DPDP Act · India

DPDP safeguards apply from
May 2027. People are part of them.

The DPDP Rules 2025, notified in November 2025, bring the Act’s duties into force in May 2027, including reasonable security safeguards for personal data and reporting personal data breaches to the Data Protection Board, and KeenSec helps you build the workforce side of that evidence before then.

Framework
Digital Personal Data Protection Act 2023 and DPDP Rules 2025 (G.S.R. 846(E))
In force
Board provisions now; security, breach and penalty provisions from May 2027
Where awareness fits
Rule 6 requires technical and organisational measures; training is how most organisations meet the organisational part
KeenSec evidence
Simulation results, report logs, training certificates, policy acknowledgements

What changes in May 2027

The duties that
start in May 2027.

The Rules were notified in November 2025 and phase in over 18 months.

ProvisionWhat it requiresFrom
Security safeguardsReasonable safeguards against breaches, including access control, logging, backups and technical and organisational measures.May 2027 · Rule 6
Breach intimationTell affected people and the Data Protection Board without delay, then send the Board a detailed report within 72 hours.May 2027 · Rule 7
LogsKeep personal data, traffic data and logs for at least one year, including processing by a vendor.May 2027 · Rule 8
PenaltiesUp to ₹250 crore for failing to take safeguards and up to ₹200 crore for failing to report a breach.May 2027 · Schedule
Data Protection BoardEstablished on 13 November 2025 as a digital office; members are yet to be appointed.Now · G.S.R.

Where breaches start

A breach can begin
with one sign-in.

A credential entered on a fake login page, or a spreadsheet sent to the wrong address, can become a breach you must report to the Board. It will also usually be a cyber incident for CERT-In within 6 hours.

SAMPLE PROGRAMME

DPDP awareness quarter

  • Data protection policy sent for acknowledgement
  • Micro-lesson: spotting a fake KYC or payroll request
  • Credential-capture simulation on email and WhatsApp
  • Phishing Reporter rolled out to every inbox
  • Quarterly evidence export for the DPO

Illustrative programme.

Expectation to record

What you can show
when someone asks.

SAFEGUARDS

Staff are tested against realistic phishing.

Simulation results across email, SMS, WhatsApp and more, by team and campaign.

DETECTION

Staff report what looks wrong.

Phishing Reporter logs, with automated analysis, show who reported and how fast the team could act.

TRAINING

Staff know how to handle personal data.

LMS completions, assessments and certificates for data-handling courses.

POLICY

Staff have read your data protection policy.

Policy Manager keeps dated acknowledgements per person and version.

Policy Manager records employee policy acknowledgement. It is not data-principal consent management: consent from customers and other data principals needs a dedicated consent process.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))13 November 2025 · Gazette of India · phased commencement
  2. Commencement of the DPDP Act, 2023 (G.S.R. 843(E))13 November 2025 · which sections start when
  3. Establishment of the Data Protection Board of India (G.S.R. 844(E))13 November 2025
  4. Digital Personal Data Protection Act, 202311 August 2023 · sections 7(i), 8(5), 8(6) and the Schedule
  5. PIB backgrounder on the DPDP Rules17 November 2025

Questions buyers ask

Frequently asked questions.

When do DPDP obligations apply?

The Rules were notified in November 2025. The Data Protection Board provisions apply now, consent manager rules after one year, and the main duties, including security safeguards, breach reporting and penalties, after 18 months, in May 2027.

Do the DPDP Rules require security awareness training?

Not by name. Rule 6 lists minimum safeguards, including appropriate technical and organisational measures. Training and testing staff is a common way to meet the organisational part; your counsel decides what is enough.

Can we run phishing simulations on employees under DPDP?

Section 7(i) of the Act allows processing for employment purposes and to protect the employer from loss or liability without consent. Whether your programme fits is a question for your counsel; KeenSec processes the data on your behalf, under your contract.

Does KeenSec make us compliant with the DPDP Act?

No tool makes you compliant on its own. KeenSec helps you build workforce awareness evidence for the safeguards the Act expects, and your counsel and auditor decide whether you meet it.

Let’s connect the dots

Build DPDP awareness evidence
before May 2027.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo