India's DPDPA Compliance Deadline: May 2027

Leading Data Privacy & Data Protection Law firm in India

Free compliance tools and expert DPDPA, GDPR, and cross-border data protection guidance for businesses in India and worldwide.

7
Offices Across India
97
Country Network
106+
Privacy Articles
20+
Years Experience
🇮🇳 India Focus

DPDPA 2023 — Are You Ready?

India's comprehensive data protection law is here. With enforcement approaching May 2027, organisations must act now.

Aug 2023
DPDPA Enacted
Digital Personal Data Protection Act, 2023 receives Presidential assent
Jan 2025
Draft Rules Published
DPDP Rules, 2025 released for public consultation
Nov 2025
Final Rules Notified
Rules finalised and enforcement machinery begins
May 2027
Full Enforcement
All obligations in effect, penalties enforceable
₹250 Cr
Maximum Penalty
Per contravention
44
Sections
In the DPDPA
3-Phase
Rollout
Graduated enforcement
SDF
Obligations
Significant Data Fiduciaries

Why Choose Our Data Privacy Lawyers in India

A full-spectrum data privacy practice combining deep regulatory expertise with technology-driven solutions.

Pan-India Presence

8 offices covering every major business hub. Local knowledge of state-level compliance requirements.

97-Country Network

Cross-border data compliance through our international network. One firm for global privacy needs.

End-to-End Advisory

From compliance audits to regulatory filings, breach response to policy drafting. Full-spectrum privacy support.

Jidesh Kumar

Jidesh Kumar

Managing Partner
IP, Corporate & Litigation

Advises multinational corporations on IT Act compliance, data protection frameworks, and cross-border data transfers. Leads the firm's IP and technology practice.

Rajesh Sivaswamy

Rajesh Sivaswamy

Senior Partner
M&A, Private Equity & Cross-Border

Drives the firm's legal technology initiatives including AI-powered compliance tools. Advises on data governance for corporate transactions and regulated industries.

Dhruv Kaushal

Dhruv Kaushal

Partner
Technology, Data Privacy & AI

Advises technology, media and telecom companies on DPDPA and privacy compliance, AI governance and emerging-technology law. Recognised as Counsel of the Year for Data Privacy.

Aniket Ghosh

Aniket Ghosh

Partner
Data Privacy & Competition Law

Advises on DPDPA compliance, privacy audits, and competition law intersections with data regulation. Handles regulatory filings and enforcement matters.

Sindhuja Kashyap

Sindhuja Kashyap

Partner
Corporate Compliance & PE

Advises private equity and corporate clients on compliance frameworks including data protection obligations in M&A transactions and fund structuring.

Latest Insights

Expert analysis on India's DPDP Act and global data privacy.

View All Insights →
11 Jun 2026

From Human Fault to Algorithmic Accountability: Tort Law in the AI Era

Artificial Intelligence (AI) is transforming the way decisions are made across critical sectors worldwide. This shift from automation to autonomy presents significant challenges for traditional tort law, which has historically been built around concepts such as human fault, foreseeability and direct causation. Introduction Unlike traditional software systems that operate according to predefined instructions, modern AI […]

Read More
9 Jun 2026

Cyber Operations, Artificial Intelligence and the Law of State Responsibility

Examine how artificial intelligence, cyber-attacks and digital surveillance challenge traditional principles of State responsibility under international law.

Read More
30 Apr 2026

Cyber Law in India: A Critical Analysis of the Information Technology Act, 2000

Introduction Cyber law refers to the body of legal principles governing the use of the internet, digital technologies, and electronic communications. It encompasses a wide range of issues, including cybercrime, e-commerce, data protection, online privacy, and intellectual property rights in the digital environment. The rapid proliferation of digital technologies particularly the internet, mobile devices, and […]

Read More
27 Apr 2026

D&O Insurance in the Age of Data Governance: Premium Realities under India’s DPDP Regime

Introduction India’s enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) marks a decisive shift toward a modern data protection regime anchored in accountability, consent, and enforcement. While the statute is primarily directed at “data fiduciaries,” its implications extend well beyond operational compliance. At the boardroom level, the Act has triggered a reassessment […]

Read More
23 Apr 2026

Click-Wrap Agreements and India’s Data Privacy Law: Aligning Digital Consent with the DPDP Framework

Introduction The architecture of modern digital commerce rests on an unassuming yet powerful legal device: the click-wrap agreement. Whether subscribing to a SaaS platform, downloading a mobile application, or accepting updated privacy terms, users routinely click "I Agree," thereby forming binding contracts. While courts globally have generally upheld such agreements, their intersection with evolving data […]

Read More
20 Apr 2026

Checklist Before Collecting Indian User Data by Multinational Corporations

Navigating India’s Digital Personal Data Protection Act, 2023 Introduction: India’s Data Privacy Inflection Point India is not merely a market but the world’s largest pool of digital consumers, with over 900 million internet users and a rapidly expanding digital economy. For Multinational Corporations (MNCs), collecting personal data from Indian users whether for targeted advertising, product […]

Read More

Stay Ahead of Privacy Regulations

Weekly updates on DPDPA developments, global enforcement actions, and compliance tips. Join 500+ privacy professionals.

No spam. Unsubscribe anytime. We respect your privacy (obviously).

Who must comply with India’s DPDP Act, and by when

Key takeaway

India’s Digital Personal Data Protection Act, 2023 applies to any organisation, based in India or abroad, that decides why and how the digital personal data of people in India is processed. Those organisations are Data Fiduciaries. The DPDP Rules, 2025 phase the obligations in, with full enforcement from May 2027 and penalties of up to INR 250 crore per contravention. If your organisation collects, stores or processes the personal data of individuals in India, the Act almost certainly applies to you.

Who this is for: in-house counsel, compliance and privacy leads, and founders who need to know what applies to them, by when, and what to do first.

What this page covers

  1. Who qualifies as a Data Fiduciary, and what triggers the Act
  2. The phased enforcement timeline running to May 2027
  3. Penalties under the DPDP Act, including the INR 250 crore maximum
  4. How the DPDP Act compares with the GDPR
  5. A practical compliance roadmap
  6. Answers to the questions organisations ask most

Last updated: 10 August 2026

Primary sources: Ministry of Electronics and Information Technology, Data Protection Framework for the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025; EUR-Lex, Regulation (EU) 2016/679 (GDPR) for the GDPR comparisons on this page.

India’s DPDP Act, 2023: The Complete Guide

Everything businesses need to know about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, from scope and consent to penalties and compliance.

Reviewed and current as of July 2026
Overview and current status

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive data protection law. It governs the processing of digital personal data, gives individuals rights over their data, and places binding obligations on the organisations that handle it. It received Presidential assent on 11 August 2023, and the Digital Personal Data Protection Rules, 2025 were notified in November 2025, triggering a phased rollout.

The law was not brought into force all at once. Its provisions commence in phases notified alongside the 2025 Rules:

Phase 1: Nov 2025

The regulator goes live

The Data Protection Board of India is established, and the definitions and Board provisions take effect.

Phase 2: around Nov 2026

Consent Managers

The registration and obligations framework for Consent Managers becomes operational (about 12 months after notification).

Phase 3: around mid 2027

Core obligations enforceable

Notice and consent, security safeguards, breach notification, retention, children’s data, Significant Data Fiduciary duties, cross-border rules and data-principal rights become enforceable (about 18 months after notification).

Exact commencement dates are set by the Government’s notification. Because readiness work takes months, most organisations should begin now rather than wait for the final date.

Who and what it covers
  • Digital personal data. The Act applies to personal data collected in digital form, or collected on paper and later digitised. Purely offline records never digitised are outside its scope.
  • Within India: processing of digital personal data inside India.
  • Outside India (extraterritorial reach): processing outside India, if it is connected with offering goods or services to individuals in India.
  • Not covered: data processed by an individual for a purely personal or domestic purpose, and personal data that the individual (or someone under a legal duty) has made publicly available.
  • No “sensitive data” category. Unlike the GDPR and the earlier 2019 Bill, the Act treats all personal data uniformly and has no separate class of sensitive or critical data.
Key definitions
TermMeaning
Data PrincipalThe individual the personal data relates to. For a child it includes the parent or lawful guardian; for a person with disability, the lawful guardian.
Data FiduciaryAny person who, alone or with others, determines the purpose and means of processing personal data.
Data ProcessorAny person who processes personal data on behalf of a Data Fiduciary.
Personal dataAny data about an individual who is identifiable by or in relation to such data.
ProcessingAny automated operation on digital personal data: collection, storage, use, sharing, disclosure, erasure and more.
ConsentFree, specific, informed, unconditional and unambiguous agreement, given by a clear affirmative action, limited to the data necessary for the stated purpose.
Consent ManagerA Board-registered platform that lets individuals give, manage, review and withdraw consent through a single interoperable interface.
Significant Data FiduciaryA Data Fiduciary (or class) notified by the Government because of the volume, sensitivity or risk of its processing. Extra obligations apply.
Data Protection OfficerAn India-based officer a Significant Data Fiduciary must appoint, answerable to its board and the contact point for grievances.
Data Protection Board of IndiaThe regulator that inquires into breaches, hears complaints and imposes penalties.
ChildAn individual who has not completed 18 years of age.
Lawful grounds for processing

Personal data may be processed only for a lawful purpose, on one of two bases: consent (Section 6), or a defined legitimate use (Section 7). There is no open-ended “legitimate interests” balancing test as under the GDPR. The legitimate uses are a closed list:

  • Data the individual voluntarily provided for a specified purpose and has not objected to.
  • Provision by the State of a subsidy, benefit, service, certificate, licence or permit.
  • Performance of a function of the State under law, or in the interest of India’s sovereignty, integrity or security.
  • Compliance with a legal obligation to disclose information to the State.
  • Compliance with a judgment, decree or order.
  • Responding to a medical emergency threatening life or health.
  • Measures during an epidemic or threat to public health.
  • Measures to ensure safety or assistance during a disaster or breakdown of public order.
  • Employment purposes, or safeguarding the employer from loss or liability.
Notice, consent and Consent Managers

Notice (Section 5): every consent request must be accompanied by a clear, plain-language, itemised notice stating the personal data collected, the purpose, how to withdraw consent, how to exercise rights, and how to complain to the Board. It must be available in English or any language in the Eighth Schedule to the Constitution.

Consent (Section 6): must be free, specific, informed, unconditional and unambiguous, and limited to the data necessary for the stated purpose. Individuals can withdraw consent at any time, and withdrawing must be as easy as giving it. On withdrawal, processing must stop within a reasonable time.

Consent Managers: individuals can give, manage, review and withdraw consent through a Consent Manager, a company registered with the Board that runs an interoperable, transparent, accessible platform and is accountable to the individual.

Your rights as a Data Principal

Right to access

Obtain a summary of your personal data being processed and the identities of everyone it has been shared with.

Right to correction and erasure

Have inaccurate data corrected or completed, and personal data erased when it is no longer needed.

Right to grievance redressal

A readily available means to raise concerns with the Data Fiduciary or Consent Manager, answered within a set time.

Right to nominate

Nominate another person to exercise your rights if you die or become incapacitated.

Duties of a Data Principal

  • Do not impersonate another person when providing your data.
  • Do not suppress material information when providing an official identity or address document.
  • Do not file a false or frivolous grievance or complaint.
  • Provide only verifiably authentic information when seeking correction or erasure.

Breaching a Data Principal duty can attract a penalty of up to ₹10,000.

Obligations of a Data Fiduciary
  • Accountability: you remain responsible for compliance even for processing done by a processor on your behalf, and regardless of any contrary agreement.
  • Valid processor contracts: you may engage a Data Processor only under a valid contract.
  • Accuracy: keep data complete, accurate and consistent where it is used to make decisions or shared.
  • Security safeguards: implement reasonable measures such as encryption, access control, and logging (logs retained at least one year).
  • Breach notification: notify the Board and every affected individual of a personal data breach.
  • Erasure and retention: erase data on withdrawal of consent or once the purpose is served, and cause your processors to do the same.
  • Grievance redressal: publish and run an effective grievance mechanism and respond within the published time.
  • Publish a contact: publish the business contact of a Data Protection Officer or a person able to answer questions about your processing.
Personal data breaches

A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data.

NotifyWhenWhat
Affected individualsWithout delayA concise, plain-language description of the breach, its likely consequences, the mitigation taken, steps they can take, and a contact point.
Data Protection BoardWithout delay, then a detailed report within 72 hoursInitial intimation on becoming aware, followed by a detailed report covering facts, mitigation, findings and remedial measures (the 72-hour window is extendable by the Board).

The DPDP breach duty is separate from CERT-In’s 6-hour cyber-incident reporting under the IT Act. Both can apply.

Children’s data
  • A child is anyone under 18.
  • Processing a child’s data requires verifiable consent of a parent or lawful guardian.
  • No processing that is likely to have a detrimental effect on a child’s well-being.
  • No tracking or behavioural monitoring of children.
  • No targeted advertising directed at children.
  • The Rules allow limited exemptions for certain purposes and classes (for example healthcare and education), and set out how parental consent is to be verified.
Significant Data Fiduciaries

The Government can designate a Data Fiduciary or class as a Significant Data Fiduciary (SDF) based on the volume and sensitivity of data processed and the risk to individuals, the State and public order. An SDF must:

  • Appoint a Data Protection Officer based in India, answerable to its board or governing body.
  • Appoint an independent data auditor.
  • Carry out a Data Protection Impact Assessment and a data audit every 12 months and report significant observations to the Board.
  • Verify that any algorithmic software used does not pose a risk to individuals’ rights.
  • Comply with any Government order restricting the transfer of specified data outside India.
Cross-border data transfers

India uses a negative-list (blacklist) model: a Data Fiduciary may transfer personal data outside India except to a country or territory the Government specifically restricts by notification. As of July 2026 no restricted-country list appears to have been notified, so the default remains open.

Where another law provides stricter protection or localisation (for example RBI payment-data storage, or IRDAI and SEBI norms), that stricter rule overrides the permissive default. Significant Data Fiduciaries may also face localisation of specified data by Government order.

Exemptions
  • Enforcing a legal right or claim.
  • Processing by courts, tribunals and regulatory bodies in their functions.
  • Prevention, detection, investigation or prosecution of offences.
  • Processing of non-residents’ data under a contract with a person outside India (outsourcing into India).
  • Mergers, amalgamations and similar schemes approved by a competent authority.
  • Assessing the assets and liabilities of a loan defaulter.
  • Notified State instrumentalities, and research, archiving or statistical processing that does not target individuals.
  • The Government may exempt notified classes, including certain start-ups, from some provisions, and may grant time-limited exemptions.
The Data Protection Board and appeals

The Data Protection Board of India is the regulator. It operates as a digital-by-design office and, on a breach intimation or complaint, can direct urgent remedial measures, inquire into breaches with the powers of a civil court, and impose penalties.

  • Grievance first: individuals must use the Data Fiduciary’s grievance mechanism before approaching the Board.
  • Appeals: appeals against the Board’s orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), generally within 60 days.
  • Alternate dispute resolution: the Board can refer suitable complaints to mediation.
  • Voluntary undertakings: the Board may accept a voluntary undertaking, which bars further proceedings on the same matter unless it is breached.
Penalties

Penalties under the DPDP Act are monetary (civil) only: there is no imprisonment. The Board sets the amount considering the nature, gravity and duration of the breach, whether it was repeated, any gain made, and mitigating action taken.

ContraventionMaximum penalty
Failure to take reasonable security safeguards to prevent a breach₹250 crore
Failure to notify a personal data breach₹200 crore
Breach of obligations relating to children’s data₹200 crore
Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Breach of any other provision of the Act or Rules₹50 crore
Breach of a Data Principal’s duties₹10,000

Unlike the GDPR, there is no percentage-of-turnover formula; the maximum is a fixed ₹250 crore per instance.

The DPDP Rules, 2025

The Rules operationalise the Act. Key provisions include:

AreaWhat the Rules require
Notice formatStandalone, clear, itemised, plain-language notices with links to withdraw consent, exercise rights and complain to the Board.
Consent ManagersRegistration with the Board; must be an India-incorporated company with a minimum net worth (₹2 crore) and an interoperable platform.
Security safeguardsEncryption or masking, access controls, logging and monitoring, with logs kept at least one year, plus backups and processor security terms.
Breach notificationIntimation to individuals without delay, and a detailed report to the Board within 72 hours (extendable).
RetentionLarge e-commerce, social media (2 crore+ users) and online gaming (50 lakh+ users) platforms must erase specified data 3 years after last use, with 48 hours’ advance notice.
Children’s consentTechnical measures to verify that consent is from an identifiable adult parent or lawful guardian.
SDF dutiesDPIA and data audit every 12 months, and verification of algorithmic software.
Rights and grievancesPublish how to exercise rights and the time within which grievances are resolved.
The BoardConstitution, appointment and digital functioning of the Data Protection Board.
DPDP Act vs GDPR
DimensionDPDP Act (India)EU GDPR
TerminologyData Principal, Data Fiduciary, Data ProcessorData Subject, Controller, Processor
ScopeDigital personal data only; no sensitive-data classAll personal data; special categories of sensitive data
Legal basesTwo: consent or a listed legitimate useSix, including open-ended legitimate interests
Child ageUnder 18; verifiable parental consentUnder 16 (states may lower to 13)
DPO and DPIARequired for Significant Data FiduciariesRequired for high-risk or large-scale processing
Cross-borderPermissive: allowed except to restricted countriesRestrictive: adequacy, SCCs or BCRs required
Portability and erasureNo portability; erasure tied to purpose or withdrawalPortability and right to be forgotten
PenaltiesFixed caps up to ₹250 crore; civil onlyUp to €20m or 4% of global turnover
Duties on individualsYes, with penaltiesNone
A practical compliance roadmap
  • Map your data: build an inventory of what personal data you collect, why, where it flows and who you share it with.
  • Fix your lawful basis: map each activity to consent or a listed legitimate use.
  • Rebuild notices and consent: plain-language, itemised notices, easy withdrawal, and consent records.
  • Update your privacy policy: publish a DPO or contact, rights mechanisms and grievance timelines.
  • Strengthen security: encryption or masking, access control, logging with at least one year of retention.
  • Prepare a breach playbook: detection, individual notice without delay, and the Board’s 72-hour report.
  • Set retention and erasure: purpose-based retention and automated erasure.
  • Update vendor contracts: valid processor agreements covering security, breach and erasure.
  • Handle children’s data: age assurance and verifiable parental consent; switch off tracking and targeted ads.
  • Assess SDF status: if likely designated, appoint an India-based DPO and auditor and schedule annual DPIA and audit.
  • Review cross-border flows: track any restricted-country list and stricter sectoral localisation.
  • Operationalise rights: workflows for access, correction, erasure, nomination and grievances.

This guide is general information current as of July 2026 and is not legal advice. The DPDP Rules, 2025 are being phased in and exact dates are set by Government notification. For advice on your organisation’s specific obligations, speak to King Stubb & Kasiva’s data privacy team.

Frequently Asked Questions

DPDP Act, GDPR, and data privacy compliance in India, answered.

Who needs to comply with India’s DPDP Act, 2023?
Any organisation that decides why and how the digital personal data of individuals in India is processed is a Data Fiduciary and must comply, whether it is based in India or abroad. The Act also reaches processing outside India when it relates to offering goods or services to people in India.
What are the penalties for non-compliance with the DPDP Act?
The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards that lead to a personal data breach, and up to ₹200 crore for breaching obligations on children’s data. Each penalty is decided on the nature, gravity, and duration of the default.
When do the DPDP Rules take effect?
The DPDP Rules, 2025 were notified on 13 November 2025 and commence in tranches. The Data Protection Board provisions applied immediately, the Consent Manager framework applies from 13 November 2026, and the core obligations on notice, consent, security safeguards, breach reporting, retention and data-principal rights apply from 13 May 2027.
Does the GDPR apply to Indian companies?
Yes. The EU GDPR can apply to an Indian company that offers goods or services to people in the EU or monitors their behaviour, wherever the company is located. Many Indian businesses fall under both the DPDP Act and the GDPR, and a single combined programme avoids duplicated work.
What is a Consent Manager under the DPDP Act?
A Consent Manager is a platform registered with the Data Protection Board that lets individuals give, review, manage, and withdraw consent through one interface. Data Fiduciaries that rely on consent will need to work with registered Consent Managers.
Does my company need a Data Protection Officer in India?
Organisations classed as Significant Data Fiduciaries must appoint a Data Protection Officer based in India who answers to the board or governing body. Other Data Fiduciaries still need a published contact point for data-principal queries and grievances, and many appoint a DPO voluntarily.
Can we transfer personal data outside India under the DPDP Act?
The Act allows transfers of personal data to countries other than those the government specifically restricts by notification. Sector regulators, for example in banking or insurance, can impose stricter localisation rules, so each transfer should be checked against both the Act and any sectoral requirement.
How do we prepare for a data breach under the DPDP Act?
You must be able to notify the Data Protection Board and affected individuals of a personal data breach without undue delay. Readiness means keeping a current data inventory, an incident-response plan with clear roles, and evidence of reasonable security safeguards before any breach happens.

Data Protection and Privacy Laws in India

India’s data protection framework is anchored by the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025, which together govern how organisations collect, process, store and transfer the personal data of individuals in India. Until the DPDP regime is fully operational, the Information Technology Act, 2000 and the SPDI Rules, 2011 continue to apply to sensitive personal data, alongside sector-specific requirements issued by regulators such as the RBI, SEBI and IRDAI. Businesses that also handle the data of individuals in the EU or UK must align with the GDPR, making a harmonised, cross-border compliance strategy essential.

DPDP Act Compliance & Advisory

Our data privacy lawyers help Indian and global businesses operationalise the DPDP Act through practical, audit-ready compliance. We advise on lawful consent and privacy notices, data principal rights and grievance redressal, cross-border data transfers, data breach notification, retention and deletion, and the heightened obligations that apply to Significant Data Fiduciaries, including appointing a Data Protection Officer and conducting Data Protection Impact Assessments. With penalties of up to ₹250 crore per default under the Act, we design compliance programmes that reduce regulatory and reputational risk while supporting business growth.

Data privacy lawyers across India

King Stubb & Kasiva advises on the DPDP Act, 2023 and global privacy regimes from nine offices across seven Indian cities. Wherever your data is processed, the same privacy team handles readiness assessments, consent and notice design, cross-border transfers, breach response and Data Protection Board proceedings.

Data privacy lawyers in New Delhi

RNM Tower, 5th Floor, Metro Pillar No. 331, i4, B1, NH-19, Mohan Cooperative Industrial Estate, New Delhi 110044

Telephone +91-11-41318190
New Delhi office

Data privacy lawyers in Mumbai

Nariman Point: Office No. 61, 6th Floor, Atlanta Building, Jamnalal Bajaj Road, Mumbai 400021

Lower Parel: 301A, 3rd Floor, Piramal Towers, Peninsula Corporate Park, Senapati Bapat Marg, Mumbai 400013

Andheri West: 802, 8th Floor, REMI Commercio, Shah Industrial Estate, Veera Desai Road, Mumbai 400053

Telephone +91-22-69010531
Mumbai office

Data privacy lawyers in Bengaluru

1A, Lavelle Mansion, 1/2 Lavelle Road, Bengaluru 560001

Telephone +91-80-41179111
Bengaluru office

Data privacy lawyers in Chennai

211, Alpha Wing, Second Floor, Raheja Towers, 177 Anna Salai, Chennai 600002

Telephone +91-44-28605955
Chennai office

Data privacy lawyers in Hyderabad

404, Shangrila Plaza, Road No. 2, Banjara Hills, Opposite KBR Park, Hyderabad 500034

Telephone +91-40-48516011
Hyderabad office

Data privacy lawyers in Pune

Bootstart Cowork, First Floor, Arcadian Building, Plot No. 12, Lane 5A, North Main Road, Koregaon Park, Pune 411001

Telephone +91-22-62372076
Pune office

Data privacy lawyers in Kochi

1st Floor, Manavalan Building, Amulya Street, Banerji Road, Ernakulam, Kochi 682018

Telephone +91-484-3592950
Kochi office

We act for clients in states where we do not keep an office, including Gujarat, West Bengal, Rajasthan and the north east, through the same pan-India team. Contact the data privacy practice to talk through where you stand before 13 May 2027.

DPDP guidance by topic

Our data protection commentary, grouped by the questions clients ask most. For the full statute, read the complete guide to the DPDP Act, 2023.

DPDP and Data Privacy Insights

Recent commentary from our data privacy team.