946,"faq":1947,"h1":1957,"keywords":1958,"meta":1962,"navigation":39,"ogTitle":454,"path":458,"readingTime":1963,"relatedArticles":1964,"relatedServices":1965,"seo":1966,"stem":1967,"tags":1968,"updated":926,"__hash__":1969},"dpdp\u002Fdpdp-act\u002Fwhat-is-dpdp-act.md","What Is the DPDP Act, 2023? A Plain Guide",{"type":9,"value":1688,"toc":1934},[1689,1696,1699,1703,1717,1726,1730,1763,1767,1778,1781,1785,1792,1842,1846,1849,1875,1877,1886,1890,1893,1923,1929],[12,1690,1691,1692,1695],{},"India's ",[43,1693,1694],{},"Digital Personal Data Protection Act, 2023"," (the \"DPDP Act\") is the country's first comprehensive law dedicated to protecting personal data. If your organization collects, stores, or uses the personal data of people in India — and almost every modern business does — this law now governs how you must do it.",[12,1697,1698],{},"This guide explains the Act in plain language: what it is, who it covers, what it asks of you, and where to start.",[22,1700,1702],{"id":1701},"what-the-dpdp-act-is-in-one-sentence","What the DPDP Act is, in one sentence",[12,1704,1705,1706,1709,1710,1713,1714,1716],{},"The DPDP Act sets the rules for how organizations may handle the ",[43,1707,1708],{},"digital personal data"," of individuals in India, gives individuals enforceable ",[43,1711,1712],{},"rights"," over their data, and creates a regulator — the ",[43,1715,550],{}," — to enforce it all.",[12,1718,1719,1720,1722,1723,1725],{},"It received Presidential assent on ",[43,1721,1541],{},". The detailed operational requirements come through the ",[43,1724,477],{},", which are being rolled out on a phased timeline.",[22,1727,1729],{"id":1728},"the-key-players-in-the-acts-language","The key players (in the Act's language)",[27,1731,1732,1737,1745,1750,1758],{},[32,1733,1734,1736],{},[43,1735,726],{}," — the individual the personal data is about (you, your customers, your users).",[32,1738,1739,1741,1742,155],{},[43,1740,732],{}," — the organization that decides why and how personal data is processed. This is probably ",[503,1743,1744],{},"you",[32,1746,1747,1749],{},[43,1748,742],{}," — anyone who processes personal data on behalf of a Data Fiduciary (your vendors and tools).",[32,1751,1752,1754,1755,155],{},[43,1753,752],{}," — a higher-risk Data Fiduciary, notified by the government, with extra duties. ",[16,1756,1757],{"href":76},"Learn more about SDFs",[32,1759,1760,1762],{},[43,1761,761],{}," — a new, registered intermediary that lets people manage their consents in one place.",[22,1764,1766],{"id":1765},"who-has-to-comply","Who has to comply",[12,1768,1769,1770,1773,1774,1777],{},"Practically every organization that processes the digital personal data of people in India. The Act applies to processing ",[43,1771,1772],{},"within India",", and also to processing ",[43,1775,1776],{},"outside India"," where it relates to offering goods or services to people in India.",[12,1779,1780],{},"It covers data collected digitally, and non-digital data that is later digitized. Purely personal or domestic use is excluded, and certain government processing has specific treatment.",[22,1782,1784],{"id":1783},"what-the-act-requires-of-you","What the Act requires of you",[12,1786,1787,1788,1791],{},"At its heart, the DPDP Act asks you to process personal data ",[43,1789,1790],{},"lawfully, for clear purposes, with consent (or another permitted ground), and no more than you need",". In practice that means:",[27,1793,1794,1804,1810,1816,1822,1830,1836],{},[32,1795,1796,1799,1800,1803],{},[43,1797,1798],{},"Notice & consent."," Tell people clearly what you collect and why, and obtain consent that is free, specific, informed, unconditional, and unambiguous — with withdrawal as easy as giving it. (We build this in our ",[16,1801,1802],{"href":153},"Consent Management service",".)",[32,1805,1806,1809],{},[43,1807,1808],{},"Purpose limitation & minimization."," Collect only what you need, and only use it for the purpose you stated.",[32,1811,1812,1815],{},[43,1813,1814],{},"Accuracy & retention limits."," Keep data accurate, and delete it when the purpose is served.",[32,1817,1818,1821],{},[43,1819,1820],{},"Security safeguards."," Protect data with reasonable technical and organizational measures.",[32,1823,1824,1827,1828,1803],{},[43,1825,1826],{},"Honor Data Principal rights."," Provide access, correction, erasure, grievance redressal, and nomination. (See ",[16,1829,203],{"href":202},[32,1831,1832,1835],{},[43,1833,1834],{},"Breach notification."," Notify the Data Protection Board and affected individuals if a personal data breach occurs.",[32,1837,1838,1841],{},[43,1839,1840],{},"Children's data."," Obtain verifiable parental consent for under-18s and avoid tracking or targeting them.",[22,1843,1845],{"id":1844},"rights-of-the-data-principal","Rights of the Data Principal",[12,1847,1848],{},"The Act gives individuals the right to:",[626,1850,1851,1857,1863,1869],{},[32,1852,1853,1856],{},[43,1854,1855],{},"Access"," a summary of their personal data and who it has been shared with.",[32,1858,1859,1862],{},[43,1860,1861],{},"Correction, completion, updating, and erasure"," of their data.",[32,1864,1865,1868],{},[43,1866,1867],{},"Grievance redressal"," through a readily available mechanism.",[32,1870,1871,1874],{},[43,1872,1873],{},"Nomination"," of another person to exercise their rights in case of death or incapacity.",[22,1876,1175],{"id":875},[12,1878,1879,1880,1882,1883,1885],{},"The Data Protection Board can impose significant financial penalties — up to ",[43,1881,938],{}," for certain failures (for example, inadequate security safeguards leading to a breach). Penalties are decided after due process and are graded to the nature and gravity of the breach. See ",[16,1884,1383],{"href":874}," for the detail.",[22,1887,1889],{"id":1888},"how-to-actually-comply","How to actually comply",[12,1891,1892],{},"Reading the law is the easy part. The hard part is making your systems match it. A sensible sequence:",[626,1894,1895,1902,1912],{},[32,1896,1897,1623,1899,1901],{},[43,1898,1387],{},[16,1900,85],{"href":84}," — map your data and your gaps.",[32,1903,1904,1907,1908,1911],{},[43,1905,1906],{},"Fix the gaps"," through ",[16,1909,1910],{"href":263},"technical implementation"," — consent, rights, retention, security.",[32,1913,1914,354,1917,1920,1921,155],{},[43,1915,1916],{},"Stay compliant",[16,1918,1919],{"href":357},"managed compliance"," and, where needed, a ",[16,1922,317],{"href":316},[12,1924,1925,1926,1928],{},"The fastest way to see your own position is our free ",[16,1927,406],{"href":18}," — five minutes for an instant readiness snapshot.",[416,1930,1931],{},[12,1932,1933],{},"This guide is general information about the DPDP Act, 2023, not legal advice. Confirm specifics against the official notified text or with a qualified lawyer.",{"title":422,"searchDepth":423,"depth":423,"links":1935},[1936,1937,1938,1939,1940,1941,1942],{"id":1701,"depth":426,"text":1702},{"id":1728,"depth":426,"text":1729},{"id":1765,"depth":426,"text":1766},{"id":1783,"depth":426,"text":1784},{"id":1844,"depth":426,"text":1845},{"id":875,"depth":426,"text":1175},{"id":1888,"depth":426,"text":1889},"Fundamentals","2026-02-10","A plain-English guide to India's Digital Personal Data Protection Act, 2023 — what it is, who it covers, what it requires, and how to comply.","Cornerstone guide",[1948,1951,1954],{"q":1949,"a":1950},"When was the DPDP Act passed?","The Digital Personal Data Protection Act was passed by Parliament and received Presidential assent on 11 August 2023. Its provisions are being brought into force in phases through the DPDP Rules.",{"q":1952,"a":1953},"Does the DPDP Act apply to small businesses?","Yes. The Act applies to almost any organization that processes the digital personal data of people in India, regardless of size. Some obligations are lighter for smaller players, but the core duties apply broadly.",{"q":1955,"a":1956},"What is the penalty for non-compliance?","Financial penalties can reach up to ₹250 crore for certain breaches, imposed by the Data Protection Board of India after due process.","What is the DPDP Act, 2023? A plain-English guide",[1959,1960,1961],"DPDP Act 2023","Digital Personal Data Protection Act","DPDP compliance India",{},"9 min read",[697,455],[460,461],{"title":1686,"description":1945},"dpdp-act\u002Fwhat-is-dpdp-act",[],"z6HT6wTlr_eXLUkfQmMpIZ4JAHsdf3ze0SeM287H8f8",1780230334848]