Guides/8 min read

The DPDP Act 2023: a practical compliance guide

What the Digital Personal Data Protection Act requires, who it binds, the 2027 enforcement timeline, and how to build a defensible programme.

Updated 22 June 2026

What the DPDP Act covers

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection statute. It governs the processing of digital personal data and creates enforceable duties for Data Fiduciaries — the organisations that decide why and how personal data is processed.

Core principles include lawful processing on a valid basis (most commonly consent), clear notice, purpose limitation, storage limitation, reasonable security safeguards, and accountability for breaches.

Who must comply and by when

The DPDP Rules, 2025 were notified on 13 November 2025, with full compliance expected by 13 May 2027. That window is the time organisations have to inventory their personal data, establish lawful bases, and stand up breach and retention controls.

Significant Data Fiduciaries — designated on the basis of data volume, sensitivity or risk to fundamental rights — carry additional duties: appointing a Data Protection Officer, conducting periodic Data Protection Impact Assessments, and undergoing an annual data audit.

  • ▹Record a lawful basis and notice for every consent-based dataset
  • ▹Set and enforce retention clocks; dispose of data past its purpose
  • ▹Apply the strictest handling to children's data
  • ▹Be ready to run the two-tier breach notification within tight windows

How Praman helps

Praman turns these duties into continuous, automated checks. Each obligation carries its statutory citation and a pass / at-risk / fail status linked to immutable evidence. When the rules change, you version the obligation — no software release required — and the platform proves which version applied on any date.

FAQ

When does the DPDP Act take full effect?

The DPDP Rules were notified on 13 November 2025, with full compliance targeted for 13 May 2027.

Is consent always required?

No. Consent is the most common basis, but the Act also recognises certain legitimate uses, legal mandates and public-interest grounds. Each dataset should record its specific lawful basis.

Turn this obligation into a live check.

Praman evaluates it against your real systems and proves the result.

Request a demo

This guide is general information, not legal advice. Verify obligations with qualified counsel.