Confidential online consultations • Same-day slots available Call directly

August 17, 2026 · dixit.abhishek570@gmail.com

India’s DPDP Act 2023 – A Practical Guide to the 2025 Rules

What every business and individual should know about India's new Digital Personal Data Protection framework in 2026 - obligations, user rights, penalties, and a compliance checklist.

Digital shield over an outline of India, illustrating India's data protection law

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) has been on the statute book for a while, but 2025 was the year it started to bite. With the draft DPDP Rules, 2025 released for consultation and phased enforcement now underway, every business that touches Indian users — and every citizen who signs up for an app — needs to understand what has actually changed.

This post is a practical, plain-English walk-through of what the DPDP framework demands in 2026, aimed at founders, small businesses and individuals. It is not legal advice on any specific matter — if you are building a product that collects personal data, please talk to counsel.

What the DPDP Act actually is

The DPDP Act is India’s first horizontal, cross-sector data-protection statute. Unlike the earlier IT Act rules, it applies to any processing of digital personal data in India, and it also reaches out to processing outside India that offers goods or services to Indian users.

The Act sets up three roles you should know by name:

  • Data Principal — the individual whose data is being processed (i.e. you and me).
  • Data Fiduciary — the entity that decides why and how to process personal data (typically the company running the app or website).
  • Data Processor — a third party that processes data on behalf of a fiduciary (payroll SaaS, analytics vendor, cloud storage provider).

What the 2025 Rules add

The Rules turn the Act’s broad principles into operational obligations. A few of the changes worth flagging for anyone running a consumer product in India:

  • Clear-and-plain consent notices in English and every language listed in the Eighth Schedule of the Constitution — not buried in a 40-page privacy policy.
  • Verifiable parental consent for anyone under 18. Age-gating alone will not do; fiduciaries must have a defensible verification mechanism.
  • Breach reporting to the Data Protection Board and to affected principals, without undue delay.
  • Retention limits: personal data must be erased once the specified purpose is served and the retention period lapses.
  • Significant Data Fiduciary (SDF) designations for large processors, triggering DPIAs, audits and appointment of a Data Protection Officer.

Your rights as a Data Principal

If you are a user, the DPDP Act gives you a small but meaningful bundle of rights — and you can exercise them by writing to the company’s designated grievance officer:

  • Right to access a summary of your personal data being processed.
  • Right to correction, completion, updating and erasure.
  • Right to nominate someone who can exercise your rights if you die or become incapacitated.
  • Right to grievance redressal — escalating to the Data Protection Board if the company does not respond in a reasonable time.

A short compliance checklist for small businesses

If you run a startup, a D2C brand or even a professional practice that collects personal data (yes, that includes law firms), the following four-step checklist is a sensible starting point:

  1. Map your data. Write down every category of personal data you collect, why you collect it, how long you keep it and which third parties see it.
  2. Refresh your notice and consent flows. Move away from pre-ticked boxes and vague “we may use your data” language.
  3. Sign DPA-style contracts with processors. Every vendor that touches personal data on your behalf should be bound by contractual security, retention and breach-reporting obligations.
  4. Publish a grievance officer contact. A working email and a promised response window is non-negotiable.

Penalties are real

Financial penalties under the DPDP Act can go up to ₹250 crore per instance for the most serious defaults (failure to protect data, non-notification of breaches). Beyond fines, the reputational cost of a public order from the Data Protection Board — particularly for a consumer-facing brand — is likely the more painful outcome.

Bottom line

DPDP is not a “privacy policy update” project. It is an operations project. The businesses that treat it as a chance to clean up their data hygiene will actually come out stronger. The ones that treat it as a paper exercise will find themselves reacting to an enforcement notice they could have avoided.

Need help auditing your data flows, drafting a compliant privacy notice, or responding to a data principal request? Book a consultation and we can walk through your specific situation.