Konfirmity

DPDP Compliance:Twelve Duties,Three Deadlines

The DPDP Rules, 2025 were notified on 13 November 2025 and published in the Gazette the following day, starting a phased clock rather than a single deadline. The Rules name the seven security measures, the two breach clocks, the retention floors, the withdrawal standard and the ninety-day grievance ceiling — so the work is specific rather than vague.

Book a call
DPDP compliance

[01] Why DPDP Is on Your Roadmap

DPDP reaches further than most teams assume, binds foreign companies serving Indian users, arrives in enterprise procurement as contract terms, and diverges from GDPR in four ways that make a ported programme non-compliant by default.

// The Reality

Rule 1 splits commencement into three tranches, and most coverage collapses them into a single date — which is how teams end up building the wrong thing first.

// The Three Dates

Each tranche is counted from Gazette publication on 14 November 2025.

  • 14 November 2025 — definitions and the Board provisions
  • Mid-November 2026 — rule 4, Consent Manager registration
  • Mid-May 2027 — rules 3 and 5 to 16, the operational duties
  • Mid-May 2027 — rules 22 and 23, research and exemptions

// Business Impact

The tranche carrying your engineering work is the eighteen-month one, and it is a single cliff rather than a ramp. Nothing in rules 3 or 5 to 16 phases in gradually, and the Board is being constituted now — ahead of the duties it will enforce.

// Strategic Advantage

Itemising the personal data you hold, and proving you can erase it on cue across every system and processor, is a data-engineering project wearing a legal deadline. Teams that start on the inventory rather than the policy document arrive with something that actually operates.

[02] What DPDP Actually Requires

DPDP is an Act, a set of notified Rules and five roles: the roles decide which duties attach to you, and the Rules name those duties specifically — rule by rule, with the measures spelled out rather than left to a risk assessment.

Data Principal

The individual the data is about

The person whose personal data is processed, including a child's lawful guardian. Carries rights to access, correction, erasure, grievance redressal and nomination — and, under section 15, duties of her own.

Data Fiduciary

Determines purpose and means

Carries the substantive duties: notice, consent, safeguards, breach intimation, retention, rights fulfilment. There is no size threshold. A ten-person startup processing Indian users' personal data is a Data Fiduciary on the same terms as a bank.

Data Processor

Processes on a fiduciary's behalf

Section 8(2) permits engagement only under a valid contract. The compliance burden sits with the fiduciary but reaches the processor contractually, which is why processor-side readiness is now a sales question rather than a legal one.

Significant Data Fiduciary

Notified, never self-assessed

A Data Fiduciary, or class of them, that the Central Government notifies as significant under section 10. Adds an annual DPIA and audit, algorithmic due diligence and a localisation duty under rule 13. Until you are notified, rule 13 does not bind you.

Consent Manager

Registered consent intermediary

A registered intermediary through which a Data Principal gives, manages, reviews and withdraws consent, registered with the Board under rule 4 against Part A of the First Schedule. Nothing compels an ordinary fiduciary to route consent through one.

[03] Understanding DPDP Implementation

There is no DPDP certificate — there is a set of duties that either operate or do not, and an evidence trail that has to exist before the Board asks for it. The sequence below front-loads the data work, because everything else depends on knowing exactly what you hold.

[1/6] DATA ITEMISATION & ROLE DETERMINATION (WEEK 1-3)

Work out which entity you are, then itemise what you hold. Every duty keys off the role, and almost every duty keys off the inventory — so getting either wrong invalidates the rest of the exercise.

// What Happens

A defensible role determination and an itemised record of the personal data you hold, by category, purpose, system and processor.

// Deliverables

  • Role determination per processing activity — fiduciary or processor
  • Itemised personal data inventory by category and purpose
  • System and processor map per data category
  • Cross-border flow register

// Effort

  • Timeline: 2-3 weeks
  • Your involvement: 15-25 hours

// activities

  • Role Determination: Who decides purpose and means, activity by activity
  • Itemisation: Named data elements, not categories like 'contact information'
  • Purpose Mapping: Each element to the specific purpose it serves
  • System Map: Where each element lives, including processors and backups
  • Flow Register: What leaves India, to whom, under what contract

[05] A Smarter Security Investment

When platform, service, and execution are considered together, Konfirmity delivers security and compliance with fewer tradeoffs and clearer long-term costs.

DIY Manual

Platform

None

Service

None

Audit

$15K

Year 1 total

$15K

Annual

$5K

Generic Platform

Platform

$25K

Service

None

Audit

$15K

Year 1 total

$40K

Annual

$30K

Traditional Consultant

Platform

None

Service

$50K

Audit

$15K

Year 1 total

$65K

Annual

$25K

Konfirmity

Platform

Included

Service

Included

Audit

$15K

Year 1 total

$50K

Annual

$35K

[05] FAQ's

What DPDP Compliance Actually Involves

There are three, not one. Rules 1, 2 and 17 to 21 came into force on 14 November 2025, the day the Rules were published in the Gazette. Rule 4, governing Consent Manager registration, comes into force one year after that date. Rules 3 and 5 to 16, which carry almost every operational duty you have to build for, plus rules 22 and 23, come into force eighteen months after publication. So the date that matters for notice, consent, security safeguards, breach reporting, retention, children's data, Significant Data Fiduciary duties and data-principal rights is in mid-May 2027.

No. Unlike the Significant Data Fiduciary category, which the Central Government notifies based on volume and sensitivity of data and other factors, the baseline Data Fiduciary duties apply regardless of headcount, revenue or user count. A ten-person startup processing the personal data of Indian users is a Data Fiduciary with the same core obligations as a bank. The Third Schedule retention rules do carry user-count thresholds, but those add a duty for large platforms rather than removing one for small ones.

No. This claim circulates widely and it is wrong. Section 33 of the Act has exactly two sub-sections: sub-section (1) lets the Board impose the penalty specified in the Schedule, and sub-section (2) lists the seven matters the Board must have regard to when fixing the amount. There is no sub-section (3) and no doubling provision. The Schedule's highest figure is 250 crore rupees, and it attaches to one duty only — the security-safeguards duty in section 8(5). Failure to report a breach sits in a separate 200 crore band, and most other contraventions fall into a 50 crore residual band.

Not as a general rule. Rule 15 permits transfer of personal data outside India, subject to any requirements the Central Government specifies by general or special order about making that data available to a foreign State or to a person or entity under its control. The one localisation duty in the Rules sits in rule 13(4) and applies only to Significant Data Fiduciaries, for classes of personal data the Central Government specifies on a committee's recommendation. Sector rules are a separate matter, and RBI's payment-data circular is stricter than DPDP.

Yes, where the processing relates to offering goods or services to Data Principals in India. Section 3 extends the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering goods or services to Data Principals within the territory of India. A US or Singapore SaaS company with Indian customers is in scope, which is why DPDP clauses are now appearing in Indian enterprise procurement paperwork aimed at foreign vendors.

Less than you fear on security, more than you expect on consent and retention. Rule 6's seven measures map closely onto an existing ISMS, so that phase is largely evidence mapping. What is genuinely new: itemised notice rather than categorised, withdrawal at parity with capture, verifiable parental consent for everyone under eighteen, the 48-hour pre-erasure warning, and rule 8(3)'s one-year minimum log retention — which runs against the delete-on-request reflex GDPR trains.

No. There is no DPDP certificate or registry for ordinary Data Fiduciaries. Notified Significant Data Fiduciaries owe an annual DPIA and an audit by an independent data auditor under section 10(2) and rule 13, and must furnish significant observations to the Board — but that is an obligation rather than a credential. For everyone else, compliance is demonstrated through artefacts: notice versions, consent and withdrawal records, log retention, a breach register against both rule 7 clocks, erasure job records, and a grievance log measured against your published period.

[07] get started

Get started in the way that fits you best -- see the platform in action, speak directly with a security expert, or get real proof through a free external scan of your environment.

See the platform in action. We'll show you:

Adaptation to your specific stack

Integration with your existing tools

Custom evidence collection workflows

Dashboard views for stakeholders

Speak directly with one of our security experts:

Security program design for your industry

Compliance roadmap (SOC 2 → ISO)

Risk assessment and treatment planning

Vendor security review guidance

BOOK A CALL

Want proof? We'll scan your surface for free:

Exposed assets and misconfigurations

SSL/TLS vulnerabilities

Vendor risk in your supply chain

Comparison to industry benchmarks