Quick Answer
The Digital Personal Data Protection Act 2023 applies to all IT and SaaS companies processing personal data of Indian citizens. With Rules notified on November 13, 2025, the three-phase compliance rollout is already active. Phase I obligations apply now, with full enforcement beginning May 2027. Penalties reach up to ₹250 crore per breach.
The Digital Personal Data Protection Act 2023 (DPDP Act) is now moving from legislation to enforcement. With the DPDP Rules 2025 notified on November 13, 2025, India’s data protection framework has a firm timeline that IT and SaaS companies can no longer treat as a future concern.
The three-phase rollout is structured to give organizations a strategic window. Phase I is active right now. Phase II begins November 2026. Full enforcement begins May 2027. Companies that use this window productively will be well-positioned; those that wait will face a compliance sprint under enforcement pressure.
This blog is written for CTOs, Chief Privacy Officers, General Counsel, and compliance heads at IT and SaaS companies. We cover every major obligation under the DPDP Act, the additional requirements for Significant Data Fiduciaries, a practical ten-point compliance checklist, the penalty structure, a GDPR comparison for companies with EU exposure, and a six-step programme to start your compliance build now.
What Is the DPDP Act and Who Does It Apply To?
The Digital Personal Data Protection Act 2023 is India’s primary data protection legislation, governing the processing of digital personal data of individuals (referred to as “Data Principals”) by entities (referred to as “Data Fiduciaries”). It received Presidential assent on August 11, 2023, and the DPDP Rules 2025 were notified on November 13, 2025, triggering the phased compliance timeline.
The DPDP Act applies to:
- IT and technology companies incorporated in India that process personal data of Indian citizens
- Foreign companies that process the personal data of Indian residents in connection with offering goods or services to them
- SaaS platforms, cloud service providers, and software product companies operating in India
In short, if your company handles the personal data of individuals located in India, the DPDP Act applies to your operations. For a full breakdown of the legal framework, refer to our analysis of the DPDP Legal Framework for IT Companies.
What Are the Three Phases of the DPDP Compliance Rollout for IT Companies?
The DPDP Rules 2025 introduce a phased implementation schedule. This structure gives companies a defined runway, but each phase carries specific, enforceable obligations.
Phase | Timeline | Key Obligations |
Phase I | November 2025 (NOW ACTIVE) | Notice and consent framework, privacy policy publication, grievance redressal mechanism, appointment of consent manager registration |
Phase II | November 2026 | Data processing agreements with processors, Data Principal rights mechanisms (access, correction, erasure, grievance), children’s data verification systems |
Phase III | May 2027 (Full Enforcement) | Full SDF obligations (DPIA, DPO appointment, algorithmic accountability, annual audit), cross-border transfer compliance, complete penalty regime activated |
Phase I is not a preparatory stage. It carries live obligations for notice requirements, consent collection, and grievance mechanisms. Companies that have not yet addressed Phase I requirements are already in a gap position.
Are You a Significant Data Fiduciary (SDF)?
The DPDP Act creates a two-tier structure. Most IT companies operate as standard Data Fiduciaries. However, the Central Government may classify certain companies as Significant Data Fiduciaries (SDFs) based on:
- Volume and sensitivity of personal data processed
- Risk of harm to Data Principals
- National security and public order considerations
- Potential impact on sovereignty and integrity of India
If your company is designated an SDF, four additional obligations apply:
- Data Protection Impact Assessment (DPIA): Mandatory for all high-risk processing activities
- Annual Data Audit: Conducted by an independent auditor
- Data Protection Officer (DPO): A senior, independent officer accountable to the Board
- Algorithmic Accountability: Policies governing the deployment of automated decision-making systems
SaaS companies processing data at scale, platforms with significant user bases, and companies deploying AI-driven products should proactively assess whether SDF designation is likely. For a detailed treatment of AI regulation under the DPDP framework, see our AI Regulation Blog.
What Are the Key DPDP Obligations for Every IT Company?
Regardless of SDF status, all IT companies processing personal data of Indian citizens must meet the following baseline obligations.
1. Consent Management
Consent under the DPDP Act is not a checkbox. It must be:
- Granular: Specific to each purpose of processing
- Withdrawable: Data Principals must be able to withdraw consent as easily as they gave it
- Plain language: Written in clear, simple terms
- Multilingual: Available in all 22 scheduled languages of the Eighth Schedule of the Indian Constitution, upon request
Notice must be given before consent is sought, stating the personal data to be collected and the purpose for which it will be processed. For IT companies with legacy consent flows, a full audit and rebuild of consent architecture is typically required.
2. Data Processing Agreements (DPAs)
Where IT companies engage third-party processors (cloud vendors, sub-processors, analytics providers), written contracts must establish that:
- The processor processes data only on documented instructions
- Adequate technical and organizational security measures are in place
- The processor does not engage further sub-processors without authorization
SaaS companies that are themselves processors for enterprise clients must ensure their own agreements with clients reflect DPDP-compliant terms.
3. Data Principal Rights: Systems Must Support
The DPDP Act grants Data Principals the following rights, and IT companies must build operational systems to respond:
- Right to access: Information about personal data being processed
- Right to correction and erasure: Accurate and complete data, with deletion upon withdrawal of consent or end of lawful purpose
- Right to grievance redressal: A functional mechanism with defined response timelines
- Right to nominate: The ability to nominate another individual to exercise rights in the event of death or incapacity
These rights are not aspirational. Systems, workflows, and response SLAs must be in place before Phase II goes live in November 2026
4. Children's Data: Verifiable Parental Consent
The DPDP Act defines a “child” as any individual under 18 years of age. This threshold is stricter than the GDPR standard of under 16 in most EU member states.
For any IT company whose platform may be accessed by minors, verifiable parental consent is mandatory before processing a child’s data. Behavioral tracking and targeted advertising directed at children are prohibited outright.
5. Cross-Border Data Transfers
The DPDP Act permits cross-border transfers to countries notified by the Central Government as approved destinations. The approved country list has not been finalized as of this publication. IT companies with global operations must monitor the notification closely and build a transfer mechanism that can be adjusted as the approved list is established.
For companies already maintaining GDPR Standard Contractual Clauses or Binding Corporate Rules for EU transfers, a parallel assessment for DPDP transfer compliance is required.
6. Data Breach Notification
In the event of a personal data breach, Data Fiduciaries must notify:
- The Data Protection Board of India (DPBI)
- Affected Data Principals
Notification must be made without undue delay. The DPDP Rules 2025 provide specific requirements for the content of breach notifications. Companies must have an incident response plan, a breach register, and internal escalation protocols in place before Phase III enforcement begins.
DPDP Compliance Checklist for IT Companies
# | Compliance Requirement | Phase Due | Status |
1 | Publish a DPDP-compliant privacy notice | Phase I (Now) | |
2 | Audit and rebuild consent collection flows | Phase I (Now) | |
3 | Establish a grievance redressal mechanism | Phase I (Now) | |
4 | Map all personal data flows and processing activities | Phase I (Now) | |
5 | Execute DPDP-compliant DPAs with all processors | Phase II (Nov 2026) | |
6 | Build Data Principal rights request workflows | Phase II (Nov 2026) | |
7 | Implement children’s data verification system | Phase II (Nov 2026) | |
8 | Assess SDF designation risk | Phase II (Nov 2026) | |
9 | Appoint DPO (if SDF) and establish DPIA programme | Phase III (May 2027) | |
10 | Commission first annual data audit (if SDF) | Phase III (May 2027) |
What Are the Penalties for DPDP Non-Compliance?
The DPDP Act establishes a tiered penalty structure administered by the Data Protection Board of India. Penalties are assessed per breach, not per data subject.
Breach Category | Maximum Penalty |
Failure to implement reasonable security safeguards | Up to ₹250 crore |
Failure to notify the DPBI or Data Principals of a breach | Up to ₹200 crore |
Non-compliance with children’s data obligations | Up to ₹200 crore |
Non-compliance with SDF-specific obligations | Up to ₹150 crore |
Breach of any other provision of the Act or Rules | Up to ₹50 crore |
The DPBI has the authority to investigate, call for information, and impose penalties. The Board operates independently, and its orders are enforceable as decrees of a civil court. For IT companies with institutional clients and enterprise contracts, DPDP non-compliance also creates downstream contractual and reputational exposure. For a broader corporate compliance view, see our DPDP in Corporate.
How Does the DPDP Act Compare to the GDPR for Companies with EU Exposure?
IT and SaaS companies serving both Indian and European markets must maintain dual compliance programmes. The following table identifies the key structural differences.
Dimension | DPDP Act 2023 (India) | GDPR (EU) |
Territorial scope | Personal data of Indian residents processed in India or abroad in connection with offering goods/services | Personal data of EU residents processed inside or outside the EU |
Children’s age threshold | Under 18 | Under 16 (varies by member state, minimum 13) |
Legal bases for processing | Consent and “certain legitimate uses” (narrower than GDPR) | Six lawful bases including legitimate interests |
Data localization | Cross-border transfers permitted to notified countries only | Transfers permitted with appropriate safeguards (SCCs, BCRs, adequacy decision) |
DPO requirement | Mandatory for SDFs | Mandatory where processing is large-scale or involves special categories |
Penalty structure | Up to ₹250 crore per breach | Up to €20 million or 4% of global turnover, whichever is higher |
Right to be forgotten | Right to erasure upon consent withdrawal or end of lawful purpose | Broader right including processing based on legitimate interests |
Breach notification timeline | Without undue delay (specific timelines in Rules) | Within 72 hours to supervisory authority |
Consent language | Must be available in all 22 scheduled languages | Must be in clear and plain language of the user |
Companies that have already invested in GDPR compliance infrastructure will find meaningful overlap in areas such as consent management, DPAs, and breach notification. However, the DPDP Act’s stricter children’s data threshold, narrower transfer permissions, and language requirements mean that GDPR compliance does not create automatic DPDP compliance.
How to Build a DPDP Compliance Programme: A Six-Step Approach
A DPDP compliance programme is not a one-time project. It is an operational function that requires governance, systems, and ongoing maintenance. The six-step approach we use at Altacit Global for IT and SaaS companies across Bangalore, Hyderabad, and Chennai is structured as follows:
Step 1: Personal Data Inventory and Flow Mapping
Map all categories of personal data collected, the purpose of collection, where data is stored, who has access, how long it is retained, and where it flows (including to processors and across borders).
Step 2: Gap Assessment Against DPDP Obligations
Assess current consent flows, privacy notices, DPAs, rights mechanisms, and security controls against DPDP Act and DPDP Rules 2025 requirements. Document all gaps with a prioritized remediation plan.
Step 3: Consent and Notice Architecture Rebuild
Redesign consent collection to meet granularity, withdrawability, and plain language requirements. Update privacy notices to meet the content standards set out in the Rules.
Step 4: Contracts and Vendor Management
Review and update all third-party processor agreements to incorporate DPDP-compliant terms. For SaaS companies, update customer agreements to reflect Data Fiduciary and processor responsibilities clearly.
Step 5: Rights and Grievance Infrastructure
Build internal workflows to handle Data Principal requests within statutory timelines. Establish and publish a grievance redressal mechanism with a named officer and a functional contact point.
Step 6: Governance, Training, and Monitoring
Appoint a DPO if required, establish an internal data protection committee, deliver role-specific training, and implement a monitoring schedule tied to the Phase II and Phase III compliance milestones.
Start Your DPDP Compliance Programme Now
The three-phase DPDP rollout gives IT and SaaS companies a structured window to build a compliant, sustainable data protection programme. Phase I is active. Phase II is twelve months away. Full enforcement begins in May 2027. The companies that act now will meet May 2027 as a governance milestone, not a deadline crisis.
Altacit Global works with IT and SaaS companies across Bangalore, Hyderabad, and Chennai to design and implement DPDP compliance programmes that are legally sound and operationally practical. Whether you need a gap assessment, a full compliance build, or ongoing legal support, our team is ready to help your organization meet its obligations under the Digital Personal Data Protection Act 2023.
Contact Altacit Global today to schedule a DPDP compliance consultation for your company.
Frequently Asked Questions: DPDP Compliance for IT Companies
Q1: When does the DPDP Act fully come into force for IT companies?
The DPDP Act 2023 received Presidential assent on August 11, 2023. The DPDP Rules 2025 were notified on November 13, 2025, triggering a phased rollout. Phase I obligations are active now. Phase II obligations take effect November 2026. Full enforcement, including all SDF obligations and the complete penalty regime, begins May 2027.
Q2: What is a Data Protection Officer (DPO) and does my company need one?
A DPO is a senior individual responsible for overseeing data protection strategy and ensuring compliance with the DPDP Act. Under the DPDP Act, a DPO is mandatory only for companies designated as Significant Data Fiduciaries. However, even companies not designated as SDFs benefit operationally from appointing a privacy lead or privacy counsel to manage compliance obligations on an ongoing basis.
Q3: Do SaaS companies have DPDP obligations for their clients' data?
Yes. SaaS companies typically operate as Data Processors on behalf of their enterprise clients, who are the Data Fiduciaries. As processors, SaaS companies must process personal data only on documented instructions from the fiduciary, implement adequate security measures, and comply with the terms of a written Data Processing Agreement. Where a SaaS company also collects and processes its own user data (such as account information or usage analytics), it operates as a Data Fiduciary for that data and must meet the full range of fiduciary obligations.
Q4: What happens if our company has a data breach before May 2027?
The breach notification obligation applies as soon as the relevant phase of the DPDP Rules comes into effect. Companies should not assume that pre-May 2027 breaches carry no regulatory consequence. The DPBI has broad investigative powers, and obligations active during Phase I and Phase II are enforceable. All IT companies should implement an incident response plan and breach notification workflow now, not at Phase III.
Q5: Can an IT company appoint an external DPO?
The DPDP Act requires the DPO of an SDF to be based in India and be accountable directly to the Board of the company. While the Act does not explicitly prohibit an external appointment, the DPO’s accountability structure and the requirement for the role to report to the Board suggest that the individual should function as an integrated, accountable officer rather than an outsourced service provider. Altacit Global can advise on structuring the DPO function to meet regulatory requirements while reflecting your company’s governance model.



