DPDP Act, 2023
COMPLIANCE TIMELINE — NO GRACE PERIOD
14 NOV 2025
Rules notified. Data Protection Board becomes operational.
14 NOV 2026
Enforcement powers begin. Consent Manager registration opens.
14 MAY 2027
Full compliance mandatory. No grace period thereafter.
PENALTIES FOR NON-COMPLIANCE
₹250 Cr
Weak security safeguards or a data breach
₹200 Cr
No breach notice; children's-data lapses
₹150 Cr
Significant Data Fiduciary duties & other violations
Penalties are cumulative and imposed per violation.
THE 5 BIGGEST CHALLENGES WE SEE
Data Discovery &
Classification
Finding and categorising personal data
Consent Mechanism
Overhaul
Granular, reversible consent across systems
Third-Party
Accountability
Extending DPDP duties to vendors and partners
Incident Reporting
Readiness
Breach notification and response processes
Cultural Shift
Building a privacy-first mindset organisation-wide
OUR PRIVACY AUDIT LIFECYCLE
01
PLAN 02
PREPARE 03
FIELDWORK 04
EVALUATE 05
REPORT 06
FOLLOW UP 07
IMPROVE KEY AREAS WE AUDIT
Governance & Accountability
Laws & Regulatory Compliance
Data Inventory & Processing
Data Subject Rights
Consent Management
Data Security & Encryption
Retention & Secure Disposal
Breach & Incident Response
How we can help
Our data privacy specialists combine deep industry and technical knowledge to deliver DPDP readiness assessments, gap analysis, consent and data-flow mapping, vendor due diligence, and audit-ready documentation.
Connect at services@moore-singhi.in