Digital Personal Data Protection Act, 2023

Is your organisation ready for penalties of up to ₹250 crore?

India's DPDP Act applies to every business that handles the personal data of people in India — whether you are a 12-person startup or a listed enterprise, and whether or not you are based in India. The DPDP Rules were notified on 13 November 2025, and the substantive obligations become enforceable on 13 May 2027. Find out in ten minutes where you actually stand.

  Time until full enforcement — 13 May 2027
Days
Hours
Minutes
Seconds
Compliance Timeline

Three dates that decide your exposure

The DPDP Rules, 2025 commence in phases. The clock on the obligations that carry the largest penalties is already running.

Active Now
13 November 2025

Rules notified · Data Protection Board constituted

The DPDP Rules were notified and the Data Protection Board of India was established, along with the provisions governing its appointments and procedure. The supervisory machinery exists from this date onward.

Upcoming
13 November 2026

Consent Manager framework takes effect

Registration and obligations for Consent Managers come into force. Organisations relying on consent at scale need their notice and consent architecture ready to interoperate well before this date.

Final Deadline
13 May 2027

All substantive obligations enforceable

Notice and consent, security safeguards, breach notification, retention limits, children's data rules, processor contracts and Data Principal rights all become fully enforceable, with the Schedule's penalties available to the Board.

Schedule to the Act

What non-compliance actually costs

The Schedule to the DPDP Act sets the maximum monetary penalty the Data Protection Board may impose for each class of breach. These are per-instance ceilings, not annual caps.

₹250 Cr

Failure to take reasonable security safeguards

The single largest exposure under the Act. Encryption, access control, logging and backups are not optional hygiene — they are a statutory duty under Section 8(5).

Section 8(5)
₹200 Cr

Failure to notify a personal data breach

Both the Data Protection Board and every affected Data Principal must be informed. Silence, or a delayed disclosure, is penalised separately from the breach itself.

Sections 8(6) & 8(7)
₹200 Cr

Breach of children's data obligations

Verifiable parental consent, and a prohibition on tracking, behavioural monitoring and targeted advertising directed at children under 18.

Section 9
₹150 Cr

Breach of Significant Data Fiduciary duties

Notified SDFs must appoint an India-resident Data Protection Officer and an independent data auditor, and carry out periodic Data Protection Impact Assessments.

Section 10
₹50 Cr

Breach of any other provision

The catch-all. Defective notice, invalid consent, unserved rights requests, missing processor contracts and over-retention all land here.

Residual entry
₹10,000

Breach of Data Principal duties

Individuals are not exempt either. Frivolous or false complaints and impersonation carry a penalty on the individual under Section 15.

Section 15

Penalties are determined by the Board having regard to the nature, gravity and duration of the breach, and the remedial action taken.

Free Rapid Assessment

Where does your organisation actually stand?

22 questions across 9 compliance domains, roughly ten minutes. You will get a readiness score, a domain-by-domain breakdown and your priority gaps.

DPDP Rapid Assessment

 

Entity Profile & Applicability

3 questions
1. Roughly how many individuals (customers, employees, users) is personal data held for?
2. Has the organisation formally determined whether it acts as a Data Fiduciary, a Data Processor, or both, for each processing activity?
3. Does a current Record of Processing Activities / data inventory exist (what is collected, why, where it is stored, who it is shared with)?

Notice & Consent Management

4 questions
4. Is an itemised notice given at or before collection, stating the personal data collected, the purpose, how to exercise rights, and how to complain to the Data Protection Board?
5. Is consent free, specific, informed, unconditional and unambiguous - collected by clear affirmative action rather than pre-ticked boxes or bundled T&C acceptance?
6. Can consent be withdrawn as easily as it was given, and is the withdrawal logged and propagated downstream to processors?
7. Is notice made available in English and in the Eighth Schedule languages, as Section 5(3) requires?

Data Principal Rights

2 questions
8. Is there a working process to serve rights requests - access, correction, completion, erasure and nomination - within a defined turnaround?
9. Has a Data Protection Officer or a designated contact person been appointed and published for grievance redressal?

Reasonable Security Safeguards

3 questions
10. Is personal data encrypted both in transit and at rest?
11. Is access to personal data controlled on a least-privilege basis with logging and periodic access reviews?
12. Are backups, monitoring and continuity measures in place so that personal data can be restored after a security incident?

Breach Response & Notification

2 questions
13. Is there a written personal data breach response plan that names roles, escalation paths and notification timelines?
14. Could the organisation notify the Data Protection Board and every affected Data Principal within the prescribed timeline, with the required details?

Retention, Erasure & Accuracy

2 questions
15. Are defined retention periods set per data category, with erasure once the purpose is served or consent is withdrawn?
16. Where personal data is used to make a decision affecting a Data Principal or is shared with another Fiduciary, are steps taken to ensure it is complete, accurate and consistent?

Children's Data & Guardianship

2 questions
17. Is the personal data of children (under 18) or of persons with disabilities under lawful guardianship processed, and is verifiable parental/guardian consent obtained?
18. Are tracking, behavioural monitoring and targeted advertising directed at children specifically suppressed?

Processor & Vendor Governance

2 questions
19. Are all third parties that touch personal data engaged under a valid written contract carrying DPDP obligations (purpose limitation, security, breach reporting, deletion on exit)?
20. Is vendor security assessed before onboarding and re-assessed periodically?

Cross-Border Transfer & SDF Duties

2 questions
21. Is it known which countries personal data is transferred to or stored in (including cloud regions and support teams outside India)?
22. If notified as a Significant Data Fiduciary, could the additional duties - appointing an India-resident DPO, an independent data auditor and periodic Data Protection Impact Assessments - be met?

Your results are ready

Tell us who you are and we will unlock your readiness score straight away. A copy is sent to our compliance team so that a specialist can walk you through the findings if you would like.

=
We practise what we assess. Your answers and details are used solely to produce this report and to contact you about it — never sold, and never shared with third parties.
Answer honestly — an optimistic score helps no one.

This rapid assessment is an educational readiness indicator, not legal advice, and does not create a lawyer–client relationship. For a binding view on your obligations under the DPDP Act, 2023, consult qualified legal counsel.

Assessment Coverage

Nine domains, mapped to the Act

Both assessments work through the same nine domains. The rapid version samples each one; the full version tests every control point within it.

Entity Profile & Applicability

Whether you are a Data Fiduciary, a Processor or both for each activity, plus a Record of Processing Activities covering what you collect, why, where it lives and who you share it with.

Notice & Consent Management

Itemised Section 5 notice, granular unbundled consent, withdrawal that is as easy as giving consent, and availability in the Eighth Schedule languages.

Data Principal Rights

Access, correction, completion, erasure and nomination requests served within a defined turnaround, with a published grievance contact or DPO.

Reasonable Security Safeguards

Encryption in transit and at rest, least-privilege access with logging, monitoring, and backups whose restores have actually been tested.

Breach Response & Notification

A written response plan with named roles, and the practical ability to notify the Board and every affected Data Principal within the prescribed timeline.

Retention, Erasure & Accuracy

Retention schedules per data category, erasure once the purpose is served or consent is withdrawn, and accuracy controls where data drives decisions.

Children's Data & Guardianship

Age assurance, verifiable parental or guardian consent, and technical suppression of tracking and targeted advertising aimed at children.

Processor & Vendor Governance

Valid written contracts carrying DPDP obligations for every processor, a maintained vendor register, and security due diligence that is repeated, not one-off.

Cross-Border Transfer & SDF Duties

Knowing every destination country and cloud region your data reaches, and readiness for the additional duties that follow an SDF notification.

Full DPDP Assessment

The ten-minute view is a starting point. This is the audit.

Our full assessment is a guided engagement led by a JJPMS compliance specialist. We work through 180+ control points across all nine domains, review your actual notices, contracts and system configuration, and hand you an evidence-backed remediation roadmap you can take to your board.

  • 180+ control points tested against the Act and the DPDP Rules, 2025 — not a generic privacy checklist.
  • Evidence review of your live notices, consent flows, processor contracts and security configuration.
  • Gap register with each finding mapped to the specific section and its penalty ceiling.
  • Prioritised roadmap with owners, effort estimates and target dates against the May 2027 deadline.
  • SDF readiness view covering DPO appointment, independent audit and DPIA obligations should you be notified.
180+Control Points
9Domains
2–3Weeks Typical

Request the Full Assessment

Share your details and a JJPMS compliance specialist will get in touch to scope the engagement.

=

Thank you — request received

Our executive will talk to you soon.

A JJPMS compliance specialist will reach out on the phone number and email you provided to scope your full DPDP assessment.

Frequently Asked

Questions we hear most

Is the DPDP Act enforceable today, or can we wait?

Partly enforceable, and no. The Act received assent in August 2023, and the DPDP Rules were notified on 13 November 2025. The Data Protection Board of India exists from that date. The Consent Manager provisions follow on 13 November 2026, and the remaining substantive obligations become enforceable on 13 May 2027.

The work that takes longest — data discovery, re-architecting consent, renegotiating processor contracts, closing security gaps — is exactly the work that cannot be compressed into the final quarter. Organisations that start in the last few months typically discover they cannot even identify where their personal data sits.

Does the Act apply to a small company, or one based outside India?

There is no turnover or headcount threshold for the Act to apply. If you process digital personal data of individuals in India, you are in scope. It also applies extraterritorially: an entity outside India is covered where the processing relates to offering goods or services to Data Principals in India.

Size affects one thing only — whether the Central Government notifies you as a Significant Data Fiduciary, which adds duties such as an India-resident DPO, an independent data auditor and periodic DPIAs. It does not exempt anyone from the baseline obligations.

How does the rapid assessment differ from the full one?

The rapid assessment is 22 self-reported questions, roughly ten minutes, sampling each of the nine domains. It gives you a directional readiness score and shows which domains are weakest. It is free and you get the result immediately.

The full assessment is a guided engagement across 180+ control points in which we review your actual artefacts — live notices, consent flows, processor contracts, system configuration — rather than relying on self-reporting. It produces a gap register mapped to specific sections and penalty ceilings, plus a prioritised remediation roadmap.

What happens to the answers we submit?

Your answers and contact details are sent to our compliance team at support@jjpmetasystems.com so that a specialist can interpret the result with you if you would like. They are used for that purpose alone. We do not sell them, and we do not share them with third parties.

Is this legal advice?

No. Both assessments are compliance readiness tools, and this page is general information about the DPDP Act, 2023. Neither constitutes legal advice, and neither creates a lawyer–client relationship. For a binding view on how the Act applies to your specific circumstances, consult qualified legal counsel. We are happy to work alongside your counsel on the technical and operational remediation.

Take the Rapid Assessment
Chat with us