DPDP Compliance:Twelve Duties,Three Deadlines
The DPDP Rules, 2025 were notified on 13 November 2025 and published in the Gazette the following day, starting a phased clock rather than a single deadline. The Rules name the seven security measures, the two breach clocks, the retention floors, the withdrawal standard and the ninety-day grievance ceiling — so the work is specific rather than vague.
Book a call
[01] Why DPDP Is on Your Roadmap
DPDP reaches further than most teams assume, binds foreign companies serving Indian users, arrives in enterprise procurement as contract terms, and diverges from GDPR in four ways that make a ported programme non-compliant by default.
// The Reality
Rule 1 splits commencement into three tranches, and most coverage collapses them into a single date — which is how teams end up building the wrong thing first.
// The Three Dates
Each tranche is counted from Gazette publication on 14 November 2025.
- 14 November 2025 — definitions and the Board provisions
- Mid-November 2026 — rule 4, Consent Manager registration
- Mid-May 2027 — rules 3 and 5 to 16, the operational duties
- Mid-May 2027 — rules 22 and 23, research and exemptions
// Business Impact
The tranche carrying your engineering work is the eighteen-month one, and it is a single cliff rather than a ramp. Nothing in rules 3 or 5 to 16 phases in gradually, and the Board is being constituted now — ahead of the duties it will enforce.
// Strategic Advantage
Itemising the personal data you hold, and proving you can erase it on cue across every system and processor, is a data-engineering project wearing a legal deadline. Teams that start on the inventory rather than the policy document arrive with something that actually operates.
[02] What DPDP Actually Requires
DPDP is an Act, a set of notified Rules and five roles: the roles decide which duties attach to you, and the Rules name those duties specifically — rule by rule, with the measures spelled out rather than left to a risk assessment.
Data Principal
The individual the data is about
The person whose personal data is processed, including a child's lawful guardian. Carries rights to access, correction, erasure, grievance redressal and nomination — and, under section 15, duties of her own.
Data Fiduciary
Determines purpose and means
Carries the substantive duties: notice, consent, safeguards, breach intimation, retention, rights fulfilment. There is no size threshold. A ten-person startup processing Indian users' personal data is a Data Fiduciary on the same terms as a bank.
Data Processor
Processes on a fiduciary's behalf
Section 8(2) permits engagement only under a valid contract. The compliance burden sits with the fiduciary but reaches the processor contractually, which is why processor-side readiness is now a sales question rather than a legal one.
Significant Data Fiduciary
Notified, never self-assessed
A Data Fiduciary, or class of them, that the Central Government notifies as significant under section 10. Adds an annual DPIA and audit, algorithmic due diligence and a localisation duty under rule 13. Until you are notified, rule 13 does not bind you.
Consent Manager
Registered consent intermediary
A registered intermediary through which a Data Principal gives, manages, reviews and withdraws consent, registered with the Board under rule 4 against Part A of the First Schedule. Nothing compels an ordinary fiduciary to route consent through one.
[03] Understanding DPDP Implementation
There is no DPDP certificate — there is a set of duties that either operate or do not, and an evidence trail that has to exist before the Board asks for it. The sequence below front-loads the data work, because everything else depends on knowing exactly what you hold.
[1/6] DATA ITEMISATION & ROLE DETERMINATION (WEEK 1-3)
Work out which entity you are, then itemise what you hold. Every duty keys off the role, and almost every duty keys off the inventory — so getting either wrong invalidates the rest of the exercise.
// What Happens
A defensible role determination and an itemised record of the personal data you hold, by category, purpose, system and processor.
// Deliverables
- Role determination per processing activity — fiduciary or processor
- Itemised personal data inventory by category and purpose
- System and processor map per data category
- Cross-border flow register
// Effort
- Timeline: 2-3 weeks
- Your involvement: 15-25 hours
// activities
- Role Determination: Who decides purpose and means, activity by activity
- Itemisation: Named data elements, not categories like 'contact information'
- Purpose Mapping: Each element to the specific purpose it serves
- System Map: Where each element lives, including processors and backups
- Flow Register: What leaves India, to whom, under what contract
[05] A Smarter Security Investment
When platform, service, and execution are considered together, Konfirmity delivers security and compliance with fewer tradeoffs and clearer long-term costs.
DIY Manual
Platform
None
Service
None
Audit
$15K
Year 1 total
$15K
Annual
$5K
Generic Platform
Platform
$25K
Service
None
Audit
$15K
Year 1 total
$40K
Annual
$30K
Traditional Consultant
Platform
None
Service
$50K
Audit
$15K
Year 1 total
$65K
Annual
$25K
Konfirmity
Platform
Included
Service
Included
Audit
$15K
Year 1 total
$50K
Annual
$35K
[05] FAQ's
What DPDP Compliance Actually Involves
There are three, not one. Rules 1, 2 and 17 to 21 came into force on 14 November 2025, the day the Rules were published in the Gazette. Rule 4, governing Consent Manager registration, comes into force one year after that date. Rules 3 and 5 to 16, which carry almost every operational duty you have to build for, plus rules 22 and 23, come into force eighteen months after publication. So the date that matters for notice, consent, security safeguards, breach reporting, retention, children's data, Significant Data Fiduciary duties and data-principal rights is in mid-May 2027.
No. Unlike the Significant Data Fiduciary category, which the Central Government notifies based on volume and sensitivity of data and other factors, the baseline Data Fiduciary duties apply regardless of headcount, revenue or user count. A ten-person startup processing the personal data of Indian users is a Data Fiduciary with the same core obligations as a bank. The Third Schedule retention rules do carry user-count thresholds, but those add a duty for large platforms rather than removing one for small ones.
No. This claim circulates widely and it is wrong. Section 33 of the Act has exactly two sub-sections: sub-section (1) lets the Board impose the penalty specified in the Schedule, and sub-section (2) lists the seven matters the Board must have regard to when fixing the amount. There is no sub-section (3) and no doubling provision. The Schedule's highest figure is 250 crore rupees, and it attaches to one duty only — the security-safeguards duty in section 8(5). Failure to report a breach sits in a separate 200 crore band, and most other contraventions fall into a 50 crore residual band.
Not as a general rule. Rule 15 permits transfer of personal data outside India, subject to any requirements the Central Government specifies by general or special order about making that data available to a foreign State or to a person or entity under its control. The one localisation duty in the Rules sits in rule 13(4) and applies only to Significant Data Fiduciaries, for classes of personal data the Central Government specifies on a committee's recommendation. Sector rules are a separate matter, and RBI's payment-data circular is stricter than DPDP.
Yes, where the processing relates to offering goods or services to Data Principals in India. Section 3 extends the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering goods or services to Data Principals within the territory of India. A US or Singapore SaaS company with Indian customers is in scope, which is why DPDP clauses are now appearing in Indian enterprise procurement paperwork aimed at foreign vendors.
Less than you fear on security, more than you expect on consent and retention. Rule 6's seven measures map closely onto an existing ISMS, so that phase is largely evidence mapping. What is genuinely new: itemised notice rather than categorised, withdrawal at parity with capture, verifiable parental consent for everyone under eighteen, the 48-hour pre-erasure warning, and rule 8(3)'s one-year minimum log retention — which runs against the delete-on-request reflex GDPR trains.
No. There is no DPDP certificate or registry for ordinary Data Fiduciaries. Notified Significant Data Fiduciaries owe an annual DPIA and an audit by an independent data auditor under section 10(2) and rule 13, and must furnish significant observations to the Board — but that is an obligation rather than a credential. For everyone else, compliance is demonstrated through artefacts: notice versions, consent and withdrawal records, log retention, a breach register against both rule 7 clocks, erasure job records, and a grievance log measured against your published period.
[07] get started
Get started in the way that fits you best -- see the platform in action, speak directly with a security expert, or get real proof through a free external scan of your environment.
See the platform in action. We'll show you:
Adaptation to your specific stack
Integration with your existing tools
Custom evidence collection workflows
Dashboard views for stakeholders
Speak directly with one of our security experts:
Security program design for your industry
Compliance roadmap (SOC 2 → ISO)
Risk assessment and treatment planning
Vendor security review guidance
Want proof? We'll scan your surface for free:
Exposed assets and misconfigurations
SSL/TLS vulnerabilities
Vendor risk in your supply chain
Comparison to industry benchmarks
