Digital Personal Data Protection Act, 2023

The DPDP Act 2023 compliance deadline is approaching. Are you prepared?

In today's digital economy, protecting personal data is both a regulatory obligation and a foundation for customer trust. The Digital Personal Data Protection Act, 2023 (DPDPA) introduces India's framework for how organisations collect, use, store, share, protect and erase digital personal data. The Digital Personal Data Protection Rules, 2025 translate these obligations into practical requirements, making it essential for organisations to assess their current practices and prepare for compliance.

Days
Hours
Minutes
Seconds
until the principal compliance date — 14 May 2027
Three-phase rollout

The Act and Rules are coming into force in three phases

01
Phase 1: 14 November 2025

Institutional foundation

The first phase brought key institutional and procedural provisions into force. It established the Data Protection Board of India, which is responsible for handling complaints, conducting inquiries and deciding penalties under the Act. Supporting rules relating to the Board's composition, appointments, functioning and digital proceedings also became effective, creating the regulatory structure required to administer the DPDP Act 2023.

02
Phase 2: 14 November 2026

Consent Managers

The framework for the registration and regulation of Consent Managers becomes effective. These are entities that enable individuals to give, review, manage and withdraw consent through an accessible platform.

03
Phase 3: 14 May 2027 — Principal compliance date

Full compliance required

The main compliance requirements become fully effective. Organisations will need to implement clear privacy notices, valid consent mechanisms, appropriate security safeguards, personal data breach reporting procedures, Data Principal rights and grievance processes, protections for children's personal data, data retention and secure erasure practices, and stronger accountability for vendors and Data Processors.

With the principal compliance date of 14 May 2027 approaching, organisations should begin preparing now. DPDP Act 2023 compliance is not limited to publishing a privacy policy. It requires coordinated changes across business processes, technology systems, contracts, governance, vendor management and employee practices. Data Secure helps you understand the requirements, identify gaps and become DPDP Act 2023 ready through a clear, practical and structured approach.

Is your business DPDP Act 2023-ready?

Your organisation may collect personal information through:

Websites and mobile applications Customer registrations and enquiries Employee and recruitment records Sales and marketing activities Vendors and business partners CCTV, access systems and visitor records Customer-support interactions

Personal data can include a person's name, phone number, email address, identification details, location, financial information or any other information that can identify them.

Under the DPDP Act 2023 framework, organisations must handle this information responsibly and use it only for lawful purposes.

Ask yourself
  • ?Do we know what personal data we collect?
  • ?Have we clearly explained why we collect it?
  • ?Can people request correction or deletion of their data?
  • ?Is personal data protected from misuse or unauthorised access?
  • ?Do our employees and vendors know their responsibilities?
If the answer to any of these questions is unclear, your organisation may have a compliance gap.
What your business needs to do

Six practical actions to close the gap

01

Know your data

Understand what personal data you collect, where it is stored, why it is required and who can access it.

02

Inform people clearly

Use simple privacy notices that explain what information is collected and how it will be used.

03

Manage consent

Take valid consent where required and provide an easy way for people to withdraw it.

04

Protect personal data

Use suitable security measures and restrict access to authorised people.

05

Respond to individuals

Create a process for handling requests relating to access, correction, updating, deletion and complaints.

06

Prepare for data breaches

Know what to do if personal data is accidentally exposed, lost, stolen or misused.

Penalties for non-compliance

Non-compliance can carry significant monetary penalties

If your business is found to be non-compliant with the DPDP Act 2023, it may face significant monetary penalties, including:

₹250 crore

Failure to implement reasonable security safeguards

₹200 crore

Failure to report a personal data breach

₹200 crore

Violations involving children's personal data

₹150 crore

Breach of Significant Data Fiduciary obligations

₹50 crore

Other violations of the Act or Rules

Our DPDP Act 2023 Compliance Solution

Data Secure makes compliance understandable and manageable through 5 practical steps

01
Step 1

Understand

We study how your organisation collects and uses personal data. This includes your departments, websites, applications, employees, customers, systems and vendors.

02
Step 2

Identify gaps

We compare your current practices with DPDP Act 2023 requirements and identify what needs to change.

03
Step 3

Build the framework

We prepare the essential documents and processes required for your organisation.

04
Step 4

Implement

We work with your business, legal, HR, IT, security and marketing teams to put the framework into daily practice.

05
Step 5

Maintain

We provide ongoing support so your compliance programme remains effective as your business, technology and data use change.

What we deliver

Ten deliverables that build your compliance programme

01

DPDP Act 2023 Readiness Assessment

We review how your organisation currently handles personal data, identify compliance gaps and provide a practical action plan based on priority and risk.

Sections 8(1), 8(4), 10(2) · Rule 13
02

Personal-data inventory

A clear record of what personal data you collect, why you collect it, where it is stored, who can access it, who receives it and how long is it retained. This gives your organisation the visibility needed to manage personal data responsibly.

Sections 4, 5, 6(10), 8(1), 8(2), 8(7), 11(1) · Rule 3
03

Privacy notices

We prepare easy-to-understand privacy notices for customers, employees, job applicants, website visitors and other individuals. Each notice explains what personal data is collected, why it is used and how individuals can withdraw consent, exercise their rights or raise a complaint.

Section 5 · Rule 3
04

Consent management process

We advise and support your team in developing a practical consent management process. This includes guidance on consent wording, collection forms, digital consent journeys, preference management and maintaining appropriate consent records.

Section 6 (1,3,4,6,10) · Rules 3, 4
05

Data Principal Rights Process

We help to establish a clear process for receiving, verifying, tracking and responding to requests relating to access, correction, updating, completion, erasure, grievances and nomination.

Sections 8(9), 8(10), 11–14 · Rules 9, 14
06

Data-retention plan

We will assist in determining how long different categories of personal data should be retained and when they should be securely deleted.

Sections 8(7), 8(8), 12(3) · Rule 8
07

Vendor compliance

Conduct privacy checks and review contractual requirements for service providers that handle personal data.

Sections 8(1), 8(2), 8(5), 8(7)(b) · Rule 6(1)(f)
08

Data-breach response plan

Define clear responsibilities and actions for identifying, managing and reporting a personal-data breach. The plan includes internal escalation, incident assessment, regulatory and individual notifications, communication templates, incident records and corrective actions.

Sections 8(5), 8(6) · Rules 6, 7
09

Employee training

We provide simple, role-based training that helps management, employees and operational teams understand their responsibilities when handling personal data.

Sections 8(4), 8(5) · Rule 6(1)(g)
10

Compliance documentation

We prepare the policies, procedures, templates, checklists and records that help demonstrate compliance with the DPDP Act 2023 and DPDP Rules.

Full programme documentation

Disclaimer: The services above are designed to support compliance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The exact requirements applicable to an organisation will depend on its industry, activities, role and use of personal data.

Why choose Data Secure?

An end-to-end privacy partner, not a one-off vendor

End-to-End Privacy Support

From readiness assessments and privacy frameworks to audits, training, automation and managed DPO services, we support your complete compliance journey under one roof.

Practical and Tailored Solutions

We do not believe in a one-size-fits-all approach. Our solutions are designed around your industry, business objectives, geographical presence and personal-data processing activities.

Experienced and Certified Professionals

Our team combines LLB/LLM legal expertise with globally recognised IAPP-certified privacy credentials, aligning your compliance programme with international standards and best practices.

Support Beyond Initial Compliance

We help organisations maintain compliance through ongoing assessments, regulatory updates, employee training, privacy audits and through our DPO services.

Take the first step

Book a DPDP Act 2023 readiness discussion with Data Secure today!

DPDP Act 2023 compliance is not limited to publishing a privacy policy. It requires coordinated changes across business processes, technology systems, contracts, governance, vendor management and employee practices.