DPDP Act Explained: What India’s Data Protection Law Means for Your Organisation in 2026

DPDP Act 2023 Explained: What India’s Data Protection Law Means for Organisations in 2026

India’s data protection landscape has moved from policy discussion to implementation. The Digital Personal Data Protection (DPDP) Act, 2023 and Digital Personal Data Protection Rules, 2025 have been notified, with their provisions being brought into force in phases.

For organisations that collect, store or process digital personal data, 2026 is the preparation year. The principal operational compliance requirements are scheduled to take effect on 13 May 2027, while specific provisions concerning Consent Managers take effect earlier, on 13 November 2026.

For HR, payroll, finance and government systems that handle large volumes of employee and citizen information, understanding this timeline is essential.

What Is the DPDP Act, 2023?

The Digital Personal Data Protection Act, 2023 establishes India’s legal framework for processing digital personal data. It sets out responsibilities for organisations handling personal data and provides rights and protections for individuals, known as Data Principals.

The Act covers digital personal data processed in India and also applies to certain processing outside India where the processing is connected with offering goods or services to Data Principals in India.

Personal data can include information such as:

  1. Name, address, email address and telephone number
  2. Government-issued identity information
  3. Financial and employment information
  4. Location and online identifiers
  5. Photographs and other identifying information
  6. Biometric information where collected digitally
  7. Health or education information where processed as part of an organisation’s activities

The practical implication is straightforward: if an organisation’s HRMS, payroll, citizen-service portal or enterprise application stores information that can identify an individual, DPDP compliance should form part of its data-governance planning.

The DPDP Compliance Timeline

The DPDP framework has a phased commencement structure rather than a single “go-live” date.

13 November 2025 — Framework notified

The DPDP Rules, 2025 were notified and the Data Protection Board of India was established as part of the phased implementation framework.

13 November 2026 — Consent Manager provisions

The provisions relating to the registration and obligations of Consent Managers take effect.

This date is particularly relevant to organisations intending to operate as Consent Managers. It should not be interpreted as a requirement for every organisation that collects consent to register as a Consent Manager.

13 May 2027 — Principal operational provisions

The major operational requirements for Data Fiduciaries and Data Principals are scheduled to take effect, including provisions relating to notice, security safeguards, personal data breaches, Data Principal rights, children’s data, retention and erasure, and additional obligations applicable to Significant Data Fiduciaries.

The key message for organisations is therefore simple: 2026 is the time to prepare, not wait.

Six Practical DPDP Compliance Principles

Rather than treating DPDP as a document that sits with the legal team, organisations should translate its requirements into operational controls.

1. Lawful and transparent processing

Personal data should be processed on a valid legal basis and individuals should receive appropriate information about how their data is being processed.

2. Purpose limitation

Organisations should clearly understand why personal data is being collected and avoid using it for unrelated purposes without an appropriate basis.

3. Data minimisation

Only the personal data reasonably required for the intended business or service purpose should be collected.

4. Data accuracy

Organisations should maintain appropriate processes for keeping personal data accurate and enabling correction when required.

5. Retention and erasure

Personal data should not be retained indefinitely without a legitimate reason. Organisations should define retention policies and establish processes for deletion or erasure when applicable, while accounting for situations where another law requires information to be retained.

6. Security safeguards

Organisations need appropriate technical and organisational safeguards to protect personal data against unauthorised access, loss, misuse and other security risks.

These principles should ultimately be reflected in systems, workflows, access controls, audit trails and operational procedures rather than remaining only in policy documents.

Data Principal Rights Under the DPDP Act

The DPDP framework gives individuals important rights in relation to their personal data.

These include rights relating to:

  1. Access to information about personal data and its processing
  2. Correction of inaccurate or incomplete personal data
  3. Erasure of personal data where applicable
  4. Withdrawal of consent
  5. Grievance redressal
  6. Nomination of another individual to exercise specified rights in the event of death or incapacity

Organisations therefore need more than an email address for privacy requests. They need documented workflows that can identify the request, authenticate the requester, route it to the appropriate team, track actions and maintain evidence of completion.

Who Does the DPDP Act Apply To?

The framework primarily regulates organisations acting as Data Fiduciaries and Data Processors handling digital personal data within its scope.

It can also apply to organisations outside India where processing is connected with offering goods or services to Data Principals in India.

Large organisations that may be classified as Significant Data Fiduciaries (SDFs) have additional responsibilities under the framework. Depending on the applicable requirements, these can include appointing a Data Protection Officer in India, conducting Data Protection Impact Assessments, undertaking audits and meeting other governance obligations.

For large enterprises, PSUs and government organisations processing employee or citizen data at scale, determining whether additional obligations may apply should be part of the 2026 compliance assessment.

What Organisations Should Do in 2026

The most important practical question is not simply, “Is DPDP live?”

It is:

“What should our organisation do before the May 2027 compliance date?”

A sensible preparation programme should include:

  1. Map personal-data flows across HR, payroll, finance, applications and third-party systems.
  2. Identify data categories collected from employees, citizens, customers and other individuals.
  3. Review collection and notice processes to ensure individuals receive appropriate information.
  4. Review access controls so employees can access only the information required for their responsibilities.
  5. Define retention schedules for different categories of personal data.
  6. Establish rights-request workflows for access, correction, erasure and other applicable requests.
  7. Review third-party processors and vendors that handle personal data.
  8. Strengthen incident-response procedures and establish clear escalation paths for personal-data breaches.
  9. Maintain audit trails and compliance evidence so the organisation can demonstrate what happened and when.
  10. Assess whether SDF obligations could become relevant based on the organisation’s scale, data processing and applicable government notifications.

This preparation can significantly reduce the disruption associated with implementing compliance controls later.

DPDP Penalties: What Organisations Need to Know

This preparation can significantly reduce the disruption associated with implementing compliance controls later.

DPDP Penalties: What Organisations Need to Know

The DPDP Act provides for significant financial penalties for specified breaches. The maximum amounts specified in the Act include:

Violation Maximum Penalty

Failure to take reasonable security safeguards resulting in a personal data breach ₹250 crore

Failure to notify a personal data breach as required ₹200 crore

Non-compliance relating to children’s personal data ₹200 crore

Failure by a Significant Data Fiduciary to fulfil specified obligations ₹150 crore

Breach of other provisions of the Act ₹50 crore

Breach of specified Data Principal duties ₹10,000

The important distinction is that these are statutory maximum penalties, not automatic fines.

The principal penalty and enforcement provisions form part of the phased commencement framework, with the major operational provisions scheduled to apply from 13 May 2027. Organisations should therefore use 2026 to identify and address weaknesses rather than waiting for the enforcement date.

How CSII Helps Organisations Prepare for DPDP Compliance

For HRMS, payroll and government systems, DPDP readiness should be built into the technology environment rather than treated as a separate policy exercise.

CSII follows an Assess → Align → Implement → Monitor → Assure approach.

Assess

Identify where personal data enters the system, how it moves between modules and which users, applications and third parties can access it.

Align

Map business processes and system controls against applicable DPDP requirements, including data access, consent, retention, security and rights-management processes.

Implement

Configure appropriate role-based access, audit trails, workflow controls, security measures and data-management processes within the application environment.

CSII’s Government HRMS & Finance Management System is designed to support structured HR and finance operations with auditability and compliance-oriented controls.

Its HRMS & Payroll platform can support organisations in managing employee information, payroll processes, access controls and related workflows in a structured digital environment.

Monitor

Organisations should continuously monitor access, data activity, retention, incidents and compliance workflows rather than treating compliance as a one-time project.

For broader employer obligations, organisations can also refer to CSII’s 2026 HR compliance guide and PF, ESI and TDS compliance guide.

Assure

Audit trails, reports and documented processes provide evidence that controls are operating as intended and help management identify areas requiring improvement.

For organisations handling employee information at scale, this approach can turn DPDP readiness from a compliance checklist into a measurable technology and governance programme.

Why DPDP Preparation Matters for HRMS and Government Systems

HRMS and payroll platforms can contain extensive personal information, including employee identity details, employment records, financial information, attendance information and, depending on implementation, biometric or health-related information.

Government and PSU systems may process personal data at an even larger scale.

This makes data governance particularly important across:

  1. Employee onboarding
  2. Payroll and salary processing
  3. Attendance and biometric systems
  4. Leave and performance management
  5. Employee documents
  6. Benefits and statutory deductions
  7. Pension and retirement processes
  8. Citizen-facing government services
  9. Finance and administrative systems

A strong DPDP programme therefore needs collaboration between HR, IT, security, legal, finance and system administrators.

Frequently Asked Questions

When did the DPDP Act come into force?

The DPDP Act, 2023 and DPDP Rules, 2025 were notified as part of a phased implementation framework. Different provisions commence on different dates. The key dates are 13 November 2025, 13 November 2026 and 13 May 2027.

What are the major DPDP compliance deadlines?

The principal dates are:

  1. 13 November 2025: DPDP Rules notified and Board established as part of the implementation framework.
  2. 13 November 2026: Consent Manager registration provisions commence.
  3. 13 May 2027: Principal operational compliance provisions commence for most Data Fiduciaries.

Who is a Data Fiduciary?

A Data Fiduciary is an entity that determines the purpose and means of processing personal data under the DPDP Act.

What is a Significant Data Fiduciary?

A Significant Data Fiduciary is a Data Fiduciary that may be notified as significant based on factors specified under the Act and Rules. Such organisations are subject to additional compliance and governance requirements.

What is the maximum DPDP penalty?

The maximum penalty specified under the DPDP Act is ₹250 crore for failure to take reasonable security safeguards resulting in a personal data breach.

This is a maximum statutory penalty, not an automatic fine for every security incident.

Is there a 90-day deadline for every erasure request?

Organisations should not treat 90 days as a universal erasure deadline. The applicable requirements depend on the relevant DPDP provisions, Rules and circumstances of processing. Organisations should instead establish documented rights-request workflows with appropriate timelines and escalation mechanisms.

Does DPDP apply to HR and payroll data?

Yes. Digital personal data processed through HRMS and payroll systems can fall within the scope of the DPDP framework. Examples include employee identity information, contact details, employment records, financial information and other information that relates to an identifiable individual.

Does DPDP apply to government and PSU organisations?

The applicability depends on the organisation’s role, processing activities and any applicable statutory exemptions or government notifications. Government and PSU organisations handling significant volumes of personal data should therefore conduct a structured applicability and readiness assessment.

How does CSII help with DPDP readiness?

CSII helps organisations embed data-governance and security-oriented controls into HRMS and enterprise workflows through an Assess → Align → Implement → Monitor → Assure approach.

Its solutions can support structured access control, auditability, workflow management, data governance and compliance reporting.

Contact CSII’s team to discuss a DPDP readiness assessment for your organisation.

Conclusion

DPDP compliance should not be treated as a project that begins in May 2027.

The phased implementation gives organisations valuable preparation time. 2026 is the opportunity to map personal data, review systems, strengthen security, establish rights workflows, define retention policies and create evidence-based governance processes.

For organisations running HRMS, payroll, finance and government applications, the right approach is to build privacy and security controls into the technology itself rather than bolt them on after implementation.

Prepare now. Build the controls into your systems. Be ready before the compliance deadline arrives.

CSII Software Solutions helps enterprise, PSU and government organisations build structured digital HR and enterprise systems with security, auditability and compliance-oriented capabilities.

Disclaimer: This article reflects the Digital Personal Data Protection Act, 2023, Digital Personal Data Protection Rules, 2025 and the notified commencement framework available as of September 2026. Organisations should verify the latest notifications, amendments, rules and guidance issued by the Ministry of Electronics and Information Technology (MeitY) and the Data Protection Board of India before making legal or compliance decisions.