DPDP Act Compliance for Indian Enterprises: What CXOs Must Do Before the Deadline

TL;DR
May 2027 is the wrong date to plan against. The consent manager provisions land in November 2026. That is roughly eight weeks away.
The substantive obligations commence about 18 months after notification, in mid-May 2027. Notice, security safeguards, breach reporting, retention, children's data, SDF duties and cross-border rules all switch on together.
The biggest penalty ceiling is ₹250 crore, for failing to take reasonable security safeguards. That is an engineering problem, not a legal one.
You now have three retention clocks. CERT-In requires 180 days of logs. DPDP Rule 6 requires one year of logs and personal data. Sector rules sit on top.
One breach triggers two regulators. CERT-In at 6 hours. The Data Protection Board without delay, then a detailed report within 72 hours.
Rule 6 controls take 12 to 18 months to build properly. Counting back from May 2027, the work starts now.
Why the May 2027 DPDP deadline is the wrong date to plan against
Most Indian boards have been told the DPDP deadline is May 2027. That number has bought a lot of comfort and very little action.
It is the wrong number to plan against, for two reasons.
The first is nearer. The consent manager provisions commence roughly twelve months after notification, which puts them in mid-November 2026. If consent infrastructure is part of your compliance model, that date is weeks away, not years.
The second is arithmetic. The May 2027 obligations include the Rule 6 security safeguards, which carry the highest penalty ceiling in the Act. Encryption at rest, access control, logging, monitoring and one year of retention across a real enterprise estate is a 12 to 18 month programme. Counted back from May 2027, it should already be underway.
There is a third thing nobody says out loud. The Data Protection Board cannot inspect every company. Enforcement will follow breaches. Whether you are compliant on paper matters far less than whether you can answer a regulator's questions the week after an incident.
DPDP Act compliance deadlines: The phased timeline
The Digital Personal Data Protection Rules, 2025 were notified in November 2025, with commencement staggered across three points.
Phase | Timing | What commences |
|---|---|---|
Immediate | November 2025 | Definitions, procedural provisions, and the Data Protection Board framework |
12 months | Mid-November 2026 | Consent manager registration and the obligations attached to it |
18 months | Mid-May 2027 | Notice, security safeguards, breach notification, retention and erasure, children's data, Significant Data Fiduciary duties, cross-border transfer, data principal rights |
A note on precision. Published sources differ by a day on the notification date, which shifts the downstream dates correspondingly. Confirm the exact days against the Gazette notification before you put them in a board pack or a contract. The 12 and 18 month structure is not in dispute.
DPDP Act penalties: what non-compliance costs
Penalties under the Act are fixed rupee ceilings, not a percentage of turnover. The Data Protection Board adjudicates. Appeals go to TDSAT within 60 days.
Failure | Maximum penalty |
|---|---|
Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
Failure to give the Board or affected data principals notice of a breach | ₹200 crore |
Non-compliance with additional obligations relating to children | ₹200 crore |
Non-compliance with additional obligations of a Significant Data Fiduciary | ₹150 crore |
Breach of any other provision of the Act or the Rules | ₹50 crore |
Breach of a data principal's duties | ₹10,000 |
Two things follow from that table.
The largest exposure is a security failure, not a paperwork failure. That puts it in your CISO's remit, not only your legal team's.
And a single incident can breach several obligations at once. A breach caused by weak controls, not reported correctly, involving children's data, engages three separate ceilings.
Mitigating factors are weighed before an amount is set: self-disclosure, prompt corrective action, cooperation, and your prior compliance record. Evidence of a genuine programme is worth real money at the adjudication stage, even if the programme was incomplete.
What are reasonable security safeguards under DPDP Rule 6?
Rule 6 is the ₹250 crore line. CXOs consistently underestimate it because it reads like a short list.
It requires, at minimum:
Data protection techniques — encryption, obfuscation, masking, or tokenisation mapped to the personal data
Access controls on the computer resources used by you and by your processors
Logs, monitoring and review sufficient to detect unauthorised access
Backup and continuity so processing survives a confidentiality, integrity or availability event
Retention of those logs and the personal data for one year, unless another law requires otherwise
Contractual terms binding your processors to equivalent safeguards
Read that last point again. Your vendors are in scope through your contracts. Every SaaS platform, payroll provider, marketing agency and offshore development partner that touches personal data needs a data processing agreement with real security terms. For most Indian enterprises this is the single largest piece of work, because it means finding every processor first.
The detection requirement is the hidden one. "Logs, monitoring and review, for enabling detection of unauthorised access" is not a logging requirement. It is a monitoring requirement. Logs nobody reads do not detect anything, and a regulator asking how a breach went unnoticed for four months will land exactly here. This is where a managed SOC does more for your DPDP position than another policy document.
How long must Indian enterprises retain data under DPDP and CERT-In?
Indian enterprises are now subject to overlapping retention obligations that no single vendor datasheet accounts for.
Requirement | Duration | Scope |
|---|---|---|
CERT-In directions | 180 days, within Indian jurisdiction | ICT system logs |
DPDP Rule 6 | One year | Logs and the personal data itself |
Sector regulators (RBI, SEBI, IRDAI) | Varies, often longer | Sector-specified records |
Where regimes overlap, the stricter one governs. In practice that means designing for the longest applicable period rather than tracking three separately.
Two traps sit here.
Most security platforms retain far less than a year by default. Endpoint and access tools commonly ship 14, 30 or 90 days in their standard tier. Getting to a defensible year usually means a data lake, a SIEM tier, or an external log platform, and it is a real budget line.
And Rule 6 covers logs and personal data. That interacts awkwardly with erasure obligations elsewhere in the Rules. Where retention and erasure appear to conflict, get a legal reading rather than an engineering assumption.
DPDP breach notification: The hour-by-hour reporting sequence
Everyone writes that CERT-In and DPDP both apply. Almost nobody sequences them. Here is what a single incident looks like against the clock.
Hour 0 — Detection. Your SOC confirms unauthorised access to a system holding personal data. The clock starts at noticing, not at confirming scope.
Hours 0 to 6 — CERT-In. Report within six hours of noticing, through CERT-In's channel, in its format. This is a technical incident report. You will not know everything yet, and you report anyway.
Without delay — Data Protection Board. A description of the breach: nature, extent, timing, location and likely impact. "Without delay" is not defined as a number of hours. Treat it as same day.
Without delay — Affected data principals. Each affected individual, in concise and plain language, through their registered account or contact method. They must be told what happened, the likely consequences for them, what you have done to mitigate, what they should do themselves, and how to reach a person at your organisation who can answer.
Within 72 hours — Detailed report to the Board. Updated breach information, the facts and circumstances that led to it, mitigation measures taken or proposed, findings on who caused it, remedial measures to prevent recurrence, and a report on the intimations given to data principals.
Three practical implications for a CXO.
The six-hour clock makes 24×7 monitoring a compliance dependency rather than a security preference. Nobody meets it by discovering an incident on Monday morning.
The 72-hour report demands forensic answers, including attribution. That capability either exists before the incident or it does not.
And notifying individuals is not scoped to material breaches. Build the notification mechanism now, with the contact data to execute it.
NetNXT runs CERT-In 6-hour reporting as a service default and retains logs for at least 180 days in India, with DPDP, RBI and SEBI CSCRF mapping in standard reporting. We have written separately on what to expect from a CERT-In-compliant provider.
Are you a Significant Data Fiduciary?
The Central Government designates Significant Data Fiduciaries based on factors including the volume and sensitivity of personal data processed, risk to data principals, and risks to sovereignty, electoral democracy, security of the State and public order.
No official list has been published. Organisations in fintech, telecom, e-commerce, healthcare and large consumer platforms should plan on the assumption that they may be designated.
SDF status adds real obligations: appointing a Data Protection Officer, periodic data protection impact assessments, independent audits, and due diligence on algorithmic systems that process personal data. Restrictions on transferring specified personal data outside India also attach at this level.
If designation is plausible for you, build to the SDF standard. Retrofitting a DPO function and an audit trail after designation is considerably more expensive than designing for it.
DPDP compliance checklist for CXOs
Now, before November 2026
Map your personal data. What you hold, where it sits, which systems, which vendors, why you hold it. Everything else depends on this and it takes longer than anyone expects.
Inventory your processors. Every third party touching personal data. Most enterprises find twice as many as the register shows.
Assign ownership. One accountable executive, with a named deputy. DPDP failure is an organisational failure, and someone must own it before it is tested.
Decide on the consent manager question. Whether consent managers feature in your model determines whether November 2026 is your date or a date you can watch pass.
Through 2026 into early 2027
Close the Rule 6 gaps. Encryption, access control, monitoring and one-year retention. Start with the systems holding the most personal data, not the easiest ones.
Rewrite processor contracts. Security terms, breach cooperation, audit rights. Renewal cycles make this slow, so start with the largest vendors.
Build the breach runbook and test it. Both regulators, both clocks, one exercise. A tabletop with legal, security and communications in the room will find the gaps a document will not.
Stand up detection and 24×7 coverage. The six-hour clock is the hard constraint. Whether that is internal or a managed service, decide it now.
Before May 2027
Implement the notice and consent flows, the data principal rights mechanism, and a 90-day response process for access, correction and erasure requests.
Run an independent readiness assessment. You want the gaps found by someone you hired rather than by the Board after an incident. Compliance automation makes the evidence continuous rather than a project you repeat annually.
What to ask a DPDP compliance provider
The market is crowded and much of what is being sold is documentation. Five questions separate a real provider from a policy vendor.
1. Can you retain our logs and personal data for a full year, in India, and what does that cost separately?
Most platforms retain 14 to 90 days in their standard tier. If the answer does not distinguish between the licence and the retention, the quote is incomplete.
2. Who files the CERT-In report within six hours, and is that in the contract?
"We will support you" is not accountability. Ask whether the obligation is named in the SLA and what happens when it is missed.
3. Can you produce the 72-hour Board report, including findings on cause?
That needs forensic capability, not monitoring alone. Ask to see a redacted example.
4. How do you handle our data processors?
DPDP reaches your vendors through your contracts. A provider that cannot help you discover and assess processors is solving a fraction of the problem.
5. What happens if we are designated a Significant Data Fiduciary?
Ask what changes in scope and price. A provider without an answer has not thought past the base tier.
Ask the same five of us. If our answers are weaker than someone else's for your situation, that is useful information.
What DPDP compliance actually costs, and where to spend first
DPDP compliance is being sold hard right now, and much of what is being sold is documentation.
Policies, registers and consent notices are necessary. They are also the cheap part, and they are not what carries the ₹250 crore ceiling. A company with a perfect policy set and no monitoring is exposed exactly where the Act bites hardest.
Spend in this order: know where your personal data is, control who can reach it, detect when someone reaches it who should not, and be able to prove all three for a year. The paperwork follows from that and is far easier to produce once the controls exist.
To model the monitoring and retention component against your estate, our cost calculator gives indicative ranges. Treat any output as a range to confirm, not a quote.
Nothing here is legal advice. DPDP obligations turn on how your organisation processes data, and you should take a legal reading on scope, SDF status and cross-border transfer specifically.
What changes next: SDF designations and early enforcement
Two things will shape the next eighteen months.
The first is the SDF list. When designations arrive, they will reshape the compliance cost base for whole sectors at once, and the organisations that built to the standard in advance will absorb it quietly.
The second is enforcement posture. The Board's early decisions will set the tone for what "reasonable security safeguards" means in practice. That phrase is deliberately undefined in the Act and will acquire its meaning through cases. Until then, the defensible position is a documented, monitored, evidenced control environment rather than a maximal one.
Plan for the audit you will face after an incident, not the one you hope never comes. They are the same audit.
Need to know where you actually stand before the deadline? Talk to NetNXT's team — we will assess your Rule 6 position, retention gaps and breach readiness against your real estate, not a template.
FAQ
1) When is the DPDP Act compliance deadline?
The Rules were notified in November 2025 with phased commencement. Procedural provisions took effect immediately, consent manager provisions commence around mid-November 2026, and the substantive obligations — notice, security safeguards, breach notification, retention, children's data, SDF duties and cross-border transfer — commence around mid-May 2027, eighteen months after notification. Confirm exact dates against the Gazette, as published sources differ by a day.
2) What is the maximum penalty under the DPDP Act?
₹250 crore, for failing to take reasonable security safeguards. Failure to notify a breach and non-compliance with children's data obligations each carry up to ₹200 crore, and Significant Data Fiduciary breaches up to ₹150 crore. These are fixed ceilings, not a percentage of turnover, and one incident can engage several at once.
3) What is the DPDP breach notification timeline?
Affected individuals and the Data Protection Board must be informed without delay. A detailed report follows to the Board within 72 hours, covering the facts, mitigation, findings on cause and the intimations given to individuals. This is separate from CERT-In's six-hour reporting requirement, which also applies.
4) Do CERT-In and DPDP breach reporting both apply?
Yes, simultaneously. They are parallel obligations with different regulators, triggers, formats and clocks. CERT-In requires reporting within six hours of noticing a cybersecurity incident. DPDP requires notification to the Board and to affected individuals, followed by a 72-hour detailed report. Your incident runbook must execute both.
5) How long must we retain data under the DPDP Rules?
Rule 6 requires logs and personal data to be retained for one year, unless another law requires otherwise. This sits alongside CERT-In's 180-day log retention requirement within Indian jurisdiction, and any sector rules from RBI, SEBI or IRDAI. Where they overlap, design for the longest applicable period. Most security platforms retain far less than a year by default, so budget for the gap.
