{{ p.t }}
- —{{ it }}
Source: Digital Personal Data Protection Act, 2023 (Schedule) and DPDP Rules, 2025 as notified by MeitY.
The DPDP Act is India's first comprehensive data protection law. It received Presidential assent on 11 August 2023 and governs how organisations collect, use, store, share and erase the digital personal data of individuals in India.
MeitY notified the DPDP Rules, 2025 on 13 November 2025, starting an 18-month phased rollout. The Rules turn the Act's principles into specific duties: how a notice must look, how fast a breach must be reported, how long logs must be kept and when inactive users' data must be erased.
The Act applies to processing inside India, and to processing outside India when it is connected with offering goods or services to people in India. It is enforced by the Data Protection Board of India, with appeals heard by TDSAT.
{{ r.d }}
Every business, startup, NGO, hospital, school and government body that processes digital personal data of people in India, whatever its size. Foreign companies serving Indian users are covered too.
Personal data collected in digital form, and data collected offline that is later digitised: customer records, employee files, CCTV-linked systems, app analytics, KYC and more.
Data processed for purely personal or domestic purposes, and data made publicly available by the individual or under a legal obligation. Specific exemptions exist under Section 17.
The deadlines are fixed in the notification. Consent systems, vendor contracts and data mapping take quarters to build, so most of the work has to be finished well before May 2027.
Each obligation maps to a section of the Act or a Rule, and to experts on the marketplace who deliver it.
{{ o.d }}
Sections 11 to 14 give every individual enforceable rights. Your systems need a documented way to receive, verify and answer each request, and grievances must be resolved within 90 days under Rule 14.
{{ r.d }}
The Act is sector-neutral, but the risk isn't. Pick your industry to see the data at stake, the obligations that bite hardest and the services experts usually deliver first.
{{ ind.p }}
Twenty services across the full compliance lifecycle, from the first gap assessment to representation before the Data Protection Board. Hire one expert for a single task or a firm for the whole programme.
Posting is free and takes two minutes. Your company name stays hidden until you choose to share it, and every expert signs a platform NDA before seeing details.
Reference {{ rfpRef }}. Matched experts are being notified. Expect your first proposals within 48 hours.
Illustrative profiles shown for launch preview.
There is no government-issued DPDP certificate for consultants. Our badges are platform credentials that tell you how deeply an expert has been vetted. Badges are reviewed every 12 months.
Answer the questions to see which gaps to close first.
DPDP penalties are fixed caps per instance, not a percentage of turnover. One breach can trigger several heads at once. Select what applies to estimate maximum exposure.
Illustrative only. Actual penalties are determined by the Data Protection Board after inquiry.
Global companies often assume their GDPR programme covers India. These are the differences that require changes.
Independent consultants, law firms, audit firms and privacy-tech vendors can list on DPDP.expert. Get verified once, then respond to qualified requirements from businesses that are ready to hire.
Can't find your answer? Post a question and a verified expert will reply.
{{ f.a }}
{{ f.a }}
A typical mid-size DPDP programme takes about 28 weeks, from first assessment to audit-ready evidence. {{ bufferLine }}
We use essential cookies to run this site and, only with your consent, analytics to improve it. You can change this any time.