DPDP Act 2023 · Compliance guide

DPDP Act 2023: a practical compliance checklist for Indian businesses

Updated June 2026 · ~9 min read · by Ronin Works
Short answer

India's Digital Personal Data Protection Act, 2023 applies to almost any business that handles the personal data of people in India — not just big tech. The final Rules were notified in November 2025, and the compliance deadline is 13 May 2027. To get ready: map where personal data lives, publish a privacy notice, take proper consent, appoint a grievance officer, and build processes to handle deletion requests, breaches and retention. Penalties run up to ₹250 crore per instance.

If your business collects names, phone numbers, emails, addresses, payment details or any other personal information about people in India, the DPDP Act applies to you. The good news: the obligations are practical, and a focused effort now puts you well ahead of the deadline. This is the checklist we use with our clients.

What is the DPDP Act, and who does it apply to?

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. It governs how organisations collect, store, use and share the digital personal data of individuals (called data principals).

You are a data fiduciary — and on the hook — if you decide the purpose and means of processing that data. That covers e-commerce sellers, clinics and hospitals, schools and coaching centres, agencies, SaaS startups, real-estate firms, NBFCs and almost every other business. It applies to data collected online, and to offline data that is later digitised.

The 9 obligations — in plain English

1. Privacy notice

Give people a clear, itemised notice of what personal data you collect, why, and how they can exercise their rights — in plain language, ideally available in English and Indian languages.

2. Consent

Collect data on the basis of free, specific, informed and unambiguous consent, taken for a defined purpose. Withdrawing consent must be as easy as giving it. Consent obtained by burying it in long terms doesn't count.

3. Grievance officer

Appoint and publish the contact details of a person who handles data-related complaints and requests. Significant Data Fiduciaries must also appoint a Data Protection Officer based in India.

4. Right to access, correction & erasure

People can ask what data you hold, correct it, and have it erased. You need a repeatable process to find and delete a person's data across all your systems within a reasonable, timely window.

5. Data mapping & records

Maintain a record of what personal data you process, why, and who you share it with. You can't delete, secure or report on data you can't locate — so a data inventory is the foundation everything else stands on.

6. Security safeguards

Apply reasonable security safeguards — encryption, access controls, least-privilege, logging. Failing to do so, leading to a breach, is the obligation that carries the heaviest penalty.

7. Breach notification

Have a plan to detect a personal data breach and notify both the Data Protection Board of India and the affected individuals.

8. Children's data

For users under 18, obtain verifiable parental consent and do not carry out behavioural tracking or targeted advertising directed at children.

9. Processors & retention

Put data-processing agreements in place with every vendor that touches personal data on your behalf, and delete data you no longer need under defined retention periods.

What are the penalties?

Penalties are decided by the Data Protection Board of India and can reach up to ₹250 crore per instance for failing to take reasonable security safeguards against a breach. Other failures — like not fulfilling breach-notification duties or children's-data rules — carry their own scheduled penalties. For most SMEs the bigger near-term risk is reputational and contractual: enterprise customers are already adding DPDP clauses to vendor agreements.

When do you need to be ready?

The Act was passed in 2023, and MeitY notified the final DPDP Rules in November 2025 — starting a phased, 18-month implementation clock. The Data Protection Board provisions took effect immediately; Consent Manager registration provisions switch on at 12 months (around November 2026); and full functional compliance — consent, notice, data-principal rights, grievance redressal — is required by 13 May 2027. Because building consent flows, a data inventory and erasure processes realistically takes a few months, the practical deadline to start is now.

Your step-by-step readiness checklist

Not sure where you stand?

Take our free, 2-minute DPDP Readiness Scorecard — answer 12 questions and get a per-area gap report showing exactly what to fix first.

How Ronin Works helps

We're a data-quality studio first, which makes us unusually good at the hardest part of DPDP: finding and cleaning the data itself. We map where personal data lives across your systems, de-duplicate and standardise it, then build the notice, consent, grievance, erasure and breach processes on top — and leave you audit-ready. Clean data is compliant data.

Keep reading

Not a business — just you?

The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.

Scan your exposure at Saaph.in →
Enquiry

Have a DPDP question?

Send us a note — we reply within one working day.

✓ Thank you — we'll be in touch.

This article is general information, not legal advice. The DPDP Act's rules and enforcement timeline are determined by the Government of India and may change. For a formal assessment of your obligations, consult a qualified professional or talk to Ronin Works.