Free PDF download

Is Your Tech Stack Hiding a ₹250 Crore Liability?

India's DPDP Act makes every API call, user signup, and third-party integration a point of legal accountability. With the DPDP Rules notified and full compliance due by 13 May 2027, this guide explains what that means for your organization — and what to do about it, in plain language.

What the DPDP Act's ₹250 crore penalty regime actually means for your business
Why liability applies whether you have 1 employee or 1,000
How DPDPA compliance affects VC due diligence and M&A exits
The consent, data-mapping, and third-party obligations most teams miss
A practical readiness checklist to benchmark where you stand today

Prefer to talk to a person? Our team runs DPDP readiness audits for Indian enterprises and Significant Data Fiduciaries.

Get the free guide (PDF)

Tell us where to reach you and the download starts immediately. No spam — one follow-up at most.

By downloading you agree to our privacy policy. We'll use your email only to send DPDP compliance updates you can opt out of anytime.

Where the law actually stands today

The Digital Personal Data Protection Act became law in 2023, but for two years it had no operative rules and no enforcement machinery. That changed on 14 November 2025, when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 and started an eighteen-month transition clock. The timeline below matters more than the headline penalty figures, because it determines when each obligation becomes enforceable against you.

  1. 14 November 2025

    Rules notified, Board constituted

    MeitY notified the DPDP Rules, 2025, giving the 2023 Act its operative detail and starting an eighteen-month transition. The Data Protection Board of India was established alongside its procedures for complaints and inquiries.

  2. Around November 2026

    Consent Manager registration

    The registration framework for Consent Managers becomes operational. Organisations intending to act as registered Consent Managers — the intermediaries through which individuals give, manage, review and withdraw consent — need to be registered with the Board.

  3. 13 May 2027

    Substantive obligations apply in full

    Notice and consent, reasonable security safeguards, personal data breach reporting, Data Principal rights, and the additional duties placed on Significant Data Fiduciaries all become enforceable.

May 2027 sounds comfortably distant. In practice it is not. Consent re-architecture, data mapping across systems you inherited rather than designed, and vendor contract renegotiation are multi-quarter programmes — and they run through engineering backlogs that are already full.

Does this apply to your organisation?

Almost certainly yes. Unlike most Indian regulation, the DPDP Act sets no revenue threshold, no employee-count threshold, and no blanket carve-out for early-stage companies. You are a Data Fiduciary if you determine the purpose and means of processing digital personal data, whether alone or together with others. A fifteen-person SaaS business holding customer email addresses is a Data Fiduciary in exactly the way a listed bank is.

Two points catch teams out most often. The first is reach: the Act applies to processing carried out outside India where that processing relates to offering goods or services to individuals in India, so an overseas parent or a foreign-registered subsidiary is not automatically outside its scope. The second is delegation: engaging a Data Processor — a CRM, a payroll bureau, a cloud analytics vendor — does not move the obligation off your balance sheet. You remain accountable for processing performed on your behalf, and you are expected to have a contract that governs it.

A subset of organisations will additionally be notified as Significant Data Fiduciaries, based on factors including the volume and sensitivity of the personal data they process and the risk it carries. That designation brings materially heavier duties: appointing a Data Protection Officer based in India, commissioning an independent data auditor, and running periodic Data Protection Impact Assessments.

What the penalties actually are

The ₹250 crore figure gets quoted everywhere, usually without the context that it attaches to one specific failure. The Act sets separate ceilings for separate contraventions:

ContraventionCeiling
Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failure to notify the Board and affected individuals of a personal data breach₹200 crore
Breach of the additional obligations concerning children's data₹200 crore
Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Residuary — any other contravention of the Act or Rules₹50 crore

These are maximums, not tariffs. In determining what to impose, the Data Protection Board weighs the nature, gravity and duration of the contravention, the type of personal data affected, whether the conduct was repetitive, and — importantly for anyone reading this before the deadline — what mitigating action was taken and how promptly. Demonstrable preparation is not merely good practice; it is a factor the Board is directed to consider.

What's inside the guide

Twenty-eight pages, written for the person who has to run the programme rather than the person who has to litigate it. No legalese, no vendor pitch.

01

Scope and applicability

Whether you are a Data Fiduciary, a Data Processor, or both — and why the Act reaches processing carried out outside India.

02

The consent standard

What free, specific, informed, unconditional and unambiguous consent requires in practice, plus itemised notice and withdrawal mechanics.

03

Legitimate uses

The narrow set of grounds under which you may process without consent, and the common mistake of over-reading the employment exemption.

04

Security safeguards and breach reporting

What counts as reasonable, what your notification duty looks like, and how to build an evidence trail before you need one.

05

Significant Data Fiduciary duties

DPO appointment, annual Data Protection Impact Assessments, and independent audits — and how to tell if you are likely to be designated.

06

The readiness checklist

A question-by-question benchmark across data mapping, consent, vendors, retention and incident response, scored so you can see the gaps.

Frequently asked questions

Does the DPDP Act apply to small businesses and startups?

Yes. The Act sets no revenue threshold, no employee-count threshold and no startup carve-out. If you determine why and how digital personal data is processed, you are a Data Fiduciary and the obligations apply. Certain classes of data fiduciary may receive limited exemptions by notification, but the default position is that the Act applies to you.

We use a third-party CRM and payroll provider. Does that transfer our liability?

No. Engaging a Data Processor does not transfer your obligations as a Data Fiduciary. You remain responsible for compliance, including for processing carried out on your behalf, and you are expected to have a valid contract governing that processing.

Our company is registered outside India. Are we in scope?

Possibly. The Act applies to processing of digital personal data outside India where that processing is in connection with offering goods or services to Data Principals within India.

May 2027 is still some way off. Why start now?

Because the work is slower than it looks. Re-architecting consent capture, mapping personal data across systems you inherited rather than designed, and renegotiating vendor contracts are multi-quarter programmes. Organisations that begin in 2027 will be remediating under enforcement rather than ahead of it.

This page is general information about the DPDP Act and Rules, not legal advice. For an assessment of your own obligations, our DPDP readiness audit reviews your data flows, consent design and vendor contracts against the Act.

💬Need Support Now?