Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

See how we implement it
Where most engagements startA gap assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upScore your DPDP compliance

Answer the gap assessment and get a prioritised remediation roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Home DPDP Act 2023

The DPDP Act 2023, implemented, not just explained.

Every Data Fiduciary in India now has a fixed date and a real penalty attached to it. This page gives you the working tools: score your gap against 52 statutory obligations, read what all 44 sections actually require of you, and take away a phased plan that lands before 13 May 2027.

44 sections mapped DPDP Rules 2025 IT Act interlock Nothing leaves your browser
Gap assessment

Where do you actually stand?

Fifty-two questions, each tied to a section of the Act or a rule you can be penalised under, including the Consent Manager and enforcement-readiness themes below. Answer honestly, mark anything that does not apply to you, and the score adjusts. Your answers stay in this browser and are never transmitted.

Every claim carries a citationEach question, penalty and duty on this page names the section or rule it comes from, so you can verify it against the bare Act.
Your answers never leave the browserThe assessment, calculator and board pack run entirely on your device. Nothing is uploaded, stored on our servers or shared.
Built to be handed overOutputs are structured for a board paper or an auditor, not a sales deck. Export to CSV or print to PDF at any point.
Governance and accountability0/4
The board or senior management has formally accepted accountability for DPDP compliance, with a named owner.
Hook: S. 8(1) and S. 8(10)
You maintain a current record of every purpose for which personal data is processed.
Hook: S. 4 and S. 5
Compliance with the Act is reviewed on a defined cycle, with findings tracked to closure.
Hook: S. 8(4)
Contracts with every processor impose the Acts obligations in writing.
Hook: S. 8(2)
Notice and consent0/6
Every consent request is accompanied by an itemised notice in plain language.
Hook: S. 5(1) and Rule 3
The notice is available in English and the Eighth Schedule languages the Data Principal may choose.
Hook: S. 5(3)
Consent is free, specific, informed, unconditional and unambiguous, with a clear affirmative action.
Hook: S. 6(1)
Withdrawing consent is as easy as giving it, and withdrawal stops processing.
Hook: S. 6(4) and S. 6(6)
Consent given before commencement has been refreshed by a grandfathering notice.
Hook: S. 5(2)
Where you rely on legitimate uses rather than consent, each instance is documented and justified.
Hook: S. 7
Data Principal rights0/5
Data Principals can obtain a summary of their personal data and the processing activities.
Hook: S. 11
Correction, completion, updating and erasure requests are actioned and evidenced.
Hook: S. 12
A named grievance redressal mechanism is published and responds inside the published period.
Hook: S. 13 and Rule 14
Access, correction, updating and erasure requests are answered within ninety days.
Hook: Rule 13
Data Principals can nominate another individual to exercise their rights.
Hook: S. 14
Security safeguards0/5
Personal data is encrypted, obfuscated, masked or protected by virtual tokens.
Hook: Rule 6(1)(a)
Access control is enforced on every system holding personal data.
Hook: Rule 6(1)(b)
Logs, monitoring and review are retained for one year to detect and investigate unauthorised access.
Hook: Rule 6(1)(c)
Backups, continuity measures and integrity checks are tested, not just documented.
Hook: Rule 6(1)(d)
Processor contracts impose the same safeguards down the supply chain.
Hook: Rule 6(1)(e)
Breach management0/5
A breach response plan names the decision makers and runs to a fixed clock.
Hook: S. 8(6) and Rule 7
Affected Data Principals are notified without delay, in plain language.
Hook: Rule 7(1)
The Data Protection Board receives a detailed report within seventy-two hours.
Hook: Rule 7(2)
The CERT-In six hour reporting obligation is run alongside the DPDP clock.
Hook: IT Act S. 70B
Breach drills are run and the lessons feed back into controls.
Hook: S. 8(5)
Retention and erasure0/4
A retention schedule ties every category of personal data to a defined period.
Hook: S. 8(7) and Rule 8
Personal data is erased once the purpose is no longer being served.
Hook: S. 8(7)
Where Schedule III applies, the three year limit is enforced automatically.
Hook: Rule 8(1) and Schedule III
Data Principals are told at least forty-eight hours before erasure.
Hook: Rule 8(3)
Children and persons with disability0/4
Verifiable parental consent is obtained before processing a childs personal data.
Hook: S. 9(1) and Rule 10
Tracking, behavioural monitoring and targeted advertising to children are switched off.
Hook: S. 9(3)
Age is determined reliably, not self-declared without checks.
Hook: Rule 10(1)
Consent of a lawful guardian is obtained for persons with disability.
Hook: S. 9(2)
Significant Data Fiduciary duties0/5
You have assessed whether the Significant Data Fiduciary thresholds apply to you.
Hook: S. 10(1)
A Data Protection Officer based in India is appointed and published.
Hook: S. 10(2)(a)
An independent data auditor performs the annual audit.
Hook: S. 10(2)(b)
An annual Data Protection Impact Assessment is completed.
Hook: S. 10(2)(c) and Rule 12
Algorithmic software is diligence-checked for risk to Data Principals.
Hook: Rule 12(3)
Transfers and third parties0/3
Cross-border transfers are mapped and checked against restrictions notified by the Central Government.
Hook: S. 16
Every processor and sub-processor is inventoried with a lawful basis for sharing.
Hook: S. 8(2)
Sectoral localisation requirements that bite harder than the Act are identified and met.
Hook: Rule 12(4)
13 November 2026 · Rule 4

Consent Managers, and whether Rule 4 lands on you.

Rule 4 is the first substantive obligation to commence, six months ahead of everything else. It is also the one most organisations wrongly assume does not apply to them.

What a Consent Manager is

A registered intermediary through which a Data Principal can give, review, manage and withdraw consent in one place, defined at Section 2(g) and governed by Rule 4.

Why 13 November 2026 matters

Rule 4 is the only rule commencing on that date. Registration and the obligations attached to it begin then, a full six months before the rest of the Rules bite.

The two positions you can be in

Either you become a Consent Manager, which is a regulated activity with a net worth test, or you interact with one. Most organisations are in the second position and still have work to do.

Assess your position

Consent Manager readiness

0%
0 of 6 answered
You have determined whether you will rely on a Consent Manager at all, and recorded that decision.
Hook: Rule 4 and S. 2(g)
If you intend to act as a Consent Manager, you meet the incorporation and net worth conditions in Part A of the First Schedule.
Hook: First Schedule, Part A
Any Consent Manager you engage is, or has applied to be, registered with the Data Protection Board.
Hook: Rule 4(1)
Your consent records can be handed to a Consent Manager in a readable, machine-usable form.
Hook: First Schedule, Part B
Your systems can accept a withdrawal of consent routed through a Consent Manager and act on it.
Hook: S. 6(4) to (6)
Contracts with any Consent Manager cover duties, audit rights and breach obligations.
Hook: Rule 4(2)

These answers count towards your overall readiness score above and stay in your browser.

How Vedhacon helps

From decision to a working consent pipeline.

Decide which side of Rule 4 you are on

A short structured assessment of your business model against the First Schedule, ending in a written, defensible decision your board can sign.

Registration support if you are becoming one

We prepare the Board application, the net worth evidence, the technical description and the governance framework the First Schedule asks for.

Consent records fit to hand over

We restructure your consent store so it can be read, exported and reconciled by a Consent Manager, rather than trapped in application logs.

Withdrawal that actually propagates

We map every downstream system a withdrawal must reach, then build and test the propagation so withdrawal is as easy as giving consent, as Section 6(4) requires.

Contracts and audit rights

Template and negotiate the Consent Manager agreement, covering duties, audit access, breach reporting and exit.

A dry run before the date

We run a simulated registration and a simulated withdrawal in the quarter before 13 November 2026, so the first live one is not the first one.

The quiet trap. Rule 4 commencing early is widely read as only affecting firms who want to be Consent Managers. It does not. If any consent you rely on will be routed through a Consent Manager, your systems must be able to receive and honour that traffic from the same date, and your contracts must already be in place.
13 May 2027 · Full enforceability

Full enforceability, and how ready you actually are.

On 13 May 2027 the remaining Rules apply and the Act becomes enforceable in full. The question is not whether you know the law, but whether you can evidence compliance with it on that date.

What switches on

Rules 3 and 5 to 16, plus 22 and 23. Notice, Consent Manager duties, State processing, security safeguards, breach intimation, erasure, contact publication, children, exemptions, SDF duties, rights and cross-border conditions.

What the Board can do from then

Inquire into a complaint and impose penalties up to Rs 250 crore per contravention. Section 33(2) makes documented, prompt mitigation a real mitigating factor.

What good looks like by then

Not a policy folder. A running control environment with evidence, an owner per obligation, and a tested breach runbook on both the six-hour and seventy-two hour clocks.

Assess your position

Enforcement readiness

0%
0 of 5 answered
You have a dated plan that reaches full compliance before 13 May 2027, with named owners per workstream.
Hook: Rule 1(4)
A data discovery exercise has been completed, so you know every system holding personal data.
Hook: S. 8(1)
Budget for the DPDP programme is approved and ring-fenced through to May 2027.
Hook: S. 8(1)
You re-test readiness at least quarterly rather than assuming the first assessment still holds.
Hook: S. 8(10)
Evidence of compliance is being collected as you go, in a form an auditor or the Board would accept.
Hook: S. 8(10) and Rule 12

These answers count towards your overall readiness score above and stay in your browser.

How Vedhacon helps

Carrying the programme, not just reviewing it.

A posture baseline you can trust

We validate your self-assessment with evidence sampling, because the gap between believed and demonstrable compliance is where penalties live.

A dated plan to 13 May 2027

Workstreams, owners, dependencies and budget, working backwards from the deadline rather than forwards from today.

We build, not just advise

Notices, consent flows, RoPA, retention schedules, DPIAs, breach runbooks and the grievance mechanism, delivered as working artefacts.

Evidence collected as you go

Every control ships with the evidence an auditor or the Board would ask for, captured at the time rather than reconstructed later.

Quarterly re-test

Readiness decays. We re-score you each quarter and reopen only what moved, so the programme stays honest.

Board-ready reporting

A one-page position your board and, if needed, the Data Protection Board can read without translation.

Counting backwards. A realistic DPDP programme runs six to seven months of build before it reaches a steady state, and discovery alone often takes eight weeks in a mid-sized estate. From 13 May 2027 that puts the honest start line in the second half of 2026. Organisations starting in 2027 will be compressing work that does not compress.
Interactive tool
Penalty exposure

What a bad day actually costs you.

The Schedule to the Act sets a separate ceiling for each category of failure, and the Board can impose them for the same incident. Tick what could realistically go wrong today and see the statutory ceiling you are carrying, with the provision cited for every line.

Select the failures you could not confidently rule out

Figures are the statutory maximum per instance. The Board sets the actual amount under S. 33(2), weighing the nature, gravity and duration of the breach, whether you mitigated it, and your conduct afterwards. Repeat instances can be assessed separately.

That number is not fixed. Every figure above is a ceiling the Board may impose under Section 33(2), and it weighs the nature of the breach, the harm caused and what you did to mitigate it. A documented programme is the single biggest lever you control.
See how to bring it down
Interactive tool
Significant Data Fiduciary

Are you a Significant Data Fiduciary?

Significant Data Fiduciary status is not something you opt into. The Central Government notifies a Data Fiduciary, or a class of them, under S. 10(1) on the factors below. If you are designated, four additional duties attach and a separate ₹150 crore penalty category opens. Answer honestly — this is the same screen we run in a scoping call.

This is an indicator, not a designation. Only the Central Government notifies a Significant Data Fiduciary under Section 10(1). Use this to decide whether to prepare for those duties now, because a DPO, an independent auditor and an annual DPIA cannot be stood up in a fortnight.
Talk through your position
What the law requires

All 44 sections, the Rules, and the IT Act that still applies.

Most summaries stop at the headline duties. This is the full instrument, section by section, with what each one demands of you on the left and what we build for you on the right. Search it, filter it by chapter, and switch between the three instruments.

Showing 44 of 44
S. 1
Short title and commencement

The Act commences in phases by Government notification; different provisions may start on different dates.

Ch 1 · Preliminary
What we deliverCommencement tracker mapped to your programme plan, so no obligation is missed as each phase is notified.
S. 2
Definitions

Defines Data Principal, Data Fiduciary, Data Processor, personal data, processing, consent manager and more.

Ch 1 · Preliminary
What we deliverDefinition mapping workshop that classifies your entities and datasets against every defined term.
S. 3
Application of the Act

Applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to Data Principals in India.

Ch 1 · Preliminary
What we deliverApplicability and extraterritoriality opinion, with a documented scoping decision you can defend.
S. 4
Grounds for processing personal data

Processing is lawful only on consent or a legitimate use. No other ground exists.

Ch 2 · Obligations of Data Fiduciary
What we deliverLawful basis register for every processing activity, with evidence for each determination.
S. 5
Notice

A clear, itemised notice must accompany or precede the consent request, in English or any Eighth Schedule language.

Ch 2 · Obligations of Data Fiduciary
What we deliverPlain-language notice suite, versioned, with multilingual variants and a change log.
S. 6
Consent

Consent must be free, specific, informed, unconditional, unambiguous, with clear affirmative action, and as easy to withdraw as to give.

Ch 2 · Obligations of Data Fiduciary
What we deliverConsent architecture and withdrawal flows, wired to downstream systems so withdrawal actually stops processing.
S. 7
Certain legitimate uses

Sets out the specific legitimate uses, including voluntary provision, State functions, medical emergency and employment purposes.

Ch 2 · Obligations of Data Fiduciary
What we deliverLegitimate use assessment templates with documented necessity and proportionality reasoning.
S. 8
General obligations of Data Fiduciary

Accountability for processing by processors, data accuracy, security safeguards, breach handling, erasure and grievance redressal.

Ch 2 · Obligations of Data Fiduciary
What we deliverAccountability framework: RACI, processor oversight, retention schedule and grievance workflow.
S. 9
Processing of personal data of children

Verifiable parental consent required; no tracking, behavioural monitoring or targeted advertising directed at children.

Ch 2 · Obligations of Data Fiduciary
What we deliverAge assurance and parental consent design, plus a tracking and advertising control review.
S. 10
Additional obligations of Significant Data Fiduciary

Appoint a DPO in India, appoint an independent data auditor, conduct periodic DPIAs and audits.

Ch 2 · Obligations of Data Fiduciary
What we deliverDPO mandate, independent audit programme and a repeatable DPIA methodology with evidence retention.
S. 11
Right to access information about personal data

Data Principals may obtain a summary of personal data processed and the identities of recipients.

Ch 3 · Rights and Duties of Data Principal
What we deliverAccess request workflow with system-of-record discovery and a defensible response pack.
S. 12
Right to correction and erasure of personal data

Right to correction, completion, updating and erasure of personal data.

Ch 3 · Rights and Duties of Data Principal
What we deliverCorrection and erasure runbooks that propagate across primary, backup and downstream systems.
S. 13
Right of grievance redressal

Data Fiduciary must provide a readily available grievance mechanism and respond within a prescribed period.

Ch 3 · Rights and Duties of Data Principal
What we deliverGrievance intake, SLA tracking and escalation path, with an auditable response register.
S. 14
Right to nominate

Data Principals may nominate another individual to exercise rights in the event of death or incapacity.

Ch 3 · Rights and Duties of Data Principal
What we deliverNomination capture and verification process built into your rights portal.
S. 15
Duties of Data Principal

Data Principals must not impersonate, suppress information or register false grievances.

Ch 3 · Rights and Duties of Data Principal
What we deliverDuty notices embedded in your rights portal, with abuse handling guidance.
S. 16
Processing of personal data outside India

The Central Government may restrict transfer of personal data to notified territories.

Ch 4 · Special provisions
What we deliverTransfer mapping, restricted-territory monitoring and contractual safeguards for each route.
S. 17
Exemptions

Sets out exemptions including enforcement of legal rights, judicial functions, and processing of non-resident data under foreign contract.

Ch 4 · Special provisions
What we deliverExemption applicability assessment, documented so reliance can be evidenced on inspection.
S. 18
Power of Central Government to amend Schedule

The Government may amend the Schedule of penalties, subject to limits.

Ch 4 · Special provisions
What we deliverPenalty exposure model refreshed whenever the Schedule changes.
S. 19
Establishment of Board

Establishes the Data Protection Board of India.

Ch 5 · Data Protection Board of India
What we deliverRegulator engagement briefing so your team knows who decides what.
S. 20
Composition and qualifications for appointment of Chairperson and Members

Composition, qualifications and expertise requirements for the Board.

Ch 5 · Data Protection Board of India
What we deliverIncluded in the regulator engagement briefing.
S. 21
Salary, allowances payable to and term of office

Terms of service for Chairperson and Members.

Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 22
Disqualifications for appointment and continuation

Grounds on which a Member may be removed.

Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 23
Resignation by Members and filling of vacancy

Resignation and vacancy procedure.

Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 24
Proceedings of Board

Board proceedings and validity of acts.

Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 25
Officers and employees of Board

Board may appoint officers and employees.

Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 26
Members and officers to be public servants

Members and officers deemed public servants.

Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 27
Powers and functions of Board

The Board directs remedial measures, inquires into breaches and imposes penalties.

Ch 6 · Powers, functions and procedure
What we deliverRegulator-ready evidence pack so you can answer a Board inquiry quickly and completely.
S. 28
Procedure to be followed by Board

Board procedure on complaints, inquiry and natural justice; functions as a digital office.

Ch 6 · Powers, functions and procedure
What we deliverInquiry response playbook with named owners and evidence retrieval steps.
S. 29
Appeal to Appellate Tribunal

Appeals against Board orders lie to the TDSAT within 60 days.

Ch 7 · Appeal and alternate dispute resolution
What we deliverAppeal readiness checklist and document retention rules for the limitation window.
S. 30
Orders passed by Appellate Tribunal to be executable as decree

Tribunal orders execute as a civil court decree.

Ch 7 · Appeal and alternate dispute resolution
What we deliverReference material in your compliance library.
S. 31
Alternate dispute resolution

The Board may refer a complaint for mediation or other dispute resolution.

Ch 7 · Appeal and alternate dispute resolution
What we deliverMediation preparation guidance within the grievance workflow.
S. 32
Voluntary undertaking

A person may give a voluntary undertaking to the Board, which bars further proceedings on that matter.

Ch 7 · Appeal and alternate dispute resolution
What we deliverVoluntary undertaking strategy and drafting support when remediation is the better route.
S. 33
Penalties

Penalties up to 250 crore rupees per the Schedule, determined after inquiry.

Ch 8 · Penalties and adjudication
What we deliverQuantified penalty exposure model by processing activity, used to sequence remediation.
S. 34
Crediting of sums realised to Consolidated Fund of India

Penalties credited to the Consolidated Fund.

Ch 8 · Penalties and adjudication
What we deliverReference material in your compliance library.
S. 35
Protection of action taken in good faith

Protects good-faith acts of the Board and Government.

Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 36
Power to call for information

The Government may require information from the Board or any Data Fiduciary.

Ch 9 · Miscellaneous
What we deliverInformation request handling procedure with a single accountable owner.
S. 37
Power of Central Government to issue directions to block

Blocking of access on repeated penalty, in the interests of the general public.

Ch 9 · Miscellaneous
What we deliverEscalation and business continuity planning for a blocking scenario.
S. 38
Consistency with other laws

The Act is in addition to and not in derogation of other laws.

Ch 9 · Miscellaneous
What we deliverConflict-of-laws mapping across DPDP, IT Act, sectoral regulators and contracts.
S. 39
Bar of jurisdiction

No civil court may hear matters the Board is empowered to decide.

Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 40
Power to make rules

Empowers the Government to make rules, giving effect to the DPDP Rules.

Ch 9 · Miscellaneous
What we deliverRules change monitoring wired into your regulatory tracker.
S. 41
Laying of rules and notifications before Parliament

Rules must be laid before Parliament.

Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 42
Power to remove difficulties

Government may remove difficulties within three years of commencement.

Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 43
Amendment to Information Technology Act, 2000

Omits Section 43A of the IT Act.

Ch 9 · Miscellaneous
What we deliverGap remediation where your contracts still cite Section 43A and reasonable security practices.
S. 44
Amendment to other Acts

Amends the Telecom Regulatory Authority of India Act and the Right to Information Act.

Ch 9 · Miscellaneous
What we deliverRTI interface review for public authorities and RTI-exposed vendors.
No obligation matches that search. Try a broader term.
Implementation roadmap

A phased programme that lands before the deadline.

Roughly twenty-eight weeks of build, then a steady state. Start now and you finish with room to spare. Start in 2027 and you are negotiating with the Board rather than preparing for it.

1

Discover

Weeks 1 to 4

We find the personal data you hold and the duties it attracts, so the rest of the programme is scoped on evidence rather than guesswork.

  • Data discovery and mapping across systems and vendors
  • Records of processing and purpose register
  • Gap assessment against all 44 sections
  • Significant Data Fiduciary threshold analysis
2

Design

Weeks 5 to 12

We write the controls that the Act and the Rules actually ask for, in language your business and your auditor can both use.

  • Notice and consent architecture, including grandfathering
  • Retention schedule and erasure logic
  • Policy suite, roles and RACI
  • Processor contract clauses and vendor due diligence
3

Implement

Weeks 13 to 28

Controls stop being documents. We build the mechanisms, wire them into your systems, and prove they work.

  • Consent capture and withdrawal journeys
  • Rights fulfilment workflow inside ninety days
  • Security safeguards under Rule 6, including one year logging
  • Breach runbook on the 72-hour and 6-hour clocks
4

Assure

Ongoing

Compliance is a state you maintain, not a project you finish. We keep the evidence current and the Board answerable.

  • Annual DPIA and independent audit support
  • DPO as a service, India based
  • Breach drills and control testing
  • Board reporting pack and regulatory change watch
Interactive tool
Board reporting

Walk into the board meeting with the paper already written.

Once you have run the gap assessment above, this builds a one-page summary in the language a board actually responds to: where you stand, what it exposes you to, what happens next and by when. It prints clean to PDF. Everything is generated in this browser from your own answers.

Run the gap assessment first. Your board summary builds itself as you answer.

How we work

Three ways to engage, priced to the scope you need.

We scope on the size of your estate and the duties that actually attach to you, not on headcount bands. Tell us where you are and we will come back with a fixed proposal.

Assess

Startups and growing teams

A fixed-scope engagement that tells you exactly where you stand and what it will take. You get a defensible gap report rather than a sales pitch.

  • Gap assessment against all 44 sections
  • Data map and purpose register
  • Prioritised remediation backlog
  • Board-ready findings pack
Most chosen

Implement

Mid-size Data Fiduciaries

The full build. We design the controls, put them into your systems and leave you with evidence that stands up to an auditor or the Board.

  • Everything in Assess
  • Notice, consent and rights journeys
  • Security safeguards and breach runbook
  • Processor contracts and vendor diligence
  • Training for the people who operate it

Sustain

Significant Data Fiduciaries

Named DPO capacity, annual DPIA and audit, and someone accountable when the Board writes to you. For organisations where privacy failure is a board-level risk.

  • Everything in Implement
  • DPO as a service, India based
  • Annual DPIA and independent audit support
  • Breach response retainer and drills
  • Quarterly board reporting
Practitioner led

Built by people who run governance, risk and compliance for a living, not by a template vendor.

Law plus engineering

We write the policy and then wire the control, so the two do not drift apart six months later.

Cross jurisdiction

If you also carry GDPR, CCPA or ISO obligations, we map them once rather than running parallel programmes.

Evidence first

Every control ships with the artefact that proves it, ready for an auditor or the Data Protection Board.

FAQ

The questions we get asked most.

Who is a Data Fiduciary under the DPDP Act 2023?

Any person who alone or with others determines the purpose and means of processing digital personal data. It is the Indian equivalent of a controller. If you decide why and how personal data is processed, you are a Data Fiduciary and the duties in Sections 4 to 10 apply to you directly.

When does the DPDP Act 2023 actually become enforceable?

The DPDP Rules 2025 were notified on 13 November 2025 with a tiered commencement. Rules 1, 2 and 17 to 21 applied immediately. Rule 4, covering Consent Manager registration, applies from 13 November 2026. The substantive obligations in Rules 3 and 5 to 16, along with Rules 22 and 23, apply from 13 May 2027.

What are the penalties for non-compliance?

The Schedule to the Act sets penalties up to Rs 250 crore for failure to maintain reasonable security safeguards, up to Rs 200 crore for failing to notify a breach and for breach of childrens data obligations, up to Rs 150 crore for breach of Significant Data Fiduciary duties, and up to Rs 50 crore for any other contravention.

How long do we have to report a personal data breach?

Affected Data Principals must be informed without delay in plain language, and the Data Protection Board must be notified without delay with a detailed report inside seventy-two hours. Separately, CERT-In directions require reporting of specified incidents within six hours, so most organisations run both clocks together.

Does the DPDP Act replace the IT Act and the SPDI Rules?

Section 44(2) omits Section 43A of the IT Act, which carried the SPDI Rules. The rest of the IT Act 2000 stays in force, including Section 66E on privacy violation, Section 69 and 69A powers, Section 70B for CERT-In, Section 72A on disclosure in breach of contract, and Section 79 intermediary due diligence.

What makes an organisation a Significant Data Fiduciary?

The Central Government notifies Significant Data Fiduciaries based on volume and sensitivity of personal data, risk to Data Principals, risk to electoral democracy, security of the State and public order. Once notified, you must appoint an India-based Data Protection Officer, commission an independent data auditor, and carry out an annual Data Protection Impact Assessment.

How does this assessment score our compliance?

Each of the 41 questions maps to a statutory hook in the Act or the Rules. You answer Yes, Partly or No, and can mark a question not applicable. Yes scores two points, Partly scores one, No scores zero, and not applicable is removed from the denominator, so the percentage always reflects only the obligations that genuinely apply to you.

Why Vedhacon

You carry the liability. We carry the work.

The Act makes the Data Fiduciary accountable, and nothing we do changes that. What we can change is how much of it you have to hold in your own head, and how exposed you are on the day someone asks you to prove it.

A named senior owner, not a rotating pool

One accountable consultant leads your programme end to end. You will know who is answering when the Board writes, and so will they.

We do the work, not just the report

Most advisers hand you a gap list and leave. We write the notices, build the consent flows, stand up the RoPA and test the breach runbook with your teams.

Fixed scope and fixed fee

Priced per milestone before we start. No hourly drift, no surprise variation once the discovery finds more than expected.

Deadline-anchored delivery

Every plan is built backwards from 13 May 2027 with slack designed in, so a slipped dependency does not become a missed statutory date.

Evidence by default

Each control ships with its proof attached, in the form Section 33(2) and Rule 12 would expect, so mitigation is demonstrable rather than asserted.

We stay after go-live

Readiness decays as systems change. Quarterly re-scoring and an on-call line mean you are not alone the first time something goes wrong.

What changes for you

What you get to stop worrying about.

You stop tracking the deadline

We hold the plan, the dependencies and the calendar. You get a one-page position when it changes, not a spreadsheet to police.

One place for every DPDP question

Your team stops guessing. Ambiguous questions come to us and come back with a written, reasoned answer you can file as evidence.

Someone senior answers when it goes wrong

If a breach lands at 2am, the runbook is already written, rehearsed and owned. The six-hour clock is not the moment to start reading Rule 7.

What we bring to it
Practitioner-led

Built and run by working governance, risk and compliance practitioners, not generalist consultants reading the Act for the first time.

Cross-jurisdiction fluency

GDPR, CCPA and CPRA, PIPL and the DPDP Act side by side, so a global estate gets one coherent control set instead of four conflicting ones.

Full IT Act interlock

CERT-In six-hour reporting, Section 70B log retention and intermediary due diligence handled together with DPDP, because they did not go away.

Education as well as delivery

The GRC Academy and community exist so your team can eventually run this without us. That is the intended outcome.

What we will not claim. No consultant can make you compliant on paper alone, and nobody can indemnify you out of a statutory duty. What we can do is make sure that when the Data Protection Board asks what you did and when you did it, the answer already exists in writing.
Talk to us

Tell us where you are. We will tell you what it takes.

If you have run the assessment above, mention your score and we will open the conversation from there. No obligation, and no answers leave your browser unless you choose to include them.

Please tell us your name.
Please enter a valid work email.
Please tell us your organisation.

We use what you send only to answer you. Read our privacy notice.