On 13 November 2025, the Ministry of Electronics and Information Technology (MeitY) released the Digital Personal Data Protection Act and Rules, completing India’s data protection framework. The phased rollout spans 18 months - core provisions and the Data Protection Board take effect immediately, consent manager obligations follow in 12 months, and full compliance requirements in 18 months.

The Rules mandate clear consent notices, breach reporting within 72 hours, parental consent for children, data retention norms, and stricter duties for Significant Data Fiduciaries, including annual audits and data protection and impact assessment (DPIA). Cross-border transfers adopt a “negative list” approach, aligning India closer to global standards like GDPR.

For businesses, this is more than compliance - it’s a strategic imperative to embed privacy-by-design, strengthen governance, and build trust in the digital economy.

Key highlights of the DPDPA

  1. The DPB acts as the central authority for enforcing the DPDP Act. It has powers to investigate breaches, adjudicate disputes, and impose penalties up to INR 250 crore. The Board ensures accountability and compliance across organisations handling personal data.
  2. The Act mandates specific timelines for responding to data principal requests such as access, correction, withdrawal of consent, and grievance resolution. This ensures faster and more transparent handling of individual rights.
  3. Consent Managers are now part of a regulated framework, enabling individuals to manage and withdraw consent easily across multiple platforms. This strengthens user control over personal data processing.
  4. A comprehensive compliance framework covering consent and notices, breach reporting, data retention, children’s data safeguards, cross-border transfers, Data Protection Impact Assessment (DPIAs), and additional obligations for Significant Data Fiduciaries (SDF).
Read more
What our leaders have to say
testimonial client avatar
A contemporary #DataPrivacy regime as a part of India’s #RegulatoryEcosytem, one of the six ecosystems that we are shaping, is critical to help shape #VibrantBharat. The #DPDPA rules represent a significant milestone, balancing two critical priorities-safeguarding individual data rights and fostering responsible business innovation. This is an opportunity for businesses to build trust through responsible data use, advance AI safety and align with global data governance standards.
Vishesh C. Chandiok CEO, Grant Thornton Bharat
testimonial client avatar
DPDPA is a defining moment in India’s digital journey. When organisations protect personal data with integrity, we don’t just meet regulations; we strengthen citizen trust and help shape a #VibrantBharat.
Deepankar Sanwalka Senior Partner, Grant Thornton Bharat

Impact of DPDPA

  • Customer profiling, authentication, sensitive data
  • Process outsourcing - fintech partnerships, data processing, product alliances
  • Risk management - credit, AML, fraud and insurance
  • Financial information and transaction data
  • Fingerprints, facial recognition data for secure access
  • Personal preferences and behaviour
  • Device information and location
  • Personal data from online activities
  • Communication records, media consumption patterns, browsing histories
  • Name, address and contact numbers
  • Consumer preferences
  • Payment and transaction data
  • Browsing histories, shopping preferences, feedback and reviews
  • Service usage, feedback, loyalty programme details
  • Patient health records
  • Health insurance
  • Clinical trial data
  • Biometric and genetic data
  • Appointment histories, feedback, health monitoring data
  • Diagnostic results, treatment plans, prescription records
  • Travel itinerary
  • Payment information
  • Reservation information
  • Guest feedback
  • Credit card details, transaction histories, billing information
  • Identity data - Name, date of birth, gender, profile picture
  • Behavioural data - Browsing history, social media likes, comments, and shares
  • Health data - Fitness activity, medical history
  • Communication data - Chat messages, voice call recordings, emails or feedback submitted via platforms

The experts viewpoint

The video is playing. This video is playing in mini-player mode.

The video is playing. This video is playing in mini-player mode.

How Grant Thornton Bharat can help?

10.

Align IT systems with DPDP requirements through expert collaboration

11.

Resolve data breach disputes with expert intervention

Our resources

Digital Personal Data Protection Act and Rules - 2025

Digital Personal Data Protection Act and Rules - 2025

India’s DPDP Rules 2025 introduce phased compliance, stronger consent and security norms, and a Data Protection Board, boosting national privacy standards.

From mandate to momentum

From mandate to momentum

Digital Personal Data Protection Act (DPDPA) 2023 and final rules as notified on 13 November 2025

    How will the DPDP Act impact Financial Services?
    Report

    How will the DPDP Act impact Financial Services?

    The DPDP Act of 2023 aims to protect personal data, empower individuals, and enforce strict data handling standards.

    A step closer to new privacy laws in India

    A step closer to new privacy laws in India

    Stay ahead of regulatory changes. Learn how the DPDP Draft Rules impact your organisation/industry.

    Building consumer trust through robust data protection
    Flyer

    Building consumer trust through robust data protection

    DPDPA marks a significant paradigm shift, emphasising stringent data protection and privacy measures that will redefine how businesses will operate.