← Back to Blogs
August 25, 2026

The DPDP Act and DPDP Rules: What Every Organization Needs to Track

The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive personal data protection law, and its associated Rules translate the Act’s principles into concrete operational obligations. For any organization that collects, stores, or processes personal data of individuals in India, this is no longer a “future compliance item” — it is a present-day operating requirement.

What the Act Actually Covers

The DPDP Act applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to individuals in India. It introduces two key roles: the Data Fiduciary (the organization that decides why and how personal data is processed) and the Data Principal (the individual the data belongs to). A subset of fiduciaries that handle especially large volumes or particularly sensitive categories of data can be notified as Significant Data Fiduciaries (SDFs), who face additional obligations such as appointing a Data Protection Officer, conducting periodic Data Protection Impact Assessments, and independent data audits.

What the Rules Add

Where the Act sets out principles, the Rules set out mechanics: how consent notices should be presented, how consent managers are registered and operate, the process for reporting personal data breaches to the Data Protection Board of India (DPBI), the safeguards required before processing children’s data, and the retention and erasure timelines that apply once the purpose of processing is no longer being served.

  • Consent architecture: Notices must be clear, itemized, and available in English or any language listed in the Eighth Schedule of the Constitution — no more bundled, buried consent clauses.
  • Consent managers: A new registered intermediary category that lets individuals give, manage, and withdraw consent across multiple fiduciaries from a single interface.
  • Children’s data: Verifiable parental consent is required before processing a child’s data, and behavioural monitoring or targeted advertising directed at children is prohibited outright.
  • Breach notification: Personal data breaches must be reported to the Data Protection Board and, in many cases, to affected individuals — with defined content and timelines, not a vague “best effort” standard.
  • Cross-border transfer: The Act takes a negative-list approach — transfers are generally permitted except to countries the Central Government restricts, a marked shift from the more prescriptive localization debates of earlier drafts.
The organizations that struggle most are not the ones with no data protection program — they are the ones whose program was built for GDPR or a generic “privacy policy” template and never re-mapped against the DPDP Act’s specific consent, breach-notification, and grievance-redressal mechanics.

What to Do Now

Practically, this means running a data mapping exercise to know what personal data you hold and why, rewriting consent notices to be itemized and purpose-specific, standing up a documented breach-response workflow with clear internal ownership, and reviewing every third-party and cross-border data flow against the current restricted list. None of this is a one-time project — the DPDP framework is designed to evolve, and your compliance posture needs a named owner and a review cadence, not a policy document that gets filed away.

At ITPMS, our independent audit engagements are built specifically to pressure-test this: we review your data flows, consent mechanisms, and breach-response readiness against the DPDP Act and Rules as they stand today, with no software or licenses to sell — only findings you can act on.

Ready to protect your IT investment?

Stay ahead of compliance deadlines and procurement pitfalls. Let ITPMS be your independent shield.