India's DPDPA Compliance Deadline: May 2027

Data Privacy & DPDP Law Firm in India

Free compliance tools and expert guidance for businesses navigating India and global privacy law.

7
Offices Across India
97
Country Network
106+
Privacy Articles
20+
Years Experience
🇮🇳 India Focus

DPDPA 2023 — Are You Ready?

India's comprehensive data protection law is here. With enforcement approaching May 2027, organisations must act now.

Aug 2023
DPDPA Enacted
Digital Personal Data Protection Act, 2023 receives Presidential assent
Jan 2025
Draft Rules Published
DPDP Rules, 2025 released for public consultation
Nov 2025
Final Rules Notified
Rules finalised and enforcement machinery begins
May 2027
Full Enforcement
All obligations in effect, penalties enforceable
₹250 Cr
Maximum Penalty
Per contravention
44
Sections
In the DPDPA
3-Phase
Rollout
Graduated enforcement
SDF
Obligations
Significant Data Fiduciaries

Why KSK for Data Privacy?

A full-spectrum data privacy practice combining deep regulatory expertise with technology-driven solutions.

Pan-India Presence

8 offices covering every major business hub. Local knowledge of state-level compliance requirements.

97-Country Network

Cross-border data compliance through our international network. One firm for global privacy needs.

End-to-End Advisory

From compliance audits to regulatory filings, breach response to policy drafting. Full-spectrum privacy support.

Jidesh Kumar

Jidesh Kumar

Managing Partner
IP, Corporate & Litigation

Advises multinational corporations on IT Act compliance, data protection frameworks, and cross-border data transfers. Leads the firm's IP and technology practice.

Rajesh Sivaswamy

Rajesh Sivaswamy

Senior Partner
M&A, Private Equity & Cross-Border

Drives the firm's legal technology initiatives including AI-powered compliance tools. Advises on data governance for corporate transactions and regulated industries.

Dhruv Kaushal

Dhruv Kaushal

Partner
Technology, Data Privacy & AI

Advises technology, media and telecom companies on DPDPA and privacy compliance, AI governance and emerging-technology law. Recognised as Counsel of the Year for Data Privacy.

Aniket Ghosh

Aniket Ghosh

Partner
Data Privacy & Competition Law

Advises on DPDPA compliance, privacy audits, and competition law intersections with data regulation. Handles regulatory filings and enforcement matters.

Sindhuja Kashyap

Sindhuja Kashyap

Partner
Corporate Compliance & PE

Advises private equity and corporate clients on compliance frameworks including data protection obligations in M&A transactions and fund structuring.

Latest Insights

Expert analysis on India's DPDP Act and global data privacy.

View All Insights →
11 Jun 2026

From Human Fault to Algorithmic Accountability: Tort Law in the AI Era

Artificial Intelligence (AI) is transforming the way decisions are made across critical sectors worldwide. This shift from automation to autonomy presents significant challenges for traditional tort law, which has historically been built around concepts such as human fault, foreseeability and direct causation. Introduction Unlike traditional software systems that operate according to predefined instructions, modern AI […]

Read More
9 Jun 2026

Cyber Operations, Artificial Intelligence and the Law of State Responsibility

Examine how artificial intelligence, cyber-attacks and digital surveillance challenge traditional principles of State responsibility under international law.

Read More
30 Apr 2026

Cyber Law in India: A Critical Analysis of the Information Technology Act, 2000

Introduction Cyber law refers to the body of legal principles governing the use of the internet, digital technologies, and electronic communications. It encompasses a wide range of issues, including cybercrime, e-commerce, data protection, online privacy, and intellectual property rights in the digital environment. The rapid proliferation of digital technologies particularly the internet, mobile devices, and […]

Read More
27 Apr 2026

D&O Insurance in the Age of Data Governance: Premium Realities under India’s DPDP Regime

Introduction India’s enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) marks a decisive shift toward a modern data protection regime anchored in accountability, consent, and enforcement. While the statute is primarily directed at “data fiduciaries,” its implications extend well beyond operational compliance. At the boardroom level, the Act has triggered a reassessment […]

Read More
23 Apr 2026

Click-Wrap Agreements and India’s Data Privacy Law: Aligning Digital Consent with the DPDP Framework

Introduction The architecture of modern digital commerce rests on an unassuming yet powerful legal device: the click-wrap agreement. Whether subscribing to a SaaS platform, downloading a mobile application, or accepting updated privacy terms, users routinely click "I Agree," thereby forming binding contracts. While courts globally have generally upheld such agreements, their intersection with evolving data […]

Read More
20 Apr 2026

Checklist Before Collecting Indian User Data by Multinational Corporations

Navigating India’s Digital Personal Data Protection Act, 2023 Introduction: India’s Data Privacy Inflection Point India is not merely a market but the world’s largest pool of digital consumers, with over 900 million internet users and a rapidly expanding digital economy. For Multinational Corporations (MNCs), collecting personal data from Indian users whether for targeted advertising, product […]

Read More

Stay Ahead of Privacy Regulations

Weekly updates on DPDPA developments, global enforcement actions, and compliance tips. Join 500+ privacy professionals.

No spam. Unsubscribe anytime. We respect your privacy (obviously).

Data privacy practice

Data privacy and DPDP lawyers in India

King Stubb & Kasiva is an Indian law firm whose data privacy practice advises companies on the Digital Personal Data Protection Act, 2023, the DPDP Rules, 2025 and global privacy laws such as the GDPR and CCPA. The practice is led by partners Jidesh Kumar, Rajesh Sivaswamy, Dhruv Kaushal, Aniket Ghosh and Sindhuja Kashyap, and works from nine offices across seven Indian cities.

DPDP Act guide

The DPDP Act in India: a complete guide on one page

A plain-language summary of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, prepared by the King Stubb & Kasiva data privacy practice. Each topic links to our detailed analysis.

Last reviewed 29 September 202618 topicsGeneral information, not legal advice

01What the DPDP Act is

The Digital Personal Data Protection Act, 2023 (Act 22 of 2023) is India’s first general law on the protection of personal data. It received Presidential assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) were notified on 13 November 2025 and set out how the Act works in practice.

Once fully in force, the Act replaces the data protection regime under section 43A of the Information Technology Act, 2000 and the SPDI Rules, 2011.

02When it applies: the commencement timeline

  1. 14 November 2025The Data Protection Board provisions and Rules 1, 2 and 17 to 21 came into force.
  2. 13 November 2026The Consent Manager framework (Rule 4) applies.
  3. 13 May 2027The core obligations apply, including notice, consent, security safeguards, breach intimation, retention, children’s data, Significant Data Fiduciary duties and data principal rights.

A proposal to shorten the 18-month transition was discussed in early 2026, but no amendment has been notified, so 13 May 2027 remains the compliance date. Until then, section 43A of the IT Act and the SPDI Rules continue to apply.

03Who the Act applies to

The Act applies to digital personal data processed in India, whether collected in digital form or collected offline and digitised later. It also applies to processing outside India if it is connected with offering goods or services to people in India.

  • It does not apply to personal data processed by an individual for a personal or domestic purpose.
  • It does not apply to personal data that the individual has made publicly available, or that someone is legally obliged to make public.

04Key terms

  • Data Principal: the individual the personal data relates to. For a child, it includes the parent or lawful guardian, and for a person with a disability, their lawful guardian.
  • Data Fiduciary: the person or company that decides the purpose and means of processing.
  • Data Processor: anyone who processes personal data on behalf of a Data Fiduciary.
  • Consent Manager: a company registered with the Data Protection Board through which individuals give, manage and withdraw consent.
  • Significant Data Fiduciary: a Data Fiduciary the Central Government notifies as significant, based on factors such as the volume and sensitivity of the data it processes.

06Processing without consent: legitimate uses

Section 7 lists the situations in which personal data may be processed without consent:

  • for a purpose for which the individual voluntarily provided the data and has not said they do not consent
  • State subsidies, benefits, services, licences and permits, and other functions of the State
  • complying with a legal obligation to disclose information to the State, or with a judgment, decree or order
  • medical emergencies, treatment during an epidemic or public health threat, and safety during a disaster or breakdown of public order
  • employment purposes, including protecting the employer from loss or liability

07Obligations of Data Fiduciaries

  • Keep personal data complete, accurate and consistent where it is used to make a decision about the individual or is shared with another Data Fiduciary.
  • Take reasonable security safeguards. Rule 6 sets minimum measures, including encryption, masking or tokenisation, access controls, logs and monitoring, backups, and keeping logs for at least one year.
  • Engage Data Processors only under a valid contract.
  • Erase personal data when consent is withdrawn or the purpose is no longer served, unless the law requires it to be kept.
  • Publish the contact details of a Data Protection Officer or a person who can answer questions about processing, and run a grievance redressal mechanism.

08Personal data breaches

Under Rule 7, a Data Fiduciary must inform each affected individual without delay, and the Data Protection Board without delay. A detailed report must reach the Board within 72 hours of becoming aware of the breach, covering the facts, likely impact, mitigation, the cause and the remedial measures taken, unless the Board allows longer on request.

This runs alongside the CERT-In Directions of April 2022, which require specified cyber incidents to be reported to CERT-In within six hours of noticing them.

09Retention and erasure

Personal data must be erased once the purpose is served, unless the law requires otherwise. Rule 8 and the Third Schedule set a three-year period of inactivity, with 48 hours’ notice before erasure, only for large e-commerce entities (2 crore or more users in India), online gaming intermediaries (50 lakh or more) and social media intermediaries (2 crore or more).

Every Data Fiduciary must also keep personal data, related traffic data and processing logs for at least one year for the purposes in the Seventh Schedule.

10Children and persons with disabilities

A child is anyone under 18. Processing a child’s personal data needs the verifiable consent of a parent or lawful guardian. Data Fiduciaries must not process children’s data in a way likely to harm their well-being, and must not track, behaviourally monitor or target advertising at children.

Rule 10 allows parental consent to be verified through reliable identity details the Data Fiduciary already holds, details the parent provides, or a virtual token such as one issued through DigiLocker. The Fourth Schedule exempts classes such as healthcare professionals, educational institutions and crèches for specified purposes. For persons with disabilities, the guardian must be verified under Rule 11.

11Significant Data Fiduciaries and Data Protection Officers

A Significant Data Fiduciary must appoint a Data Protection Officer based in India who is responsible to its board, appoint an independent data auditor, and carry out a Data Protection Impact Assessment and an audit every 12 months (Rule 13). It must also check that algorithmic software does not put individuals’ rights at risk, and keep specified personal data in India if the government requires it. No Significant Data Fiduciary had been notified as of September 2026.

Other Data Fiduciaries do not have to appoint a DPO, but must publish the contact details of a person who can answer questions about their processing.

12Rights and duties of Data Principals

Data Fiduciaries must publish a response period for these requests of no more than 90 days (Rule 14). Individuals also have duties, such as not impersonating anyone and not filing false or frivolous complaints; a breach can attract a penalty of up to ₹10,000.

  • Access: a summary of the personal data being processed and the processing, and the identities of others it has been shared with.
  • Correction, completion, updating and erasure.
  • Grievance redressal, which must be used before going to the Board.
  • Nomination of another person to exercise these rights on death or incapacity.

13Cross-border data transfers

Personal data may be transferred outside India except to countries the Central Government restricts by notification. No country has been restricted so far. Sector laws that impose stricter localisation, such as RBI’s payment data rules, continue to apply, and Rule 15 lets the government set requirements for making data available to foreign states.

14Exemptions

Most obligations do not apply where processing is needed to enforce a legal right or claim, by courts and regulators performing their functions, for preventing, investigating or prosecuting offences, for processing in India of non-residents’ data under a foreign contract, for approved mergers and schemes of arrangement, or to ascertain the financial position of loan defaulters. The government may also exempt notified State bodies, processing for research, archiving or statistics, and classes of Data Fiduciaries such as startups.

15The Data Protection Board, appeals and penalties

The Data Protection Board of India inquires into breaches, directs remedial measures and imposes penalties. It can refer disputes to mediation and accept voluntary undertakings. The Board was established on 13 November 2025; as of September 2026, no Chairperson or Members had been reported as appointed. Appeals against its orders go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days.

The Schedule to the Act sets maximum penalties by type of breach. There are no criminal offences under the Act.

Up to ₹250 crorefailing to take reasonable security safeguards
Up to ₹200 crorefailing to notify a personal data breach
Up to ₹200 crorebreaching the obligations on children’s data
Up to ₹150 crorebreaching the additional obligations of a Significant Data Fiduciary
Up to ₹50 croreany other breach of the Act or Rules
Up to ₹10,000breach of a Data Principal’s duties

16How the DPDP Act fits with other laws

The Act applies in addition to other laws, and prevails where they conflict. Sector regulators such as RBI, SEBI and IRDAI continue to set their own data rules. Section 44(3) amended section 8(1)(j) of the RTI Act to exempt personal information; a challenge to that amendment was referred to a larger bench of the Supreme Court in February 2026, which declined an interim stay.

18How to prepare before 13 May 2027

  • Map the personal data you collect, where it is stored, who it is shared with and why.
  • Rewrite privacy notices and consent flows to meet Rule 3 and section 6, with an easy way to withdraw consent.
  • Review contracts with vendors and processors, and your cross-border data flows.
  • Put Rule 6 security safeguards in place and keep logs for at least one year.
  • Prepare a breach response plan that meets the 72-hour report to the Board and CERT-In’s six-hour rule.
  • Set retention periods and erasure processes, and a way to handle rights requests within your published response period.
  • Check whether you process children’s data or could be notified as a Significant Data Fiduciary.

Enquire about DPDP compliance

Tell us what your organisation does with personal data and what you need, whether a gap assessment, privacy notices and consent flows, vendor contracts, DPO support, a breach or a question about the Rules. A member of the data privacy team will respond.

Offices

Data privacy lawyers across India

The same data privacy team advises from each of King Stubb & Kasiva's offices, covering DPDP readiness assessments, consent and notice design, cross-border transfers, breach response and proceedings before the Data Protection Board.

Head office

Data privacy lawyers in New Delhi

RNM Tower, 5th Floor, Metro Pillar No. 331, i4, B1, NH-19, Mohan Cooperative Industrial Estate, New Delhi 110044

Data privacy lawyers in Mumbai

Nariman Point: Office No. 61, 6th Floor, Atlanta Building, Jamnalal Bajaj Road, Mumbai 400021

Lower Parel: 301A, 3rd Floor, Piramal Towers, Peninsula Corporate Park, Senapati Bapat Marg, Mumbai 400013

Andheri West: 802, 8th Floor, REMI Commercio, Shah Industrial Estate, Veera Desai Road, Mumbai 400053

Data privacy lawyers in Chennai

211, Alpha Wing, Second Floor, Raheja Towers, 177 Anna Salai, Chennai 600002

Data privacy lawyers in Hyderabad

404, Shangrila Plaza, Road No. 2, Banjara Hills, Opposite KBR Park, Hyderabad 500034

Data privacy lawyers in Pune

Bootstart Cowork, First Floor, Arcadian Building, Plot No. 12, Lane 5A, North Main Road, Koregaon Park, Pune 411001

Data privacy lawyers in Kochi

1st Floor, Manavalan Building, Amulya Street, Banerji Road, Ernakulam, Kochi 682018

Clients in states without a King Stubb & Kasiva office, including Gujarat, West Bengal and Rajasthan, are advised by the same team. Contact the data privacy practice or run the free DPDP compliance scorecard.

Insights

DPDP guidance by topic

Detailed commentary from the data privacy practice, grouped by the questions clients ask most.

FAQ

Frequently asked questions

When do the DPDP Act obligations apply?

The DPDP Rules, 2025 were notified on 13 November 2025. The Consent Manager provisions apply from 13 November 2026, and the core obligations on notice, consent, security safeguards, breach intimation, data principal rights and retention apply from 13 May 2027.

Does every company need a Data Protection Officer?

No. Only entities notified as Significant Data Fiduciaries must appoint a Data Protection Officer based in India. Other Data Fiduciaries must publish the business contact details of a person who can answer questions about how they process personal data.

Does the DPDP Act apply to companies outside India?

Yes, where they process digital personal data in connection with offering goods or services to people in India.

What are the penalties under the DPDP Act?

The Schedule to the Act sets maximum penalties by type of breach: up to ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to notify a personal data breach or for breaching the obligations on children’s data, ₹150 crore for breaching the additional obligations of a Significant Data Fiduciary, and ₹50 crore for other breaches. The Data Protection Board decides the amount in each case.

What does the King Stubb & Kasiva data privacy practice advise on?

DPDP compliance and gap assessments, privacy notices and consent design, Data Protection Officer support, Significant Data Fiduciary readiness, vendor and data processing agreements, breach response, cross-border transfers, and GDPR and CCPA compliance for Indian companies with global operations.