Skip to main content
Back to Blog

India's DPDPA 2023 Is Now Live: What Every Mumbai Business Must Know

New Post > HTML view HOW TO USE: 1. Go to blogger.com > New Post 2. Click the pencil icon to switch to "HTML" view 3. Select all existing content and DELETE it 4. Paste this entire code 5. Switch back to "Compose" view to preview 6.

May 11, 2026 17 min read AbdulRazzaq Shaikh
⚠️ Compliance Deadline Alert: DPDPA's foundational provisions are LIVE as of November 13, 2025. Full compliance required by May 13, 2027. Is your business ready?
Compliance & Data Privacy · May 2025

India's DPDPA 2023 Is Now Live:
What Every Mumbai Business Must Know

The Digital Personal Data Protection Act, 2023 and its DPDP Rules 2025 are now fully operational. For businesses in Mumbai, Mira Road, Thane, and Navi Mumbai — this is the most significant data law India has ever enacted. Here is your definitive guide from IDOSS.

📅 Published: May 11, 2025
Read Time: 12 minutes
📍 IDOSS, Mira Road, Mumbai
DPDPA 2023 DPDP Rules 2025 Data Privacy India Cyber Security Mumbai Compliance

What Is the DPDPA — And Why Should You Care?

India's Digital Personal Data Protection Act, 2023 (DPDPA) is the country's first comprehensive data privacy legislation. Passed by Parliament on August 11, 2023, and operationalized through the DPDP Rules 2025 notified on November 13, 2025, it establishes the legal framework for how organizations collect, store, process, and transfer the personal data of Indian citizens.

The law rests on seven core principles: consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and accountability.

"The DPDP Rules empower individuals with greater control over their personal data and enable organisations to build trust through responsible data practices — creating a privacy-first ecosystem that balances innovation with accountability."

— Ministry of Electronics and Information Technology (MeitY), November 2025

Whether you run a fintech startup in Mira Road, a retail brand in Mumbai, an IT firm in Thane, or a manufacturing unit anywhere in India — if you handle digital personal data of Indian residents, the DPDPA applies to you.


Key Numbers at a Glance

₹250 Cr
Max penalty for security safeguard failures
72 hrs
Time limit to report a data breach
7 days
To respond to Data Principal requests
May 2027
Full compliance deadline
18 mo
Phased compliance window from Nov 2025
6,915
Public inputs received during consultation

DPDPA Enforcement Timeline: Know Your Deadlines

The DPDPA is implemented in phases — giving businesses time to adapt while holding them immediately accountable for foundational obligations.

August 11, 2023
DPDPA Enacted by Parliament

India's Digital Personal Data Protection Act is passed and receives Presidential assent — India's first comprehensive digital privacy law.

January 3, 2025
Draft DPDP Rules Released for Public Consultation

MeitY publishes draft rules, inviting feedback across Delhi, Mumbai, Guwahati, Kolkata, Hyderabad, Bengaluru, and Chennai. 6,915 public inputs received.

November 13, 2025 ✅ LIVE NOW
DPDP Rules 2025 Officially Notified

MeitY officially notifies DPDP Rules 2025 and establishes the Data Protection Board of India (DPBI). Foundational obligations — consent, breach reporting, data principal rights, security — take effect immediately. 18-month compliance window begins.

Mid 2026 (Approx.)
Consent Manager Obligations Active

Businesses using third-party consent management platforms must verify compliance and update contracts to align with DPBI-registered Consent Manager requirements.

May 13, 2027
Full Compliance Required

All DPDPA provisions become mandatory — including Significant Data Fiduciary (SDF) obligations: DPO appointment, annual DPIAs, independent audits, and algorithmic risk assessments.

⏰ Don't Wait for 2027

Foundational obligations — consent notices, 72-hour breach reporting, data principal rights, and security safeguards — are active right now. Non-compliance today carries real financial and reputational risk.


Who Does the DPDPA Apply To?

The DPDPA applies to any entity processing digital personal data in connection with:

  • Data collected digitally within India — websites, apps, platforms, CRMs, digital forms
  • Non-digital records subsequently digitized — physical documents scanned or entered into a system
  • Processing activities targeting Indian residents — even if your organization is headquartered outside India
ℹ️ Scope Clarifications

The DPDPA does not apply to individuals processing data for personal/household purposes, or to data publicly disclosed by the data principal themselves. Unlike GDPR, it does not cover offline/non-digital records unless digitized.

Key Roles Defined Under DPDPA

🏢

Data Fiduciary

Any entity that determines the purpose and means of processing personal data. If your organization decides WHY and HOW data is collected, you are a Data Fiduciary — with the highest compliance burden under this law.

👤

Data Principal

The individual to whom personal data relates. For minors, this includes the parent or lawful guardian. Data principals have six enforceable rights under the Act.

⚙️

Data Processor

Any entity processing data on behalf of a Data Fiduciary (e.g., cloud providers, payroll processors). Data Fiduciaries must contractually ensure their processors comply.

🔗

Consent Manager

A uniquely Indian concept: a registered intermediary helping users manage their consent across platforms. Must be registered with the Data Protection Board of India.


Core Obligations for Businesses (Data Fiduciaries)

If your organization is a Data Fiduciary, these foundational obligations are active immediately following the November 2025 notification:

📋

Clear Consent Notices

Issue a separate, plain-language notice for every data collection activity — specifying what data is collected, for what purpose, and how users can withdraw consent at any time.

🎯

Purpose Limitation

Use personal data only for the specific purpose for which consent was obtained. When consent is withdrawn, delete data from your systems and instruct processors to do the same.

🚨

72-Hour Breach Notification

Report ALL personal data breaches to the Data Protection Board within 72 hours — regardless of severity. There is no minimum threshold. Notify affected individuals too.

🛡️

Security Safeguards

Implement and maintain reasonable technical and organizational security measures to protect personal data. This is the highest-penalty area — up to ₹250 crore.

👶

Children's Data Protection

Obtain verifiable parental consent before processing data of minors under 18. Implement age-gating. Behavioral tracking and targeted advertising to children is restricted.

⚖️

Grievance Redressal

Establish a functional mechanism for data principals to raise complaints. Respond to formal requests within 7 days (Rule 14) through a documented process.

Additional Obligations for Significant Data Fiduciaries (SDFs) — Effective May 2027

Organizations processing large volumes or sensitive categories of data may be classified as SDFs. They face enhanced requirements:

  • Appoint a Data Protection Officer (DPO) who is an Indian resident
  • Conduct annual Data Protection Impact Assessments (DPIAs)
  • Commission independent audits of all data processing activities
  • Perform algorithmic risk verification
  • Comply with restrictions on cross-border data transfers
✅ Relief for Startups & MSMEs

The Act includes provisions to exempt smaller organizations from certain obligations like DPO appointment and annual audits. However, basic consent, security safeguards, and grievance mechanisms remain mandatory for all businesses regardless of size.


Rights of Data Principals (Your Customers & Employees)

Chapter III of the DPDPA grants six enforceable rights to all individuals. Your customers, users, and employees can legally exercise these against your organization today:

  • Right to Access — Obtain a summary of personal data processed, identities of data fiduciaries and processors with access, and information about processing activities.
  • Right to Correction — Request correction of inaccurate or incomplete personal data held about them.
  • Right to Erasure — Request deletion of personal data when it is no longer needed for the specified purpose or when consent is withdrawn.
  • Right to Withdraw Consent — Withdraw consent at any time, after which the organization must cease processing and delete the data.
  • Right to Grievance Redressal — File complaints and receive responses through the data fiduciary's grievance mechanism within 7 days.
  • Right to Nominate — Nominate another individual to exercise rights on their behalf in the event of death or incapacity.
🚫 Operational Reality

Your organization needs a functional system to receive, verify, and fulfill these requests within 7 days. This requires people, processes, and technology — not just a policy document. IDOSS can help you build this infrastructure quickly.


DPDPA Penalties: What's at Stake for Your Business

The Data Protection Board of India (DPBI) is empowered to investigate violations, impose financial penalties, and mandate remediation actions. Unlike earlier drafts of the law, the DPDPA 2023 does not include criminal penalties or imprisonment — but financial consequences are severe.

Violation / Non-Compliance Area Maximum Penalty
Failure to maintain reasonable security safeguards Up to ₹250 Crore
Failure to notify the Board or affected individuals of a breach Up to ₹200 Crore
Non-fulfilment of obligations related to children's data Up to ₹200 Crore
Non-fulfilment of additional Significant Data Fiduciary obligations Up to ₹150 Crore
Failure to fulfil Data Principal rights (access, correction, erasure) Up to ₹50 Crore
Any other provision of the Act or Rules Up to ₹50 Crore

These are maximum caps. Actual fines depend on the nature and gravity of the breach, whether it is a first or repeat offense, the volume of data affected, and the remediation steps taken. Proactive compliance significantly reduces your exposure.

💡 Reputational Risk Is Equally Real

Beyond financial penalties, a publicly reported data breach or DPBI investigation causes lasting brand damage — especially for Mumbai businesses in fintech, IT services, and e-commerce where customer trust is a core competitive asset.


DPDPA vs GDPR: Critical Differences

Many Mumbai businesses are already familiar with Europe's GDPR. While conceptually similar, there are key differences that make a GDPR-only approach insufficient for India:

Aspect DPDPA 2023 (India) GDPR (Europe)
Sensitive Data All personal data treated uniformly — no separate "sensitive" category Special categories (health, biometric, racial) with heightened protection
Contractual Necessity Not included as a lawful basis Recognized as a lawful processing ground
Legitimate Interests Not included — consent is the primary ground Recognized as a lawful processing ground
Non-Digital Records Excluded unless digitized Applies to both digital and physical records
Consent Manager India-specific registered intermediary No direct equivalent
Criminal Penalties Financial penalties only Varies by member state
Max Penalty ₹250 Crore (~€28M) €20M or 4% of global annual turnover

GDPR compliance does not automatically equal DPDPA compliance. If you are already GDPR-compliant, IDOSS can perform a quick gap assessment and build an India-specific compliance layer on top of your existing framework.


Your DPDPA Compliance Checklist for 2025

Use this as a starting point for your compliance program. Red-priority items are enforceable right now.

🔴 Immediate Priority (Active Now — Non-Negotiable)

  • Audit all digital data collection points — websites, apps, APIs, CRMs, forms
  • Draft and publish clear, plain-language consent notices for each data collection purpose
  • Implement a data breach detection system and 72-hour notification workflow to the DPBI
  • Build a mechanism to handle data principal requests (access, correction, erasure, withdrawal) within 7 days
  • Review and update data processing agreements with all third-party processors and vendors
  • Implement security controls: encryption, access controls, MFA, and vulnerability management
  • Create a children's data policy with age verification and parental consent workflows
  • Establish a documented grievance redressal mechanism with response timelines

🟡 Mid-Term Priority (Before May 2027)

  • Conduct Data Protection Impact Assessments (DPIA) on all high-risk processing activities
  • Assess whether your organization qualifies as a Significant Data Fiduciary (SDF)
  • Appoint or designate a Data Protection Officer (DPO) if required
  • Commission an independent data protection audit
  • Review and align cross-border data transfer practices for DPDPA conformity
  • Train all employees who handle personal data on DPDPA obligations and best practices
  • Integrate with or evaluate a DPBI-registered Consent Manager platform if applicable

How IDOSS Helps Mumbai Businesses Achieve DPDPA Compliance

At IDOSS — headquartered in Mira Road, Mumbai — we are a specialized Infra, DevOps, and Security firm. We combine legal compliance awareness with deep technical execution to help businesses across the Mumbai Metropolitan Region achieve and maintain DPDPA compliance.

01 — AUDIT

Data Discovery & Classification

We map every data flow in your infrastructure — databases, APIs, SaaS tools, cloud storage — and classify it for DPDPA scope. You cannot protect what you cannot see.

02 — DESIGN

Consent Architecture

We design and implement technically robust consent management systems — from cookie banners and privacy notices to full consent lifecycle management across your digital platforms.

03 — SECURITY

Security Hardening & Breach Response

We deploy encryption, access controls, SIEM monitoring, and incident response playbooks aligned with DPDPA's 72-hour breach notification requirement. Security by design.

04 — DPO

DPO-as-a-Service

Our team provides virtual Data Protection Officer services — advising on compliance, overseeing DPIAs, handling regulatory correspondence, and acting as your DPBI point of contact.

05 — DEVSECOPS

Privacy-First DevOps Integration

We embed DPDPA-compliant data handling into your CI/CD pipelines — privacy by design from code commit to production deployment. No retroactive fixes at audit time.

06 — TRAINING

Staff Training & Awareness

Compliance fails at the human layer. We deliver customized DPDPA training for technical teams, HR, sales, and leadership — including scenario-based workshops for your industry.

🏙️ Proudly Serving Mumbai & MMR

IDOSS serves businesses across Mumbai, Mira Road, Thane, Navi Mumbai, Vasai, and Virar. We understand the compliance landscape for local SMEs, startups, IT firms, and large enterprises alike. Our team is available for on-site assessments across the Mumbai Metropolitan Region.


Frequently Asked Questions About DPDPA

Does DPDPA apply to my small business or startup in Mumbai?

Yes — if you digitally collect personal data of Indian residents for any non-personal purpose. The government may notify exemptions for startups and MSMEs from certain obligations like DPO appointment and annual audits, but core consent and security requirements apply to everyone. Contact IDOSS for a tailored assessment specific to your business size and sector.

What counts as "personal data" under the DPDPA?

The DPDPA defines personal data as "any data about an individual who is identifiable by or in relation to such data." This includes names, email addresses, phone numbers, device IDs, IP addresses, and location data. Unlike the GDPR, the DPDPA does not define a separate "sensitive personal data" category — all personal data is regulated uniformly.

What is the Data Protection Board of India (DPBI)?

The DPBI is the central enforcement authority established under the DPDPA. Formally constituted on November 13, 2025, it has powers to investigate violations, impose penalties up to ₹250 crore, mandate remediation actions, and oversee grievance redressal — operating through a digitalized and expedited process.

We are already GDPR-compliant. Do we still need to worry about DPDPA?

Yes. GDPR compliance is a strong foundation but does not translate directly. Key gaps include: no "legitimate interests" or "contractual necessity" basis under DPDPA; the India-specific Consent Manager framework; mandatory 72-hour breach notification (no threshold); and different data principal rights structures. IDOSS can perform a rapid gap assessment for your organization.

What must we do if we suffer a data breach?

You must notify the Data Protection Board of India within 72 hours of becoming aware of any personal data breach — regardless of severity. You must also notify affected individuals. Failure to do so carries penalties up to ₹200 crore. IDOSS provides breach response retainer services so you are never caught unprepared.

Can foreign companies doing business in India be penalized under DPDPA?

Yes. The DPDPA applies to processing activities targeting Indian residents, regardless of where the organization is headquartered. Global SaaS platforms, e-commerce sites, and digital services with Indian users fall within scope and must comply.

What is a Significant Data Fiduciary (SDF)?

An SDF is an organization classified by the government based on the volume and sensitivity of data processed, and the potential risk posed to data principals. SDFs face enhanced obligations from May 2027: DPO appointment, annual DPIAs, independent audits, and algorithmic risk verification. IDOSS can help you assess whether your organization may qualify as an SDF.

Is Your Business DPDPA-Ready?

Get a free DPDPA compliance gap assessment from IDOSS — Mumbai's trusted Infra DevOps Security partner based in Mira Road. We will identify your risks, prioritize your actions, and build a compliance roadmap that fits your timeline and budget.

ID
IDOSS Security & Compliance Team
Infra · DevOps · Security | Mira Road, Mumbai, Maharashtra

IDOSS is a specialized Infra, DevOps, and Security firm based in Mira Road, Mumbai. Our certified security professionals, DevOps engineers, and compliance specialists help organizations across India navigate complex regulatory landscapes while building resilient, secure infrastructure. This article is for informational purposes and does not constitute legal advice.