DPDPA Rules 2025 are now in effect

India's ₹250 Crore Privacy Law is Here. Is Your Business Ready?

Learn every section of the DPDPA Act 2023 & Rules 2025 - explained in plain language for founders, CISOs, developers, and every Indian citizen. No jargon. No boring lectures. Just clarity.

FKGRCPDP+

Join growing community of GRC professionals learning DPDPA

44
Sections in the Act
22
Rules Published 2025
₹250 Cr
Maximum Penalty Per Violation
140 Cr+
Citizens Protected

Most Indian Businesses Are Not Ready for DPDPA

The law is live. The penalties are real. But understanding what to do - and how to do it - remains a maze of legal jargon and confusion.

Penalties Are Stacking

A single data breach can trigger multiple violations - security failure (₹250 Cr) + notification failure (₹200 Cr) = ₹450 Crore in combined penalties.

No Clear Guidance

63 million MSMEs in India lack in-house legal teams. Most can't afford Big-4 consultants. They need plain-language, actionable compliance help.

Citizens Don't Know Their Rights

DPDPA gives every Indian the right to access, correct, and delete their data. But 99% of citizens have never heard of these rights.

The Digital Personal Data Protection Act, 2023

India's first comprehensive data protection law. Here are the 5 pillars every business and citizen must understand.

Consent is King

Companies must get your free, specific, informed consent before processing your personal data. Pre-ticked checkboxes and bundled consent are now illegal.

Your Rights, Your Data

Every Indian citizen (Data Principal) can access, correct, delete their data, and file complaints with the Data Protection Board.

Company Obligations

Data Fiduciaries must secure data, limit collection to stated purposes, delete data when no longer needed, and report breaches.

Real Penalties

Violations carry penalties up to ₹250 Crore per instance. The Data Protection Board can investigate, penalize, and even block access.

Global Reach

Applies to companies outside India if they process data of Indian citizens - affecting every global tech company with Indian users.

DPDPA Penalty Table - Every Fine You Must Know

These are maximum penalties per violation. Multiple violations stack. A single breach event can trigger ₹450+ Crore in combined penalties.

ViolationMaximum PenaltySeverity
Failure to take reasonable security safeguards (Section 8(4))₹250 CroreCritical
Failure to notify Board and Data Principals of breach (Section 8(5), 8(6))₹200 CroreCritical
Non-compliance with children's data obligations (Section 9)₹200 CroreCritical
Non-compliance with Significant Data Fiduciary obligations (Section 10)₹150 CroreHigh
Breach of any other provision of the Act or Rules₹50 CroreHigh
Breach of duties by Data Principal (Section 15)₹10,000Low

Learn DPDPA - Section by Section, Rule by Rule

A 40-day video series covering all 44 sections and all 22 rules of DPDPA. Explained in plain language for tech, non-tech, legal, and non-legal audiences.

Foundation - Day 1

What is a Law, Act, Bill & Rule?

12 min
Foundation - Day 2

What is Data? Personal Data? Digital Personal Data?

11 min
Foundation - Day 3

What is Privacy? The Puttaswamy Story

14 min
Overview - Day 6

DPDPA in One Video - Complete Overview

15 min
Deep Dive - Day 15

Section 6: Consent - The Heart of DPDPA

18 min
Deep Dive - Day 17

Section 8: The Compliance Bible

16 min

All 44 Sections - Chapter by Chapter

We break down the entire DPDPA Act chapter by chapter, section by section. Click any chapter to start learning.

I

Chapter I: Preliminary

Definitions & Applicability

Sec 1-2
II

Chapter II: Obligations

Data Fiduciary Duties, Consent, Children's Data

Sec 3-10
III

Chapter III: Rights & Duties

Your Rights as a Data Principal + Your Duties

Sec 11-15
IV

Chapter IV: Special Provisions

Consent Managers, Exemptions, Cross-Border

Sec 16-18
V

Chapter V: Data Protection Board

Board Structure, Inquiry, Appeals

Sec 19-28
VI

Chapter VI: Penalties

The ₹250 Crore Penalty Schedule

Sec 29-30
VII

Chapter VII: Miscellaneous

Blocking, Government Powers, Transitional Provisions

Sec 31-44

Whether You're a Founder or a Citizen - DPDPA Affects You

Startup Founders

Avoid ₹250 Cr penalties. Build compliant products from Day 1. Earn customer trust as a competitive advantage.

CISOs & DPOs

Implement Section 8 obligations, manage breach notifications, and prepare for Data Protection Board audits.

Developers & CTOs

Design DPDPA-compliant consent flows, build data deletion APIs, and implement security safeguards in your stack.

Every Indian Citizen

Know your rights under Sections 11-14. Access, correct, or delete your data from any company. File complaints.

Download the Free DPDPA Compliance Checklist

A step-by-step checklist covering all critical compliance requirements - security safeguards, consent architecture, breach notification process, and Data Principal rights management. Built for startup founders and CISOs.

We respect your privacy. No spam, ever. Unsubscribe anytime.

Weekly DPDPA Insights - Straight to Your Inbox

Every Friday: one DPDPA section decoded, one compliance tip, one action item. Join GRC professionals staying ahead of India's data protection curve.