Insights  ·  Kurdukar & Co.

The DPDP Act is Enforceable. Is Your Company Ready?

30 May 2026

A note for CFOs, from a lawyer fifteen years into practice.

When I started practice, a senior partner told me something I have never forgotten: every major regulatory shift in India follows the same arc. First, companies decide it is someone else's problem. Then they decide it is a future problem. Then the regulator arrives, and it becomes an expensive problem. FEMA went that way. GST went that way. IBC went that way. The DPDP Act will be no different — except the penalty figures are larger.

The Digital Personal Data Protection Act, 2023 is not in draft. It is not awaiting notification. The Rules were notified on 13 November 2025. The Data Protection Board of India is constituted and has enforcement powers. The law is operational. At this point, the only question worth asking is whether your company is ready for it.

Who It Applies To

The Act applies to any organisation that processes digital personal data in India. It also applies to organisations outside India that process personal data of Indian individuals while offering them goods or services. There is no turnover floor, no sector carve-out for manufacturing or services. A company with an HR portal, a customer database, or a vendor onboarding system is within scope. The extraterritorial reach catches foreign subsidiaries and holding companies with Indian data flows equally.

The Act calls such organisations Data Fiduciaries. The framing is borrowed from trust law, and that is not incidental. A fiduciary holds something on behalf of another, with duties attached. The Act is quite explicit that personal data is held in that capacity — not owned, not freely deployable. That distinction will matter when the Board begins adjudicating.

The Timeline

The Rules set out an eighteen-month phased implementation ending 13 May 2027. I want to be clear about what that window is for: it is for building systems, revising contracts, training personnel, and establishing governance structures. It is not a grace period within which you can defer the decision to start.

From 13 November 2025 — The Board is operational and enforcement is live. Companies should already have begun data mapping and internal gap assessments.

By November 2026 — Consent Manager registration requirements come into force, as do obligations for Significant Data Fiduciaries.

By 13 May 2027 — Full operationalisation, including cross-border transfer restrictions under Section 16. That date closes the window; it does not open it.

The Core Obligations

I will go through these without softening them, because the penalty exposure attached to each makes softening counterproductive.

Consent and notice. Personal data can only be collected on specific lawful grounds, and where consent is the basis, it must be informed, specific, and unambiguous. The notice to the individual must be plain language and purpose specific. The consent clause buried in your standard terms will not pass scrutiny. Customer onboarding, CRM pipelines, HR data collection — all of it needs to be reviewed against this standard.

Security safeguards. The Act requires security measures commensurate with the nature of the data held. Breach of this obligation is the highest-penalty provision in the Act — up to ₹250 crore per instance. The question I ask clients is simple: if the Board asked you tomorrow for your board-approved data security framework, what document would you produce?

Breach notification. A data breach must be reported to the Board and to affected individuals without delay. The penalty for failure is up to ₹200 crore. An incident response plan that has no DPDP notification protocol built into it is, as of today, incomplete.

Retention and erasure. Data held beyond the purpose for which it was collected must be erased. This cuts across data warehouse design, backup and archival policy, and every third-party processing agreement your company has. It is an obligation that does not resolve itself without deliberate action.

Children's data. Processing personal data of anyone under 18 requires verifiable parental consent. The penalty is up to ₹200 crore. Any business with consumer-facing operations needs to establish whether minors fall within its data footprint.

Significant Data Fiduciaries

The Central Government may designate certain organisations as Significant Data Fiduciaries, based on the volume and sensitivity of data processed and the nature of risk to individuals. The designation carries a distinct, heavier set of obligations.

An Indian-resident Data Protection Officer must be appointed, reporting directly to the Board of Directors — not to the CTO, not to the Legal team. Annual independent audits and periodic Data Protection Impact Assessments become mandatory. Cross-border movement of government-specified data categories is restricted. Boards that have not yet considered whether this designation might apply to them are already a step behind where they should be.

Cross-Border Transfers

India has not adopted the GDPR adequacy model. Rule 15 of the DPDP Rules establishes a negative list regime: transfers abroad are permitted unless the Central Government restricts a specific country or territory by notification. No countries are currently on the restricted list.

That can change by gazette notification, without advance notice, at any time. For companies with offshore data centres, foreign group entities that process Indian data, or cloud infrastructure outside India, the compliance position that holds today is not guaranteed to hold tomorrow. That contingency needs to be structured into contracts and operations now, while there is time to do it properly.

The Penalty Figures

These are the Board's maximum penalties per instance. They belong in front of your Audit Committee.

₹250 croreFailure to maintain adequate security safeguards
₹200 croreFailure to notify a data breach
₹200 croreNon-compliance with children's data provisions
₹150 croreFailure to meet Significant Data Fiduciary obligations

The Board has discretion in determining the actual penalty and will consider the gravity of the breach, the number of individuals affected, and the organisation's compliance history. An organisation that has made a genuine, documented attempt at compliance will be in a materially different position from one that has not. That distinction has practical consequences.

What the Board Needs to Own

DPDP compliance left entirely to the IT department will not be done properly. I say that without any disrespect to IT departments — it is simply the wrong governance structure for what the Act requires. This needs board-level ownership, which means a few concrete things.

The board should commission and receive a data mapping exercise and gap assessment. It should approve a compliance roadmap with a budget, milestones, and named accountability. It should determine whether SDF designation is a realistic prospect for the company. It should ensure vendor contracts and employment agreements are reviewed for DPDP alignment. And it should confirm, on the record, that incident response protocols exist and have been tested.

None of this is technically complicated. What it requires is that someone with the authority to make it happen decides to make it happen.

Fifteen years of practice is enough to have seen what happens to companies that engage with a regulatory shift early versus those that engage when the enforcement notices start arriving. The difference is not just financial. It is reputational, operational, and in some cases existential.

The DPDP Board is functional. The first enforcement actions will come. The time to have this conversation is now, not after that first headline.

If you want to talk through where your organisation stands, write to Ajinkya@kurdukarandco.com or schedule a consultation directly.