India's data protection law, in two minutes.
The Digital Personal Data Protection Act, 2023 (the DPDP Act) and its Rules 2025 decide how organisations may collect and use personal data about people in India, and what rights those people have.
A plain-English summary, checked on 28 September 2026. It is not legal advice.
Who is who
Four roles appear everywhere in the law.
The key dates
The law is passed; most duties start in May 2027.
- Aug 2023The Act is passedThe Digital Personal Data Protection Act, 2023 becomes law.
- 13 Nov 2025The Rules are notifiedThe DPDP Rules 2025 are published. The Board provisions apply at once.
- Nov 2026Consent ManagersRegistration of Consent Managers with the Board applies, 12 months after the Rules.
- May 2027Most duties applyNotice, consent, security, breach notice, rights and erasure: 18 months after the Rules.
What you must do
Six duties cover most of the Act. The section numbers are for your legal team.
Questions people ask
Short answers; the glossary explains every term.
Does the DPDP Act apply to my company?
Yes, if you process digital personal data in India, or data collected offline and then digitised. It also applies to companies outside India that offer goods or services to people in India. Purely personal or household use is outside it.
When do I have to comply?
Most duties apply from May 2027, 18 months after the Rules were notified on 13 November 2025. The Board provisions already apply, and Consent Manager registration applies from November 2026. Building notices, consent records and breach processes takes months, so most organisations start now.
What are the penalties?
The Act sets penalties per breach of duty, imposed by the Data Protection Board after an inquiry: up to Rs 250 crore for failing to keep reasonable security safeguards, and up to Rs 200 crore for failing to report a breach or for breaching the duties on children's data.
What is a Significant Data Fiduciary?
An organisation the government names for extra duties because of the volume or sensitivity of the data it handles, or the risk to people. It must appoint a Data Protection Officer based in India and an independent data auditor, and run a DPIA and an audit every year.
Is FOCTTA a Consent Manager?
No. A Consent Manager is a company registered with the Data Protection Board to manage people's consents on their behalf. FOCTTA is software that your organisation uses to collect, record and prove consent and to run the rest of its DPDP programme.
How does this sit with RBI, SEBI or IRDAI rules?
Sector rules still apply alongside DPDP. Most sector cyber rules require a first incident report within 6 hours: to CERT-In, to RBI on its DAKSH portal, to SEBI, and for insurers to CERT-In with a copy to IRDAI. FOCTTA tracks these clocks next to the DPDP ones.
Where FOCTTA helps
Start with the duty that worries you most.
Every term on this page is in the glossary. For the law section by section, see Regulations, or check how ready you are in three minutes.