Skip to content
Shastra · The DPDP Act

India's data protection law, in plain English.

Pre-registration open

The Digital Personal Data Protection Act applies to almost any organisation handling the personal data of people in India. This is what DPDP compliance actually asks for, without the legalese.

The vocabulary

The eight terms that matter.

Most DPDP confusion is vocabulary. Learn these and the rest of the Act reads normally.

Data Fiduciary
You, if you decide why and how personal data gets processed. The Act puts the obligations here.
Data Principal
The person the data is about. They hold the rights you have to service.
Data Processor
A third party processing data on your behalf. You stay accountable for what they do.
Significant Data Fiduciary
A larger or higher-risk fiduciary, designated by the government, with extra duties including audits and impact assessments.
Consent Manager
A registered intermediary through which a Data Principal can give, manage and withdraw consent.
ROPA
Record of Processing Activities: the documented account of what you process, why, and who you share it with.
DPIA
Data Protection Impact Assessment: a structured risk assessment, required of Significant Data Fiduciaries.
Cross-border transfer
Sending personal data outside India, permitted except to countries the government restricts.
The obligations

What the Act asks of you.

Grouped by the work each one creates rather than by section number.

  • Lawful basis and notice

    A valid reason to process, and a notice people can actually understand.

  • Consent management

    Where you rely on consent it must be specific, informed, and as easy to withdraw as to give.

  • Purpose limitation

    Data collected for one purpose cannot quietly serve another.

  • Data principal rights

    Access, correction, erasure and grievance, each on a defined clock.

  • Children’s data

    Verifiable parental consent, and no tracking or targeted advertising.

  • Breach notification

    Report personal data breaches, on a deadline, with specified detail.

  • Processor accountability

    You remain responsible for every vendor that touches the data.

  • Retention limits

    Stop keeping data once its purpose is served.

The timeline

What the 2025 Rules changed.

The DPDP Rules were notified in November 2025 with a transition period to full compliance, putting the deadline around 12 May 2027. Some obligations land earlier.

More detail

That is our reading of the published timeline, not legal advice. Where the specifics matter, get advice from a qualified practitioner. Please do not take a legal position from a product page.

Why it is hard

The gap is operational, not legal.

Most teams can read the Act and follow it. The difficulty is that satisfying it means knowing, continuously, what personal data you hold, why, who you share it with, and what each person agreed to.

More detail

That information usually lives across several systems and nobody’s head in particular, which is why we treat DPDP data governance as an infrastructure problem rather than a documentation exercise.

Questions

Common questions.

Who does the DPDP Act apply to?
Broadly, any organisation processing the digital personal data of people in India, including processing outside India where goods or services are offered to people in India. Confirm your specific exposure with a qualified adviser.
Is a consent banner enough for DPDP compliance?
No. A banner records a choice. It does nothing about purpose limitation, retention, data principal rights, processor accountability, breach handling, or the ROPA you need to demonstrate any of it. Consent management is one obligation among several.
What is a Significant Data Fiduciary?
A Data Fiduciary designated by the government based on factors such as volume and sensitivity of data and risk to Data Principals. Designation brings additional duties, including a DPIA and independent audits.
How does Shastra help with DPDP compliance?
Shastra is being built to hold the governance state the Act requires you to know (what data exists, for what purpose, under what basis, shared with whom) and to run the consent, rights and breach workflows and produce the records that follow. It is pre-launch, so this describes intent rather than a shipped product.
Is this legal advice?
No. This is a plain-English summary to help you understand the shape of the obligation. It is not legal advice and should not be relied on as a legal position.
Early access

Shastra is pre-launch.

Pre-registration is open, and no pricing is published while the product is still being built.

Related: the DPDP Act explained · the Compliance Copilot