What the DPDPA Covers
The DPDPA applies to the processing of "digital personal data" — any data about an individual collected in digital form or digitised after collection. The Act establishes two primary categories of regulated parties. Data Fiduciaries determine the purpose and means of processing personal data. Significant Data Fiduciaries (SDFs) are government-designated entities whose scale, sensitivity, or national security implications warrant heightened obligations: mandatory Data Protection Officer, mandatory Data Audits, mandatory algorithmic impact assessments, and data localisation requirements to be specified by government notification.
The DPDPA defines seven lawful processing grounds: consent (the primary ground), voluntary provision for contractual performance, compliance with legal obligations, medical emergencies, employment purposes, public interest processing, and research/archiving under prescribed conditions. Unlike GDPR's six bases, DPDPA heavily emphasises consent — which must be free, specific, informed, unconditional, and unambiguous. The Act mandates Consent Managers: MeitY-registered intermediaries through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries via a single interface.
Who Must Comply
The following entities are subject to India DPDPA Compliance Hub obligations:
- →Indian companies processing digital personal data of individuals in India
- →Foreign companies processing personal data of Indian Data Principals outside India in connection with goods or services offered to them
- →Significant Data Fiduciaries (government-designated) — additional obligations apply: DPO, data audit, algorithmic impact assessment, localisation
- →Data Processors (vendors) acting on behalf of Data Fiduciaries — must enter into written data processing contracts
- →SaaS platforms and cloud services used by Indian enterprises that process personal data of Indian users
- →Fintech, healthcare, and e-commerce companies collecting Indian user data for targeting, profiling, or personalisation
Penalties and Enforcement History
The DPDPA establishes a tiered penalty structure adjudicated by the Data Protection Board of India. Schedule 1 specifies penalties: failure to implement reasonable security safeguards resulting in a personal data breach — up to ₹250 crore (≈$30M). Failure to notify Data Principals and the Board of a breach — up to ₹200 crore. Failure by a Significant Data Fiduciary to observe additional obligations — up to ₹150 crore. Violation of children's data processing restrictions — up to ₹200 crore. Other violations — up to ₹50 crore per violation. The DPB is empowered to investigate, impose penalties, and order discontinuation of processing. Appeals lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) and then to High Courts.
Enforcement Timeline
Regulatory Comparison
| Dimension | India DPDPA | GDPR | CCPA / CPRA |
|---|---|---|---|
| Enforcement Body | Data Protection Board of India | National DPAs + EDPB | CPPA + California AG |
| Max Penalty | ₹250 crore (≈$30M) per violation | €20M or 4% global turnover | $7,500 per intentional violation |
| Data Localisation | Required for Significant DFs (to be specified) | No — standard SCCs/BCRs | No requirement |
| Consent Basis | Explicit, purpose-specific, withdrawable | One of 6 lawful bases (consent preferred) | Opt-out right (not consent-first) |
| Cross-Border Transfer | Allowed unless government restricts countries | Adequacy decisions/SCCs/BCRs required | No specific restriction |
| Children's Data | 18+ or guardian consent (age-gating required) | 13+ in most states (member state variation) | 16+ (opt-in for 13–16) under CPRA |
Mitigation Strategy
Begin by determining whether your organisation qualifies as a Data Fiduciary under the DPDPA and, if so, whether you are likely to be designated a Significant Data Fiduciary (SDF). SDF designation criteria will be specified by MeitY notification but are expected to include: volume of personal data processed (likely 10M+ users), sensitivity of data, national security or public order implications, risk to electoral democracy, and cross-border transfer volumes. SDFs face additional obligations: Data Protection Officer (must be India-resident), annual data audit, algorithmic impact assessments, and data localisation for specified data categories. Even if you are not an SDF, begin compliance mapping now — the breach notification timeline and consent requirements apply to all Data Fiduciaries.
The DPDPA's primary processing ground is consent — more prominently than GDPR. Consent must be: free (no bundling unrelated consents), specific (for defined purposes), informed (notice explaining purpose, categories, third-party sharing), unconditional (no contingent on service access unless genuinely required), and unambiguous (affirmative act; no pre-ticked boxes). The Draft DPDPA Rules require consent to be given through a "consent artefact" — a machine-readable digital record of each consent, including the entity, purpose, data categories, and withdrawal mechanism. Data Principals have the right to withdraw consent at any time. Withdrawal must be processed within a reasonable time, and post-withdrawal processing must cease (subject to legal retention obligations). Build your consent infrastructure to support artefact generation and withdrawal workflows before enforcement begins.
The DPDPA requires Data Fiduciaries to notify both the Data Protection Board and affected Data Principals of a personal data breach "without delay." The Draft Rules propose a 72-hour notification window for the DPB (aligned with GDPR), with Data Principal notification to follow. Breach notification must include: nature of breach, categories and approximate volume of data affected, likely consequences, and remedial measures taken or proposed. Critical first steps: implement security incident detection logging for all personal data systems; define and document what constitutes a "personal data breach" vs a security incident; establish an internal escalation protocol with clear ownership; and engage legal counsel to assess breach notification obligations before your first incident, not after.
Frequently Asked Questions
A: Yes. The DPDPA applies extra-territorially when a non-Indian entity processes the personal data of Data Principals located in India in connection with offering goods or services to them. This mirrors the GDPR's "establishment or targeting" principle. A US or EU company offering a SaaS product to Indian enterprises, or a consumer app with Indian users, must comply with DPDPA obligations including consent requirements, breach notification, and Data Principal rights — regardless of where the company is incorporated or where the data is stored (subject to cross-border transfer restrictions, which are to be specified by government notification).
A: A Significant Data Fiduciary (SDF) is a category of Data Fiduciary that the central government designates by notification based on: volume and sensitivity of personal data processed, risk to rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, national security implications, and cross-border transfer volumes. SDFs face additional obligations not required of other Data Fiduciaries: appointment of a Data Protection Officer (India-resident), appointment of an independent data auditor, algorithmic impact assessments for processing activities, and data localisation for specified categories. MeitY has not yet published the SDF designation list as of mid-2025, but large tech platforms, payment aggregators, and major consumer internet companies are widely expected to be designated.
A: Before or at the time of collecting personal data, a Data Fiduciary must provide a clear and plain-language notice specifying: what personal data is being collected, the purpose for which it will be processed, the manner in which Data Principal rights may be exercised, and the manner in which the Data Principal can raise a grievance. Consent must be a clear affirmative act — no pre-ticked boxes, no bundled consents for unrelated purposes. The Draft DPDPA Rules require consent to be recorded in a "consent artefact" — a structured machine-readable record. Data Principals may withdraw consent at any time, and withdrawal must be processed within a timeline specified in rules (expected to mirror GDPR's "reasonable time" standard). Importantly, the DPDPA does not permit "legitimate interests" as a standalone processing ground — consent or one of the other six specified lawful purposes must always apply.
A: The DPDPA's maximum penalty is ₹250 crore (approximately $30M USD), applied per violation. GDPR's maximum is €20M or 4% of global annual turnover — whichever is higher — meaning a large MNC could face a €500M+ GDPR fine while the same company's DPDPA exposure is capped near $30M. For small and medium companies, the DPDPA penalty ceiling is significant relative to revenue. However, the Data Protection Board is a new institution with limited enforcement precedent as of 2025. Unlike GDPR's 5+ years of active enforcement with documented fines exceeding €4.5B across the EU, the DPDPA's enforcement trajectory is uncertain. Practical compliance posture: treat DPDPA obligations as seriously as GDPR obligations for data collected from Indian users, as the penalty and reputational risk is real even if early enforcement actions are targeted rather than mass-market.
A: A Consent Manager is a MeitY-registered intermediary through which a Data Principal can provide, manage, review, and withdraw consents across multiple Data Fiduciaries through a single platform. Think of it as an interoperable consent dashboard. Data Fiduciaries are not required to use a Consent Manager for all consent collection — they can maintain their own consent artefacts directly. However, if a Data Principal uses a Consent Manager to withdraw consent, the Data Fiduciary must give effect to that withdrawal. Consent Managers must be registered with MeitY, maintain interoperable standards specified in the Rules, maintain a consent artefact log, and allow Data Principals to review and modify consents. The Consent Manager ecosystem is modelled on the Account Aggregator framework in Indian fintech and is expected to become the dominant consent infrastructure for large consumer-facing platforms.
India DPDPA Compliance Guide → Consent management, Data Principal rights, breach notification timelines, and cross-border transfer rules for companies processing Indian personal data.
This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.