Ask a leadership team how their DPDPA preparation is going, and you will usually hear a confident answer. The privacy notice has been rewritten. Legal has reviewed the vendor contracts. Consent language has been drafted, redrafted, and approved. The policy binder is thick, current, and impressive.
Now ask a different question. A customer filled in a form on your website last Tuesday. Which application received that data? Which database is it sitting in right now? Which vendors can see it, and what exactly will delete it when the purpose is served? The confidence tends to evaporate, because the honest answer at most organisations is: we would have to check.
That gap, between what the policy says and what the systems actually do, is where DPDPA compliance will be won or lost. With the Digital Personal Data Protection Rules, 2025 notified on 14 November 2025, the clock is now running, and the organisations treating this as a legal drafting exercise are preparing for an exam the regulator is not going to set.
The Rules Are Here, and They Are Specific
The Digital Personal Data Protection (DPDP) Rules bring the Digital Personal Data Protection Act, 2023 into effect by defining how organisations must comply in practice. Together, they create India’s most comprehensive data privacy framework and establish clear responsibilities for organisations that collect and process personal data.
The Act is built on seven core privacy principles: consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and accountability. The DPDP Rules translate these principles into practical compliance requirements.
Key Compliance Requirements
Every Data Fiduciary must:
- Provide a clear, purpose-specific consent notice before collecting personal data.
- Respond to requests to access, correct, update, or erase personal data within 90 days.
- Notify affected individuals without undue delay if a personal data breach occurs, explaining what happened, the likely impact, and the measures being taken.
- Complete compliance within the prescribed 18-month implementation period.
Additional Requirements for Significant Data Fiduciaries
Organisations designated as Significant Data Fiduciaries (SDFs) have additional responsibilities because they process large volumes or sensitive categories of personal data. These include:
- Conducting independent data protection audits.
- Performing Data Protection Impact Assessments (DPIAs).
- Applying enhanced governance and risk management for high-risk processing activities.
The Data Protection Board of India will oversee compliance and handle complaints through a digital platform, while appeals will be heard by the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Penalties for Non-Compliance
The DPDP Rules are backed by significant financial penalties. Organisations can face:
- Up to ₹250 crore for failing to implement reasonable security safeguards.
- Up to ₹200 crore for failing to report a personal data breach or violating obligations related to children’s data.
- Up to ₹50 crore for other violations under the Act and Rules.
These penalties make it clear that DPDP compliance is no longer just a legal obligation; it is a business and governance priority.
Why a Documents-First Approach Doesn’t Work
Many organisations start DPDP compliance by updating privacy policies and consent forms. While necessary, documents alone cannot demonstrate compliance.
| Requirement | Why Documents Aren’t Enough |
| Data erasure | You must know where personal data is stored across all systems. |
| Breach notification | You need visibility into affected systems, data, and individuals. |
| Consent withdrawal | Processing must stop across applications, not just on paper. |
| Data subject rights | Requests must be tracked, verified, and completed within the required timeline. |
This is why DPDP compliance is more than a legal exercise. It requires legal, IT, security, engineering, HR, and business teams to work together with shared visibility into data, controls, and risks.
The Five Pillars of DPDPA Readiness
Becoming DPDPA-ready is about building the right operational capabilities—not just meeting legal requirements. In our experience, organisations that achieve compliance consistently focus on these five pillars.
| Pillar | Why It Matters |
| Data Discovery & Classification | Identify what personal data you collect, where it is stored, who owns it, and why it is processed. You can’t protect data you don’t know exists. |
| Data Flow Mapping | Track how personal data moves across applications, cloud platforms, vendors, and business processes. Visibility is essential for accountability and regulatory compliance. |
| Access & Security Controls | Protect personal data through strong access management, encryption, logging, monitoring, vulnerability management, and incident response. |
| Data Retention & Deletion | Ensure personal data is retained only as long as necessary and can be deleted across all systems when required by law or user requests. |
| Third-Party Risk Management | Assess and monitor vendors that process personal data to ensure they meet your security and privacy obligations. |
These five pillars work together to build a sustainable privacy program. Weakness in any one area can make it difficult to meet DPDPA obligations, respond to regulatory requests, or demonstrate compliance during an audit.
What Will the Regulator Ask For?
During an investigation or after a data breach, regulators are unlikely to focus on your privacy policy alone. Instead, they’ll want evidence that your privacy and security controls are working in practice.
Be prepared to demonstrate:
- Data flow maps showing where personal data is collected, stored, shared, and processed.
- Access logs identifying who had access to the affected data.
- Data retention records explaining why the data was retained and whether retention policies were followed.
- Vendor risk assessments and third-party security controls.
- Security safeguards, including access controls, encryption, monitoring, and incident response measures.
- Incident response records showing how the breach was identified, investigated, contained, and reported.
How CyRAACS Helps Organisations Achieve DPDPA Readiness
At CyRAACS, we approach DPDPA the way the Rules themselves demand: as a combination of governance, technology, security, and operational discipline, not a documentation project. Our DPDPA readiness programme takes organisations through data discovery and flow mapping, a structured gap assessment against the Act and the 2025 Rules, and risk assessments covering privacy, security, and third-party processing.
From there, we review the controls that matter in practice- access, encryption, logging, retention, deletion, and incident response- and validate them through vulnerability assessments and penetration testing, because safeguards protecting personal data should be tested, not assumed. And through the CyRAACS Compliance Management Platform, evidence stays continuously audit-ready instead of being assembled in a panic after a regulator’s letter arrives.
The Bottom Line
DPDPA is not a documentation exercise. It is a data governance challenge, and the eighteen-month window is shorter than it looks once discovery, remediation, and validation are laid out on a calendar. Organisations that focus only on policies may achieve paper compliance, but when the regulator asks how personal data is collected, processed, protected, retained, and deleted, the answer cannot be that there is a policy for that. The answer has to be: we can show you exactly how it works.
That is where true DPDPA readiness begins. To see where your organisation stands against the DPDP Rules today, explore CyRAACS’ GRC services, or if you operate across jurisdictions, our comparison of GDPR vs DPDPA is a useful next read.
Frequently Asked Questions (FAQs)
1. What is the difference between the DPDP Act and the DPDP Rules?
The Digital Personal Data Protection (DPDP) Act, 2023 establishes the legal framework for protecting personal data in India, while the DPDP Rules, 2025 explain how organisations must comply in practice. The Rules provide operational requirements for consent management, data subject rights, breach notifications, security safeguards, and compliance obligations.
2. Who needs to comply with the DPDP Rules?
The DPDP Rules apply to all Data Fiduciaries that collect, store, or process digital personal data in India. Organisations designated as Significant Data Fiduciaries (SDFs) have additional obligations, including data protection audits, Data Protection Impact Assessments (DPIAs), and enhanced governance measures.
3. What are the key requirements under the DPDP Rules?
Some of the most important requirements include:
- Issuing clear, purpose-specific consent notices.
- Responding to data subject requests within the prescribed timelines.
- Reporting eligible personal data breaches without undue delay.
- Implementing reasonable security safeguards.
- Managing data retention and deletion.
- Monitoring third-party processors that handle personal data.
4. Why are privacy policies alone not enough for DPDP compliance?
Privacy policies explain an organisation’s commitments, but regulators will also expect evidence that those commitments are implemented. Organisations must be able to demonstrate where personal data is stored, how it is processed, who can access it, how consent is managed, and how data is deleted when required.
5. What evidence should organisations maintain for a DPDP audit or investigation?
Organisations should be prepared to provide evidence such as:
- Data inventories and data flow maps.
- Access logs and user activity records.
- Data retention and deletion records.
- Third-party risk assessments.
- Security control documentation.
- Incident response and breach management records.
Maintaining this evidence continuously makes regulatory investigations and audits significantly easier




