DPDP Act penalties explained

India's Digital Personal Data Protection Act sets statutory penalties up to ₹250 crores per incident. See what that means for compliance teams.

Published . Updated .

Short answer

The Digital Personal Data Protection Act governs digital personal data in India.

The statute allows penalties up to ₹250 crores per incident for serious non-compliance.

That figure is a statutory maximum, not an AUDIX customer outcome.

What the Act covers

It covers processing of digital personal data of individuals in India.

Organizations must support consent, grievance redressal, and reasonable security safeguards.

Cross-border transfers and purpose limitation also sit in the compliance scope.

Primary rules are published by MeitY as the Digital Personal Data Protection Rules, 2025.

Enforcement timeline

Most substantive DPDP Act obligations take effect on May 13, 2027—18 months after MeitY notified the Rules in 2025.

Customer contracts and board oversight already treat DPDP as the operating standard for many Indian fiduciaries before that date.

Security safeguard evidence—access control, encryption, logging—is where technical teams spend the most preparation time.

How AUDIX supports DPDP readiness

AUDIX maps DPDP controls to continuous evidence from cloud, identity, and ticketing integrations.

It supports DPO grievance workflows with response tracking.

Residency and transfer posture stay visible in one dashboard.

Security safeguard evidence refreshes from live integrations.

Next steps

Map your stack to DPDP controls before enforcement milestones land.

Pair DPDP work with SOC 2 or ISO 27001 when you sell globally.

Read the Act on India Code, then book a 30-minute AUDIX scoping call.

Primary sources

Digital Personal Data Protection Rules, 2025 (MeitY) — official publication at meity.gov.in.

Ministry of Electronics and IT (MeitY) — parent ministry for digital governance in India.

Penalties cited here are statutory ceilings in law—not projected outcomes for any specific organization.

More articles on the AUDIX GRC blog. Contact the team via the contact page.