DPDP Act, 2023


COMPLIANCE TIMELINE — NO GRACE PERIOD


14 NOV 2025

Rules notified. Data Protection Board becomes operational.

14 NOV 2026

Enforcement powers begin. Consent Manager registration opens.

14 MAY 2027

Full compliance mandatory. No grace period thereafter.

PENALTIES FOR NON-COMPLIANCE


₹250 Cr
Weak security safeguards or a data breach
₹200 Cr
No breach notice; children's-data lapses
₹150 Cr
Significant Data Fiduciary duties & other violations

Penalties are cumulative and imposed per violation.

THE 5 BIGGEST CHALLENGES WE SEE


Data Discovery &
Classification

Finding and categorising personal data

Consent Mechanism
Overhaul

Granular, reversible consent across systems

Third-Party
Accountability

Extending DPDP duties to vendors and partners

Incident Reporting
Readiness

Breach notification and response processes

Cultural Shift

Building a privacy-first mindset organisation-wide

OUR PRIVACY AUDIT LIFECYCLE


01
PLAN
02
PREPARE
03
FIELDWORK
04
EVALUATE
05
REPORT
06
FOLLOW UP
07
IMPROVE

KEY AREAS WE AUDIT


Governance & Accountability
Laws & Regulatory Compliance
Data Inventory & Processing
Data Subject Rights
Consent Management
Data Security & Encryption
Retention & Secure Disposal
Breach & Incident Response

How we can help

Our data privacy specialists combine deep industry and technical knowledge to deliver DPDP readiness assessments, gap analysis, consent and data-flow mapping, vendor due diligence, and audit-ready documentation.

Connect at services@moore-singhi.in