DPDP compliance,
done properly.
Consent. DSR. Breach. DPO. DPIA. Every obligation in the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, in one platform your team can actually operate. Seven dedicated modules cover consent management, data subject requests, breach notification, DPIA, gap assessment, data retention and cross-border transfers, backed by an AI advisor that keeps you audit-ready. Phase 3 enforcement hits May 2027. Start now.
If any of this sounds familiar, you're in the right place.
Most DPOs and acting-DPOs walking into DPDP for the first time run into these four exact problems. dcomply is built for the person handed "DPDP compliance" as a new responsibility.
You've read the Act. You've read the Rules. You still can't tell what your first 30 days should look like.
Legal handed you a 40-page checklist. IT handed you a firewall report. Neither of them owns the DPDP programme.
You have a privacy policy PDF from 2019. It doesn't cover children's data, doesn't cover the SDF criteria, and doesn't get you audit-ready.
The board asked what happens if there's a breach tomorrow. You don't have a real answer.
If your organisation is a hospital or a fintech, you may also want to look at the Healthcare door or the Fintech door where DPDP sits inside a wider regulator stack.
Here's what sits above the Act.
DPDP is the foundation. The 2025 Rules sit on top. The Data Protection Board of India (DPBI) enforces both. Sectoral overlays for RBI, SEBI, IRDAI, health and education add further layers depending on your industry. dcomply ships modules for each layer.
Everything You Need to Know About the DPDP Act 2023
The Digital Personal Data Protection Act is India's landmark data protection legislation. Here's what it means for your business.
What is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 was enacted on August 11, 2023, India's first dedicated, comprehensive data protection law. It applies to all entities that collect and process digital personal data of Indian citizens, both within India and abroad.
The Act defines clear rights for Data Principals (individuals whose data is collected), obligations for Data Fiduciaries (businesses processing data), and creates the Data Protection Board of India as the regulatory body for enforcement.
Read Full DPDP Guide →Who Must Comply?
If your business has any of the following, you need to comply:
- A website with a contact or sign-up form
- A mobile app available to Indian users
- An e-commerce store with Indian customers
- A SaaS product used by Indian businesses
- A CRM or customer database with Indian records
- Any digital product processing Indian citizen data
This includes startups, MSMEs, enterprises, NGOs, and foreign companies offering services to Indian users. There is no size exemption.
Penalties Under DPDP
The DPDP Act carries some of the steepest penalties in Indian regulatory history:
| Security safeguard breach | Up to ₹250 Cr |
| Failure to notify data breach | Up to ₹200 Cr |
| Non-fulfilment of DSR duties | Up to ₹150 Cr |
| Consent violations | Up to ₹50 Cr |
| Maximum aggregate penalty | ₹250 Crore |
Enforcement begins when the Data Protection Board is constituted following Rules notification.
7 Modules Built Specifically for DPDP Compliance
No other platform covers the full breadth of DPDP requirements. dcomply gives you every module you need, consent, DSR, breaches, policies, assessments, and AI guidance.
Consent Management
DPDP-compliant consent banners, purpose-based collection, preference centres, and full audit trails. Embed in any website in under 5 minutes.
Explore Consent Management systemDSR Portal- Data Subject Rights
Automate access, correction, erasure, and portability requests. Built-in SLA tracking, identity verification, and audit-ready response records.
Learn moreBreach Notification
72-hour breach notification workflows to the Data Protection Board and affected individuals. Incident registry, severity classification, and PDF export.
Learn morePrivacy Policy Generator
Generate DPDP-compliant privacy notices, cookie policies, and data processing agreements. Auto-updates when law changes, no lawyer needed.
Learn moreDPIA. Data Protection Impact Assessment
Guided DPIA workflows for high-risk processing activities. Risk scoring, mitigation tracking, and Board-ready DPIA reports aligned to DPDP requirements.
Explore DPIA. Data Protection Impact AssessmentGap Assessment & Penalty Estimator
Map your current posture against all DPDP requirements. Calculates your estimated penalty exposure (up to ₹250 Cr) and prioritises remediation steps.
Learn moreDPDP AI Advisor. Your Always-On Compliance Expert
Ask any question about the DPDP Act 2023 and get precise, citation-backed answers instantly. The AI Advisor monitors regulatory updates, flags obligations relevant to your business, and generates compliance checklists, policy clauses, and Board submission templates on demand.
Explore DPDP AI Advisor12-Point DPDP Compliance Checklist
Every obligation your organisation must fulfil under the Digital Personal Data Protection Act 2023, and how dcomply covers each one.
| # | DPDP Requirement | dcomply covers this | Module | Penalty if missed |
|---|---|---|---|---|
| 1 |
Appoint a Data Fiduciary contact / DPO Designate a person responsible for compliance and grievance redressal |
✓ | DPO-as-a-Service | Up to ₹50 Cr |
| 2 |
Publish a DPDP-compliant Privacy Notice Clear notice in English + 22 scheduled languages, explaining what data is collected and why |
✓ | Policy Generator | Up to ₹50 Cr |
| 3 |
Obtain explicit, purpose-specific consent Free, specific, informed, and unambiguous consent for each processing purpose, no pre-checked boxes |
✓ | Consent Management | Up to ₹50 Cr |
| 4 |
Establish a DSR (Data Subject Requests) mechanism Honour rights to access, correction, erasure, and grievance redressal within stipulated timelines |
✓ | DSR Portal | Up to ₹150 Cr |
| 5 |
Register as Consent Manager (if applicable) Entities managing consent on behalf of multiple Data Fiduciaries must register with the DPB |
✓ | Consent Manager Reg. | Up to ₹50 Cr |
| 6 |
Conduct DPIA for high-risk processing Significant Data Fiduciaries must conduct Data Protection Impact Assessments for high-risk activities |
✓ | DPIA | Up to ₹50 Cr |
| 7 |
Implement Breach Notification to DPA within 72 hours Notify the Data Protection Board and affected individuals promptly after a personal data breach |
✓ | Breach Notification | Up to ₹200 Cr |
| 8 |
Maintain processing records and audit trails Keep complete records of data processing activities, consent logs, and DPB correspondence |
✓ | Audit Reports | Up to ₹50 Cr |
| 9 |
Appoint DPO if designated as Significant Data Fiduciary SDFs must appoint a Data Protection Officer resident in India and report to the Board of Directors |
✓ | DPO-as-a-Service | Up to ₹50 Cr |
| 10 |
Implement Data Minimisation Collect only the data that is necessary for the stated purpose, no excessive or speculative collection |
✓ | Gap Assessment | Up to ₹50 Cr |
| 11 |
Establish cross-border transfer safeguards Transfer of personal data outside India only to countries on the Government's approved list, with adequate safeguards |
✓ | Cross-Border Transfers | Up to ₹250 Cr |
| 12 |
Train staff on DPDP obligations All employees handling personal data must understand their obligations and the organisation's privacy practices |
✓ | DPDP AI Advisor | Regulatory Risk |
DPDP Act. Enforcement Timeline
How the law has evolved and when enforcement begins
Start Your DPDP Journey- Free Tools
No account required. Understand your DPDP obligations in minutes.
dcomply vs Consultant vs DIY
There are three ways to approach DPDP compliance. Only one gives you ongoing automation, 24/7 monitoring, and guaranteed currency.
| dcomply | Compliance Consultant | DIY / Spreadsheets | |
|---|---|---|---|
| Cost | From ₹1,499/mo | ₹2–10 Lakhs/year | Time cost is high |
| Time to set up | Under 1 hour | 4–12 weeks | Months of research |
| Always up to date with Rules | Auto-updated | Only at review cycles | Manual research required |
| 24/7 monitoring | Always on | Not included | Not possible |
| Automated DSR fulfilment | Fully automated | Manual, billable hours | Spreadsheet tracking only |
| Penalty estimator (₹250 Cr) | Built in | On request (extra cost) | Not available |
| Audit-ready reports | One-click PDF | Prepared manually | Not available |
| Breach notification (72 hr) | Automated workflow | Manual, with delays | No structured process |
| AI Compliance Advisor | Included | Human expert (expensive) | Not available |
Frequently Asked Questions About DPDP Compliance
Everything you need to know about the Digital Personal Data Protection Act 2023 and how to comply.
However, all Data Fiduciaries, regardless of SDF status, must designate a contact person for grievance redressal. dcomply's DPO-as-a-Service module covers both requirements: virtual DPO services for SDFs and grievance officer designation for all others.
- Scope: GDPR covers both digital and manual processing; DPDP covers only digital personal data.
- Legal bases: GDPR has six legal bases; DPDP primarily relies on consent and specified legitimate uses.
- DPO: GDPR requires a DPO for most large-scale processors; DPDP only mandates a DPO for Significant Data Fiduciaries.
- Consent Manager: DPDP introduces the unique concept of a Consent Manager, not present in GDPR.
- Penalties: GDPR is the higher of 4% of global turnover or €20M; DPDP has fixed caps up to ₹250 Crore per violation type.
- Children's data: Both require parental consent, but DPDP sets the threshold at 18.
"The board stopped asking scary questions."
"We started the DPDP programme with two spreadsheets and a PDF. Six weeks later we had a DSR portal, a breach playbook, and a DPO on subscription. The board stopped asking scary questions."
DPDP-ready from ₹9,999/month
All 27 DPDP modules — Consent, DSR, DPIA, Breach, Grievance Officer, Deep Scan, Custom Subdomain DSR — bundled in the Data Privacy pack.
See DPDP pricing & plansRead next
Get DPDP Compliant in 5 Minutes
Stop worrying about ₹250 Crore penalties. Start your free dcomply account and activate the DPDP modules your business needs, today.
Trusted by compliance teams across India • Setup in under an hour • Cancel anytime