DPDP door. Consent, DSR, breach, DPO. Full stack.

DPDP compliance,
done properly.

Consent. DSR. Breach. DPO. DPIA. Every obligation in the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, in one platform your team can actually operate. Seven dedicated modules cover consent management, data subject requests, breach notification, DPIA, gap assessment, data retention and cross-border transfers, backed by an AI advisor that keeps you audit-ready. Phase 3 enforcement hits May 2027. Start now.

7 DPDP Modules
₹250 Cr Penalty Protected
AI Powered
No credit card required | Setup in under 5 minutes | Always up to date with latest rules
DPDP Alert Real-time compliance status
Consent Rate 94.2%
DSR Response SLA On Track
Overall DPDP Score 87 / 100
Live compliance dashboard, always current
Sound familiar?

If any of this sounds familiar, you're in the right place.

Most DPOs and acting-DPOs walking into DPDP for the first time run into these four exact problems. dcomply is built for the person handed "DPDP compliance" as a new responsibility.

You've read the Act. You've read the Rules. You still can't tell what your first 30 days should look like.

Legal handed you a 40-page checklist. IT handed you a firewall report. Neither of them owns the DPDP programme.

You have a privacy policy PDF from 2019. It doesn't cover children's data, doesn't cover the SDF criteria, and doesn't get you audit-ready.

The board asked what happens if there's a breach tomorrow. You don't have a real answer.

If your organisation is a hospital or a fintech, you may also want to look at the Healthcare door or the Fintech door where DPDP sits inside a wider regulator stack.

Your regulator stack

Here's what sits above the Act.

DPDP is the foundation. The 2025 Rules sit on top. The Data Protection Board of India (DPBI) enforces both. Sectoral overlays for RBI, SEBI, IRDAI, health and education add further layers depending on your industry. dcomply ships modules for each layer.

Sectoral overlays
RBI Cybersecurity Framework, SEBI CSCRF, IRDAI Cyber Guidelines, healthcare rules. Applied on top of DPDP for regulated entities.
Data Protection Board of India (DPBI)
Constituted. Adjudicates complaints, imposes penalties up to ₹250 Cr, handles appeals under Section 27 of the Act.
DPDP Rules 2025
Notified in draft January 2025. Cover consent artefacts, Rule 11 children's data, breach notification format, cross-border transfer conditions.
DPDP Act 2023
The foundation. Enacted 11 August 2023. Phase 1 active. Phase 3 (full enforcement) expected May 2027. Every Indian data fiduciary lives here.
Understanding DPDP

Everything You Need to Know About the DPDP Act 2023

The Digital Personal Data Protection Act is India's landmark data protection legislation. Here's what it means for your business.

What is the DPDP Act 2023?

The Digital Personal Data Protection Act 2023 was enacted on August 11, 2023, India's first dedicated, comprehensive data protection law. It applies to all entities that collect and process digital personal data of Indian citizens, both within India and abroad.

The Act defines clear rights for Data Principals (individuals whose data is collected), obligations for Data Fiduciaries (businesses processing data), and creates the Data Protection Board of India as the regulatory body for enforcement.

Read Full DPDP Guide →
Who Must Comply?

If your business has any of the following, you need to comply:

  • A website with a contact or sign-up form
  • A mobile app available to Indian users
  • An e-commerce store with Indian customers
  • A SaaS product used by Indian businesses
  • A CRM or customer database with Indian records
  • Any digital product processing Indian citizen data

This includes startups, MSMEs, enterprises, NGOs, and foreign companies offering services to Indian users. There is no size exemption.

Penalties Under DPDP

The DPDP Act carries some of the steepest penalties in Indian regulatory history:

Security safeguard breach Up to ₹250 Cr
Failure to notify data breach Up to ₹200 Cr
Non-fulfilment of DSR duties Up to ₹150 Cr
Consent violations Up to ₹50 Cr
Maximum aggregate penalty ₹250 Crore

Enforcement begins when the Data Protection Board is constituted following Rules notification.

The Complete Stack

7 Modules Built Specifically for DPDP Compliance

No other platform covers the full breadth of DPDP requirements. dcomply gives you every module you need, consent, DSR, breaches, policies, assessments, and AI guidance.

Consent Management

DPDP-compliant consent banners, purpose-based collection, preference centres, and full audit trails. Embed in any website in under 5 minutes.

Explore Consent Management system
DSR Portal- Data Subject Rights

Automate access, correction, erasure, and portability requests. Built-in SLA tracking, identity verification, and audit-ready response records.

Learn more
Breach Notification

72-hour breach notification workflows to the Data Protection Board and affected individuals. Incident registry, severity classification, and PDF export.

Learn more
Privacy Policy Generator

Generate DPDP-compliant privacy notices, cookie policies, and data processing agreements. Auto-updates when law changes, no lawyer needed.

Learn more
DPIA. Data Protection Impact Assessment

Guided DPIA workflows for high-risk processing activities. Risk scoring, mitigation tracking, and Board-ready DPIA reports aligned to DPDP requirements.

Explore DPIA. Data Protection Impact Assessment
Gap Assessment & Penalty Estimator

Map your current posture against all DPDP requirements. Calculates your estimated penalty exposure (up to ₹250 Cr) and prioritises remediation steps.

Learn more
DPDP AI Advisor. Your Always-On Compliance Expert

Ask any question about the DPDP Act 2023 and get precise, citation-backed answers instantly. The AI Advisor monitors regulatory updates, flags obligations relevant to your business, and generates compliance checklists, policy clauses, and Board submission templates on demand.

Explore DPDP AI Advisor
DPDP Checklist

12-Point DPDP Compliance Checklist

Every obligation your organisation must fulfil under the Digital Personal Data Protection Act 2023, and how dcomply covers each one.

# DPDP Requirement dcomply covers this Module Penalty if missed
1 Appoint a Data Fiduciary contact / DPO
Designate a person responsible for compliance and grievance redressal
DPO-as-a-Service Up to ₹50 Cr
2 Publish a DPDP-compliant Privacy Notice
Clear notice in English + 22 scheduled languages, explaining what data is collected and why
Policy Generator Up to ₹50 Cr
3 Obtain explicit, purpose-specific consent
Free, specific, informed, and unambiguous consent for each processing purpose, no pre-checked boxes
Consent Management Up to ₹50 Cr
4 Establish a DSR (Data Subject Requests) mechanism
Honour rights to access, correction, erasure, and grievance redressal within stipulated timelines
DSR Portal Up to ₹150 Cr
5 Register as Consent Manager (if applicable)
Entities managing consent on behalf of multiple Data Fiduciaries must register with the DPB
Consent Manager Reg. Up to ₹50 Cr
6 Conduct DPIA for high-risk processing
Significant Data Fiduciaries must conduct Data Protection Impact Assessments for high-risk activities
DPIA Up to ₹50 Cr
7 Implement Breach Notification to DPA within 72 hours
Notify the Data Protection Board and affected individuals promptly after a personal data breach
Breach Notification Up to ₹200 Cr
8 Maintain processing records and audit trails
Keep complete records of data processing activities, consent logs, and DPB correspondence
Audit Reports Up to ₹50 Cr
9 Appoint DPO if designated as Significant Data Fiduciary
SDFs must appoint a Data Protection Officer resident in India and report to the Board of Directors
DPO-as-a-Service Up to ₹50 Cr
10 Implement Data Minimisation
Collect only the data that is necessary for the stated purpose, no excessive or speculative collection
Gap Assessment Up to ₹50 Cr
11 Establish cross-border transfer safeguards
Transfer of personal data outside India only to countries on the Government's approved list, with adequate safeguards
Cross-Border Transfers Up to ₹250 Cr
12 Train staff on DPDP obligations
All employees handling personal data must understand their obligations and the organisation's privacy practices
DPDP AI Advisor Regulatory Risk
Key Dates

DPDP Act. Enforcement Timeline

How the law has evolved and when enforcement begins

August 2023
DPDP Act enacted and received Presidential assent on Aug 11, 2023
2024
Draft DPDP Rules published for public consultation (Jan 2025). Stakeholder feedback received.
2025
Final DPDP Rules expected to be notified. Data Protection Board of India to be constituted.
2025–26
Enforcement begins. DPB starts accepting complaints. Penalties start applying to non-compliant entities.
Now
Time to prepare. Every month without compliance is a month of exposure.
Don't wait for the enforcement notice. The DPDP Act has been law since August 2023. Companies that begin compliance now will have audit trails, documented processes, and full readiness before the Data Protection Board starts issuing notices. Companies that wait will face rushed implementation, and heightened regulatory scrutiny.
Why dcomply

dcomply vs Consultant vs DIY

There are three ways to approach DPDP compliance. Only one gives you ongoing automation, 24/7 monitoring, and guaranteed currency.

dcomply Compliance Consultant DIY / Spreadsheets
Cost From ₹1,499/mo ₹2–10 Lakhs/year Time cost is high
Time to set up Under 1 hour 4–12 weeks Months of research
Always up to date with Rules Auto-updated Only at review cycles Manual research required
24/7 monitoring Always on Not included Not possible
Automated DSR fulfilment Fully automated Manual, billable hours Spreadsheet tracking only
Penalty estimator (₹250 Cr) Built in On request (extra cost) Not available
Audit-ready reports One-click PDF Prepared manually Not available
Breach notification (72 hr) Automated workflow Manual, with delays No structured process
AI Compliance Advisor Included Human expert (expensive) Not available
DPDP FAQs

Frequently Asked Questions About DPDP Compliance

Everything you need to know about the Digital Personal Data Protection Act 2023 and how to comply.

The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first comprehensive data protection law, enacted on August 11, 2023. It governs how organisations collect, process, store, and share the personal data of Indian citizens in digital form. The Act establishes the rights of Data Principals (individuals), including rights to access, correct, and erase their data, and obligations for Data Fiduciaries (businesses processing data) including obtaining lawful consent, maintaining security, and notifying breaches. The Act creates the Data Protection Board of India to oversee enforcement and adjudicate complaints.

The DPDP Act was enacted in August 2023 but requires Rules to be notified before enforcement begins. The Government published draft DPDP Rules for public consultation in January 2025. The final Rules are expected to be notified in 2025, after which the Data Protection Board of India will be constituted. Once the Board is formed, it can begin receiving complaints and initiating enforcement proceedings, including levying penalties. Organisations should not wait for the final Rules before beginning compliance, the law is already in effect.

Any entity, startup, MSME, large enterprise, NGO, or government body, that collects or processes the digital personal data of Indian citizens must comply. This includes: websites with any form that collects user data; mobile apps available on Indian app stores; e-commerce platforms selling to Indian customers; SaaS products used by Indian businesses or individuals; banks, NBFCs, and financial services companies; healthcare providers with patient data; and foreign companies offering goods or services to Indian users. There is no minimum size or revenue threshold, the law applies equally to a two-person startup and a Fortune 500 company.

Penalties under the DPDP Act are structured by violation type: failure to implement reasonable security safeguards carries a penalty of up to ₹250 Crore; failure to notify a personal data breach carries up to ₹200 Crore; failure to fulfil Data Subject Request obligations carries up to ₹150 Crore; non-compliance by a Consent Manager carries up to ₹200 Crore; and most other violations carry penalties up to ₹50 Crore per instance. The Data Protection Board has full discretion to investigate and impose penalties based on severity, intent, and the harm caused to individuals.

The fastest path to DPDP compliance follows this sequence: (1) Run a Gap Assessment to understand your current posture and priority gaps; (2) Activate the Consent Management module and deploy DPDP-compliant consent banners on your website and app; (3) Set up the DSR Portal to handle data subject requests; (4) Use the Policy Generator to publish a compliant Privacy Notice; (5) Configure Breach Notification workflows so you can respond within 72 hours if a breach occurs. Most organisations using dcomply can have a working compliance framework operational in under one week. Start your free account to begin.

A formal DPO appointment is mandatory only for entities designated as Significant Data Fiduciaries (SDFs) by the Government of India. The Government will determine SDF status based on factors including: volume of personal data processed, sensitivity of data processed, potential risk to national security, and the potential impact on rights of Data Principals.

However, all Data Fiduciaries, regardless of SDF status, must designate a contact person for grievance redressal. dcomply's DPO-as-a-Service module covers both requirements: virtual DPO services for SDFs and grievance officer designation for all others.

A Consent Manager is a new legal entity type introduced by the DPDP Act. It is a platform, registered with the Data Protection Board, and through which a Data Principal (individual) can give, manage, review, and withdraw their consent across multiple Data Fiduciaries using a single interface. Think of it as a centralised consent wallet. Consent Managers must be registered with the DPB, meet interoperability and security standards, and maintain records for a minimum period. If your business aggregates consent on behalf of other Data Fiduciaries, you may need to register as a Consent Manager.

Both laws protect individuals' personal data but differ in several key ways:
  • Scope: GDPR covers both digital and manual processing; DPDP covers only digital personal data.
  • Legal bases: GDPR has six legal bases; DPDP primarily relies on consent and specified legitimate uses.
  • DPO: GDPR requires a DPO for most large-scale processors; DPDP only mandates a DPO for Significant Data Fiduciaries.
  • Consent Manager: DPDP introduces the unique concept of a Consent Manager, not present in GDPR.
  • Penalties: GDPR is the higher of 4% of global turnover or €20M; DPDP has fixed caps up to ₹250 Crore per violation type.
  • Children's data: Both require parental consent, but DPDP sets the threshold at 18.
If you are already GDPR compliant, you are partially prepared for DPDP, but you still need India-specific implementations around consent records, DSR mechanisms in Indian languages, and DPB notification formats.

Yes. The Act is notified and Phase 1 is active. The Data Protection Board of India (DPBI) has been constituted. Phase 3, which brings full enforcement of breach, consent, and cross-border obligations, is expected in May 2027. Preparation takes months, not weeks, so most organisations start now rather than wait for the Phase 3 deadline to arrive. dcomply's Gap Assessment module is the shortest path from where you are today to a working DPDP programme.

If your organisation is a Significant Data Fiduciary (SDF), yes. dcomply's SDF Determination module tells you whether you qualify against the notified criteria. Even if you are not required to appoint a DPO, most companies with over 10,000 data principals appoint one voluntarily because the Board Report of any listed group asks the question, and enterprise buyers ask it in their vendor security questionnaires.

They need to be re-validated against DPDP standards. dcomply's Consent Manager Registration module handles the migration and re-consent workflow, including a bulk re-consent email that logs whether each principal actively renewed, explicitly withdrew, or did not respond within a defined window. Non-response is not consent under DPDP, so those records must be paused or purged.

Yes for small and mid-sized organisations. The platform covers the mechanics of consent, DSR, breach, DPIA and retention. dcomply also offers a virtual DPO (vDPO) subscription from ₹2,499 per month that gives you access to a qualified DPO without a full-time hire, plus an on-demand legal review of complex data situations. Most Series-A to Series-C companies run DPDP off the vDPO tier for the first two years.

dcomply's Breach Notification module walks you through the mandatory fields, triggers the DPBI notification timeline, and archives the full audit chain for later inspection. The module also runs an urgency check that flags any breach involving children's data, SDF data, or over 500 principals for expedited handling. The DPBI-ready export is one click.
Real teams, real DPDP programmes

"The board stopped asking scary questions."

"We started the DPDP programme with two spreadsheets and a PDF. Six weeks later we had a DSR portal, a breach playbook, and a DPO on subscription. The board stopped asking scary questions."
Head of Legal & Compliance, a mid-sized listed IT services company.
What DPDP compliance costs

DPDP-ready from ₹9,999/month

All 27 DPDP modules — Consent, DSR, DPIA, Breach, Grievance Officer, Deep Scan, Custom Subdomain DSR — bundled in the Data Privacy pack.

See DPDP pricing & plans
DPDP Act 2023 Ready

Get DPDP Compliant in 5 Minutes

Stop worrying about ₹250 Crore penalties. Start your free dcomply account and activate the DPDP modules your business needs, today.

Trusted by compliance teams across India • Setup in under an hour • Cancel anytime