Key questions
Each answer is checked against the primary document
Eight questions get a page of their own, because a short answer does not settle them. Every page answers the question in its first forty words, names the provision it relies on, and says what would have to happen for the answer to change. Shorter questions are answered on the FAQ.
- Who does the DPDP Act apply to?
Digital personal data processed in India, and processing outside India connected with offering goods or services to people in India.
- When is the DPDP compliance deadline?
Consent Manager registration by November 2026. Full compliance by May 2027. Both dates are on the parliamentary record.
- Is the Data Protection Board of India operational?
No. It has no appointed chairperson and no appointed members, and its powers do not start until May 2027.
- What are the penalties under the DPDP Act?
Seven entries in the Schedule, running to 250 crore rupees. None has been imposed, and the penalty sections are not yet in force.
- How long must personal data be kept, and when must it be erased?
A one year floor for security logs and a three year dormancy trigger for erasure. The two do not conflict.
- In which languages must a DPDP notice be given?
English or any of the twenty-two languages in the Eighth Schedule to the Constitution, at the Data Principal's option.
- Do I need fresh consent for data collected before the Act?
No. Section 5(2) requires a notice, not fresh consent. Most published guidance gets this wrong.
- Who can register as a Consent Manager?
An Indian company with a net worth of at least two crore rupees, independent certification and records kept for at least seven years.
If a question you have is not answered here or on the FAQ, write to editor@indiadatalaw.org. Questions asked more than once become pages.