Compliance11 min read2222 words

DPDP Compliance in India: What Is Law—and What Is Just Advice?

A privacy meeting can become expensive very quickly when nobody asks one simple question: where exactly does that requirement come from?

AquaConsento

Published: September 9, 2026

A privacy meeting can become expensive very quickly when nobody asks one simple question: where exactly does that requirement come from?

One person says the DPDP Act requires encryption. Another says every company needs a Data Protection Officer. A vendor presentation says a dedicated compliance platform is necessary. Someone else has heard that every breach follows a 72-hour deadline.

All four statements may sound credible. They are not equally accurate.

For teams working on DPDP compliance in India, the useful discipline is to separate three things that are often mixed together: what the law actually requires, what sensible organisations may do to prepare or operate those requirements, and what a technology provider recommends because its product can support the process.

That distinction is especially important in 2026 because the DPDP framework is being brought into force in stages.

Before Debating Compliance, Check Whether the Provision Is in Force

The Digital Personal Data Protection Act received presidential assent on 11 August 2023. The Act itself anticipated phased commencement: section 1(2) allows different provisions to come into force on different dates. Digital Personal Data Protection Act, 2023

The Government used that power in its notification dated 13 November 2025.

Some provisions came into force when the notification was published. Section 6(9), dealing with registration of Consent Managers, and a related Board provision were assigned a one-year commencement period. Much of the substantive compliance framework—including sections 3 to 5, most of section 6, sections 7 to 10 and the Data Principal rights provisions in sections 11 to 17—was assigned an 18-month commencement period. Official DPDP commencement notification, G.S.R. 843(E)

The final Digital Personal Data Protection Rules, 2025 follow a similar structure. Rules 1, 2 and 17–21 took effect on publication; Rule 4 is scheduled one year later; Rules 3, 5–16, 22 and 23 are scheduled eighteen months later. Digital Personal Data Protection Rules, 2025

So, on 18 September 2026, it would be inaccurate to describe the entire substantive DPDP regime as already operative. It would be equally misleading to say that nothing has happened yet.

The practical answer depends on the provision.

That is more than a legal technicality. If a board paper, implementation plan or software proposal says “DPDP requires this today,” the commencement status should be checked before the statement becomes a project requirement.

A Useful Way to Separate Law From Advice

The distinction becomes easier to see when common compliance topics are placed side by side.

TopicWhat the statutory framework saysWhat sensible preparation may look likeWhat is a technology or implementation choice
Consent and noticeThe Act contains notice and consent requirements tied to specified purposes, subject to commencementMap existing consent journeys, notices and evidence before the provisions become operativeBuying a specific consent platform or AI consent engine
Consent withdrawalThe Act provides a right to withdraw consent, with comparable ease to giving it, subject to commencementTest whether withdrawals can be acted on consistently across dependent systemsA particular real-time API or orchestration architecture
Security safeguardsSection 8 requires reasonable security safeguards; Rule 6 provides detailed minimum categories once operativeReview access, logging, incident handling, resilience and processor controlsA specific security product, architecture or “DPDP cloud”
Breach responseRule 7 specifies different notifications and timing once operativeBuild an incident workflow and rehearse responsibilities before the deadline mattersA particular breach-management dashboard
DPO and auditSpecific DPO, independent data-auditor and periodic-audit duties apply to Significant Data Fiduciaries under section 10 once operativeEstablish privacy ownership and internal assurance appropriate to the organisationAssuming every company legally needs a DPO or dedicated audit product

The third column should not be read as “unnecessary.”

Technology can be valuable precisely because statutory language usually describes an obligation or outcome rather than the detailed operating system needed to deliver it at enterprise scale.

The problem begins when that implementation choice is introduced as if Parliament prescribed it.

Does DPDP Require Encryption? The Real Answer Is More Useful

“DPDP requires encryption” is the kind of sentence that travels well in a presentation. The official text is more nuanced.

Section 8(5) of the Act requires reasonable security safeguards to prevent personal data breaches. The final Rule 6, once operative, adds detail. It refers to appropriate data-security measures such as encryption, obfuscation, masking or virtual tokens, together with access controls, logging and monitoring, continuity measures, processor-contract provisions and broader technical and organisational safeguards.

For a security team, the difference matters.

The requirement is not “purchase an encryption product.” Nor does Rule 6 reduce security to encryption alone. The organisation has to put appropriate safeguards around the processing environment.

Encryption may form part of that design. So may masking, access restrictions, monitoring and backups.

A CISO should therefore be wary of both extremes: treating encryption as the whole DPDP security programme, or arguing that security architecture can wait because the detailed Rule is not yet operative.

Good DPDP readiness uses the lead time to assess the control environment without pretending that every design choice is statutory wording.

The 72-Hour Breach Claim Is Only Half the Story

Another commonly repeated statement is that “DPDP requires every breach to be reported within 72 hours.”

Rule 7 is more specific.

When it becomes operative, affected Data Principals are to be informed without delay. The initial description to the Data Protection Board is also to be provided without delay. The 72-hour period applies to additional, updated information that must be given to the Board, unless the Board allows a longer period following a written request.

So the operational model is not simply:

breach occurs → start one 72-hour clock

There are different communications, with different information needs and timing language.

That distinction matters when Security, Legal and Communications teams design an incident process. An organisation that prepares only for “the 72-hour report” may still have unresolved work around affected-person communication and initial Board notification.

This is a good example of why summaries are useful for awareness but dangerous as substitutes for the source text.

Does Every Organisation Need a Data Protection Officer (DPO)?

Not necessarily. Under the DPDP framework, the requirement to appoint a Data Protection Officer (DPO) is not automatically imposed on every Data Fiduciary.

Section 10 allows the Central Government to designate certain organisations as Significant Data Fiduciaries based on specified factors. Once that provision becomes applicable, those organisations are required to appoint a DPO based in India, engage an independent data auditor, and carry out measures such as periodic Data Protection Impact Assessments and audits.

Section 8(9) takes a slightly different approach. It requires a Data Fiduciary to publish the business contact details of its DPO, where one is applicable, or of another person who can respond to Data Principal queries on its behalf.

In practice, some organisations may still choose to appoint a senior privacy leader before any formal DPO obligation applies. That can be a sensible governance decision, particularly where personal data processing is complex or spread across multiple business functions.

The important distinction is this: good governance and a legal requirement are not always the same thing. A company may decide that appointing a DPO, running internal privacy reviews, or conducting readiness assessments is the right thing to do, even when those steps are not universally mandated for every organisation.

The same principle applies to DPDP audits in India. Internal audits and readiness checks can be useful for many businesses, but the specific requirements for an independent data auditor and periodic audits under Section 10 are tied to the Significant Data Fiduciary framework.

What About the “22-Language Requirement”?

This claim also needs careful wording.

Sections 5 and 6 of the Act give the Data Principal an option to access relevant notice or consent-request content in English or a language specified in the Eighth Schedule to the Constitution, once those provisions come into force.

That is not the same sentence as:

Every business must permanently display every notice in all Eighth Schedule languages at the same time.

A business serving users across India may conclude that a multilingual consent and notice capability is the cleanest way to make those choices accessible. That may be excellent implementation planning.

But the feature should be justified by the organisation's user base and compliance design, rather than sold as though the Act requires one identical multilingual interface for every company.

This distinction—between the legal outcome and the chosen technical method—appears throughout DPDP Act compliance.

Good Practice Still Matters When It Is Not Written Into the Act

There is a danger in this discussion: once a team learns that a particular spreadsheet, dashboard or control is not explicitly prescribed by statute, it may conclude that the work is unnecessary.

That would be the wrong lesson.

Consider a data inventory.

The Act does not provide a standard workbook and instruct companies to maintain columns for purpose, system, processor, retention rule and owner. Yet an enterprise that cannot identify where personal data is processed is going to have a harder time implementing notices, consent, rights handling, security, erasure or processor governance coherently.

The same applies to assigning named control owners, documenting decisions, testing privacy workflows and maintaining evidence.

These are operational methods. Their value comes from helping the business deliver the underlying obligations reliably.

A useful compliance programme therefore needs two kinds of precision: Legal should know which obligations come from the statute, while Product, Engineering, Security and Operations should know how those obligations will actually work inside the organisation.

That is also the right way to approach DPDP compliance management. The programme should connect legal interpretation to real systems without pretending that the operating artefacts themselves are legislation.

Software Is a Tool, Not a Statutory Requirement

There is no provision in the Act that says an enterprise must buy DPDP compliance software.

For a small organisation with limited processing, existing systems and carefully managed procedures may be enough for many operational tasks. At enterprise scale, the picture can be quite different. Consent records may cross products and channels, Data Principal requests can involve several owners, processor information may sit with Procurement, and compliance evidence may be spread across multiple applications.

That is where software can earn its place.

It can make workflows easier to coordinate, give teams better visibility and reduce the effort involved in reconstructing evidence. Those are business and operational advantages—not proof that the particular product is legally mandatory.

For organisations trying to translate the framework into actual enterprise controls, AquaConsento's practical DPDP compliance guidance for Indian enterprises brings consent, rights, security, governance and implementation topics together in one place.

The distinction is worth preserving in every vendor discussion: a DPDP compliance solution can support compliance work, but buying one does not make every legal interpretation correct or transfer the Data Fiduciary's accountability to the software provider.

Teams moving from interpretation into delivery can also use AquaConsento's control-by-control DPDP implementation checklist to map controls to owners, implementation work and evidence. That checklist is an operational aid, not a substitute for the Act or Rules.

A Simple Habit for Testing Compliance Claims

The next time a presentation, RFP or meeting note says “DPDP requires…”, do not start by arguing about whether the proposed control is a good idea.

First identify the source.

If the claim comes from the Act or Rules, check the relevant section or rule. Then check the commencement notification. Finally, read the wording closely enough to see whether it mandates a particular method or instead sets an outcome that can be achieved in different ways.

This three-part check—source, commencement, method—is simple enough to use in Legal reviews, procurement meetings and product planning.

It changes the quality of the conversation.

A vendor may still recommend a real-time compliance dashboard. The team can then evaluate that dashboard on its operational merits rather than because somebody labelled it a legal requirement.

Security may still choose encryption as an appropriate safeguard. It can do so within a broader control design instead of reducing Rule 6 to a single technology.

Privacy may still appoint a senior owner before any formal DPO obligation applies. The organisation can call that what it is: prudent governance.

That kind of clarity is valuable because it preserves room for good professional judgement.

Frequently Asked Questions

Is the entire DPDP Act fully operative in September 2026?
No. The Government's November 2025 commencement notification introduced different commencement periods for different provisions. Some provisions took effect on Gazette publication, a smaller group was assigned a one-year period, and substantial obligations were assigned an eighteen-month period.
Does DPDP Act compliance require dedicated software?
The Act does not prescribe a particular DPDP compliance platform or software product. Technology can support consent, workflow management, rights handling, security operations and evidence, but the need for a particular product depends on the organisation's scale and operating model.
Does every Data Fiduciary need a DPO?
The specific DPO appointment requirement in section 10 applies to Significant Data Fiduciaries once that provision is operative and applicable. Section 8 separately refers to contact information for a DPO, if applicable, or another person able to respond on behalf of the Data Fiduciary.
Does Rule 7 simply give an organisation 72 hours to report every breach?
No. The final Rule distinguishes between communications. Affected Data Principals and the initial Board notification are addressed with “without delay” timing, while specified additional information to the Board is subject to the 72-hour period, once Rule 7 becomes operative.

Precision Is Part of Compliance

There is already plenty of DPDP advice in circulation. The harder job is deciding what weight to give it.

The statutory text deserves one label. Sensible implementation work deserves another. Vendor recommendations should be judged on whether they solve a real operating problem.

Mixing those categories does not make a compliance programme stricter. It usually makes it harder to manage.

For Indian enterprises preparing through the current phased commencement period, precision is therefore a practical control in its own right. Teams can prepare early, invest in technology and strengthen governance without claiming that every prudent decision has already been prescribed by law.

When a new DPDP requirement lands in your inbox, the useful response is straightforward: find the source, check when it applies, and separate the required outcome from the method being recommended.

That is a stronger foundation for DPDP compliance than a long checklist built on assumptions.

Related Topics:

AquaConsento

Expert at AquaConsento

Experienced professional in compliance and data protection. Passionate about helping businesses navigate DPDP compliance with practical, actionable insights.

Stay Updated on DPDP

Get the latest compliance guides, regulatory updates, and best practices delivered to your inbox.

No spam. Unsubscribe anytime.

Need Help with DPDP Compliance?

Our experts can help you understand how these regulations apply to your business.

Book Demo
Chat on WhatsApp
+91 6290447344