India's data protection law, in plain English.
The Digital Personal Data Protection Act applies to almost any organisation handling the personal data of people in India. This is what DPDP compliance actually asks for, without the legalese.
The eight terms that matter.
Most DPDP confusion is vocabulary. Learn these and the rest of the Act reads normally.
- Data Fiduciary
- You, if you decide why and how personal data gets processed. The Act puts the obligations here.
- Data Principal
- The person the data is about. They hold the rights you have to service.
- Data Processor
- A third party processing data on your behalf. You stay accountable for what they do.
- Significant Data Fiduciary
- A larger or higher-risk fiduciary, designated by the government, with extra duties including audits and impact assessments.
- Consent Manager
- A registered intermediary through which a Data Principal can give, manage and withdraw consent.
- ROPA
- Record of Processing Activities: the documented account of what you process, why, and who you share it with.
- DPIA
- Data Protection Impact Assessment: a structured risk assessment, required of Significant Data Fiduciaries.
- Cross-border transfer
- Sending personal data outside India, permitted except to countries the government restricts.
What the Act asks of you.
Grouped by the work each one creates rather than by section number.
Lawful basis and notice
A valid reason to process, and a notice people can actually understand.
Consent management
Where you rely on consent it must be specific, informed, and as easy to withdraw as to give.
Purpose limitation
Data collected for one purpose cannot quietly serve another.
Data principal rights
Access, correction, erasure and grievance, each on a defined clock.
Children’s data
Verifiable parental consent, and no tracking or targeted advertising.
Breach notification
Report personal data breaches, on a deadline, with specified detail.
Processor accountability
You remain responsible for every vendor that touches the data.
Retention limits
Stop keeping data once its purpose is served.
What the 2025 Rules changed.
The DPDP Rules were notified in November 2025 with a transition period to full compliance, putting the deadline around 12 May 2027. Some obligations land earlier.
More detail
That is our reading of the published timeline, not legal advice. Where the specifics matter, get advice from a qualified practitioner. Please do not take a legal position from a product page.
The gap is operational, not legal.
Most teams can read the Act and follow it. The difficulty is that satisfying it means knowing, continuously, what personal data you hold, why, who you share it with, and what each person agreed to.
More detail
That information usually lives across several systems and nobody’s head in particular, which is why we treat DPDP data governance as an infrastructure problem rather than a documentation exercise.
Common questions.
Who does the DPDP Act apply to?
Is a consent banner enough for DPDP compliance?
What is a Significant Data Fiduciary?
How does Shastra help with DPDP compliance?
Is this legal advice?
Shastra is pre-launch.
Pre-registration is open, and no pricing is published while the product is still being built.
Related: the DPDP Act explained · the Compliance Copilot