India · DPDP Act 2023 · DPDP Rules 2025
India DPDP Act Compliance Service
Formiti helps organisations that process personal data of people in India meet the Digital Personal Data Protection Act before full obligations apply on 13 May 2027. We assess your gaps, act as your DPO or contact person, rebuild consent and notices, and support Significant Data Fiduciaries, delivered remotely and backed by Privacy360.
Who the DPDP Act applies to
The Act covers digital personal data processed in India, and processing outside India that is linked to offering goods or services to people in India. That means it reaches far beyond Indian companies.
- Indian companies of any size that collect customer, employee or user data
- Foreign companies selling apps, SaaS, e-commerce or services to people in India
- Global groups with Indian subsidiaries, shared service centres or offshore teams
- Edtech, health, fintech and gaming platforms handling children's or high-risk data
DPDP Rules 2025: key deadlines
13 November 2025
Rules published
The DPDP Rules 2025 were published in the Official Gazette. The Data Protection Board provisions took effect immediately.
13 November 2026
Consent managers
Registration and obligations for consent managers apply one year after publication.
13 May 2027
Full obligations
Notices, consent, security safeguards, breach notification, data principal rights, children's data and Significant Data Fiduciary duties apply 18 months after publication.
What's included
Readiness assessment
A gap analysis of your processing against the DPDP Act and Rules, a data inventory, and a prioritised roadmap to the 13 May 2027 deadline.
Outsourced DPO and India contact
Formiti acts as your DPO or designated contact person, answering data principal questions and running the grievance process the Act requires.
Consent and notices
Itemised notices, consent flows, consent manager integration, withdrawal as easy as giving consent, and verifiable parental consent for children's data.
Significant Data Fiduciary support
Periodic DPIAs, annual audit coordination, algorithmic risk checks and the India-based DPO that SDFs must appoint.
Need a DPO across India and other markets? See our outsourced DPO service.
Delivered remotely by a global team
We don't claim a local office. Our privacy specialists deliver the DPDP programme remotely, working in Indian business hours where needed, and bring the same methods we use for GDPR, UK GDPR, Thailand PDPA and other regimes. One team covers India alongside your other markets.
Privacy360 for India DPDP
Privacy360, our privacy operations platform, now includes India DPDP layers across its modules and regional settings:
- Records of processing tagged to DPDP purposes and data principals in India
- Consent and notice tracking, including withdrawals and parental consent
- Data principal rights and grievance requests with DPDP timelines
- Breach logs that support the Board's 72-hour report
- DPIA and audit workflows for Significant Data Fiduciaries
- India regional settings alongside GDPR and other jurisdictions
Pricing
India DPDP Act Readiness Estimator
Estimate your organisation's readiness effort, timeline and indicative cost for India's Digital Personal Data Protection (DPDP) Act. Takes about 2 minutes.
Your first 30 days
- 1
Kick-off call to confirm scope, systems and the people involved.
- 2
Data discovery: we map where personal data of individuals in India is collected, stored and shared.
- 3
Gap report against the Act and Rules, ranked by risk and deadline.
- 4
Quick wins: updated privacy notice, grievance contact and breach response steps.
- 5
Agreed roadmap and owners for the remaining work up to May 2027.
Frequently asked questions
India DPDP Act questions
Does the DPDP Act apply to companies outside India?
Yes. The DPDP Act applies to processing of digital personal data outside India if it is connected to offering goods or services to individuals in India. A foreign company selling to Indian customers needs to comply even without an Indian office.
When do the DPDP Rules come fully into force?
The Rules were published on 13 November 2025. Consent manager provisions apply from 13 November 2026, and most Data Fiduciary obligations, including notices, security safeguards, breach notification and rights requests, apply from 13 May 2027.
What are the penalties under the DPDP Act?
The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to notify a breach or breaching obligations for children's data.
What is a Significant Data Fiduciary?
A Significant Data Fiduciary is an organisation the Central Government designates based on the volume and sensitivity of data, risk to individuals and wider public interest. SDFs must appoint an India-based DPO and an independent data auditor, and carry out periodic DPIAs and audits.
How fast must a personal data breach be reported?
The Rules require the Data Fiduciary to inform affected individuals without delay and to send the Data Protection Board a detailed report within 72 hours of becoming aware of the breach.
Can my GDPR programme be reused for the DPDP Act?
Partly. Data mapping, security controls and rights processes carry over well, but the DPDP Act has its own consent and notice rules, consent managers, parental consent for everyone under 18 and a grievance process. Our estimator reduces your score if you already have a GDPR-aligned programme.
Does Formiti have an office in India?
No. Formiti delivers the India DPDP service remotely from its global team, combining privacy specialists with the Privacy360 platform. We work in your time zone and can act as your designated DPDP contact.
Related guides
- India's DPDP Rules 2025: a new era of privacy and data trust
- Outsourced DPO service across 120+ jurisdictions
- Cross-border data transfer compliance in 2026
Start your DPDP programme now
Large programmes take up to 150 days. Starting early leaves time for vendor contracts and consent changes.