Digital Personal Data Protection

Build trust into every data decision.

Move from legal obligation to operational confidence. We help organisations translate India’s DPDPA framework into practical controls, clear accountability and evidence that stands up to scrutiny.

DPDPA implementation timeline

The DPDPA Compliance Clock Is Running

000Days
00Hours
00Minutes
00Seconds

From 14 May 2027, organisations must be ready to meet India’s full digital personal data protection obligations.

40+ yearsof professional advisory experience
Governance-ledcontrols designed around accountability
Business-readypractical implementation, not paperwork alone
Ahmedabad-basedsupporting organisations across India

The essentials

What the DPDPA changes for your organisation

The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data. It places responsibility on organisations to use personal data lawfully, protect it and respect the rights of individuals.

01

Purpose and transparency

Use personal data for clear, lawful purposes, supported by understandable notices and valid consent or another permitted use.

02

Minimisation and accuracy

Limit processing to what is necessary, maintain accuracy and avoid retaining data after its purpose is exhausted.

03

Security safeguards

Apply reasonable technical and organisational measures to reduce personal-data breach risk.

04

Individual rights

Create workflows for access information, correction, updating, erasure, grievances and nomination.

05

Children’s data

Implement required parental consent and protective controls where applicable.

06

Accountability

Maintain evidence of decisions, responsibilities, vendor oversight and incident handling.

Phased commencement

The compliance window is open

The Government notified phased commencement in November 2025. Use the transition period to map data, close control gaps and operationalise repeatable processes.

From 14 November 2025

Institutional framework begins

Definitions, the Data Protection Board framework and specified enabling provisions commenced.

From 14 November 2026

Specified provisions commence

Specified consent-manager and related Board provisions are scheduled one year after publication.

From 14 May 2027

Core operational duties commence

Most substantive obligations are scheduled after eighteen months.

Review the official notification, DPDP Act and DPDP Rules, 2025.

How we help

From gap assessment to sustained compliance

Our Governance, Privacy & Compliance practice combines regulatory understanding, systems thinking and audit discipline.

Readiness and gap assessment

Evaluate current practices and prioritise a remediation roadmap.

Data inventory and flow mapping

Document data, purposes, systems, recipients, retention and owners.

Notices, consent and rights

Design notices, consent records, withdrawal paths and request procedures.

Policies and governance

Define roles, escalation, records, training and oversight.

Processor and vendor assurance

Assess third parties and strengthen contractual safeguards.

Breach and audit readiness

Create response playbooks, evidence packs and testing routines.

Quick readiness check

Compliance starts before the deadline.

If two or more questions are difficult to answer, a structured review can turn uncertainty into a prioritised action plan.

Five questions for management

  • Do we have an approved personal-data inventory?
  • Can we demonstrate when, how and why consent was obtained?
  • Are retention and deletion rules applied consistently?
  • Can employees and vendors escalate a breach?
  • Can leadership see evidence that controls work?
Discuss your readiness

Turn your transition period into an advantage.

Start with a focused conversation about your data environment and current controls.

Email our advisory team