As India targets a $1 trillion digital economy by 2030, the Digital Personal Data Protection (DPDP) Act, 2023, along with the DPDP Rules, 2025, introduces a fundamental shift in legal liability for corporate India. The regulatory landscape transitions from simple policy compliance to strict statutory fiduciary accountability.
With the principal operational rules taking full effect on 13 May 2027, boardrooms face immediate legal and operational obligations.
Managing compliance requires aligning corporate workflows with statutory deadlines:
Nov 13, 2025 | Initial administrative and framework rules commenced.
Nov 13, 2026 | Rule 4 (Consent Manager Framework) goes live.
May 13, 2027 | Become fully enforceable.
Treating May 13, 2027 as a deferred deadline exposes companies to significant regulatory risk. Conducting enterprise-wide data mapping, amending vendor contracts, restructuring notice procedures, and building defensible audit trails requires extended lead time.
The DPDP framework replaces broad, bundled agreements with specific, statutory consent obligations.
The Rule 3 notice mandate: Before requesting consent, a Data Fiduciary must issue an itemised, standalone notice detailing the exact categories of personal data collected and their specific processing purposes. Under the Eighth Schedule mandate, this notice must be accessible in English and any of the 22 scheduled Indian languages.
The legacy data requirement: Section 6 mandates clear, affirmative action. For legacy datasets collected prior to the Act, Data Fiduciaries must issue retrospective notices to existing Data Principals before the operational deadline.
The Consent Manager intermediary: Under Rule 4, Data Principals may grant, review, or withdraw consent using Board-registered Consent Managers—statutory intermediaries acting as agents for the individual.
Data Principal <---> Consent Manager Intermediary <---> Data Fiduciary
The DPDP Schedule establishes statutory financial penalties for non-compliance:
Failure to implement reasonable security safeguards (Section 8(5)): Statutory maximum up to ₹250 crore.
Failure to notify the Board and affected principals of a breach (Section 8(6)): Statutory maximum up to ₹200 crore.
Contraventions relating to children’s personal data (Section 9): Statutory maximum up to ₹200 crore.
Breach of Significant Data Fiduciary (SDF) duties (Section 10): Statutory maximum up to ₹150 crore.
These statutory ceilings are evaluated under the Data Protection Board's adjudicatory discretion, taking into account mitigating factors and contemporaneous evidence. Protecting the enterprise requires documented risk assessments, continuous system logging under Rule 6, and tested breach-notification playbooks.
About the author: Bhumi Sharma is an Associate at Foresight Law Offices India.
Disclaimer: The opinions expressed in this article are those of the author(s). The opinions presented do not necessarily reflect the views of Bar & Bench.
If you would like your Deals, Columns, Press Releases to be published on Bar & Bench, please fill in the form available here.