India's Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and published in the Gazette the following day, which started a phased clock rather than a single deadline. A DPDP compliance checklist therefore has to do two things at once: list the twelve duties the Rules actually impose, and tell you which of them bind on which date. This guide does both, working from the notified text of G.S.R. 846(E) rather than from summaries of it.
The short version: almost every operational duty you have to build for lands eighteen months after publication, in mid-May 2027, and the work it describes takes considerably longer than the time left.
The DPDP Deadlines That Actually Bind You

Three DPDP deadlines bind you, not one, because rule 1 splits commencement into three tranches: 14 November 2025 for the Board provisions, one year later for Consent Managers, and eighteen months later for every operational duty. Most coverage collapses these into a single date, which is how teams end up building the wrong thing first.
| Tranche | What comes into force | When |
|---|---|---|
| In force now | Rules 1, 2 and 17 to 21: short title, definitions, and the provisions constituting the Data Protection Board, appointing its Chairperson and Members, and governing its terms and procedure | On Gazette publication, 14 November 2025 |
| One year | Rule 4: registration and obligations of Consent Managers, against Part A of the First Schedule | One year after publication, mid-November 2026 |
| Eighteen months | Rules 3 and 5 to 16, plus 22 and 23: notice, consent, security safeguards, breach intimation, retention and erasure, contact person, children's data, Significant Data Fiduciary duties, data-principal rights, cross-border transfer and research exemptions | Eighteen months after publication, mid-May 2027 |
Two things follow. First, the Board is being constituted now, ahead of the duties it will enforce, so the institution will exist well before the enforcement window opens. Second, the tranche that carries your engineering work is the eighteen-month one, and it is a single cliff rather than a ramp. Nothing in rules 3 or 5 to 16 phases in gradually.
Work Out Which Entity You Are First

You are one of three things under the Act: a Data Fiduciary, a Data Processor, or a Significant Data Fiduciary. Work out which before anything else, because every one of the twelve duties below keys off that role, and getting it wrong invalidates the rest of the exercise.
A Data Fiduciary determines the purpose and means of processing. It carries the substantive duties: notice, consent, safeguards, breach intimation, retention, rights fulfilment. There is no size threshold. A ten-person startup processing Indian users' personal data is a Data Fiduciary on the same terms as a bank.
A Data Processor processes on a fiduciary's behalf. Section 8(2) of the Act is blunt about the relationship: a Data Fiduciary may involve a Data Processor "only under a valid contract." The compliance burden sits with the fiduciary, but it reaches you contractually, which is why processor-side readiness is now a sales question.
A Significant Data Fiduciary is a Data Fiduciary, or a class of them, that the Central Government notifies as significant under section 10 of the Act. You do not opt in or self-assess. Until you are notified, rule 13 does not apply to you. When you are, it adds an annual DPIA and audit, algorithmic due diligence and a localisation duty.
The DPDP Compliance Checklist: Twelve Duties

Each of the twelve items names the rule it comes from, so you can check the source rather than take this on trust. Eleven of the twelve commence at the eighteen-month mark; only Consent Manager registration under rule 4 runs on the earlier one-year clock.
1. Rewrite the Consent Notice
Rule 3 requires the notice to stand on its own, understandable independently of anything else you have published. In clear and plain language it must give, at minimum, an itemised description of the personal data and the specific purposes and the goods, services or uses enabled by the processing. It must also give the communication link and describe the other means by which the Data Principal can withdraw consent, exercise her rights, and complain to the Board.
"Itemised" is the word that breaks most existing notices. A privacy policy saying you collect "contact and usage information" does not itemise anything.
2. Rebuild Consent Capture and Withdrawal
Rule 3(c)(i) sets the standard that matters most in practice: withdrawal must be available "with the ease of doing so being comparable to that with which such consent was given." One-click in, one-click out. If consent was captured at signup and withdrawal requires emailing support, you fail this on its face.
3. Decide Your Consent Manager Position
Rule 4 creates a registered class of Consent Managers, who must apply to the Board and satisfy Part A of the First Schedule. Note what rule 4 does not say: it does not compel an ordinary Data Fiduciary to route consent through one. Your task before the one-year date is to make sure your consent records and withdrawal mechanics could interoperate with a Consent Manager if your sector converges on one, not to assume you must integrate.
4. Implement the Seven Minimum Security Safeguards
Rule 6 is the most prescriptive rule in the set, and the one tied to the largest penalty. It names seven minimum measures:
- Data security measures such as encryption, obfuscation, masking, or virtual tokens mapped to the data.
- Access control over the computer resources used by the fiduciary or its processor.
- Visibility on access through logs, monitoring and review, sufficient to detect unauthorised access and support investigation and remediation.
- Reasonable measures for continued processing where confidentiality, integrity or availability is compromised, such as backups.
- Retention of those logs and personal data for one year, unless another law requires otherwise.
- An appropriate provision in the contract with any Data Processor requiring reasonable security safeguards.
- Appropriate technical and organisational measures for effective observance of the safeguards.
Item 5 surprises people. The security rule itself imposes a retention floor, which is a deliberate anti-tampering measure and a direct constraint on aggressive deletion policies. If you already run a log pipeline for another framework, the same plumbing serves here: see our guide to logging and monitoring for ISO 27001, and to access controls for rule 6(1)(b).
5. Build the Two-Stage Breach Runbook
Rule 7 sets two clocks running from the moment you become aware of a breach, and conflating them is the single most common error in circulating summaries.
| Recipient | What you send | When |
|---|---|---|
| Each affected Data Principal | Description, nature, extent and timing; consequences relevant to her; mitigation already implemented or under way; safety measures she can take; business contact details of someone who can answer her questions | Without delay |
| The Board, first intimation | Description including nature, extent, timing and location of occurrence, and likely impact | Without delay |
| The Board, detailed submission | Updated detail; broad facts, circumstances and reasons; mitigation implemented or proposed; findings on who caused it; remedial measures to prevent recurrence; a report on the intimations given to affected Data Principals | Within 72 hours of becoming aware, or a longer period the Board allows on a written request |
There is no 72-hour clock on telling individuals. Their clock is "without delay," which is tighter.
6. Set Retention Clocks and Erasure Triggers
Rule 8 applies a three-year inactivity clock to three classes in the Third Schedule: e-commerce entities with at least two crore registered users in India, online gaming intermediaries with at least fifty lakh, and social media intermediaries with at least two crore. For those classes, personal data must be erased three years after the Data Principal last approached the fiduciary or exercised her rights, or the Rules' commencement, whichever is latest, unless retention is necessary under another law.
Rule 8(2) adds an operational step teams forget: at least forty-eight hours before erasure, you must tell the Data Principal it is coming and that logging in or exercising a right will stop it.
And rule 8(3) applies to everyone, not just the Third Schedule classes: retain personal data, associated traffic data and processing logs for a minimum of one year from the date of processing. If you have already set retention schedules for another framework, our ISO 27001 data retention guide covers the mechanics; the DPDP floors sit on top of them.
7. Publish a Contact Person or DPO
Rule 9 requires every Data Fiduciary to prominently publish, on its website or app, the business contact information of the Data Protection Officer if applicable, or of a person who can answer questions about processing, and to repeat it in every response to a rights request. It is the cheapest item on this list and among the most visible if missed.
8. Handle Children and Lawful Guardians
Rule 10 requires verifiable parental consent before processing a child's personal data, with due diligence that the person identifying as the parent is an identifiable adult, meaning eighteen or over, verified against reliable details you already hold or details voluntarily provided, including through a virtual token issued by an authorised entity or a Digital Locker service provider. Rule 11 covers lawful guardians of persons with disability. Rule 12 carves out exemptions for classes and purposes in the Fourth Schedule.
Note the age. DPDP's child threshold is eighteen, well above GDPR's thirteen-to-sixteen range, so a consent flow ported from a European product will be non-compliant by default.
9. Meet the Significant Data Fiduciary Duties
Section 10(2) of the Act already requires a notified Significant Data Fiduciary to appoint a Data Protection Officer who is based in India, represents the entity, is responsible to its Board of Directors or equivalent governing body, and is the point of contact for grievance redressal, and to appoint an independent data auditor to evaluate compliance.
On top of that, rule 13 adds four duties: a Data Protection Impact Assessment and an audit once every twelve months; furnishing a report of significant observations from both to the Board; due diligence that algorithmic software used for hosting, display, upload, modification, publication, transmission, storage, updating or sharing of personal data is not likely to pose a risk to Data Principals' rights; and ensuring that personal data specified by the Central Government, on a committee's recommendation, together with its traffic data, is not transferred outside India.
10. Stand Up Rights Fulfilment and Grievance Redressal
Rule 14 requires you to prominently publish the means by which rights requests are made and any identifier a Data Principal needs to supply. It requires you to publish your grievance-response period, which cannot exceed ninety days, and to implement measures that make the system actually respond within it. It also covers nomination of one or more individuals to exercise rights.
11. Fix Your Processor Contracts
Two provisions meet here. Section 8(2) of the Act permits engaging a processor only under a valid contract. Rule 6(f) requires that contract to contain an appropriate provision for taking reasonable security safeguards. Existing vendor agreements signed before either was in force will not satisfy this by accident, and the remediation is a contract-paper exercise across your whole vendor estate. If you have not mapped that estate yet, start with vendor risk mapping.
12. Re-Check Cross-Border Transfers
Rule 15 is more permissive than the draft that preceded it and more permissive than most teams assume. Personal data may be transferred outside India, subject to requirements the Central Government may specify by general or special order regarding making that data available to a foreign State or to a person or entity under its control or acting as its agency. The restrictive localisation duty sits in rule 13(4), and only for Significant Data Fiduciaries.
Want this mapped against what you already have?
Share your work email and we'll walk your current notice, consent and breach process against the twelve duties and mark what your existing ISO 27001 or SOC 2 work already covers.
What DPDP Non-Compliance Actually Costs

DPDP penalties top out at 250 crore rupees, and that ceiling attaches to exactly one duty. The Schedule to the Act sets seven bands, and section 33(1) lets the Board impose them after an inquiry and an opportunity to be heard. The figures are frequently misquoted, so here is the Schedule as enacted.
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach, under section 8(5) | Up to 250 crore rupees |
| Failure to give the Board or affected Data Principals notice of a personal data breach, under section 8(6) | Up to 200 crore rupees |
| Breach of the additional obligations in relation to children, under section 9 | Up to 200 crore rupees |
| Breach of the additional obligations of a Significant Data Fiduciary, under section 10 | Up to 150 crore rupees |
| Breach of a Data Principal's own duties under section 15 | Up to 10,000 rupees |
| Breach of a voluntary undertaking accepted by the Board under section 32 | Up to the amount applicable to the breach that prompted the section 28 proceedings |
| Breach of any other provision of the Act or Rules | Up to 50 crore rupees |
Three corrections worth making, because each one circulates as fact:
- 250 crore is not a general-purpose number. It attaches to one thing only, the security-safeguards duty in section 8(5). Failure to report a breach sits in a separate 200 crore band, and most other contraventions fall into the 50 crore residual band.
- Penalties cannot be doubled. Section 33 has exactly two sub-sections: the power to impose the Schedule amount, and the seven matters the Board must weigh in fixing it. There is no sub-section (3) and no doubling provision. Claims of 500 crore exposure have no basis in the Act.
- The Schedule sets ceilings, not tariffs. Every entry reads "may extend to," and section 33(2) requires the Board to have regard to the nature, gravity and duration of the breach, the type of data affected, whether it was repetitive, gain realised or loss avoided, mitigation taken, proportionality, and the likely impact of the penalty on the person. Prompt mitigation is written into the statute as a factor.
Where Your Sector Piles Requirements on Top
DPDP is a floor. For regulated industries the binding standard is often a sector instrument that already demanded more, and where the two differ the stricter one governs. The 4 instruments below were issued between 2018 and 2024, all before the DPDP Rules, so most regulated entities are further along than they think. Teams coming from GDPR can reuse a good deal too, though our GDPR compliance checklist diverges from this one on consent basis, child age and log retention.
Fintech and Other RBI, SEBI or IRDAI Regulated Entities
Three instruments matter and all three predate the DPDP Rules. RBI's Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, issued 7 November 2023 and effective 1 April 2024, sets out IT governance, infrastructure and services management, IT and information security risk management, business continuity, and information systems audit. RBI's "Storage of Payment System Data" circular of 6 April 2018 imposes a genuine localisation duty on payment system data that DPDP's rule 15 does not. SEBI's Cybersecurity and Cyber Resilience Framework, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 of 20 August 2024, replaced the earlier broad guidelines with an audit-grade framework for regulated entities. For insurers and intermediaries, the IRDAI Information and Cyber Security Guidelines, 2023, dated 24 April 2023, take a data-centric approach to securing policyholder information.
The practical consequence is that a regulated entity's DPDP programme is mostly a mapping exercise onto controls it already operates, plus the genuinely new parts: itemised notice, withdrawal parity, the 48-hour pre-erasure warning and rights fulfilment.
Healthtech and Anyone Holding Patient Records
Health data has no special category under DPDP, which surprises teams arriving from HIPAA or GDPR. What it does have is a retention conflict. Regulation 1.3.1 of the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 requires a physician to maintain indoor-patient medical records for three years from the commencement of treatment, and the Clinical Establishments (Central Government) Rules, 2012 and their state equivalents add their own record duties. Rule 8(1) accommodates this, erasure yields where retention is necessary for compliance with another law, but only if you can point to the law per data category rather than asserting it globally.
If you participate in the Ayushman Bharat Digital Mission, the ABDM Health Data Management Policy governs consent artefacts and data flows in that ecosystem alongside DPDP. And the draft Digital Information Security in Healthcare Act of 2018 was never enacted, so it is not a compliance obligation.
B2B SaaS Selling to Indian Enterprises
If you process on a customer's behalf you are a Data Processor, and your exposure arrives through section 8(2) and rule 6(f) as contract terms rather than as direct regulatory duty. Expect Indian enterprise buyers to require a DPDP-specific addendum, security safeguards mirroring rule 6, breach notification fast enough for the customer to meet its own rule 7 clocks, sub-processor disclosure and flow-down, and deletion and return commitments that respect rule 8(3)'s one-year log floor. The vendors that answer these cleanly in a security questionnaire will close faster than those discovering the questions during procurement.
Get the DPDP Implementation Checklist for Your Sector
Each of the 3 checklists below is built around one sector's actual regulatory stack rather than a generic list with conditional rows. Every one is a working document covering all 12 duties, with owners, target dates and evidence locations, plus worked examples you can copy rather than blank rows to fill.
For fintech and regulated entities
DPDP Implementation Checklist for Fintech
For RBI, SEBI and IRDAI regulated entities: the twelve DPDP duties mapped against the IT Governance Master Direction, the payment-data localisation circular, CSCRF and the IRDAI cyber guidelines, marking where the sector rule is stricter and therefore governs.
For healthtech and providers
DPDP Implementation Checklist for Healthtech
For teams holding patient records: consent and notice for clinical data, the retention conflict between medical-record duties and rule 8 erasure resolved per data category, ABDM consent artefacts, and breach response across clinical systems.
For B2B SaaS and processors
DPDP Implementation Checklist for B2B SaaS
For processors serving Indian enterprises: section 8(2) contract requirements, rule 6(f) safeguard clauses, sub-processor flow-down, breach timelines that let your customer meet rule 7, and worked answers to the DPDP questions now appearing in enterprise procurement.
Auditing What You Built
Implementation and assurance are different exercises. A Significant Data Fiduciary must run a DPIA and an audit every twelve months under rule 13(1) and furnish significant observations to the Board under rule 13(2). Everyone else should still audit, because the Board's inquiry powers do not wait for an annual cycle and because the evidence that proves a duty was met has to exist before it is asked for.
The audit checklist below takes each duty and asks the three questions an assessor asks: what control operates, what artifact proves it operated, and who owns it.
For internal audit and assurance
The DPDP Audit Checklist
Rule-by-rule test procedures with the evidence each one requires: notice versions, consent and withdrawal records, rule 6 log retention, the breach register against both rule 7 clocks, 48-hour pre-erasure notices, grievance response against your published period, and the DPIA and audit reports rule 13 requires.
DPDP Compliance Questions Teams Actually Ask
These are the 14 DPDP compliance questions that come up most often in scoping calls, including the three where the widely circulated answer is simply wrong: the penalty ceiling, the 72-hour clock, and whether DPDP forces data localisation.
There are three, not one. Rules 1, 2 and 17 to 21 came into force on 14 November 2025, the day the Rules were published in the Gazette. Rule 4, which governs Consent Manager registration, comes into force one year after that date. Rules 3 and 5 to 16, which carry almost every operational duty you have to build for, plus rules 22 and 23, come into force eighteen months after publication. So the date that matters for notice, consent, security safeguards, breach reporting, retention, children's data, Significant Data Fiduciary duties and data-principal rights is in mid-May 2027.
No. This claim circulates widely and it is wrong. Section 33 of the DPDP Act has exactly two sub-sections: sub-section (1) lets the Board impose the penalty specified in the Schedule, and sub-section (2) lists the seven matters the Board must have regard to when fixing the amount. There is no sub-section (3), and nothing in the Act permits the Board to double a Schedule amount. The Schedule's highest figure is 250 crore rupees, and that is the ceiling.
Partly. Rule 7 sets two separate clocks. The Board gets a first intimation without delay, describing the breach's nature, extent, timing, location and likely impact. The detailed submission, covering the broad facts and causes, mitigation measures, findings on who caused the breach, remedial steps and a report on what you told affected individuals, is due within seventy-two hours of becoming aware, or a longer period the Board allows on a written request. Affected Data Principals must be told without delay. There is no 72-hour clock on notifying individuals.
No. Unlike the Significant Data Fiduciary category, which the Central Government notifies based on volume and sensitivity of data and other factors, the baseline Data Fiduciary duties apply regardless of headcount, revenue or user count. A ten-person startup processing the personal data of Indian users is a Data Fiduciary with the same core obligations as a bank. The Third Schedule retention rules do carry user-count thresholds, but those add a duty for large platforms rather than removing one for small ones.
Not as a general rule. Rule 15 permits transfer of personal data outside India, subject to any requirements the Central Government specifies by general or special order about making that data available to a foreign State or to a person or entity under its control. The one localisation duty in the Rules sits in rule 13(4) and applies only to Significant Data Fiduciaries, for classes of personal data the Central Government specifies on a committee's recommendation. Sector rules are a separate matter, and RBI's payment-data circular is stricter than DPDP.
Rule 6 does not leave it to judgment. It names seven minimum measures: encryption, obfuscation, masking or virtual tokens for the data itself; access control over the computer resources used; logging, monitoring and review that makes unauthorised access detectable; backups or equivalent measures for continued processing; retention of those logs and personal data for one year; a contractual provision obliging your Data Processor to take reasonable safeguards; and appropriate technical and organisational measures for effective observance. Anything above that is judgment. These seven are the floor.
Rule 14(3) requires every Data Fiduciary and Consent Manager to prominently publish, on its website or app, the period within which it responds to grievances, and that period cannot exceed ninety days. The rule also requires you to implement appropriate technical and organisational measures so the system actually responds within the period you published. Publishing ninety days and then missing it is a breach of the rule, not compliance with it.
Erasure is real but it is not unconditional, and rule 8 pulls in two directions. Under rule 8(1), fiduciaries in the Third Schedule classes must erase personal data after the specified period of inactivity unless retention is necessary for compliance with any law in force. But rule 8(3) requires every Data Fiduciary to retain personal data, associated traffic data and processing logs for a minimum of one year from the date of processing, for the Seventh Schedule purposes. The Rules' own illustration makes the point: an e-book platform must keep order and payment logs for at least a year even after the buyer deletes her account.
You do not self-assess into the category. The Central Government notifies a Data Fiduciary, or a class of them, as Significant under section 10 of the Act, having regard to factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on India's sovereignty and integrity, risk to electoral democracy, security of the State, and public order. The Seventh Schedule to the Rules designates a MeitY officer to carry out the assessment for that notification. Until you are notified, rule 13 does not bind you.
A Consent Manager is a registered intermediary through which a Data Principal can give, manage, review and withdraw consent, and it must be registered with the Board under rule 4 against the conditions in Part A of the First Schedule. Nothing in the Rules compels an ordinary Data Fiduciary to route consent through one. What rule 4 creates is a registered class of providers and the obligations they carry. Your practical task is to make sure your consent records and withdrawal mechanics can interoperate with one if your sector converges on it.
Yes, where the processing relates to offering goods or services to Data Principals in India. Section 3 of the Act extends it to processing of digital personal data outside India where that processing is in connection with any activity related to offering goods or services to Data Principals within the territory of India. A US or Singapore SaaS company with Indian customers is in scope, which is why DPDP clauses are now appearing in Indian enterprise procurement paperwork aimed at foreign vendors.
GDPR work carries a long way but does not finish the job. Consent, notice, breach response, security measures and rights fulfilment all map reasonably well. Four things do not. DPDP has no legitimate-interest basis of the GDPR kind, so consent and the Act's legitimate-uses list carry more weight. Verifiable parental consent applies to everyone under eighteen, not under thirteen to sixteen. Rule 8(3)'s minimum one-year log retention cuts against a delete-on-request reflex. And the Rules name specific security measures rather than leaving them to a risk assessment.
The Digital Information Security in Healthcare Act was released as a draft by the Ministry of Health and Family Welfare in 2018 and was never enacted. Health data in India is now governed by the DPDP Act and the DPDP Rules alongside sector instruments such as the ABDM Health Data Management Policy and medical-record retention duties. Plan for DPDP. Treat any vendor pitch that sells you DISHA readiness as a signal to check what else they have got wrong.
The Act does not prescribe an evidence list, so work backwards from what each duty would look like if contested. Notice versions with effective dates. Consent records showing what was itemised, when it was captured and how it was withdrawn. Access logs and monitoring records covering the one-year retention floor in rules 6 and 8(3). A breach register with times of awareness, first intimation and the 72-hour submission. Retention and erasure job records including the 48-hour advance notice under rule 8(2). A grievance log measured against your published period. For Significant Data Fiduciaries, the annual DPIA and audit reports and the observations furnished to the Board.
Turn the checklist into a working DPDP programme
Book a demo and we'll spend 30 minutes mapping your data flows against the twelve duties, marking what your existing ISO 27001, SOC 2 or GDPR work already covers and what the Rules genuinely add.
Book a demo
Start With the Data Inventory
The DPDP compliance checklist is long but it is not vague. The Rules name the seven security measures, the two breach clocks, the retention floors, the withdrawal standard and the ninety-day grievance ceiling. What makes the eighteen-month tranche hard is not ambiguity, it is that itemising the personal data you hold, and proving you can erase it on cue across every system and processor, is a data-engineering project wearing a legal deadline.
Start with the itemisation. Everything else in this list, notice, consent, erasure, breach scope, rights fulfilment, depends on knowing exactly what you hold and where. Teams that treat DPDP as a policy-document exercise will discover in May 2027 that they wrote accurate descriptions of systems they cannot actually operate against.
Konfirmity is a security-driven compliance platform covering ISO 27001, SOC 2 and HIPAA out of the box and DPDP through the custom-framework engine, run self-serve or with the fully-managed service where our team runs the programme for you. The team behind Konfirmity has supported more than 6,000 security audits. Book a demo and we'll give you 30 minutes of DPDP guidance whether or not you buy anything.




