Home / Advisory Services / Data Privacy – DPDP Act

Advisory Services

Data Privacy – DPDP Act

Get ready for India’s Digital Personal Data Protection Act with a programme that covers law, process and technology.

Privacy consultant mapping personal data flows with a client
Image placeholder: Privacy consultant mapping personal data flows with a client

Overview

What it is and who needs it

The Digital Personal Data Protection Act 2023 (DPDP Act) is India’s law on how organisations collect and use digital personal data. The Digital Personal Data Protection Rules 2025, notified in November 2025, put the Act into operation and bring its provisions into force in phases.

The Act applies to organisations that process digital personal data in India and to those outside India that offer goods or services to people in India. It sets duties on notice and consent, security safeguards, breach notification, retention and the rights of individuals, with penalties of up to INR 250 crore for the most serious failures.

Who needs it

  • Any business that processes personal data of customers, users or employees in India
  • SaaS, fintech, e-commerce and health-technology companies handling large volumes of data
  • Overseas companies offering goods or services to people in India
  • Organisations likely to be notified as Significant Data Fiduciaries
Workshop wall with a personal data inventory
Image placeholder: Workshop wall with a personal data inventory

Scope

What is covered

Data discovery and mapping

What personal data you hold, where it is, why you have it and who it is shared with.

Notice and consent design

Clear, itemised notices and consent flows that can be withdrawn as easily as given.

Rights of individuals

A process for access, correction, erasure, grievance and nomination requests.

Breach notification

A procedure and templates for informing affected individuals and the Data Protection Board.

Retention and deletion

Retention periods by purpose, with deletion once the purpose is served.

Children’s data

Verifiable parental consent and limits on tracking and targeted advertising.

Significant Data Fiduciaries

Data Protection Officer, independent data auditor and impact assessments.

Vendor contracts

Contract terms and oversight for the processors that handle data on your behalf.

Readiness timeline

The Act comes into force in phases

The DPDP Rules 2025 set three commencement points. Data mapping and consent redesign take time, so the work needs to start well before the last one.

November 2025

On notification

The DPDP Rules are notified. Provisions that establish the Data Protection Board of India, and the definitions the framework relies on, take effect.

November 2026

After 12 months

The provisions on registration and obligations of Consent Managers take effect.

May 2027

After 18 months

The main obligations apply: notice and consent, security safeguards, breach notification, rights of individuals, children’s data and Significant Data Fiduciary duties.

Draft note: schedule as notified by MeitY in November 2025 (G.S.R. 846(E)) and checked against published sources on 3 October 2026. Confirm the exact commencement days against the Official Gazette before this page is published.

Our approach

How we work, step by step

01

Discover

We inventory personal data, systems, purposes and third parties.

02

Assess

Current practice is compared with the Act and the Rules, and gaps are ranked.

03

Design

Notices, consent flows, the rights process, breach procedure and retention schedule are drafted.

04

Implement

We work with product, legal and IT teams to build the changes and update vendor contracts.

05

Train

Staff who handle personal data learn what is expected of them.

06

Sustain

Periodic reviews keep the programme current, with vDPO support if you need it.

Deliverables

What you receive

  • Personal data inventory and data flow maps
  • Gap assessment report with a prioritised roadmap
  • Notice and consent templates
  • Rights request and grievance procedure
  • Breach response plan with notification templates
  • Retention schedule and vendor contract clauses
Data flow map and DPDP gap assessment report
Image placeholder: Data flow map and DPDP gap assessment report

Why iSecurify

Three reasons customers choose us

01

Law, process and technology together

Privacy consultants and security engineers work on the same plan.

02

Built on what you have

Existing ISO 27001 controls and policies are reused wherever they fit.

03

Ready ahead of the deadline

The roadmap is planned backwards from the commencement dates.

Questions

Frequently asked questions

When do we need to comply?

The Rules bring the Act into force in phases. Provisions on the Data Protection Board took effect on notification in November 2025, the Consent Manager provisions follow in November 2026, and the main obligations for organisations apply from May 2027.

Does the Act apply to employee data?

Yes, where it is digital personal data. The Act permits certain processing for employment purposes without consent, but duties such as security safeguards still apply.

What must we do if there is a personal data breach?

Under the Rules, affected individuals and the Data Protection Board must be informed without delay, and a detailed report must reach the Board within 72 hours of becoming aware of the breach unless the Board allows longer.

What is a Significant Data Fiduciary?

An organisation notified by the Central Government on the basis of factors such as the volume and sensitivity of the data it processes. It must appoint a Data Protection Officer based in India and an independent data auditor, and carry out periodic impact assessments and audits.

We already comply with the GDPR. Is that enough?

It is a strong start, but not sufficient. The DPDP Act relies more heavily on consent and has its own requirements for notices, children’s data, Consent Managers, breach reporting and retention.

Customer stories

What our customers say

  • Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.

    Swapon Adhikary

    Director · The Hird

  • Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.

    Krutarth Pandya

  • We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.

    Nandeep Mehta

Organisations we work with

Talk to us about the DPDP Act.

Share a few details and a consultant will come back with a scope and next steps.

info@isecurify.co