AMLEGALS — Strategic Lawyering
Privacy · Governance · Strategic counsel India ↔ The world
A contemporary executive boardroom
Data protection / The leadership agenda

Data moves. Responsibility stays.

DPDPA advisory and privacy governance for the decisions that shape your business. In India. Across borders. Throughout the data lifecycle.

Explore our practice
An institutional atrium in natural light
India / International business

One business. Many borders. A clear position.

Understand the Indian and overseas dimensions of your data relationships — from market entry to cross-border operations.

Explore international advisory
An imposing government building under dramatic skies
Governance / The working record

Beyond the policy. Into the organisation.

Connect legal obligations with operational ownership, practical controls and evidence of implementation.

Explore privacy governance
Principal obligations commence
13 May 2027 · DPDP Act, 2023 & DPDP Rules, 2025
--
Days
--
Hours
--
Min
--
Sec
Organisations that trust this practice

Recent work highlights

DKMS
Deepak Nitrite
Thermax
Gather India
SEW-Eurodrive
Nazara Technologies
HCG Hospitals
Health-e
Deepak Phenolics
BioX
Deepak Chem Tech
Dräxlmaier
Independent recognition / 2026
IBLJ INDIA BUSINESS
LAW JOURNAL

Law Firm
Awards.

Recognised in Arbitration & ADR, Corporate, and Technology.

Celebrating excellence & dedication.

Founder conversations

One voice.
Wider conversations.

Anandaday Misshra
Founder & Managing Partner, AMLEGALS

Anandaday Misshra
ManageEngine Insights / DPDPA

DPDPA compliance in India: What it requires, and what it costs to get wrong

With Athira Jayakumar. A conversation on consent, governance and the business implications of privacy.

Open the conversation
HKU / Regulatory Ramblings

Respect Personal Data: A look into India's new personal data privacy law

With Ajay Shamdasani. The founder's perspective on India's data protection framework, from the Regulatory Ramblings podcast.

Open the conversation
In focus DPDP Rules 2025 — A phased transition. A practical plan. Understand the framework
Our practice

From legal obligation
to everyday operation.

Privacy touches every part of an organisation. We bring legal interpretation, governance and implementation into one conversation.

01 / Build

DPDPA implementation

Understand your position. Map the gaps. Put notices, consent, contracts and operating procedures into place.

Explore DPDPA advisory
02 / Connect

Cross-border data privacy

Coordinate Indian requirements with the privacy frameworks that govern your international operations.

Explore global privacy
03 / Govern

AI & technology governance

Connect AI use cases with legal review, human oversight, vendor terms and evidence of responsible operation.

Explore AI advisory
Specialist advice, through the full privacy lifecycle. View all practice areas
Your responsibility

A different seat.
A shared responsibility.

Find guidance for the decisions on your desk.

Legal & complianceGeneral Counsel & DPOs Leadership & financeBoards & CFOs Security & technologyCISOs & technology teams
Sector perspective

The same law.
A different business context.

A patient record, a payment journey and an AI training dataset raise different questions. Start with the context of your business.

01 Banking & financial servicesFinancial data. Vendors. Regulatory overlap. 02 Healthcare & life sciencesPatient information. Research. Digital care. 03 Technology & AIPersonal data. Model use. Accountability. 04 E-commerce & retailCustomer journeys. Consent. Retention. 05 Insurance & InsurTechPolicyholder data. Claims. Intermediaries. 06 Gaming & digital platformsChildren's data. Age assurance. User rights.
For startups & growing businesses For international companies entering India
The product · Introducing

The DPDPA File

Compliance is a file, not a claim. Fifty-six exhibits. Every obligation, mapped to a control, an owner and an artefact.

Open The DPDPA File
Exhibit · Significant Data Fiduciary

The SDF duties

Once notified an SDF, Section 10 read with Rule 13 adds an India-based DPO, an independent auditor, DPIAs and algorithmic due diligence. The exhibit lists each duty and its artefact.

56
Exhibits
44
Sections
23
Rules, 2025
7
Schedules
₹250 Cr
Maximum penalty
The framework · Proprietary

Vibe Data Privacy™

A governance framework built from the DPDPA statutory text — not translated from the GDPR. It measures your compliance stance against all 44 Sections and 23 Rules, and resolves to one Board-ready number.

Vibe Pulse Score
0 100

A single Board-ready index, assessed against the Act and the Rules — reported the way a finance committee reads a metric.

Trust Engineering

Depth across the disciplines that engineer trust.

Explore Trust Engineering

The systematic conversion of legal, regulatory, contractual and governance obligations into continuously operating business systems that can be measured, monitored and independently verified — organised across ten engineering disciplines.

Legal Engineering
01
Legal Engineering
Encode statutory obligations into machine-readable rules and continuously operating controls.
Data Privacy Engineering
02
Data Privacy Engineering
Design privacy into the data architecture itself — consent, rights, purpose limitation and erasure.
AI Governance Engineering
03
AI Governance Engineering
Govern AI systems through measurable, auditable frameworks across the model lifecycle.
Regulatory Engineering
04
Regulatory Engineering
Harmonise overlapping RBI, SEBI, IRDAI, CERT-In and global demands into one operating model.
Compliance Engineering
05
Compliance Engineering
Move compliance from periodic audits to continuous, policy-as-code verification.
Contract Engineering
06
Contract Engineering
Instrument DPA clauses, SCCs and SLA commitments into monitored contract intelligence.
Cyber Governance Engineering
07
Cyber Governance Engineering
Bridge CISO operations and board governance — incident, breach and posture management.
Risk Engineering
08
Risk Engineering
Quantify regulatory risk in business terms — penalty exposure and board-ready registers.
Evidence Engineering
09
Evidence Engineering
Design evidence chains that satisfy regulators, auditors and courts on demand.
Digital Trust Analytics
10
Digital Trust Analytics
Measure trust posture with the same rigour as financial metrics — scorecards and dashboards.
Across borders

Different markets.
Connected responsibilities.

Section 3(b) extends India's data protection regime to every organisation offering goods or services to Data Principals in India — regardless of where it is incorporated.

Multinational compliance
MNC compliance14 min

The DPDPA Obligation for Multinationals

A GDPR programme cannot be transplanted to the DPDPA. The Board examines Indian law. Not your global framework.

Read the analysis
Cross-border transfers
Cross border12 min

Cross Border Transfers Under the DPDPA

Section 16 permits transfers today. It can restrict them by executive notification tomorrow. The architecture must exist before that day.

Read the analysis
Investment due diligence
Investment & DD11 min

DPDPA Due Diligence for Foreign Investment

The gap discovered in the legal memo is the one that kills the transaction. The investors who find it have already decided.

Read the analysis
Maximum penalty · Schedule to the DPDPA, 2023
₹250
Crores

The Schedule prescribes the maximum. The Board determines the quantum under Section 33.

The only variable is your evidence — and when you begin building it.

Your starting point

What is on
your agenda?

Choose your role and priority to find relevant guidance across the practice.

Insights & knowledge

Explore the questions.
Examine the detail.

Articles, compliance analyses, working resources and answers from the AMLEGALS privacy practice.

The Consent Trap
ArticleMarch 2026

The Consent Trap: Why 90% of Indian Consent Mechanisms Will Fail DPDPA Scrutiny

Consent obtained minus consent understood equals zero legal defence. The gap between collection and validity is where the penalties live.

Read ↗
The Privacy Dividend
FrameworkMarch 2026

The Privacy Dividend: How Compliance Investment Returns More Than Penalty Avoidance

Companies that invest in trust outperform those that invest in damage control. Here is the model and the maths behind it.

Read ↗
DPDPA Readiness Survey
ReportFebruary 2026

DPDPA Readiness: A 50-Company Survey Across 12 Industries

Fifty organisations from BFSI and pharma to IT services and manufacturing. The gap between awareness and action is staggering.

Read ↗
Consent & Rights14 min
Consent Management Under DPDPA
Breach Response16 min
Data Breach Notification Under DPDPA
International13 min
Cross-Border Data Transfers Under DPDPA
Penalties14 min
DPDPA Penalties and Fines Structure
Read the full statutory analysis ↗All insights ↗
Compliance intelligence

The analyses that
define the terrain.

Each analysis maps a specific obligation to its operational reality — statutory text, regulatory overlap, implementation architecture and evidence requirements.

Compliance Cost Analysis
Cost heads, complexity bands and scope variables for implementation across organisation sizes.
13 May 2027 Deadline Roadmap
Phased commencement timeline, 30/90/180-day milestones and the Board-readiness evidence checklist.
DPDPA for CFOs
Penalty exposure quantification, Ind AS 37 provisioning, D&O insurability and Board disclosure.
Vendor Claims Register
No DPDPA certification body exists in India. How to evaluate vendor compliance claims against the statute.
Consent Manager Framework
Rule 4 registration, First Schedule Part A obligations and intermediary architecture for the consent lifecycle.
BFSI Compliance Architecture
RBI localisation, IRDAI overlay and SEBI KYC governance — reconciled with the Act Section by Section.
Cross-Border Transfers
The Section 16 negative-list regime, Rule 15 requirements and sectoral localisation mandates mapped.
GDPR vs DPDPA Comparison
Structural divergences: consent architecture, transfer mechanisms, penalties and enforcement models.
Knowledge Hub

DPDPA 2023 — every obligation,
every resource.

44 Sections. 23 Rules. One knowledge architecture — from statutory analysis to sector-specific compliance, from Board governance to operational implementation.

OfficesNew Delhi · Ahmedabad · Mumbai · Bengaluru · Pune · Kolkata · Chennai · Prayagraj · Surat · Vadodara
Speak with a practitioner ↗
Insights & answers

What practitioners and boards are asking.

Twenty-eight answers, each grounded in the statutory text rather than in a vendor's framework.

All DPDPA FAQs ↗
01What is DPDPA 2023 and who does it apply to?+
The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy legislation. It applies to all entities processing digital personal data in India, and to foreign entities processing personal data in connection with offering goods or services to Data Principals within India under Section 3. There is no revenue or size threshold — every Data Fiduciary processing digital personal data is within scope.
02What are the maximum penalties under DPDPA?+
Penalties run up to ₹250 crore under Section 33 read with the Schedule. The penalty for failure to protect children's data is up to ₹200 crore. The Data Protection Board of India determines the quantum based on the nature, gravity and duration of the breach.
03What is the Vibe Data Privacy Framework by AMLEGALS?+
Vibe Data Privacy™ is AMLEGALS' proprietary governance framework built from the DPDPA 2023 statutory text. It measures compliance across five operational layers — Signal (privacy frequency across consent records and data flows), Pulse (governance stance against all 44 Sections and 23 Rules), Drift (compliance entropy and deviations from baseline), Dividend (privacy ROI through trust metrics and audit readiness) and Culture (organisational privacy maturity) — producing a single Board-ready Vibe Pulse Score from 0 to 100.
04When will DPDPA be fully enforceable?+
The Act received Presidential Assent on 11 August 2023. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: institutional provisions including the Data Protection Board commenced on 13 November 2025; the Consent Manager framework under Rule 4 commences on 13 November 2026; and the substantive obligations on notice, consent, breach reporting, children's data, Significant Data Fiduciaries, rights and cross-border transfers commence on 13 May 2027. Treat the current period as the build window.
05How does DPDPA compare to GDPR?+
They are structurally independent frameworks. The DPDPA uses a negative-list approach for cross-border transfers under Section 16 rather than the GDPR's adequacy model; there is no right to data portability; enforcement sits with a single centralised Data Protection Board rather than multiple supervisory authorities; penalties are fixed amounts rather than revenue percentages; and the Act applies only to digital personal data, not to paper records.
06What is a Significant Data Fiduciary under DPDPA?+
Under Section 10, the Central Government may notify a Data Fiduciary as Significant based on the volume and sensitivity of data processed, risk to Data Principals and other prescribed factors. SDFs carry enhanced obligations including a mandatory DPO appointment based in India, periodic audits by independent auditors, and Data Protection Impact Assessments.
07Does DPDPA apply to foreign companies?+
Yes. Section 3 extends applicability to the processing of digital personal data outside India where that processing is in connection with offering goods or services to Data Principals within India. This extraterritorial scope means foreign companies must comply regardless of their physical location.
08What are the DPDP Rules 2025 and when were they notified?+
The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)) under Section 40. They contain 23 Rules and 7 Schedules covering notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), breach notification form and manner (Rule 7), children's data safeguards (Rule 10), SDF obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), cross-border transfer requirements (Rule 15) and the Data Protection Board (Rules 17 to 22). Commencement is phased, with the substantive obligations commencing on 13 May 2027.
09What are the consent requirements under Section 6?+
Section 6 requires consent that is free, specific, informed, unconditional and unambiguous, given by clear affirmative action. Section 5 mandates an itemised notice before or at the time of collection specifying the personal data and the purpose. Consent must be as easy to withdraw as to give under Section 6(6). Section 7 provides certain legitimate uses — historically termed deemed consent — including employment purposes, public interest and medical emergencies.
10What is the data breach notification obligation?+
Section 8(6) requires every Data Fiduciary to inform both the Data Protection Board of India and each affected Data Principal of a personal data breach. Rule 7 prescribes a staged model: affected Data Principals must be intimated without delay; the Board must receive an initial intimation without delay; and a detailed report must follow within 72 hours, or such longer period as the Board may allow on request. Failure to implement reasonable security safeguards attracting a breach carries penalties up to ₹250 crore under the Schedule.
11How does DPDPA protect children's personal data?+
Section 9 requires verifiable parental consent before processing any child's data, meaning anyone below eighteen years. Data Fiduciaries must not undertake tracking, behavioural monitoring or targeted advertising directed at children. Rule 10 prescribes the manner of obtaining verifiable parental consent. Processing that may cause a detrimental effect is prohibited, and the penalty for non-compliance is up to ₹200 crore under the Schedule.
12Does DPDPA apply to US SaaS companies selling to Indian customers?+
Yes. Section 3 applies extraterritorially where processing outside India is in connection with offering goods or services to Data Principals within India. US SaaS companies collecting personal data from Indian users through sign-ups, analytics, payment processing or support are Data Fiduciaries. Obligations include Section 5 notice, Section 6 consent, Section 8 breach notification and appointing a representative under the Rules.
13What happens if a foreign company ignores DPDPA compliance?+
Non-compliance exposes the entity to penalties up to ₹250 crore per instance under Section 33 read with the Schedule. The Board can issue directions, impose penalties and require remedial measures. Beyond money, non-compliance risks reputational damage, contract termination by Indian partners and potential blocking of services. Non-compliance with Board directions attracts further penalties under the Act.
14How is DPDPA different from PDPA Singapore and LGPD Brazil?+
The DPDPA applies exclusively to digital personal data rather than paper records, uses a negative-list approach for cross-border transfers unlike the PDPA accountability model and the LGPD adequacy model, prescribes fixed penalty amounts rather than revenue percentages, does not include a right to data portability, and centralises enforcement in a single Board. All three share a consent-centric architecture, but Section 7 on certain legitimate uses is narrower than the legitimate-interests bases in the LGPD and the PDPA exceptions.
15What is algorithmic due diligence under the DPDP Rules 2025?+
Rule 13 introduces algorithmic due diligence as an obligation for Significant Data Fiduciaries. It requires SDFs to verify that algorithmic systems processing personal data do not pose a risk to the rights of Data Principals — including algorithms used for profiling, automated decision-making or content recommendation. This is one of the first statutory algorithmic accountability requirements in Indian law.
16What are the DPDPA obligations for the BFSI sector?+
Banks, insurers, NBFCs and payment aggregators carry overlapping obligations. Under the Act: Section 5 notice, Section 6 consent, Section 8 breach notification and Section 10 SDF obligations if notified. In addition, RBI data localisation circulars mandate that payment system data be stored exclusively in India, IRDAI requires health and claims data retention, and SEBI mandates KYC data governance. The sector must reconcile these sectoral mandates with the Act to avoid regulatory conflict.
17How should a multinational structure its DPDPA compliance programme?+
Across four layers: entity mapping to identify which group entities qualify as Data Fiduciaries or Data Processors; data flow mapping to trace cross-border transfers under Section 16 and Rule 15; consent architecture design reconciling Section 6 consent with GDPR consent or legitimate interests already in place; and governance documentation including privacy notices, Data Processing Agreements, breach response protocols and DPO appointment for SDF-designated entities.
18What is a DPDPA Data Protection Impact Assessment?+
Rule 13 requires Significant Data Fiduciaries to conduct Data Protection Impact Assessments evaluating risk to Data Principals, mitigation measures and safeguard adequacy. The DPIA must be reviewed periodically and shared with the Board on request. Unlike GDPR Article 35, which requires DPIAs for all high-risk processing, the DPDPA limits this obligation to notified Significant Data Fiduciaries.
19What is the Rule 15 cross-border transfer requirement?+
Rule 15 supplements Section 16. While Section 16 empowers the Central Government to restrict transfers to notified countries on a negative-list approach, Rule 15 further allows requiring that personal data made available to any foreign State or its agencies meet prescribed requirements. Sectoral localisation mandates under the RBI, IRDAI and SEBI continue to apply independently. Unlike the GDPR, the DPDPA does not require adequacy decisions for permitted jurisdictions.
20What is the Consent Manager framework under the Rules?+
Rule 4 establishes the Consent Manager framework. A Consent Manager is an entity registered with the Board under the First Schedule Part A that acts as a single point of contact for Data Principals to give, manage, review and withdraw consent. Foreign companies can engage a registered Consent Manager, but legal responsibility for lawful processing remains with the Data Fiduciary. The registration framework commences on 13 November 2026.
21How does DPDPA apply to the insurance sector?+
Insurance companies face obligations overlaid with IRDAI requirements: Section 5 notice for policy data, Section 6 consent for health and claims data, Section 8 breach notification and potential Section 10 SDF obligations. IRDAI mandates on data retention, claims processing and policyholder data governance must be reconciled with the Act. AMLEGALS builds sector-specific reconciliation matrices mapping each IRDAI requirement to the corresponding provision.
22What DPDPA obligations apply to e-commerce platforms?+
Section 5 notice obligations at scale, Section 6 consent challenges for multiple processing purposes across marketing, analytics, personalisation and payment, Section 8 breach notification for large user bases, and potential SDF designation under Section 10 for high-volume processors. We advise on consent architecture design, vendor data processing agreements, cross-border transfer mechanisms for international fulfilment, and children's data protection under Section 9.
23Does DPDPA apply to the online gaming industry?+
Yes. Gaming platforms face acute Section 9 challenges because they cannot simply add an age gate. Verifiable parental consent under Rule 10 is required before processing any child's data, and behavioural monitoring, tracking and targeted advertising directed at children are prohibited. Gaming companies must also address Section 6 consent for gameplay analytics, in-app purchase data and social features, plus Section 8 breach notification obligations.
24What is the DPDPA compliance cost for organisations in India?+
Costs vary by organisation size, sector, processing complexity and existing governance maturity. Key cost heads include legal advisory, consent architecture implementation, privacy notice drafting, data mapping and flow analysis, breach notification infrastructure, DPO appointment for SDFs, Data Protection Impact Assessments, vendor agreement restructuring and ongoing compliance monitoring. We provide structured scope assessments so organisations can understand their specific investment requirement.
25Is there a DPDPA certification body in India?+
No. As of 2026, no DPDPA certification body exists in India. Neither the Act nor the Rules establish any certification framework. Any vendor claiming DPDPA certification, DPDPA-ready status or DPDPA audit compliance is making a claim without statutory backing. Evaluate vendor claims against the actual statutory text rather than relying on self-declared certifications.
26Who provides DPDPA compliance services in Delhi NCR?+
AMLEGALS provides counsel-led DPDPA compliance services from its New Delhi office at A-24, ILBS Colony, Vasant Kunj, New Delhi 110070. The firm advises on DPDP Act 2023 implementation, DPDP Rules 2025 compliance, consent architecture, breach notification, DPO services, cross-border transfers and Significant Data Fiduciary obligations. Contact [email protected] or +91-8448548549.
27Who provides DPDPA compliance services in Mumbai?+
AMLEGALS provides DPDPA compliance advisory from its Mumbai office. Services include implementation, consent management, breach notification protocols, DPO advisory, cross-border transfer structuring and the proprietary Vibe Data Privacy Framework assessment. The firm serves BFSI, pharmaceutical, e-commerce and technology entities across Maharashtra.
28Who provides DPDPA compliance services in Ahmedabad?+
AMLEGALS operates from its Ahmedabad office, providing comprehensive DPDPA compliance services to manufacturing, pharmaceutical, chemical and technology companies in Gujarat. Services include DPDP Act implementation, DPDP Rules compliance, consent architecture, Significant Data Fiduciary advisory and the Vibe Pulse Score assessment.
Start a conversation

What does your next decision need?

Tell us what you are working on. The practitioner with the relevant statutory expertise will respond directly. Confidential. Counsel-led. Statutory basis from the first engagement.

Data privacy desk
[email protected]
Boardline
+91-8448548549
Insights & Answers

What practitioners and boards are asking

What is DPDPA 2023 and who does it apply to?

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's comprehensive data privacy legislation. It applies to all entities processing digital personal data in India, and to foreign entities processing personal data in connection with offering goods or services to Data Principals within India under Section 3. There is no revenue or size threshold. every Data Fiduciary processing digital personal data is within scope.

What are the maximum penalties under DPDPA?

DPDPA prescribes penalties up to ₹250 Crore under Section 33 read with the Schedule. The penalty for failure to protect children's data is up to ₹200 Crore. The Data Protection Board of India determines penalties based on the nature, gravity, and duration of the breach.

What is the Vibe Data Privacy Framework by AMLEGALS?

Vibe Data Privacy™ is AMLEGALS' proprietary governance framework built from the DPDPA 2023 statutory text. It measures compliance across five operational layers. Signal (privacy frequency across consent records and data flows), Pulse (governance stance against all 44 Sections and 23 Rules), Drift (compliance entropy and deviations from baseline), Dividend (privacy ROI through trust metrics and audit readiness), and Culture (organisational privacy maturity). producing a single Board ready Vibe Pulse Score (VPS) from 0 to 100.

When will DPDPA be fully enforceable?

DPDPA received Presidential Assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: the institutional provisions, including the Data Protection Board, commenced on 13 November 2025; the Consent Manager framework (Rule 4) commences on 13 November 2026; and the substantive obligations on notice, consent, breach reporting, children data, Significant Data Fiduciaries, rights and cross-border transfers commence on 13 May 2027. Organisations should treat the current period as the build window.

How does DPDPA compare to GDPR?

DPDPA and GDPR are structurally independent frameworks. Key differences: (1) DPDPA uses a negative list approach for cross border transfers under Section 16 versus GDPR's adequacy model; (2) No right to data portability under DPDPA; (3) Centralised Data Protection Board versus multiple supervisory authorities; (4) Fixed penalty amounts versus revenue percentages; (5) DPDPA applies only to digital personal data, not paper records.

What is a Significant Data Fiduciary under DPDPA?

Under Section 10, the Central Government may notify a Data Fiduciary as Significant based on volume and sensitivity of data processed, risk to Data Principals, and other prescribed factors. SDFs have enhanced obligations including mandatory DPO appointment (based in India), periodic audits by independent auditors, and Data Protection Impact Assessments.

Does DPDPA apply to foreign companies?

Yes. Section 3 of DPDPA extends its applicability to processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. This extraterritorial scope means foreign companies offering goods or services to Data Principals within India must comply regardless of their physical location.

What are the DPDP Rules 2025 and when were they notified?

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)) under Section 40 of DPDPA. They contain 23 Rules and 7 Schedules covering notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), breach notification form and manner (Rule 7), children's data processing safeguards (Rule 10), Significant Data Fiduciary obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), cross-border transfer requirements (Rule 15), and the Data Protection Board (Rules 17 to 22). Commencement is phased, with the substantive obligations commencing on 13 May 2027.

What are the consent requirements under DPDPA Section 6?

Section 6 of DPDPA requires consent that is free, specific, informed, unconditional, and unambiguous with clear affirmative action. Section 5 mandates an itemised notice before or at the time of data collection specifying the personal data to be processed and the purpose. Consent must be as easy to withdraw as to give under Section 6(6). Section 7 provides certain legitimate uses (historically termed deemed consent) including employment purposes, public interest, and medical emergencies.

What is the data breach notification obligation under DPDPA?

Section 8(6) of DPDPA requires every Data Fiduciary to inform both the Data Protection Board of India and each affected Data Principal of a personal data breach. Rule 7 of DPDP Rules 2025 prescribes a staged model: affected Data Principals must be intimated without delay; the Data Protection Board must receive an initial intimation without delay; and a detailed report must follow within 72 hours, or such longer period as the Board may allow on request. Failure to implement reasonable security safeguards attracting a breach carries penalties up to Rs 250 Crore under the Schedule.

How does DPDPA protect children's personal data?

Section 9 of DPDPA requires verifiable parental consent before processing any child's data (below 18 years). Data Fiduciaries must not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Rule 10 of DPDP Rules 2025 prescribes the manner of obtaining verifiable parental consent. Processing children's data that may cause detrimental effect is prohibited. Penalty for non-compliance is up to Rs 200 Crore under the Schedule.

Does DPDPA apply to US SaaS companies selling to Indian customers?

Yes. Section 3 of DPDPA applies extraterritorially to the processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. US SaaS companies collecting personal data from Indian users through sign-ups, analytics, payment processing, or support are Data Fiduciaries under DPDPA. Compliance obligations include Section 5 notice, Section 6 consent, Section 8 breach notification, and appointing a representative under the DPDP Rules 2025.

What happens if a foreign company ignores DPDPA compliance?

Non-compliance exposes the entity to penalties up to Rs 250 Crore per instance under Section 33 read with the Schedule. The Data Protection Board can issue directions, impose penalties, and require remedial measures. Beyond monetary penalties, non-compliance risks reputational damage, contract termination by Indian partners, and potential blocking of services. The Data Protection Board can issue directions and impose remedial measures. Non-compliance with Board directions attracts further penalties under the Act.

How is DPDPA different from PDPA Singapore and LGPD Brazil?

DPDPA differs from Singapore PDPA and Brazil LGPD in several structural ways. DPDPA applies exclusively to digital personal data (not paper records), uses a negative-list approach for cross-border transfers (unlike PDPA accountability model and LGPD adequacy model), prescribes fixed penalty amounts rather than revenue percentages, does not include a right to data portability, and centralises enforcement in a single Data Protection Board. All three share a consent-centric architecture, but DPDPA Section 7 on certain legitimate uses is narrower than the legitimate interests bases in LGPD and PDPA exceptions.

What is algorithmic due diligence under DPDP Rules 2025?

Rule 13 of the DPDP Rules 2025 introduces algorithmic due diligence as an obligation for Significant Data Fiduciaries. It requires SDFs to verify that algorithmic systems processing personal data do not pose a risk to the rights of Data Principals. This includes ensuring algorithms used for profiling, automated decision-making, or content recommendation do not produce outcomes that are detrimental. This is one of the first statutory algorithmic accountability requirements in Indian law.

What are the DPDPA compliance obligations for the BFSI sector?

Banks, insurers, NBFCs, and payment aggregators face overlapping compliance obligations. Under DPDPA: Section 5 notice, Section 6 consent, Section 8 breach notification, and Section 10 SDF obligations (if notified). Additionally, RBI data localisation circulars mandate payment system data be stored exclusively in India. IRDAI requires health and claims data retention. SEBI mandates KYC data governance. The BFSI sector must reconcile these sectoral mandates with DPDPA to avoid regulatory conflict.

How should a multinational structure its DPDPA compliance programme?

Multinationals should structure their DPDPA programme across four layers: (1) Entity mapping to identify which group entities qualify as Data Fiduciaries or Data Processors, (2) Data flow mapping to trace cross-border transfers under Section 16 and Rule 15, (3) Consent architecture design reconciling DPDPA Section 6 consent with GDPR consent or legitimate interests already in place, and (4) Governance documentation including privacy notices, Data Processing Agreements, breach response protocols, and DPO appointment for SDF-designated entities.

What is a DPDPA Data Protection Impact Assessment?

Rule 13 of the DPDP Rules 2025 requires Significant Data Fiduciaries to conduct Data Protection Impact Assessments evaluating risk to Data Principals, mitigation measures, and safeguard adequacy. The DPIA must be reviewed periodically and shared with the Data Protection Board on request. Unlike GDPR Article 35 which requires DPIAs for all high-risk processing, DPDPA limits this obligation to notified Significant Data Fiduciaries.

What is the Rule 15 cross-border data transfer requirement under DPDP Rules 2025?

Rule 15 supplements Section 16 of DPDPA. While Section 16 empowers the Central Government to restrict transfers to notified countries (negative-list approach), Rule 15 further allows requiring that personal data made available to any foreign State or its agencies meet prescribed requirements. Sectoral localisation mandates under RBI, IRDAI, and SEBI continue to apply independently. Unlike GDPR, DPDPA does not require adequacy decisions for permitted jurisdictions.

Who provides DPDPA compliance services in Delhi NCR?

AMLEGALS provides counsel-led DPDPA compliance services from its New Delhi office at A-24, ILBS Colony, Vasant Kunj, New Delhi 110070. The firm advises on DPDP Act 2023 implementation, DPDP Rules 2025 compliance, consent architecture, breach notification, DPO services, cross-border transfers, and Significant Data Fiduciary obligations. Contact [email protected] or +91-8448548549.

Who provides DPDPA compliance services in Mumbai?

AMLEGALS provides DPDPA compliance advisory from its Mumbai office. Services include DPDPA implementation, consent management, breach notification protocols, DPO advisory, cross-border transfer structuring, and the proprietary Vibe Data Privacy Framework assessment. The firm serves BFSI, pharmaceutical, e-commerce, and technology entities across Maharashtra.

Who provides DPDPA compliance services in Ahmedabad?

AMLEGALS operates from its Ahmedabad office, providing comprehensive DPDPA compliance services to manufacturing, pharmaceutical, chemical, and technology companies in Gujarat. Services include DPDP Act implementation, DPDP Rules compliance, consent architecture, Significant Data Fiduciary advisory, and the Vibe Pulse Score assessment.

What is the Consent Manager framework under DPDP Rules 2025?

Rule 4 of the DPDP Rules 2025 establishes the Consent Manager framework. A Consent Manager is an entity registered with the Data Protection Board under the First Schedule Part A that acts as a single point of contact for Data Principals to give, manage, review, and withdraw consent. Foreign companies can engage a registered Consent Manager, but legal responsibility for lawful processing remains with the Data Fiduciary. The Consent Manager registration framework commences on 13 November 2026.

How does DPDPA apply to the insurance sector?

Insurance companies face DPDPA obligations overlaid with IRDAI regulatory requirements. Under DPDPA: Section 5 notice for policy data, Section 6 consent for health and claims data, Section 8 breach notification, and potential Section 10 SDF obligations. IRDAI mandates on data retention, claims processing, and policyholder data governance must be reconciled with DPDPA requirements. AMLEGALS builds sector-specific reconciliation matrices mapping each IRDAI requirement to the corresponding DPDPA provision.

What DPDPA obligations apply to e-commerce platforms?

E-commerce platforms processing customer data face Section 5 notice obligations at scale, Section 6 consent challenges for multiple processing purposes (marketing, analytics, personalisation, payment), Section 8 breach notification for large user bases, and potential SDF designation under Section 10 for high-volume processors. AMLEGALS advises e-commerce entities on consent architecture design, vendor data processing agreements, cross-border transfer mechanisms for international fulfilment, and children data protection under Section 9.

Does DPDPA apply to the online gaming industry?

Yes. Online gaming platforms face acute Section 9 challenges because they cannot simply add an age gate. Verifiable parental consent under Rule 10 is required before processing any child's data. Behavioural monitoring, tracking, and targeted advertising directed at children are prohibited. Gaming companies must also address Section 6 consent for gameplay analytics, in-app purchase data, and social features, plus Section 8 breach notification obligations.

What is the DPDPA compliance cost for organisations in India?

DPDPA compliance costs vary by organisation size, sector, data processing complexity, and existing governance maturity. Key cost heads include legal advisory, consent architecture implementation, privacy notice drafting, data mapping and flow analysis, breach notification infrastructure, DPO appointment (for SDFs), Data Protection Impact Assessments, vendor agreement restructuring, and ongoing compliance monitoring. AMLEGALS provides structured scope assessments to help organisations understand their specific compliance investment requirements.

Is there a DPDPA certification body in India?

No. As of 2026, no DPDPA certification body exists in India. The DPDP Act 2023 and DPDP Rules 2025 do not establish any certification framework. Any vendor claiming DPDPA certification, DPDPA-ready status, or DPDPA audit compliance is making a claim without statutory backing. Organisations should evaluate vendor compliance claims against the actual statutory text rather than relying on self-declared certifications.