Secure Minds System

DPDPA Compliance Consulting

DPDPA Compliance Consulting

Secure Minds runs Digital Personal Data Protection Act, 2023 (DPDPA) readiness engagements — applicability scoping, notice and consent architecture, Data Fiduciary obligation implementation, and Significant Data Fiduciary compliance where designated. This is practitioner-led work, delivered by consultants with 15+ years of hands-on data protection and GRC implementation experience across ISO 27001, SOC 2, and now DPDPA.

Where Enforcement Stands

The DPDPA was enacted on 11 August 2023. The final Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (Gazette, 14 November 2025), triggering a phased, 18-month enforcement rollout:

Phase Effective Date What Comes Into Force
Phase 1 13 November 2025 (in force) Data Protection Board of India established (Sec. 18–26); all 28 definitions under Sec. 2 operative
Phase 2 13 November 2026 Consent Manager registration opens with the Board (Sec. 6(9); Rule 4); Sec. 27(1)(d) Board information-call power activates; a penalty framework specific to Consent Managers is enforced — general enforcement is not yet live
Phase 3 13 May 2027 Full compliance mandatory — core obligations (Sec. 3–10) in force: applicability, notice, consent, Data Fiduciary duties, Significant Data Fiduciary framework, cross-border transfer (Sec. 16), and the general penalties regime (Sec. 29–34, fines up to ₹250 crore)

As of today, organizations are in the build phase: roughly 2–3 months remain to Phase 2 (Consent Manager registration only) and roughly 8–9 months to Phase 3, when general enforcement and the penalties regime actually activate. Waiting until the Phase 3 deadline to start is the single most common mistake we see — notice redesign, consent architecture, and Significant Data Fiduciary readiness (where applicable) all take longer than organizations expect.

Our Methodology, Mapped to the Act

Phase Section Reference What We Deliver
Applicability & Scoping Sec. 3 Determine whether processing falls within scope (digital personal data, India nexus, exemptions under Sec. 17)
Notice & Consent Architecture Sec. 5, 6 Itemized, multilingual notice (22 Eighth Schedule languages), consent capture design, Consent Manager integration where used
Deemed Consent Mapping Sec. 7 Map existing processing activities to legitimate-use exceptions instead of defaulting to explicit consent everywhere
Data Fiduciary Obligations Sec. 8 Reasonable security safeguards, data accuracy controls, storage-limitation policy, grievance redressal mechanism
Children’s & Vulnerable Persons’ Data Sec. 9 Verifiable parental/guardian consent workflow, suppression of tracking, behavioural monitoring, and targeted advertising to children
Significant Data Fiduciary Readiness Sec. 10 DPO designation, independent data auditor engagement, Data Protection Impact Assessment (DPIA), algorithmic accountability documentation — for entities likely to be notified as SDF
Data Principal Rights Sec. 11–13 Access, correction, and erasure request handling; nomination mechanism; grievance redressal SLA
Breach Response Rule 7 Detection-to-notification runbook: first intimation to the Board without delay, detailed follow-up within 72 hours, and Data Principal notification within 72 hours in plain language
Cross-Border Transfer Review Sec. 16 Transfer-mechanism assessment under India’s negative-list model (Rule 15), overlaid with sectoral restrictions (RBI, IRDAI, etc.)

Penalty Exposure Under the Schedule (Sec. 33)

The Data Protection Board determines penalties with regard to the nature, gravity, and duration of the contravention, and may enhance or reduce a penalty by up to 2x based on aggravating or mitigating factors.

Contravention Maximum Penalty
Failure to implement reasonable security safeguards (Sec. 8(5)) ₹250 crore
Failure to notify the Board and affected Data Principals of a breach ₹200 crore
Non-compliance with children’s data obligations (Sec. 9) ₹200 crore
Non-compliance with Significant Data Fiduciary additional obligations (Sec. 10) ₹150 crore

Typical Engagement Timeline

For a mid-market Indian organization, DPDPA readiness is typically achievable in 3–5 months from kickoff: applicability and data-mapping assessment (2–3 weeks), notice and consent redesign (4–6 weeks), Data Fiduciary control implementation and breach-response runbook (4–6 weeks), and Significant Data Fiduciary readiness where applicable (additional 4–8 weeks for DPIA and independent audit arrangement).

Organizations already certified to ISO/IEC 27001:2022 can reuse a substantial share of their risk assessment, access control, and incident response evidence — the security-safeguards obligation under Sec. 8(5) overlaps significantly with ISO Annex A technological controls. We scope combined ISO 27001 / DPDPA engagements to avoid duplicated work.

Frequently Asked Questions

Is DPDPA in force right now?
Partially. The Data Protection Board and all statutory definitions are already operative (Phase 1, since 13 November 2025). Phase 2 (13 November 2026) is narrow — it opens Consent Manager registration and activates a penalty framework specific to Consent Managers, not general enforcement. The core substantive obligations — notice, consent, Data Fiduciary duties — and the general penalties regime (fines up to ₹250 crore) both become mandatory together on 13 May 2027 (Phase 3). Building compliance now, ahead of Phase 3 enforcement, is the defensible position.

Does DPDPA apply to my organization if we’re not an Indian company?
Yes, if you process digital personal data of individuals located in India in connection with offering goods or services to them, regardless of where your organization is incorporated.

What’s a Significant Data Fiduciary and how do we know if we’ll be designated one?
The Central Government notifies Data Fiduciaries as “Significant” under Sec. 10 based on volume and sensitivity of personal data processed, risk to Data Principals, and other prescribed factors. Significant Data Fiduciaries face additional obligations: a India-based Data Protection Officer, an independent data auditor, and periodic DPIAs. We run a readiness assessment against the likely designation criteria as part of scoping.

How does DPDPA relate to GDPR compliance we already have?
There’s meaningful overlap — consent, breach notification, and data-principal rights concepts are directionally similar — but DPDPA’s consent-manager architecture, deemed-consent categories under Sec. 7, and the negative-list cross-border transfer model under Sec. 16 have no direct GDPR equivalent. We treat DPDPA as its own workstream, not a GDPR find-and-replace.

Discuss Today to scope your DPDPA readiness engagement.