top of page
Untitled design (1).png

India’s DPDP Act: What Organizations Need to Know in 2026

  • Writer: Syed Adnaan
    Syed Adnaan
  • Aug 13
  • 4 min read

India’s Digital Personal Data Protection Act (DPDP Act), enacted in August 2023, is now moving from paperwork into active enforcement. With the implementing Rules notified in late 2025, 2026 is the year organizations processing Indian users’ data need to move from “we’re aware of this law” to “we’re actually compliant.” Here’s where things stand.


Where the law is right now

The DPDP framework is rolling out in three phases, and it’s important to know which one applies to you:


  • Phase 1 — November 14, 2025: The DPDP Rules were formally notified, and the Data Protection Board of India (DPBI) was established in the National Capital Region with four members. This phase brought foundational provisions into force.

  • Phase 2 — November 14, 2026: The Consent Manager framework is expected to become operational. Consent Managers are registered intermediaries through which individuals (called “Data Principals”) can grant, manage, and withdraw consent for how their data is used.

  • Phase 3 — May 13, 2027: Full substantive enforcement begins. This is when the bulk of compliance obligations — audits, breach reporting duties, and penalty enforcement — become fully live.


In short: the Act is law today, but the government has given organizations roughly 18 months from the November 2025 Rules notification to get ready before the heaviest obligations and enforcement powers activate.


Who it applies to

The DPDP Act applies to the processing of digital personal data — data collected digitally, or collected offline and later digitized. It does not cover purely non-digital, non-digitized personal data.


Its reach is extra-territorial: the Act applies to organizations outside India if they process personal data of individuals in India in connection with offering goods or services, or if they profile individuals located in India — a scope similar in principle to the EU’s GDPR.


Under the Act, organizations fall into two main roles:

  • Data Fiduciaries — entities that determine the purpose and means of processing personal data.

  • Data Processors — entities that process data on behalf of a Data Fiduciary.


Certain large-scale or high-risk Data Fiduciaries can be designated Significant Data Fiduciaries (SDFs), which carry enhanced obligations, including mandatory audits and a requirement to appoint a Data Protection Officer.


What organizations are required to do

  • Obtain valid, verifiable consent before processing personal data, and support purpose limitation — data can only be used for the purpose it was collected for.

  • Enable Data Principal rights, including access, correction, and erasure of personal data.

  • Implement “reasonable security safeguards” to prevent personal data breaches — the Act doesn’t prescribe exact technical controls, but failure here carries some of the steepest penalties.

  • Report all personal data breaches, regardless of severity — unlike GDPR’s risk-based threshold, the DPDP Act’s current guidance points toward notifying the Board and affected individuals for breaches of any scale, with breach detection, assessment, and reporting expected within a tight window (commonly cited as around 72 hours).

  • Handle children’s data with the strictest global threshold: anyone under 18 is treated as a child, requiring verifiable parental consent and a prohibition on tracking, behavioral monitoring, and targeted advertising directed at them.

  • Review cross-border data transfers against a “blacklist” model — transfers are permitted by default except to countries the government specifically restricts, a notably different approach from GDPR’s adequacy-based model.

  • Register with the Consent Manager framework where applicable, once it becomes operational in November 2026.


Penalties

Penalties under the DPDP Act can reach up to ₹250 crore (roughly USD 30 million) per violation for the most serious failures, such as not implementing reasonable security safeguards to prevent a breach. The Data Protection Board of India determines fines based on factors like the nature, gravity, and duration of the violation.


The compliance gap

Despite the law being in force and penalties being significant, industry surveys cited in recent coverage suggest a large majority of organizations — figures as high as 83% — have not yet begun comprehensive DPDP implementation, and consumer awareness of the law itself remains low. That gap is expected to close quickly as Phase 2 and Phase 3 approach.


What to do now

  1. Map your data. Identify every digital personal data processing activity involving Indian users — you can’t comply with a law you can’t apply to your own data flows.

  2. Build consent infrastructure. The DPDP Act’s consent model is stricter in some respects than GDPR’s; retrofitting consent flows late is expensive.

  3. Stand up breach notification processes now. With no risk-based reporting threshold and a short reporting window under discussion, organizations need detection and escalation processes ready well before Phase 3 enforcement begins.

  4. Prepare for children’s data restrictions. If your platform has any users under 18, plan for parental consent verification and a ban on tracking/profiling this group.

  5. Watch the cross-border transfer list. The blacklist model means transfers are allowed by default — but the list of restricted destinations can change, so this needs ongoing monitoring, not a one-time review.


Why it matters for security teams

Every one of this year’s major global breaches profiled in our breach-tracking series — compromised marketing databases, vendor pivots, unencrypted data sitting in legacy systems — is exactly the kind of incident the DPDP Act’s breach-notification and “reasonable security safeguards” requirements are designed to catch. Getting ahead of DPDP compliance and getting ahead of breach risk are, in practice, the same project.


Sources: India Briefing, Shardul Amarchand Mangaldas & Co, DLA Piper Data Protection Laws of the World, Lexology, and Responsible AI Labs. This article is for general informational purposes and is not legal advice — consult qualified counsel for compliance decisions specific to your organization.



 
 
 

Recent Posts

See All

Comments


bottom of page