1. When do businesses have to comply with the DPDPA?
The Rules were notified on 14 November 2025 and the law is rolling out in phases. The core operational obligations — notice and consent, data-principal rights, breach reporting, and SDF duties — become enforceable around mid-2027, roughly 18 months after notification. The Data Protection Board and governance provisions are already live.
2. What are the penalties under the DPDP Act?
Up to ₹250 crore per instance for failing to maintain reasonable security safeguards, up to ₹200 crore for breach-notification and children-related failures, up to ₹150 crore for an SDF's lapses, and up to ₹50 crore for other breaches.
3. Is the DPDPA the same as GDPR?
No. The DPDPA is digital-only, more consent-centric, and has narrower lawful bases (no "legitimate interests"), stricter rules for children, and a negative-list approach to cross-border transfers. Many companies will comply with both, and the security controls overlap heavily.
4. Can one company be the Data Fiduciary, Data Processor, and Consent Manager?
Partly. A Data Fiduciary can process the data itself — so it is effectively its own processor — and it can capture, store, and let people withdraw consent directly; you do not need a Consent Manager to collect consent. But the Consent Manager is a separate, regulated role: under the DPDP Rules, 2025 it must be an independent, Board-registered company (with a minimum net worth and strict conflict-of-interest rules) and it is barred from also being the Data Fiduciary or Processor for the same person's data. So one party can handle the fiduciary role, the processing, and in-house consent capture — but it cannot also be the official registered Consent Manager for its own users.