Now partnering with TechDefence to deliver stronger cyber security outcomes — Learn more

Cyber News
All news →
Compliance · DPDP

DPDP Act readiness

The Digital Personal Data Protection (DPDP) Act, 2023 is India's law on processing digital personal data. It sets duties for Data Fiduciaries — organisations that decide why and how personal data is processed — and rights for Data Principals, the individuals the data is about.

Overview

In plain English

The DPDP Rules were notified in November 2025, with obligations coming into force in phases. Organisations should use the transition period to map their data, fix consent and prepare for breach notification.

Instruments covered

  • Digital Personal Data Protection Act, 2023
  • Digital Personal Data Protection Rules, 2025 (obligations phased in)

Last reviewed:

Key requirements

What DPDP expects

  1. Lawful processing and consent

    Process personal data for a lawful purpose with free, specific, informed and unambiguous consent, or on another legitimate use.

  2. Notice

    Give clear notice describing the personal data and the purpose of processing.

  3. Reasonable security safeguards

    Protect personal data with reasonable security safeguards to prevent a breach.

  4. Breach intimation

    Inform the Data Protection Board and each affected Data Principal of a personal data breach.

  5. Data Principal rights

    Support rights to access, correction, erasure and grievance redressal.

  6. Retention limits

    Erase personal data when the purpose is served, unless retention is required by law.

  7. Significant Data Fiduciary duties

    Appoint a Data Protection Officer, an independent data auditor, and carry out periodic Data Protection Impact Assessments.

How TrustNet helps

From gap to evidence

  • Data mapping and inventory
  • Consent and notice review
  • Breach notification process and playbooks
  • Grievance redressal process design
  • Security safeguards assessment

Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.

Services mapped to DPDP

FAQ

DPDP FAQ

When does the DPDP Act apply?

The Act is law, and the Rules notified in November 2025 bring obligations into force in phases. Organisations should prepare now rather than wait for the final deadline.

Who must we notify after a data breach?

The Data Protection Board of India and each affected Data Principal, in the form and manner set out in the Rules.

Are we a Significant Data Fiduciary?

The Government notifies Significant Data Fiduciaries based on factors like the volume and sensitivity of data. We help you assess your exposure.

Book a consultation

Get DPDP-ready

We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.

support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438

Under attack right now? Go to emergency help →

Today in Cyber

What's happening in cyber security

See all news →

Source: The Hacker News — headlines only, each linking to the original article.

Chat with us