Skip to main content

Eagle

DPDP Act compliance, Data Principal rights, and business obligations in India

A Simple Guide to India’s Digital Personal Data Protection 

Imagine ordering something online. You enter your name, phone number, email address, and delivery address. You make a payment, receive a confirmation, and wait for your package to arrive. It feels like a simple transaction, but behind the scenes, your personal data may pass through several systems, platforms, and service providers.

As businesses become increasingly digital, personal data has become an important part of everyday operations. The Digital Personal Data Protection Act, 2023 (DPDP Act) creates a legal framework for processing digital personal data in India while giving individuals specific rights and placing responsibilities on organizations handling their data.

For businesses, the DPDP Act is more than a privacy policy update. It affects how organizations collect, use, store, secure, and delete personal data. With the DPDP Rules, 2025, notified on 14 November 2025, organizations now have a clearer compliance roadmap, with key upcoming implementation dates on 13 November 2026 and 13 May 2027.

What Does the DPDP Act Mean for Businesses?

Think about everything a customer does on a company’s digital platform. They create an account, submit contact information, make a purchase, download an application, or contact customer support. Each interaction can involve personal data, making it important for organizations to understand why that data is collected, how it is used, and how it is protected.

The DPDP Act distinguishes between a Data Principal, the individual to whom personal data relates, and a Data Fiduciary, the organization that determines the purpose and means of processing that data. The Act establishes obligations for Data Fiduciaries and rights and duties for Data Principals.

This makes privacy a responsibility that extends beyond the legal or IT department. Marketing, HR, cybersecurity, procurement, customer support, and other teams may all interact with personal data. Effective DPDP compliance therefore requires an organization-wide approach to data governance, privacy, security, and accountability.

What Are the Rights of Individuals Under the DPDP Act?

Imagine a customer asking a simple question: “What personal data do you have about me?” Under the DPDP framework, individuals, known as Data Principals, have defined rights concerning their personal data. Organizations therefore need appropriate processes to support these rights as the relevant provisions become applicable.

The framework provides rights, including access to information about personal data, correction and erasure, grievance redressal, and nomination. The DPDP Rules, 2025 provide additional details concerning the mechanisms through which applicable rights can be exercised.

For businesses, this means preparing systems and procedures to receive, verify, track, and respond to Data Principal requests. Organizations should also identify where personal data is stored, determine who is responsible for handling requests, and ensure that relevant teams understand their roles before the applicable requirements take effect.

What Are the Upcoming DPDP Act Compliance Deadlines?

The DPDP compliance framework is being implemented in phases rather than through one single deadline. The DPDP Rules, 2025, notified on 14 November 2025, establish an 18-month phased implementation timeline. One key upcoming date is 13 November 2026, when Rule 4 (Registration and Obligations of Consent Managers) comes into force along with specified provisions of the DPDP Act.

The next major milestone is 13 May 2027, when the broader set of operational provisions of the DPDP Act and Rules takes effect. These provisions cover significant areas relating to personal data processing, Data Principal rights, organizational responsibilities, security safeguards, notices, consent, personal data breach notifications, and other compliance requirements.

These dates give organizations an important preparation window. Businesses should use this time to identify and map personal data, review privacy notices and consent mechanisms, assess third-party processors, establish retention and deletion practices, strengthen security safeguards, and prepare procedures for Data Principal requests and personal data breaches.

What Are the Penalties Under the DPDP Act?

Imagine a company discovers that personal data has been exposed. The incident itself is serious, but the regulatory consequences can add another layer of risk. Under the Schedule to the DPDP Act, failure to take reasonable security safeguards to prevent a personal data breach may attract a penalty of up to ₹250 crore.

Failure to notify the Board or affected Data Principals about a personal data breach may attract a penalty of up to ₹200 crore. Certain breaches involving children’s data may also attract penalties of up to ₹200 crore, while specified breaches of obligations by Significant Data Fiduciaries may attract penalties of up to ₹150 crore.

Other breaches covered by the Schedule may attract penalties of up to ₹50 crore, while certain duties of Data Principals can attract penalties of up to ₹10,000. These are statutory maximums, and the applicable penalty depends on the relevant provision and the circumstances considered by the Data Protection Board.

How Can Businesses Prepare for DPDP Compliance?

Imagine a company opening a digital cupboard containing customer information collected over several years. Some records are in databases, some in cloud applications, some in spreadsheets, and others with third-party service providers. Before an organization can protect its data effectively, it needs to know what data exists, where it is stored, why it is being processed, and who can access it.

A practical DPDP compliance checklist can begin with data discovery and mapping, identifying processing purposes, reviewing privacy notices, assessing consent mechanisms, establishing retention and deletion procedures, evaluating vendors, strengthening security controls, and preparing processes for handling Data Principal requests and personal data breaches.

Starting early can help organizations identify gaps before the applicable deadlines arrive. Eagle is giving Data Privacy Compliance Advisory—strengthens privacy compliance readiness across DPDPA, GDPR, and other applicable regulations. This can support organizations in assessing their privacy posture, identifying compliance gaps, and building practical governance and processes around the personal data they handle.

DPDP Act and GDPR: What Is the Difference?

Imagine a company serving customers in both India and Europe. The same customer journey may involve personal data governed by different privacy frameworks. For organizations operating internationally, understanding which regulations apply to particular processing activities is therefore an important part of privacy governance.

The DPDP Act is India’s framework for digital personal data protection, while the General Data Protection Regulation (GDPR) is the European Union’s data protection framework. Both address areas such as individual rights, transparency, and responsible processing, but their scope, terminology, obligations, and compliance mechanisms differ.

For organizations operating across jurisdictions, privacy compliance therefore requires more than applying one generic policy to every market. Eagle’s Data Privacy Compliance Advisory strengthens privacy compliance readiness across DPDPA, GDPR, and other applicable regulations, helping organizations develop a structured approach to privacy and data governance.

Why Should Businesses Start Preparing for DPDP Compliance Now?

Think about the amount of personal information a business handles every day—customer details, employee records, contact information, payment-related data, website interactions, and information shared with service providers. Managing this information responsibly requires more than simply having a privacy policy; it requires processes, controls, accountability, and ongoing oversight.

With 13 November 2026 and 13 May 2027 approaching as key implementation milestones, organizations have an opportunity to assess their current privacy practices before the applicable requirements take effect. Early preparation can help businesses understand their data landscape, identify compliance gaps, strengthen security controls, and establish processes for meeting their responsibilities under the DPDP framework.

Ultimately, DPDP compliance is about responsible personal data management. It means understanding what personal data an organization holds, why it is being processed, how it is protected, how long it should be retained, and how applicable individual rights and regulatory obligations will be addressed. With the right preparation and Data Privacy Compliance Advisory, organizations can build stronger privacy compliance readiness across DPDPA, GDPR, and other applicable regulations.

Frequently Asked Questions

What is the DPDP Act, and who does it apply to?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s legal framework governing the processing of digital personal data. It applies to any business or organization (“Data Fiduciary”) that collects, processes, stores, or uses the digital personal data of individuals (“Data Principals”) within India, as well as foreign entities offering goods or services to individuals in India.

What are the key compliance deadlines for businesses under the DPDP Act?

Following the DPDP Rules notified in November 2025, implementation is phased across an 18-month timeline:

  • 13 November 2026: Rule 4 takes effect, covering the registration and obligations of Consent Managers alongside specified core provisions.
  • 13 May 2027: Full operational provisions come into force, including strict rules on personal data processing, notices, consent, retention/deletion, breach notifications, and individual rights.

What penalties do businesses face for non-compliance under the DPDP Act?

Penalties are enforced per violation based on the Schedule to the Act:

  • Up to ₹250 crore: Failure to implement reasonable security safeguards to prevent personal data breaches.
  • Up to ₹200 crore: Failure to notify the Data Protection Board or affected individuals of a personal data breach.
  • Up to ₹200 crore: Non-compliance with obligations regarding children’s data.
  • Up to ₹150 crore: Specified violations by Significant Data Fiduciaries.

What are the key rights granted to individuals (Data Principals)?

Individuals have four major statutory rights regarding their personal data:

  • Right to Access: Request summary information about what data is processed and shared.
  • Right to Correction & Erasure: Request updating, completing, or deleting unnecessary personal data.
  • Right to Grievance Redressal: Access clear mechanisms to report privacy concerns to the organization.
  • Right to Nominate: Designate another individual to exercise privacy rights in case of death or incapacity.

How does the DPDP Act differ from Europe’s GDPR?

While both frameworks protect individual privacy, key differences include:

  • Scope: The DPDP Act applies specifically to digital personal data (or digitized offline data), whereas GDPR applies to both manual structured records and digital data.
  • Legal Bases: The DPDP Act relies heavily on explicit consent and specified “certain legitimate uses,” whereas GDPR offers six distinct legal grounds (including legitimate interests and contract performance).
  • Structure: Definitions, penalty frameworks, cross-border transfer rules, and operational mechanisms differ significantly, requiring tailored policies for each jurisdiction.