DPDP Rules notified 13 Nov 2025 · enforcement by ~May 2027

Your data register is now a legal register.

Every company, LLP, society, trust and professional practice that touches an Indian's personal data is a Data Fiduciary under the DPDP Act — whether it meant to be or not. S & S Associates build the notices, consent architecture, registers, policies and SOPs that turn that exposure into a documented, defensible compliance file.

Data Fiduciary Data Principal Consent Manager DPDP Act 2023

In short

The Digital Personal Data Protection Act, 2023 makes any entity that decides the purpose and means of processing personal data a Data Fiduciary — with duties to give notice, obtain consent, keep data secure, and report a breach to the Data Protection Board within 72 hours. Penalties reach ₹250 crore. S & S Associates map your data flows and build the full compliance file — registers, notices, consent, policies, vendor DPAs and SOPs.

0

Mandatory instruments in a complete DPDP compliance file

0

Hours to file the detailed breach report with the Board

0

Maximum penalty the Data Protection Board can impose

0

Compliance layers the 44 instruments are organised into

Who Must Comply

The Act does not ask what kind of entity you are

It asks whether you determine the purpose and means of processing personal data. Under Section 2, a "person" includes companies, societies, trusts, LLPs, sole proprietors and associations alike — for-profit or not. If any of this sits in your systems, you are already a Data Fiduciary.

Employee & HR records

Payroll, PF/ESI, appraisals and contact data of staff and consultants — the notice duty applies to every Data Principal, including employees.

Members, donors & investors

Governing-body, shareholder, donor and funder contact details — a society or not-for-profit structure gives no exemption.

Website, app & event data

Visitors, newsletter subscribers, webinar and training participants — every intake channel is a processing activity.

Vendor & client contacts

Any personal data shared with, or received from, processors and sub-processors under a service contract.

If any of the above is in your systems today, you are already a Data Fiduciary under Chapter II of the Act — the only open question is how much of your compliance file exists in writing.

Our DPDP Framework

44 instruments, organised into 7 layers

Resolutions, registers, notices, consent forms, policies, agreements and SOPs — every "shall"-type obligation in the Act mapped to a specific deliverable.

Layer 1Governance & Resolutions

Board resolutions and role allocation that place accountability for data protection on record.

Layer 2Registers & Data Mapping

Data mapping, processing inventory, consent logs and breach registers — the factual backbone.

Layer 3Statutory Notices

The itemised notices owed to every Data Principal describing what is collected, why and their rights.

Layer 4Consent Architecture

Consent forms, withdrawal mechanisms and Consent Manager workflows built to be auditable.

Layer 5Policies

Master privacy policy, plus retention and breach policies that set the rules your teams follow.

Layer 6Agreements

Vendor data processing agreements (DPAs) that make third-party processing enforceable.

Layer 7Standard Operating Procedures

Step-by-step SOPs that keep every breach, grievance and rights-request clock auditable.

The Breach Clock

Two clocks start the moment you become aware

Under Section 8(6) and Rule 7 of the DPDP Rules, 2025, the timeline runs continuously — weekends and holidays included.

Hour 0 · Without delay

Intimate the Board

Alert the Data Protection Board with the nature, extent, timing and likely impact of the breach.

Without delay

Notify Data Principals

Tell every affected individual in plain language what happened, what to do, and who to contact.

Within 72 hours

File the detailed report

Submit the full report — facts, causes, mitigation and steps to prevent recurrence — to the Board.

What's At Stake

Non-compliance is priced in crores

Under the Schedule to the Act, the Data Protection Board of India can impose these amounts directly.

₹250Cr

Failure to take reasonable security safeguards to prevent a breach.

₹200Cr

Failure to notify the Board and affected Data Principals of a breach.

₹200Cr

Non-compliance with obligations relating to children's personal data.

₹50Cr

Non-compliance with any other duty under the Act or the rules.

Penalty bands can apply cumulatively for the same incident — an inadequate safeguard and a missed breach notice are two separate exposures.

What We Deliver

Your compliance file, built to be defensible

As Company Secretaries, we produce the documents a regulator would ask for — mapped to the Act, ready to show.

Data mapping & registers

A processing inventory that records what personal data you hold, why, where it flows and who touches it.

Notices & consent forms

The statutory notices to every Data Principal and consent forms with clean, logged withdrawal mechanisms.

Policies

A master privacy policy plus retention and breach policies that set out exactly how your teams must act.

Vendor DPAs

Data processing agreements that bind your processors and sub-processors to the standard the Act expects.

Breach & SOPs

Step-by-step SOPs that keep the without-delay and 72-hour clocks auditable when an incident hits.

Free diagnostic

A short call that maps your data flows against the DPDP checklist and shows exactly where your gaps are.

Frequently Asked

The questions people actually ask

Who is a Data Fiduciary under the DPDP Act, 2023?

Any person — including a company, LLP, society, trust or sole proprietor — that determines the purpose and means of processing digital personal data in India is a Data Fiduciary under Section 2(i), whether it is for-profit or not-for-profit. There is no small-entity exemption.

What is the deadline to notify a personal data breach?

On becoming aware of a breach, a Data Fiduciary must intimate the Data Protection Board of India without delay and notify every affected Data Principal, then submit a detailed report to the Board within 72 hours (extendable only if the Board permits on written request). The clock runs continuously, including weekends and holidays.

What is the maximum penalty under the DPDP Act?

The Board can impose up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to notify a breach and for breaching children's-data obligations, and up to ₹50 crore for other contraventions. Bands can apply cumulatively for the same incident.

When does the DPDP Act become enforceable?

The DPDP Rules, 2025 were notified on 13 November 2025, starting a phased rollout. Key obligations such as security safeguards and breach notification are expected to be fully enforceable by around May 2027 — a defined window to build your compliance file before the clock matters.

What documents does a company need for DPDP compliance?

A defensible file typically includes a data mapping register, consent notices and logs, a master privacy policy, retention and breach policies, vendor DPAs, and SOPs for breach, grievance and rights-request handling. We organise these as 44 instruments across 7 layers.

How does S & S Associates help?

We run a diagnostic of your data flows, then build the registers, notices, consent architecture, policies, vendor DPAs and SOPs the Act requires — turning your exposure into a documented, defensible compliance file, with ongoing support as the rules evolve.

Start With A Diagnostic

Find out which of the 44 instruments you're missing

A short diagnostic call maps your data flows against the DPDP checklist and tells you precisely where your exposure sits — before we quote a single rupee of fee.

Book Free Diagnostic

This page is for general information only and does not constitute legal advice. Obligations, timelines and penalties under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are governed by the Act, the rules and directions of the Data Protection Board of India in force from time to time, and are being implemented in phases. Please seek formal advice for your specific circumstances.