Skip to content
Back to Blog
·14 min read·technology

DPDP Compliance Guide for Indian Businesses 2026: Complete Checklist and Deadlines

Everything Indian businesses need to know about DPDP Act 2023 compliance in 2026: what data is covered, what obligations apply, exact penalties, compliance checklist, and how to get compliant fast without hiring a big consulting firm.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder

Check DPDP Compliance
DPDP Compliance Guide for Indian Businesses 2026: Complete Checklist and Deadlines

Security exposure this creates

Unpatched vulnerabilities in your tech stack are the #1 entry point for breaches targeting Indian businesses. Here's what to watch.

DPDP compliance means meeting the requirements of India's Digital Personal Data Protection Act 2023 — a law that applies to every company that collects, stores, or processes personal data of Indian residents, regardless of where the company is based. Non-compliance carries penalties up to ₹250 crore per incident. The compliance window is open now: full enforcement is expected by November 2027, and the government is already issuing notices.

- ₹250 crore — Maximum penalty per non-compliance incident under DPDP Act
- 72 hours — Time to notify Data Protection Board after a personal data breach
- 100% — Percentage of Indian businesses collecting personal data that are covered
- Nov 2027 — Expected full enforcement date (based on phased rollout)
- 18 months — Time remaining to get fully compliant from today

What Is the DPDP Act?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection law. It was passed by Parliament in August 2023 and received Presidential assent in the same month. Rules under the Act are being finalized, with enforcement expected in phases through 2027.

The DPDP Act is India's answer to GDPR (Europe), CCPA (California), and PDPA (Singapore). It establishes:

    1. Rights for individuals (Data Principals) over their personal data
    2. Obligations for businesses (Data Fiduciaries) that handle this data
    3. A regulatory body — the Data Protection Board of India — to enforce it
    4. A consent framework for how data can be collected and used
    5. Strict penalties for non-compliance
Unlike GDPR, the DPDP Act is designed specifically for the Indian context — including provisions for India Stack, DigiLocker, and government processing of data. It is written to be technology-neutral and principle-based.

Who Is Covered?

The DPDP Act covers any entity that:

  1. Processes digital personal data within India, or
  2. Processes personal data outside India in connection with goods/services offered to individuals in India
This means:
Business TypeCovered?
Indian startups and SMBs collecting customer dataYes
E-commerce platforms with Indian customersYes
SaaS companies with Indian usersYes
Banks, NBFCs, insurersYes (also covered by RBI/IRDAI rules)
Healthcare providers storing patient dataYes
HR/payroll software processing employee dataYes
Foreign companies serving Indian customersYes
Non-profit organizations processing personal dataYes
Exception: Purely personal or domestic use (e.g., storing your own contacts) is excluded.

What Is "Personal Data" Under the DPDP Act?

Personal data means any data about an identifiable individual. Unlike some laws that have narrow definitions, the DPDP Act is broad:

    1. Name, address, phone number, email
    2. Government IDs: Aadhaar, PAN, passport, driving licence
    3. Financial data: bank account, card numbers, UPI IDs
    4. Health data: medical records, prescriptions, test results
    5. Biometric data: fingerprints, face scans, iris scans
    6. Location data, browsing history, device identifiers
    7. Inferred data: credit scores, risk profiles
Sensitive personal data (health, financial, biometric) has stricter requirements under the proposed rules.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The 7 Core Obligations for Data Fiduciaries

Before processing personal data, you must have valid consent. Under DPDP, consent must be:

    1. Free — not coerced or bundled with service access
    2. Specific — for a named purpose, not blanket consent for "all uses"
    3. Informed — user must know what data is collected and why
    4. Unconditional — not made a condition for receiving a service (unless processing is necessary for that service)
    5. Revocable — individuals can withdraw consent at any time
What this means in practice:
    1. Pre-ticked checkboxes are no longer valid consent
    2. "By continuing to use this app, you agree to our Privacy Policy" does not constitute valid consent
    3. You need a Consent Management Platform (CMP) or in-app consent mechanism
Legitimate uses without consent: Processing for employment purposes, legal obligations, medical emergencies, safety, and research under prescribed conditions do not require consent.

2. Provide a Clear Privacy Notice

At the time of collecting personal data (or before), you must give individuals:

    1. What personal data is being collected
    2. The purpose for which it is being processed
    3. How they can exercise their rights (access, correction, erasure)
    4. How they can file a complaint with the Data Protection Board
    5. Contact details of the Data Protection Officer (for Significant Data Fiduciaries)
Action: Review your existing privacy policy. DPDP requires plain language, not legal jargon. The notice must be in English and in a language the individual understands.

3. Ensure Data Quality and Accuracy

You must take reasonable steps to ensure personal data is accurate, complete, and up-to-date — particularly when processing for consequential decisions (loan approvals, insurance claims, employment decisions).

Action: Implement periodic data quality checks and a process for users to update their information.

4. Limit Data to What Is Necessary (Data Minimisation)

Collect and retain only the personal data that is necessary for the stated purpose. You cannot collect "extra" data speculatively.

Action: Audit your data collection points. Remove fields that you collect but never use. Set data retention policies.

5. Implement Security Safeguards

You must implement reasonable security safeguards to prevent breaches. The Act does not prescribe specific controls but the CERT-In and industry standards (ISO 27001, SOC 2) give guidance on what "reasonable" means.

This is where VAPT comes in: running regular vulnerability assessments and penetration tests on systems handling personal data is the most widely accepted way to demonstrate you have taken reasonable security measures.

Action required:

    1. Run VAPT on all systems handling personal data (web apps, APIs, databases, mobile apps)
    2. Implement access controls and encryption
    3. Maintain security audit logs
    4. Train employees on data security

6. Notify Breaches Within 72 Hours

If a personal data breach occurs, you must notify:

  1. The Data Protection Board within 72 hours
  2. Affected data principals within a reasonable time
A breach includes: unauthorized access, disclosure, alteration, loss, or destruction of personal data.

Action: Establish an incident response plan with specific steps for data breach scenarios, including who is responsible for DPB notification.

7. Process Data of Children With Additional Care

If you process data of children (under 18) or persons with disabilities:

    1. Obtain verifiable consent from a parent or lawful guardian
    2. Do not process data for tracking, behavioural monitoring, or targeted advertising
    3. Age-gate your services if children's data is collected

Significant Data Fiduciaries: Additional Obligations

The government will designate certain entities as Significant Data Fiduciaries (SDF) based on volume of data processed, sensitivity, national security implications, and potential harm from breach.

SDFs must:

    1. Appoint a Data Protection Officer (DPO) — an Indian resident who reports to the board
    2. Appoint an independent data auditor to conduct periodic audits
    3. Conduct Data Protection Impact Assessments (DPIA) for high-risk processing
    4. Comply with restrictions on cross-border data transfer to specific countries
The first list of SDFs has not been published as of April 2026, but large tech platforms, financial services companies handling tens of millions of records, and healthcare data processors are expected to be designated.

Cross-Border Data Transfer

Under the DPDP Act, personal data of Indian residents can be transferred internationally unless the Central Government notifies that a specific country or territory is restricted. This is an "allowlist by default" model — different from GDPR's "blocklist by default."

Until the restricted countries list is notified, international transfers are generally permitted. However, SDF rules may add stricter requirements for certain sectors.

The Penalty Framework

The Data Protection Board can impose penalties after an inquiry process. Penalties are per-incident and can be cumulative:

ViolationMaximum Penalty
Failure to notify breach (72-hour rule)₹200 crore
Failure to implement reasonable security safeguards₹250 crore
Failure to obtain valid consent₹250 crore
Processing children's data without guardian consent₹200 crore
Failure to comply with DPB orders₹150 crore
Minor violations (incorrect or incomplete notices)₹50 crore
Important: Penalties are per incident, not per affected individual. A single breach affecting one million users is one incident with a maximum ₹250 crore penalty — not ₹250 crore per user.

However, if you have systemic violations — no security controls, no consent mechanism, no breach notification process — the DPB can and will stack multiple violation counts.

DPDP Compliance Checklist for 2026

Use this checklist to assess your current state. Each item maps to a specific DPDP obligation.

    1. [ ] Identify every data collection touchpoint (website forms, mobile apps, APIs, CRMs, HR systems)
    2. [ ] Implement a consent mechanism that captures free, specific, informed, unconditional consent
    3. [ ] Display privacy notice at the point of data collection (not buried in terms)
    4. [ ] Build a consent withdrawal mechanism (users can say "stop using my data")
    5. [ ] Translate privacy notice into regional languages if serving non-English speakers
    6. [ ] Remove all pre-ticked consent boxes

Data Inventory and Governance

    1. [ ] Create a data inventory: what personal data do you hold, where is it stored, who has access
    2. [ ] Map data flows: how does data move between systems, third parties, and geographies
    3. [ ] Set retention schedules: how long do you keep different data types, and when is it deleted
    4. [ ] Document the legal basis for each processing activity (consent, contract, legal obligation)
    5. [ ] Appoint an internal privacy lead (DPO mandatory for SDFs, recommended for others)

Security Safeguards

    1. [ ] Run VAPT on all systems handling personal data — at minimum annually
    2. [ ] Implement encryption at rest and in transit for sensitive data
    3. [ ] Enable MFA for admin access to systems with personal data
    4. [ ] Implement access controls: minimum privilege, role-based access
    5. [ ] Maintain access logs and audit trails
    6. [ ] Conduct annual security awareness training for employees

Breach Response

    1. [ ] Document an incident response plan covering personal data breaches
    2. [ ] Define who notifies the DPB (72-hour requirement)
    3. [ ] Define who communicates with affected individuals
    4. [ ] Test the breach response plan at least once a year (tabletop exercise)

Data Principals' Rights

    1. [ ] Build a mechanism for users to request access to their data
    2. [ ] Build a mechanism for users to correct inaccurate data
    3. [ ] Build a mechanism for users to request erasure ("right to be forgotten")
    4. [ ] Define how you handle data principal grievances (response timeline: 30 days)
    5. [ ] Publish contact details for data principal rights requests

Third-Party and Vendor Management

    1. [ ] Identify all third-party processors (cloud providers, analytics tools, marketing platforms)
    2. [ ] Review and update contracts to include data processing agreements
    3. [ ] Ensure third parties have adequate security controls

Timeline: When Do You Need to Be Compliant?

The DPDP Act was passed in August 2023. Rules are being finalized by the Ministry of Electronics and IT (MeitY). The expected timeline:

MilestoneExpected Date
DPDP Rules finalized by MeitYMid 2026 (expected)
Data Protection Board constitutedQ3 2026 (expected)
Enforcement begins (first phase)Q4 2026 – Q1 2027
Full enforcement (SDFs + all fiduciaries)By November 2027
What this means for you: You have roughly 12–18 months to get fully compliant. But enforcement typically starts with the largest and most visible violators — if you process large volumes of sensitive data or handle financial/health records, you should be compliant now, not in 2027.

How Automated VAPT Supports DPDP Compliance

DPDP Section 8(5) requires "reasonable security safeguards to prevent personal data breach." VAPT is the industry standard for demonstrating this obligation is met. Here's how automated VAPT maps to DPDP requirements:

DPDP RequirementHow VAPT Helps
Reasonable security safeguardsVAPT report is documentary evidence of security testing
Prevent personal data breachVAPT identifies vulnerabilities before attackers exploit them
Breach notification readinessUnderstanding your attack surface helps triage breach scope faster
Third-party processor oversightVAPT on vendor-integrated APIs and third-party services
Bachao.AI's automated VAPT runs 441 security tests in under 2 hours and produces a CERT-In aligned report that can be used as evidence of DPDP security safeguard compliance. The report maps findings to severity levels and provides specific remediation steps.

Start your free VAPT scan to see your current security posture before completing your DPDP compliance checklist.

DPDP vs Other Indian Regulations: What Is Already Covered

If your business already complies with other Indian regulations, here is what you can reuse:

RegulationWhat Overlaps with DPDP
RBI Master Directions on ITSecurity controls, breach notification, third-party risk management
CERT-In Directions 20226-hour incident reporting (DPDP adds 72-hour DPB notification separately)
SEBI CSCRFCybersecurity controls, access management, audit requirements
IRDAI IT FrameworkSecurity controls, data governance
HIPAA (for India health data)Breach notification, security safeguards
Overlap is common but coverage is not complete. DPDP adds consent requirements and data principal rights that most sector regulations do not cover.

Frequently Asked Questions

Does the DPDP Act apply to B2B businesses?

Yes, if you process personal data of individuals in India — including your employees, contractors, or customers' employees. B2B companies often overlook this because their "customers" are businesses, but they process personal data of the individuals within those businesses.

Is there a DPDP penalty for small businesses?

The DPDP Act does not have a separate SMB exception. However, the Data Protection Board is expected to use graduated enforcement, focusing first on large data processors. That said, non-compliance is a legal risk regardless of company size — especially after a breach.

Does our existing privacy policy cover DPDP compliance?

Almost certainly no. Most existing privacy policies were written for general compliance and do not meet DPDP's specific requirements on consent, data principal rights, and the information notice format. You need a DPDP-specific privacy notice and consent mechanism.

What is the difference between DPDP and GDPR?

GDPR is Europe's data protection regulation. Key differences: GDPR has six legal bases for processing; DPDP primarily uses consent + legitimate uses. GDPR applies to automated decisions; DPDP has no equivalent provision yet. DPDP's cross-border transfer rules are simpler (allowlist model vs. GDPR's complex transfer mechanism). If you are GDPR compliant, you have a strong starting point but DPDP requires additional India-specific steps.

Can we use a consent banner like GDPR cookie banners?

For cookie/tracking consent, yes — but DPDP consent requirements go beyond cookies. You need consent for all personal data collection, not just analytics cookies. Your existing cookie consent banner likely does not cover DPDP consent obligations for your core product data.

How do we handle data principal rights requests?

You need a process — typically a web form, email address, or in-app mechanism — where individuals can submit requests to access, correct, or erase their data. You have 30 days to respond. If you use third-party services (CRM, analytics), you need to be able to retrieve, correct, and delete data from those systems too.


Bachao.AI helps businesses achieve DPDP compliance through automated VAPT, consent management tooling, and compliance reporting. View our DPDP compliance service or contact us for a compliance assessment.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See where your business stands against the DPDP Act 2023

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →