What the DPDP Act requires, and by when.
The Digital Personal Data Protection Act applies to almost every business that handles personal data in India. Penalties for non-compliance reach ₹250 crore. The first deadline arrives in November 2026.
New to the DPDP Act? Start with these four pages.
They cover the law, the Rules that put it into effect, whom it covers, and the deadlines. Each page links to the next.
What is the DPDP Act
Parliament passed the Act in August 2023. It sets out what companies must do with personal data.
Read → 2What are the DPDP Rules
The Rules, notified in November 2025, set out how the Act operates and fix the compliance deadlines.
Read → 3Whom does the Act apply to
The Act covers businesses of every size, in India and abroad. Check where your business stands.
Read → 4What are the deadlines
Compliance arrives in phases through 13 May 2027. See what is due by each date.
Read →Where things stand in August 2026
Some provisions of the Act are in force today and most are not. The status tracker lists every provision of the Act and the Rules with its start date.
How the Act and the Rules work together
Creates the obligations
Passed by Parliament in August 2023. It sets out what companies must do:
- Get consent before using personal data
- Tell people what you collect and why
- Erase data when the purpose ends
- Penalties up to ₹250 crore per breach
Set the procedure and the deadlines
Notified by the Government in November 2025. They set out how each obligation is met:
- What a consent notice must contain
- How Consent Managers register and operate
- How breaches must be reported
- The compliance deadlines, in phases
The Act creates the obligations. The Rules specify how each obligation is met in practice. Both come into force in phases, and the last phase completes on 13 May 2027. The Rules page has the full map.
The questions companies ask most
What are the penalties?
The Schedule sets seven penalty entries, up to ₹250 crore for failing to prevent a personal data breach. The Board that will impose them has not been appointed yet.
Read the full answer →Do we need consent for data we already hold?
No. Section 5(2) requires a notice, not fresh consent. You must tell existing users what you hold and give them a way to withdraw. Most published guidance gets this wrong.
Read the full answer →Is the Data Protection Board operational?
No. It has no chairperson and no members, and the sections that give it power do not start until 13 May 2027. Complaints cannot be filed today.
Read the full answer →