How to Comply with the DPDP Act 2023 Before the May 2027 Enforcement Deadline
- Kaustav Chowdhury

- 2 days ago
- 4 min read
The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive data protection legislation, establishing a framework for processing personal data of Indian residents. With the DPDP Rules notified on 13 November 2025, organisations face a definitive compliance deadline of 13 May 2027, when full enforcement powers and penalties take effect. The 18-month window from notification to enforcement gives businesses time to build, test, and operationalise their data protection frameworks. Penalties are severe, reaching up to Rs 250 crore for certain violations. This guide outlines the practical steps every Data Fiduciary must take to achieve compliance before the enforcement deadline.
Understanding the Phased Enforcement Timeline
The DPDP Act and Rules follow a three-phase enforcement timeline:
Phase I (13 November 2025): Constitution of the Data Protection Board of India (DPBI) and basic framework provisions take effect.
Phase II (13 November 2026): Registration for Consent Managers opens. Organisations can begin registering intermediaries that manage consent on behalf of Data Principals.
Phase III (13 May 2027): Full substantive compliance required. Enforcement powers activated, Schedule 1 penalties in effect, and the DPBI begins adjudicating complaints.
The year 2026 is the critical “build and test” period. Organisations should use this time to establish internal systems, train teams, and conduct readiness assessments. Integrating DPDP compliance into an existing compliance calendar can help ensure no deadline is missed.
Step 1: Conduct a Comprehensive Data Mapping Exercise
The foundation of DPDP compliance is a thorough data mapping exercise. Organisations must identify and document all personal data flows, including what personal data is collected, where it is stored, how it is processed, and to whom it is shared or transferred. This exercise should cover data processed directly as well as data handled by third-party Data Processors. The output should be a structured data inventory that classifies data by type, purpose, and sensitivity. Organisations engaged in cross-border data flows and technology licensing must pay particular attention to transfer mechanisms and cross-border data sharing arrangements.
Step 2: Implement Consent Mechanisms Under Section 4
Section 4 of the DPDP Act requires that consent be free, specific, informed, unconditional, and unambiguous. Organisations must deploy consent collection interfaces that allow Data Principals to provide granular, purpose-specific consent. Each purpose for processing must be separately identifiable, and bundled consent (where a single acceptance covers multiple unrelated purposes) is not permissible. Organisations must also maintain auditable records of all consent obtained and build mechanisms that allow Data Principals to withdraw consent as easily as it was given. Existing processing activities should be re-evaluated to determine whether they meet the new consent standard.
Step 3: Issue Privacy Notices Under Section 5
Section 5 requires every Data Fiduciary to provide a privacy notice at the point of data collection. The notice must be written in clear and plain language and must include an itemised description of the personal data being collected, the specified purposes of processing, the means available for Data Principals to exercise their rights, and the process for filing complaints with the DPBI. The notice must also contain a specific communication link to the Data Fiduciary’s website or application. Organisations processing data collected before the Act’s commencement must issue retrospective notices to existing Data Principals as well.
Step 4: Establish Breach Notification Protocols
Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules, 2025 establish strict breach notification obligations. Every Data Fiduciary must notify each affected Data Principal without delay when a personal data breach occurs. Additionally, a detailed report must be filed with the Data Protection Board within 72 hours of becoming aware of the breach. Unlike some international frameworks, the DPDP Act applies no materiality threshold; all breaches require notification regardless of scale. The penalty for failing to notify the Board of a breach is up to Rs 200 crore. Organisations should establish dedicated incident response teams, pre-draft notification templates, and conduct regular breach simulation exercises. Those with experience responding to regulatory investigations will find parallels in structuring these protocols.
Step 5: Protect Children’s Data Under Section 9
The DPDP Act classifies anyone under the age of 18 as a child and imposes additional obligations on Data Fiduciaries processing children’s data. Verifiable parental consent is required before any processing of a child’s personal data. Limited exceptions exist for processing related to child protection duties, issuance of government subsidies or services, and creation of email accounts. Organisations must implement robust age verification mechanisms and ensure that parental consent workflows are fully auditable and compliant with the prescribed standards.
Step 6: Implement Security Safeguards and Data Retention Policies
Section 8(5) mandates that every Data Fiduciary implement reasonable security safeguards to prevent personal data breaches. While the Act does not prescribe specific technical standards, organisations should adopt industry-standard measures including encryption, access controls, regular vulnerability assessments, and security audits. Data retention policies must define purpose-based timelines; personal data must be deleted when the specified purpose has been served or when consent is withdrawn. Failure to implement reasonable security safeguards resulting in a breach carries the highest penalty under the Act: up to Rs 250 crore. Organisations already running internal investigation frameworks can extend those structures to cover data breach investigations.
Penalty Overview
The DPDP Act prescribes penalties on a graded scale under Schedule 1:
Failure to implement reasonable security safeguards resulting in a data breach: up to Rs 250 crore
Failure to notify the Data Protection Board of a breach: up to Rs 200 crore
Non-compliance with obligations relating to children’s data: up to Rs 200 crore
Non-fulfilment of other Data Fiduciary obligations: up to Rs 150 crore
Breach of duties by Data Principals (filing frivolous complaints): up to Rs 10,000
Related Reading
For related compliance frameworks, see the guides on ESG due diligence for Indian exporters under EU regulations and implementing anti-bribery compliance programmes.
Key Takeaways
The DPDP Act, 2023 and DPDP Rules, 2025 (notified 13 November 2025) require full organisational compliance by 13 May 2027.
Data mapping, consent mechanisms under Section 4, and privacy notices under Section 5 form the foundation of compliance.
Breach notification to affected individuals and the DPBI within 72 hours is mandatory under Section 8(6) and Rule 7, with no materiality threshold.
Children’s data (anyone under 18) requires verifiable parental consent under Section 9.
Penalties range from Rs 10,000 to Rs 250 crore depending on the nature and severity of the violation.
The year 2026 is the critical window for building and testing compliance frameworks before enforcement begins.
Organisations that begin compliance efforts now will be best positioned to meet the May 2027 enforcement deadline and avoid the substantial penalties prescribed under the Act.

Comments