DPDP Act 2023 · IT Act 2000 · CERT-In

Compliance you can evidence.

India's data protection regime stops being theoretical on 14 May 2027. We map where you stand, close the gaps, and leave you with the proof.

14 Nov 2025

Rules notified

The DPDP Rules 2025 were notified. The Act commenced and the Data Protection Board was established.

Done
14 Nov 2026

Consent Managers

Consent Manager registration opens, and the Board gains power to investigate registration breaches and impose penalties.

14 May 2027

Everything else

Notice and consent, breach reporting, security safeguards, children's data, Significant Data Fiduciary duties, Data Principal rights and cross-border transfer rules all take effect.

Source: Digital Personal Data Protection Rules, 2025, notified by MeitY on 14 November 2025. Section 44(2) of the DPDP Act — which omits section 43A of the IT Act 2000 and with it the SPDI Rules 2011 — commences 13 May 2027.

What non-compliance costs

The Schedule to the DPDP Act.

These are statutory maximums, imposed by the Data Protection Board after an inquiry. They are penalties on the organisation, not on individuals.

Maximum monetary penalties under the Schedule to the Digital Personal Data Protection Act, 2023
BreachProvisionMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breachs. 8(5)₹250 crore
Failure to notify the Board or affected individuals of a personal data breachs. 8(6)₹200 crore
Breach of the additional obligations relating to children's datas. 9₹200 crore
Breach of the additional obligations of a Significant Data Fiduciarys. 10₹150 crore
Breach of any other provision of the Act or the Rulesresidual₹50 crore
Breach of a voluntary undertaking accepted by the Boards. 32Up to the amount for the underlying breach
Breach of a Data Principal's own dutiess. 15₹10,000

Still live today

IT Act 2000 and CERT-In.

The DPDP Act does not switch these off. Section 43A and the SPDI Rules govern personal data until 13 May 2027, and the CERT-In Directions apply right now.

Obligations and penalties under the IT Act 2000 and the CERT-In Directions 2022
ObligationProvisionExposure
Negligent failure to protect sensitive personal data, causing wrongful loss or gainIT Act s. 43ACompensation — no statutory ceiling
Disclosing personal information in breach of a lawful contractIT Act s. 72AUp to 3 years' imprisonment and/or ₹5 lakh
Failure to comply with a CERT-In directionIT Act s. 70B(7)Up to 1 year's imprisonment and/or ₹1 lakh
Reporting a cyber incident later than six hours after noticing itCERT-In Directions, 28 Apr 2022Penalised under s. 70B(7)
Failure to retain 180 days of ICT logs within IndiaCERT-In Directions, 28 Apr 2022Penalised under s. 70B(7)
VPN and cloud providers: customer records for 5 years after de-registrationCERT-In Directions, 28 Apr 2022Penalised under s. 70B(7)

Figures are the statutory maximums as written in the Schedule to the DPDP Act 2023 and the cited sections of the IT Act 2000. This page is a summary for orientation, not legal advice — the Board sets the actual penalty case by case, having regard to the factors in section 33(2).

How we close it

Four moves, in order.

01

Find the personal data

Data mapping across apps, databases, logs, backups and third parties. You cannot protect what nobody has written down, and section 8(5) is judged on what you actually hold.

02

Test the safeguards

Penetration testing and configuration review against the same data. The output is evidence that the safeguards were reasonable — which is the test the Board applies after a breach, not before.

03

Rehearse the six hours

A breach runbook that fits the CERT-In six-hour window and the separate DPDP duty to notify the Board and the affected individuals. Rehearsed, not filed.

04

Leave the paper trail

180 days of ICT logs held in India, clocks synchronised to NIC or NPL, consent records, and a gap register with owners and dates. Compliance is what you can show afterwards.

Scope

It probably applies to you.

The DPDP Act covers digital personal data processed in India, and personal data processed outside India where goods or services are offered to people in India. There is no revenue threshold and no employee-count exemption.

Applies to
Any organisation deciding the purpose and means of processing digital personal data — the Act calls you a Data Fiduciary
Also applies to
Processing outside India, where it relates to offering goods or services to people inside India
Your customers' data
Engaging a processor does not transfer liability. The Data Fiduciary stays answerable for the processor's failures
Significant Data Fiduciary
Government may designate you by volume and sensitivity of data, adding audit, DPIA and India-resident DPO duties under s. 10
Breach notice
Owed to both the Data Protection Board and every affected individual — the s. 8(6) duty is separate from CERT-In's
CERT-In, today
Six-hour incident reporting and 180-day in-India log retention are already in force and independent of the DPDP timeline

Eight months out

Start with the gap assessment.

We will tell you what you hold, where it leaks, and what the Board would ask for. If you are already in good shape, we will say so.