India's data protection law (DPDP Act 2023) is now fully notified. For tech companies, the exposure is real — up to ₹250 Crore in penalties, and repeat violations can get your platform blocked. Sharing our compliance framework — covers key obligations, timelines, and a full action checklist your team can use right away.
Thinkbiz Team
Thinkbiz Professional LLP

Share a few details and we'll open the full document — read it here or download a copy to keep.
Free · No spam · Takes 10 seconds
About the author
Thinkbiz Team
Thinkbiz Professional LLP
Member of the multi-disciplinary team at Thinkbiz Professional LLP, Noida.
Need expert advice on this topic?
Book a free 30-min call with one of our partners.
Summary
India's Digital Personal Data Protection (DPDP) Act, 2023 became fully enforceable when the DPDP Rules, 2025 were notified on 13 November 2025. Every organisation that determines why and how personal data is processed — a Data Fiduciary under Section 2(i) — now works to a fixed compliance clock that closes around May 2027, with maximum penalties of INR 250 crore and, for repeat offenders, the power for the Central Government to block public access to the platform entirely.
The Act applies to any Data Fiduciary — defined in Section 2(i) as any person who, alone or in conjunction with others, determines the purpose and means of processing personal data. This covers companies, LLPs, partnerships, HUFs, associations of persons and the State itself. Liability rests with the Fiduciary under Section 8(1) regardless of whether processing is outsourced to a third-party Data Processor.
The definition of personal data in Section 2(t) is deliberately broad: any data about an identifiable individual, including names, phone numbers, email addresses, IP addresses, device identifiers, transaction records and health records. Data collected on paper and later digitised is equally covered — a scanned KYC form becomes digital personal data. Only genuinely anonymised data falls outside the Act's scope.
The DPDP Rules 2025 commence in three stages, each measured from 13 November 2025:
Penalties are set by the Schedule to Section 33 and are calibrated so that non-compliance is never economically rational:
Section 37 carries the most severe consequence. Where the Board has imposed monetary penalties on a Data Fiduciary on two or more separate occasions, the Central Government may direct that public access to that Fiduciary's platform or computer resources be blocked — effectively a forced shutdown of digital operations.
The full 17-page framework sets out the end-to-end Data Fiduciary compliance process flow mapped to each applicable Section and Rule, the complete penalty schedule, the commencement timeline, and a comprehensive compliance checklist mapping every material action to its regulatory reference, deadline, priority level and penalty exposure — designed to be used as a master action register for a DPDP compliance programme. It also includes an appendix of key statutory definitions with their practical impact.
Prepared by Thinkbiz Professionals LLP, a multi-disciplinary firm of Chartered Accountants, Company Secretaries, Lawyers and Registered Valuers based in Noida, advising clients across India, the UAE, Singapore, Malaysia and the United States. This summary is general advisory information and does not constitute legal advice.