Updated for the Income-tax Act, 2025 and GST 2.0 ratesUpdated for IT Act 2025 & GST 2.0 Due datesGlossaryTDS rates
AiHisab Knowledge By Atulya Intelligence
Company Law & ROC

DPDP Act: personal data protection for businesses

2 min read Updated 03 Oct 2026 3 views
AI summary

What the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 ask of a business, the key dates, and the penalties.

8 sections

Key facts

  • The Digital Personal Data Protection (DPDP) Act, 2023 covers digital personal data of people in India: customers, employees, vendors' contacts, website and app users.
  • The DPDP Rules, 2025 were notified on 13 November 2025 and come into force in three phases.
  • A business that decides why and how personal data is used is a Data Fiduciary. The person whose data it is, is the Data Principal.
  • Penalties are imposed by the Data Protection Board of India and can go up to ₹250 crore for each failure.

Key dates

  • November 2025: Data Protection Board set up; definitions and Board procedures in force.
  • November 2026: Consent Manager registration opens.
  • May 2027: All main duties apply: notices, consent, security safeguards, breach reporting, data deletion, children's data and the rights of individuals.

What a business must do (from May 2027)

  • Notice and consent: Give a clear, standalone notice in plain language listing what data you collect and why, and take consent that is free, specific and can be withdrawn as easily as it was given. Some uses, like employment or meeting a legal duty, do not need consent.
  • Use only what you need: Collect data only for the stated purpose and delete it once that purpose is over, unless a law requires you to keep it.
  • Security: Keep reasonable safeguards such as encryption, access control, and logs of who accessed the data.
  • Breach reporting: Tell affected people without delay, and send a detailed report to the Data Protection Board within 72 hours of becoming aware of the breach.
  • Children: For anyone under 18, get verifiable consent from a parent or guardian. Tracking, behavioural monitoring and targeted ads aimed at children are not allowed.
  • Rights: Let people see, correct and erase their data, and name a contact person who answers their questions.
  • Large platforms: Big e-commerce, social media and online gaming platforms must delete data of users inactive for three years, after giving 48 hours' notice.

Penalties (maximum)

  • Failure to keep reasonable security safeguards: ₹250 crore
  • Failure to report a data breach: ₹200 crore
  • Breaking the rules on children's data: ₹200 crore
  • Significant Data Fiduciary duties not met: ₹150 crore
  • Any other breach of the Act or Rules: ₹50 crore

Common questions

Does the DPDP Act apply to a small business?

Yes. It applies to any business that handles digital personal data, whatever its size. Only some extra duties, like a Data Protection Officer and yearly audits, are limited to businesses the government names as Significant Data Fiduciaries.

Do customer and supplier records in my accounts count?

Yes. Names, phone numbers, emails, addresses and bank details of customers, suppliers and employees in your books are personal data. Restrict who can see them and keep them only as long as the law requires: books of account must be kept for 8 years under the Companies Act and for the period set by the Income-tax and GST laws.

A company registered with the Data Protection Board that lets people give, manage and withdraw consent across many businesses from one place.

Law as of October 2026. Verify against the latest notifications before relying on it.

Sources

  • Digital Personal Data Protection Act, 2023 and DPDP Rules
Was this guide helpful?