Purpose and transparency
Use personal data for clear, lawful purposes, supported by understandable notices and valid consent or another permitted use.
Digital Personal Data Protection
Move from legal obligation to operational confidence. We help organisations translate India’s DPDPA framework into practical controls, clear accountability and evidence that stands up to scrutiny.
DPDPA implementation timeline
From 14 May 2027, organisations must be ready to meet India’s full digital personal data protection obligations.
The essentials
The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data. It places responsibility on organisations to use personal data lawfully, protect it and respect the rights of individuals.
Use personal data for clear, lawful purposes, supported by understandable notices and valid consent or another permitted use.
Limit processing to what is necessary, maintain accuracy and avoid retaining data after its purpose is exhausted.
Apply reasonable technical and organisational measures to reduce personal-data breach risk.
Create workflows for access information, correction, updating, erasure, grievances and nomination.
Implement required parental consent and protective controls where applicable.
Maintain evidence of decisions, responsibilities, vendor oversight and incident handling.
Phased commencement
The Government notified phased commencement in November 2025. Use the transition period to map data, close control gaps and operationalise repeatable processes.
Definitions, the Data Protection Board framework and specified enabling provisions commenced.
Specified consent-manager and related Board provisions are scheduled one year after publication.
Most substantive obligations are scheduled after eighteen months.
Review the official notification, DPDP Act and DPDP Rules, 2025.
How we help
Our Governance, Privacy & Compliance practice combines regulatory understanding, systems thinking and audit discipline.
Evaluate current practices and prioritise a remediation roadmap.
Document data, purposes, systems, recipients, retention and owners.
Design notices, consent records, withdrawal paths and request procedures.
Define roles, escalation, records, training and oversight.
Assess third parties and strengthen contractual safeguards.
Create response playbooks, evidence packs and testing routines.
Quick readiness check
If two or more questions are difficult to answer, a structured review can turn uncertainty into a prioritised action plan.
Start with a focused conversation about your data environment and current controls.