DPDP Act 2023 enacted
11 Aug 2023Act No. 22 of 2023 receives Presidential assent (Gazette CG-DL-E-12082023-248045).
Source entry: dpdp-act-gazette →We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.
Every date below traces to the Compliance Registry, which traces to the Gazette. Put it in your board pack — attribution to CyberSigma is all we ask.
Act No. 22 of 2023 receives Presidential assent (Gazette CG-DL-E-12082023-248045).
Source entry: dpdp-act-gazette →G.S.R. 843(E). Data Protection Board provisions (ss.18–26), definitions and procedural rules take effect immediately.
Source entry: dpdp-rules-notified →Verifiable parental consent (s.6(9)) and the publication duty (s.27(1)(d)) commence one year from notification.
Source entry: dpdp-phase-2 →Notice and consent standards, data fiduciary duties, children's data and data principal rights commence at eighteen months. Published analyses split on 12 vs 13 May — confirm the day with counsel. Penalties under the Schedule (up to ₹250 crore for security-safeguard failures) become live exposure.
Source entry: dpdp-phase-3 →1. Map your processing: what personal data you hold, why, where it sits, who touches it — every later obligation depends on this record existing.
2. Decide your likely Significant Data Fiduciary exposure early: SDF status brings a DPO in India, DPIAs and an independent data audit.
3. Build consent and withdrawal flows against the Rules' standards — withdrawal must be as easy as consent.
4. Join breach response into ONE runbook with CERT-In's six-hour reporting — the same incident triggers both duties on different clocks.
5. Treat the runway as a work period, not a deadline to start: rights processes and retention rebuilds take quarters, not weeks.
We audit DPDP readiness against the full obligation set — data mapping, consent and rights flows, breach runbooks — so nothing is a surprise when a phase lands.
DPDP privacy audit →v1.0.0 · updated 2026-08-01 · CC BY 4.0 — reuse with attribution to CyberSigma.