What the DPDP Act covers
The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection statute. It governs the processing of digital personal data and creates enforceable duties for Data Fiduciaries — the organisations that decide why and how personal data is processed.
Core principles include lawful processing on a valid basis (most commonly consent), clear notice, purpose limitation, storage limitation, reasonable security safeguards, and accountability for breaches.
Who must comply and by when
The DPDP Rules, 2025 were notified on 13 November 2025, with full compliance expected by 13 May 2027. That window is the time organisations have to inventory their personal data, establish lawful bases, and stand up breach and retention controls.
Significant Data Fiduciaries — designated on the basis of data volume, sensitivity or risk to fundamental rights — carry additional duties: appointing a Data Protection Officer, conducting periodic Data Protection Impact Assessments, and undergoing an annual data audit.
- ▹Record a lawful basis and notice for every consent-based dataset
- ▹Set and enforce retention clocks; dispose of data past its purpose
- ▹Apply the strictest handling to children's data
- ▹Be ready to run the two-tier breach notification within tight windows
How Praman helps
Praman turns these duties into continuous, automated checks. Each obligation carries its statutory citation and a pass / at-risk / fail status linked to immutable evidence. When the rules change, you version the obligation — no software release required — and the platform proves which version applied on any date.