The DPDP Act
Does It Apply?
Arrow
Up to ₹250 Crore in Penalties Under the DPDP Act.
Is Your Business DPDP Ready?
KPMG Client Logo
Cybeart Client Logo
Taksh Client Logo
Adroit Client Logo
Teshahri Client Logo
Prestige Holidays Client Logo
Signify Client Logo
Energyzed Client Logo
Callation Client Logo
Verum Client Logo
KG Systems Client Logo
LCA Client Logo
Applicability Explained
Talk to an Expert
Arrow
If Your Business Handles Personal Data, the DPDP Act Likely Applies
The Act applies based on what you do with data, not what industry you are in. If any one of these is true of your business, you are almost certainly in scope. Narrow exemptions exist, and part of our assessment is telling you which ones you can legitimately claim.
You Collect Customer Data Digitally
A name with a phone number is personal data. So is an email address, a delivery address, a payment record, or an IP address tied to a person. If it identifies someone and it sits in a digital system, the Act covers it.
You Employ People In India
Employee records, payroll, attendance logs, CCTV footage and biometric attendance are all personal data. Your workforce data is in scope just as your customer data is.
You Process Data For Your Customers
If you build software, run support, handle payroll or manage infrastructure for other businesses, their customers' data passes through your systems. You may not be the Data Fiduciary, but your contracts will carry the obligations down to you, and your clients will start asking you to prove it.
You Serve Customers In India From Outside It
The Act reaches businesses with no office, no entity and no staff in India. Offering goods or services to people in India is enough to bring you into scope.
You Hold Paper Records That Get Scanned
Physical KYC files, application forms, contracts and archives sit outside the Act until the day you digitise them. Scanning brings them in.
You Share Data With Vendors
Cloud platforms, payment gateways, CRMs, analytics and marketing tools all process data on your behalf. You stay responsible for what they do with it, whatever your contract says.
Your Sector Has Its Own Data Rules
RBI, SEBI, IRDAI, TRAI, DoT and health data requirements do not go away when DPDP arrives. It layers on top, and where both apply, the stricter requirement governs.
Your Website Tracks Visitors
Analytics, advertising pixels, chat widgets and embedded forms all collect personal data, often before a visitor becomes a customer. A business with no customer database of its own can still be processing personal data through its website.
Deadlines Already Live
What We Deliver
Arrow
The Clock Is Already Running on DPDP Compliance
The DPDP Act arrives in stages, and two of them have already passed. Here is what applies to your business today, what is coming, and what it costs to wait. Dates are drawn from the Government's own notifications.
Since 2022: Six Hours to Report a Breach
If your systems were breached tonight, CERT-In requires you to report it within six hours of noticing. That rule has been in force since 2022. The SPDI Rules of 2011 still bind you too, because the provision repealing them has not yet commenced. Neither waits for DPDP. Most businesses discover both the morning they need them.
01
November 2025: The Enforcer Now Exists
The Data Protection Board of India was established in November 2025. Once its powers commence it can inquire into any breach, impose penalties and direct urgent remedial measures. It holds the powers of a civil court. Appeals go to a tribunal. And after penalties in two or more instances, the Government can order your service blocked for the public.
02
Today: Every Month of Delay Adds to the Bill
Consent captured at signup costs nothing. Consent reconstructed for two million existing users is a project. Erasure designed into a system is a feature. Erasure retrofitted across production, backups and every vendor is a rebuild. The work does not get smaller while you wait. It gets more expensive, and there is less time to do it.
03
May 2027: Full Enforcement
Notice, consent, security safeguards, breach reporting, data principal rights and children's data all become enforceable, with penalties reaching ₹250 crore. Businesses that start in 2027 will be remediating under pressure, in a market where every competent firm is already booked. Businesses that start now will be finished.
04
What We Deliver
Talk to an Expert
Arrow
Complete 360° DPDP Compliance Delivered: Assessed, Automated & Managed End to End
Seven stages of one engagement, not seven services to buy. We take your business from first discovery through to running compliance every day, with one team accountable throughout. Start early and compliance gets designed in. Start late and it gets retrofitted into live systems, which costs far more and breaks far more.
Discovery & Assessment
Step 1 of 7
Find Every Place Personal Data Hides in Your Business
You cannot protect data you do not know you hold. Personal data sits in log files, old backups, spreadsheets, test databases and SaaS tools nobody remembers signing up for. Automated discovery scans all of it and classifies what it finds, then maps how data moves in, across and out of your business. Every gap is scored against the Act, the Rules, the SPDI Rules and CERT-In. You also learn whether the Act applies to you at all, and which exemptions you can legitimately claim.
You Get: A full inventory of the personal data you hold, a gap register scored by risk, and a costed roadmap.
Learn More
Notice & Consent
Step 2 of 7
Consent and Notices That Survive a Regulator's Challenge
If a customer ever disputes that they agreed, the law puts the burden on you to prove it. Your notices are drafted to the exact form Rule 3 requires and delivered in the languages the Act mandates, version controlled so a single change updates every language at once. Consent is designed to be specific and unbundled, and your retention schedule reconciles erasure duties with your tax and sector obligations. Also covers children's data, cross-border position, employee data, and re-notifying every user who consented before the Act commenced.
You Get: Notices and consent flows ready to deploy in every language, one retention schedule that satisfies every law that applies to you, and policies your teams can follow.
Learn More
Security Safeguards
Step 3 of 7
Every Security Control the Law Requires, Implemented and Evidenced
This carries the single largest penalty in the Act, up to ₹250 crore. The Rules do not ask you to assess risk and decide for yourself. They name the controls you must have: encryption or masking, access control, logging and monitoring, backups, and a year of retained logs. Your business gets every one of them implemented, then the conflict most businesses miss gets resolved, where DPDP, CERT-In and your sector regulator each demand a different log retention period in a different place. Production data also comes out of your test environments, a finding we make almost every time.
You Get: Encryption, access control, automated monitoring and tested backups live across every system, penetration tested, with evidence documented for each control.
Learn More
Compliance Automation
Step 4 of 7
Let Your Systems Handle Consent, Rights and Grievances
Manual compliance breaks the moment you have more than a handful of requests. Our platform captures every consent as a tamper-proof record tied to the exact notice the customer saw, built to the specification MeitY published for consent management. It runs access, correction, erasure and nomination requests end to end, moves grievances through the statutory response window with automatic escalation, and enforces your retention rules on schedule, including the notice the Rules require before anything is erased.
You Get: A fully automated consent, rights and grievance platform, handling requests around the clock with every action logged as proof.
** If your business intends to register with the Data Protection Board as a Consent Manager, we also build the certifiable platform that registration requires.
Learn More
Vendors & Contracts
Step 5 of 7
Your Vendor's Mistake Becomes Your Liability
The Act holds you responsible for your processors irrespective of any agreement to the contrary. A weak vendor contract does not move that liability, it only hides it. Every vendor and sub-processor gets inventoried, agreements repapered so obligations genuinely flow down, and your cloud and SaaS platforms verified against what those contracts promise. Reassessment runs on an automated cycle, so a vendor that drifts out of compliance does not go unnoticed. If your own business processes data for others, you also get the evidence pack your enterprise customers will ask for.
You Get: Every vendor mapped and risk-rated, contracts repapered so liability flows down, cloud platforms verified, and automated reassessment that flags drift early.
Learn More
Training & Awareness
Step 6 of 7
Your People Are the Gap Technology Cannot Close
Most breaches start with an ordinary decision by someone who did not know the rule. A developer logs a customer ID. A marketer uploads a contact list. A support agent sends data to the wrong person. Every function gets trained on the mistakes it is actually likely to make, completion is tracked automatically as evidence of the organisational measures the Act requires, and your breach response gets rehearsed against the clock before you ever need it.
You Get: A workforce trained for its own risks, completion records that stand as evidence, and a breach response your team has rehearsed.
Learn More
Ongoing Compliance
Step 7 of 7
Stay Compliant as the Law Keeps Changing
DPDP is still being written. Designations, restrictions and standards are yet to be notified, and each one can change what your business must do. We watch every notification and tell you what it means for you. Alongside that, 24/7 monitoring of the systems holding your personal data, drift detection that catches a control slipping before it becomes a finding, breach response on call across all three reporting clocks, and a named point of contact your customers can reach. Independent audit and DPIA are delivered by our partner firms, because assurance has to be independent of the team that built the controls.
You Get: 24/7 monitoring, a monthly compliance report, an audit-ready evidence pack, and a team on call when something goes wrong.
Learn More
Your Obligations
How We Solve These
Arrow
The Obligations Your Business Cannot Afford to Miss
Most businesses assume compliance is a matter of intent, and that handling customer data reasonably will be enough. This Act does not work that way. It sets out eighteen specific duties, and attaches a penalty to every one.
Lawful Basis: Every Use of Personal Data Needs a Reason the Act Recognises
Arrow

You may only process personal data for a lawful purpose, and only with consent or under one of the specific legitimate uses the Act allows. Those uses are narrow and named, covering things like employment, medical emergencies and legal obligations. There is no general "legitimate interest" basis of the kind GDPR provides, which catches businesses that have built their processing around it. Every activity in your business needs a basis you can name and defend, and activities that have no basis have to stop or be re-consented.

Notice: Tell People Exactly What You Are Taking and Why, Before You Take It
Arrow

Before collecting anything you must give a notice that stands on its own, understandable without reading anything else you publish. It has to itemise every field of personal data you are collecting and state the specific purpose for each, along with a link to withdraw consent, exercise rights and complain to the Board. It must be available in English or any of the 22 languages in the Eighth Schedule, at the person's choice. A privacy policy buried inside your terms of service does not satisfy any of this, which is how most businesses currently fail it.

Consent: One Checkbox Cannot Cover Everything You Want to Do
Arrow

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. You cannot bundle five purposes into one tick, and you cannot collect more data than the stated purpose actually requires. Withdrawal has to be as easy as giving consent was, and once someone withdraws you must stop processing and make your vendors stop too. Anything in a consent that infringes the Act is invalid to that extent, so an over-broad consent does not protect you.

Proof of Consent: If It Is Questioned, You Have to Prove It
Arrow

Where consent is your basis and a question arises in a proceeding, the burden of proof sits entirely with you. You must be able to show both the notice that was given and the consent that followed it. Most consent systems record the click and the timestamp but not the version of the notice the person actually saw, which proves nothing about what they agreed to. Without that link between notice and consent, a consent record is an assertion rather than evidence.

Security Safeguards: The Rules Name the Controls, You Do Not Get to Choose
Arrow

This is not a risk-based judgement call. The Rules specify the minimum: encryption, obfuscation, masking or tokenisation; access control on the systems holding personal data; logs, monitoring and review to detect unauthorised access; backups for continuity; and retention of logs and personal data for one year. You must also put security obligations into your processor contracts. This obligation carries the largest penalty in the Act, up to ₹250 crore, which makes it the first place any assessment should look.

Technical and Organisational Measures: Controls Alone Are Not Enough
Arrow

Alongside the technical controls, you must show the policies, governance and trained people that make compliance work in practice. This is the obligation that turns a set of tools into a defensible position. It is evidenced through documentation, training completion records, review cadences and named ownership, not through the technology itself. It is also what the Board would look at when deciding whether your failure was systemic or a lapse.

Breach Reporting: Every Breach, Every Affected Person, No Exceptions
Arrow

On becoming aware of a breach you must intimate every affected person individually, without delay, telling them what happened, what it means for them, what you are doing about it and what they can do to protect themselves. The Board gets an immediate description and then a full report within 72 hours, covering the facts, the cause, the remedial measures and what you told the affected people. There is no severity threshold, so a small breach is as notifiable as a large one. Separately, CERT-In already requires reporting of data breaches within six hours of noticing them, and that duty applies today.

Data Principal Rights: People Can Ask, and You Must Answer
Arrow

People can request a summary of the data you hold, the processing you carry out, and the identity of every other business and processor you shared it with. They can require you to correct, complete, update or erase their data, and you must act on that request. They can also nominate another individual to exercise these rights if they die or become incapacitated. You have to publish how requests are made and what details you need to identify the person, so a working, published process is itself part of the obligation.

Grievance Redressal: A Published Route, With a Deadline
Arrow

You must provide a readily available grievance mechanism covering any act or omission relating to someone's personal data or their exercise of rights, and respond within the period the Rules set. The mechanism has to be prominently published, and you must implement the technical and organisational measures that let you actually meet the response window. Done properly this protects you, because a person is required to exhaust your grievance process before approaching the Board. A weak mechanism removes that protection and sends complaints straight to the regulator.

Retention and Erasure: Holding Data Longer Than You Need Is a Breach
Arrow

Data must be erased once the purpose is served or consent is withdrawn, whichever comes first, and you must cause your processors to erase their copies too. For large e-commerce, online gaming and social media platforms above the user thresholds the Rules set, data must be erased after three years of inactivity, and the person must be warned at least 48 hours before it happens. Separately, the Rules require a minimum one-year retention of personal data, traffic data and logs. Reconciling an erasure duty with a retention floor, on top of your tax and sector obligations, is where most businesses get stuck.

Accuracy: Wrong Data Used for a Decision Is Itself a Failure
Arrow

Where personal data is likely to be used to make a decision that affects someone, or disclosed to another business, you must ensure it is complete, accurate and consistent. This is narrower than a general data quality duty, and that scoping matters: it bites precisely where the consequences for the individual are real, such as credit decisions, eligibility checks, employment screening and pricing. If your systems hold three different versions of a customer record and a decision is made on the wrong one, the obligation has been breached.

Children and Persons with Disability: The Highest Bar in the Act
Arrow

Anyone under 18 is a child, with no lower threshold. You need verifiable parental consent before processing any child's data, and you must carry out due diligence that the person claiming to be the parent is an identifiable adult. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright, with no consent available to permit them. You must also not undertake any processing likely to cause a detrimental effect on a child's wellbeing, whatever consent you hold. Comparable rules apply to lawful guardians of persons with disability, where the guardian must be verified as court or authority appointed. Penalties reach ₹200 crore.

Vendors and Processors: Their Failure Is Your Liability
Arrow

You remain responsible for compliance irrespective of any agreement to the contrary, so a contract can allocate cost between you and a vendor but cannot move the legal liability. You must have a valid contract in place before engaging any processor for activity related to offering goods or services. That contract has to carry the security obligations down, and you must be able to make the processor cease processing on withdrawal and erase on instruction. If your cloud provider, CRM or payment gateway mishandles data you gave them, the Board looks at you.

Cross-Border Transfer: The Act Is Permissive, Your Regulator May Not Be
Arrow

Personal data may be transferred outside India, subject to any requirements the Government specifies, and no country restrictions have been notified so far. The binding constraints today come from elsewhere: RBI requires payment system data to be stored in India, DoT requires subscriber data and call records here, IRDAI imposes its own rules, and health data under the national health ecosystem must remain in India. Businesses designated as Significant Data Fiduciaries may also face localisation on specified categories. If you run on a foreign cloud, your sector rather than the Act usually decides what is allowed.

Significant Data Fiduciary: Higher Obligations for Businesses the Government Designates
Arrow

The Government may designate a business or class of businesses as a Significant Data Fiduciary, based on the volume and sensitivity of data processed, the risk to people's rights, and considerations of state security and public order. Designation adds an India-based Data Protection Officer answerable to your board, an independent data auditor, an annual Data Protection Impact Assessment and audit reported to the Board, and a duty to verify that your algorithmic systems do not put people's rights at risk. No designations have been made yet, which means this is a preparation question rather than a current duty, and preparing quietly beats reacting publicly.

Re-Notify Existing Customers: The Act Reaches Backwards
Arrow

The Act does not only govern data you collect from now on. Everyone who gave you consent before the Act commenced must be given a fresh notice, describing the personal data you hold, the purpose you process it for, how to exercise their rights and how to complain to the Board. You may continue processing until they withdraw consent, but the notice itself is not optional and must be given as soon as reasonably practicable. For a business with a large existing customer base this is a substantial one-time project, and almost nobody has budgeted for it.

Answer the Regulator: Records You Cannot Produce Are Records You Do Not Have
Arrow

The Central Government may require you to furnish information for specified purposes at any time, and directions issued by the Data Protection Board are binding on you. In some cases you may be directed not to disclose that a request was made. The Board has the powers of a civil court in relation to summoning people, taking evidence and inspecting records. Being able to retrieve your notices, consent records, logs and evidence quickly is part of compliance, not an administrative afterthought.

Publish Your Contact: Someone Has to Be Reachable
Arrow

You must prominently publish the business contact details of a person who can answer questions about how you handle personal data, on your website or app. Those details must also be repeated in every response you send to someone exercising their rights, which is a system behaviour rather than a web page and is routinely missed. If you are designated a Significant Data Fiduciary, this person must be your Data Protection Officer. It is one of the few obligations anyone, including a regulator, can verify from outside your business in seconds.

What You Gain
See How We Deliver
Arrow
Compliance That Strengthens Your Business, Not Just Protects It
Compliance is the reason you start. It is rarely the reason you are glad you did. The work leaves behind cleaner data, lower risk, faster sales cycles and lower costs, and most businesses find those worth more than the deadline that forced them into it.
You Finally Know What You Are Holding
Most businesses cannot answer basic questions about their own data. Where customer records actually live, which systems hold duplicates, what that decade-old database still contains. Discovery answers all of it, and that inventory keeps paying long after the compliance work is finished.
A Breach Does Less Damage
Encryption, access control and data minimisation do not prevent every incident, but they decide how much is exposed when one happens. Less data held, fewer people with access, encrypted at rest. A breach that would have been a crisis becomes a contained event.
Enterprise Deals Close Faster
Large customers send security and privacy questionnaires before they sign, and those take weeks to answer from scratch. With an evidence pack already assembled, your team answers in days. Procurement stops being the slowest part of your sales cycle.
You Spend Less Time On Manual Compliance Work
Rights requests, grievances, consent changes and erasure requests arrive whether or not you have built for them. Automated, they cost almost nothing per request. Handled manually across email and spreadsheets, every one pulls support and engineering time away from the work you hired them for.
Your Customers Are Bbout To Demand This Anyway
As enterprises complete their own programmes, they push the obligations down their supply chain. Your contracts will be reopened and DPDP terms added. Being ready before the request arrives is a commercial advantage, not just a legal one.
You Are Ready For Whatever Comes Next
The same controls carry across GDPR, HIPAA and most sectoral regimes, so entering a new market does not mean starting over. The same evidence pack answers investor and acquirer due diligence, where data liability is now a standard question.
You Stop Paying To Store Data You Do Not Need
Retention rules mean data is deleted when its purpose ends instead of accumulating forever. Smaller databases, smaller backups, lower storage and infrastructure cost, and far less to migrate the next time you change platforms.
You Have A Defensible Position If Something Goes Wrong
When the Board sets a penalty it weighs what you did to mitigate, whether the failure was repeated, and how quickly you acted. Two businesses can suffer the same breach and face very different outcomes. Evidence of implemented controls, trained staff and a rehearsed response is what separates them.
Why AccuCore
Start a Conversation
Arrow
Trusted With International Data Privacy Compliance, Now Ready for Yours
DPDP is not our first data protection law. We have built compliance under GDPR in Europe and HIPAA in the United States, where enforcement is already real. That experience is why we can tell you which obligations matter most and which parts of this law are still unfinished.
01
Built, Not Advised
We Build Compliance Into Your Systems, Not Into a Report
Most of this Act is an engineering problem. Consent records that hold up as evidence, erasure that reaches every copy including backups, rights portals, encryption and access logs all have to be built into the systems you already run. An advisory firm hands you a report and leaves that part to your team. We write the code, configure the platforms and hand over something that works.
Learn More
02
Already Built
Our Compliance Platform Is Live, Not on a Roadmap
Consent capture, rights handling, grievance workflow and automated retention already run as working software, built to the specification MeitY published for consent management. You are not funding a first build or waiting on a release. It gets configured for your business and deployed, running inside your environment under your control, not as data parked with us.
Learn More
03
Proven Under Stricter Law
We Have Done This Under GDPR and HIPAA
ACS has delivered privacy compliance work under GDPR for clients across multiple European countries, and under HIPAA in the United States. GDPR taught us how to build consent records that survive a challenge, which is exactly what this Act now demands of you. We are not learning data protection on your project.
Learn More
04
Regulatory Depth
We Know Which Rule Wins When Two Regulators Disagree
Your log retention is the clearest example. The Rules require one year. CERT-In requires its own period, held in India. RBI requires five years after an account closes. These are not alternatives you choose between, and getting it wrong means failing one regulator to satisfy another. We design one architecture that satisfies all of them, and we do the same across RBI, SEBI, IRDAI, TRAI and health data rules.
Learn More
05
One Engagement
The Problems That Need a Lawyer, an Accountant and an Engineer at Once
Your retention schedule has to satisfy the Act's erasure duty and your tax obligations simultaneously. That is not a legal question or a finance question or an engineering question. It is all three, and split across three vendors it becomes an argument nobody owns. We bring technology in house, with legal opinions from our partner law firms and financial work from our partner accounting firms. Independent audit stays with them by design, because the Act requires an auditor independent of whoever built the controls.
Learn More
06
We Stay
Compliance Does Not End When the Project Does
The law is still being written, your systems keep changing, and both create new gaps. We monitor your controls, track every notification that affects you, keep your evidence current and stay on call when something goes wrong. Most firms hand over a report and an invoice. We are still there the day you actually need help.
Learn More
07
Straight Answers
We Run This on Ourselves, and We Tell You What Is Unsettled
A law firm cannot build your consent system. A software vendor cannot tell you what the Act requires. We do both, and we hold ourselves to the same standard: AccuCore runs its own business against this framework. We will also tell you what nobody else will, which is that parts of this law are unfinished. Significant Data Fiduciary designations have not been made, cross-border restrictions have not been notified, and the standards for consent platforms have not been published. Anyone claiming certainty on those is guessing.
Learn More
For Questions That Matter
Connect Now
Arrow
Answers to the DPDP Questions Every Business Leader Asks
Is the DPDP Act actually being enforced yet?
Arrow

Not yet, and we will not pretend otherwise. The penalty provisions have not commenced, and the Data Protection Board has no members appointed on the public record. Full enforcement arrives in May 2027. But two things already bind you today: CERT-In requires breach reporting within six hours, and the SPDI Rules of 2011 still apply because the provision repealing them has not commenced. Most businesses are already non-compliant with both.

Why should we trust a technology company with a legal requirement?
Arrow

Because most of DPDP is an engineering problem. Notices, consent records, erasure, rights portals, encryption and logging are all built, not advised. We have delivered privacy compliance work under GDPR in Europe and HIPAA in the United States, two of the strictest regimes in the world. The legal opinions, contract drafting and independent audit come from our partner law and accounting firms, who are independent of the team that builds the controls, as the Act requires for audit.

Can we wait until closer to the deadline?
Arrow

You can, and many will. Two things make it expensive. The work does not shrink while you wait, and the supply of people who can do it does not grow. Every business facing the same fixed date will be looking for the same help in the same months. The other cost is technical: consent and erasure designed into a system are features, and retrofitted into a live one they are rebuilds.

We are a small business. Does this really apply to us?
Arrow

Yes. The Act sets no revenue or headcount threshold. A ten-person company with a customer database has the same core obligations as a listed enterprise. The Government has the power to exempt certain classes of business, including startups, but no such exemption has been notified. Planning on the assumption that one will arrive is a risk, not a strategy.

What happens to our data during the engagement?
Arrow

A fair question to ask a firm you are hiring to protect data. We work from the minimum access needed, prefer metadata and schema over record-level data wherever discovery allows, and sign the same processing terms we would advise you to require from any vendor. If we hold anything of yours, it is returned or deleted at the end of the engagement, with confirmation in writing.

We already comply with GDPR. Does that cover us?
Arrow

It puts you well ahead, but not across the line. Several DPDP requirements have no GDPR equivalent, including re-notifying customers who consented before the Act, the specific form the notice must take, the absence of any severity threshold for breach notification, and the duties the Act places on individuals. GDPR also has a legitimate interest basis that DPDP does not, so processing you rely on today may have no home under this Act.

We already have ISO 27001. Is that not enough?
Arrow

No, though it helps. ISO 27001 is a security management standard. DPDP is a data protection law with obligations ISO does not touch, including notice, consent, erasure, rights requests and breach reporting timelines. Your ISMS gives you a strong evidence base for the security safeguards, which is one obligation of eighteen. There is also no DPDP certification of any kind, so no certificate makes you compliant.

Can we do this ourselves?
Arrow

Parts of it, yes. Policy drafting and training are achievable in house if you have the capacity. The harder parts are data discovery across systems nobody has mapped, building consent records that hold up as evidence, and reconciling retention rules that point in opposite directions. Most businesses that start alone come back for those three.

Our vendors hold most of our customer data. Is that not their problem?
Arrow

No. The Act makes you responsible for your processors irrespective of any agreement to the contrary. A contract can allocate cost between you and a vendor, but it cannot move the legal liability. If your cloud provider or CRM mishandles data you gave them, the Board looks at you.

Is our employee data covered too, or only customer data?
Arrow

Both. Employee records, payroll, attendance, CCTV and biometric attendance are all personal data. The Act does allow processing for employment purposes without separate consent, but that only removes the consent requirement. Notice, security, retention, rights and breach obligations all still apply to your workforce data exactly as they do to customer data.

We operate in multiple countries. Which entity is actually in scope?
Arrow

Any entity processing personal data in India is in scope. So is an entity outside India that offers goods or services to people in India, even with no office, staff or subsidiary here. Group companies are separate persons under the Act, so sharing data between your Indian and overseas entities is a disclosure, not an internal transfer, and needs to be papered accordingly.

Can we keep using AWS, Google Cloud or servers outside India?
Arrow

Under DPDP itself, generally yes. The Act permits transfer abroad subject to conditions the Government may set, and no country restrictions have been notified. The real constraints come from your sector. RBI requires payment data in India, IRDAI and DoT impose their own rules, and health data under the national health ecosystem must stay in India. Your sector, not the Act, usually decides this.

What happens to our existing customers who already gave us consent?
Arrow

They have to be given a fresh notice. The Act requires you to go back to everyone who consented before it commenced, tell them what data you hold, why you process it and how to exercise their rights. For a business with a large customer base this is a project on its own, and almost nobody has budgeted for it. It also has to be done as soon as reasonably practicable, not at the deadline.

Do we need to do everything at once?
Arrow

No, and you should not try. The assessment produces a sequenced plan, and the sequence matters. Discovery comes first because nothing else can be scoped without it. Security safeguards come early because they carry the largest penalty. Consent and rights work follows once you know what data you hold. Retention and vendor work can run in parallel.

Will this disrupt our systems or slow our team down?
Arrow

Most of it runs alongside normal operations. Discovery is read-only and touches nothing. Policy, contract and training work happens in parallel. The parts that change systems, consent capture, rights handling and erasure, are built and tested before anything goes live. The sequence exists precisely so that nothing is rebuilt under pressure.

Who owns compliance internally, and how much of our time will this take?
Arrow

You need one accountable owner and access to the people who know your systems. In practice that is a few hours a week from a technical lead during discovery, decisions from whoever owns legal or finance, and a named point of contact throughout. We do not run an engagement that requires your team to become privacy specialists.

How long does it take and what does it cost?
Arrow

It depends entirely on how much data you hold and how many systems hold it. A business with one product and a single database is a very different exercise from one with fifteen years of acquisitions and no data map. We will not quote a number without looking, and any firm that quotes before seeing your estate is guessing. The assessment produces a costed plan, and you decide what to do with it.

Do we need to appoint a Data Protection Officer?
Arrow

Only if the Government designates you a Significant Data Fiduciary, and no designations have been made yet. If it does, the role has to be an individual based in India who answers to your board, which is not something an outside firm can be for you. Every business, designated or not, must publish a contact who can answer questions about how it handles personal data. That role we can fill.

Do we need to register as a Consent Manager?
Arrow

Almost certainly not. A Consent Manager is a specific licensed entity registered with the Data Protection Board, requiring an Indian company with at least two crore in net worth and independent certification. Registration opens in November 2026. Running your own consent system is a completely different thing and needs no registration at all.

What if the law changes before 2027?
Arrow

It will. Several parts are still unwritten, including Significant Data Fiduciary designations, cross-border restrictions and the standards for consent platforms. A corrigendum has already amended the Rules once. Nothing we build depends on the unsettled parts, and tracking changes is part of our ongoing service, not a separate charge.

What are you actually responsible for if we get this wrong?
Arrow

Legally, the obligations sit with you and cannot be transferred to a vendor, which is what the Act says about every processor. What we are accountable for is the work we deliver: that the controls we build match what the Rules require, that the evidence is documented, and that we tell you plainly where the law is unsettled rather than guessing. Commercial terms are set out in the engagement contract.

Let's Talk
Get Your Free Assessment
Arrow
Your DPDP Compliance Starts With One Conversation
Tell us where your business stands and we will tell you what the Act actually requires of you. A senior consultant responds within one business day, and the first call is a free 30-minute walkthrough of where you stand. No pitch, no obligation.
Valid number
Start the Conversation
Thank you. A senior consultant will review your submission and respond within one business day, with a short written summary of where your business stands against the Act.
We couldn’t submit your request at the moment. Please try again shortly or contact us at contact@accucoresolutions.com.