New to DPDP?

India's data protection law, in two minutes.

The Digital Personal Data Protection Act, 2023 (the DPDP Act) and its Rules 2025 decide how organisations may collect and use personal data about people in India, and what rights those people have.

A plain-English summary, checked on 28 September 2026. It is not legal advice.

Who is who

Four roles appear everywhere in the law.

Data FiduciaryYour organisation, when it decides why and how personal data is used. Most duties fall here.
Data PrincipalThe person the data is about: a customer, an employee, a user. For a child, the parent too.
Data ProcessorA vendor that handles data for you, such as a cloud, payroll or call-centre provider.
Data Protection BoardThe regulator that hears complaints, looks into breaches and imposes penalties.

The key dates

The law is passed; most duties start in May 2027.

  1. Aug 2023The Act is passedThe Digital Personal Data Protection Act, 2023 becomes law.
  2. 13 Nov 2025The Rules are notifiedThe DPDP Rules 2025 are published. The Board provisions apply at once.
  3. Nov 2026Consent ManagersRegistration of Consent Managers with the Board applies, 12 months after the Rules.
  4. May 2027Most duties applyNotice, consent, security, breach notice, rights and erasure: 18 months after the Rules.

What you must do

Six duties cover most of the Act. The section numbers are for your legal team.

Tell people, then askA clear notice of what you collect and why, then consent that is free, specific and easy to withdraw.DPDP S.5, S.6
Keep it safeReasonable security safeguards, including over your vendors, to prevent a breach.DPDP S.8(5)
Report breachesTell affected people and the Board without delay, and send the Board a full report within 72 hours.DPDP S.8(6), Rule 7
Erase when doneDelete data once its purpose is served or consent is withdrawn, unless a law says keep it.DPDP S.8(7), Rule 8
Answer requestsLet people see, correct and erase their data, name a nominee, and complain to you first.DPDP S.11 to S.14
Protect childrenVerifiable parental consent for a child's data, and no tracking or targeted ads at children.DPDP S.9, Rule 10
Large data holders do moreAn organisation named a Significant Data Fiduciary needs a DPO based in India, an independent auditor, and a yearly DPIA and audit.
Breach deadlinesDPDP: tell people and the Board without delay, full report in 72 hours. Sector rules (CERT-In, RBI, SEBI, IRDAI): a first report in 6 hours.
PenaltiesUp to Rs 250 crore for weak security, and up to Rs 200 crore for an unreported breach or children's-data failures.

Questions people ask

Short answers; the glossary explains every term.

Does the DPDP Act apply to my company?

Yes, if you process digital personal data in India, or data collected offline and then digitised. It also applies to companies outside India that offer goods or services to people in India. Purely personal or household use is outside it.

When do I have to comply?

Most duties apply from May 2027, 18 months after the Rules were notified on 13 November 2025. The Board provisions already apply, and Consent Manager registration applies from November 2026. Building notices, consent records and breach processes takes months, so most organisations start now.

What are the penalties?

The Act sets penalties per breach of duty, imposed by the Data Protection Board after an inquiry: up to Rs 250 crore for failing to keep reasonable security safeguards, and up to Rs 200 crore for failing to report a breach or for breaching the duties on children's data.

What is a Significant Data Fiduciary?

An organisation the government names for extra duties because of the volume or sensitivity of the data it handles, or the risk to people. It must appoint a Data Protection Officer based in India and an independent data auditor, and run a DPIA and an audit every year.

Is FOCTTA a Consent Manager?

No. A Consent Manager is a company registered with the Data Protection Board to manage people's consents on their behalf. FOCTTA is software that your organisation uses to collect, record and prove consent and to run the rest of its DPDP programme.

How does this sit with RBI, SEBI or IRDAI rules?

Sector rules still apply alongside DPDP. Most sector cyber rules require a first incident report within 6 hours: to CERT-In, to RBI on its DAKSH portal, to SEBI, and for insurers to CERT-In with a copy to IRDAI. FOCTTA tracks these clocks next to the DPDP ones.

Where FOCTTA helps

Start with the duty that worries you most.

Every term on this page is in the glossary. For the law section by section, see Regulations, or check how ready you are in three minutes.