DPDP Services sales@myndsol.com Talk to us

/India's Digital Personal Data Protection Act, 2023

DPDP compliance, made simple.

India's new data law applies to almost every business. The main duties start on 13 May 2027. MYND's compliance team helps you get ready, step by step, in plain English.

25 years of compliance work1,000+ clientsReply within one working day

A Head of HR stands in a bright office and smiles at the camera while her team works behind her
Free30-minute first call

25years

of payroll, finance and compliance work

1,000+clients

across 50+ countries trust MYND

6M+payslips

a year, full of personal data, kept safe

99%accuracy

on compliance across our engagements

/DPDP in 60 seconds

What is this law, in plain words?

DPDP stands for Digital Personal Data Protection. Three things to know.

A young man holds a phone showing a simple permission screen with one large toggle
1

It is a law about people's data.

If you keep information about people, such as names, phone numbers, salaries or health records, the DPDP Act applies to you. Even if your company is small.

Who does the Act apply to?
An HR manager reviews employee records on a laptop at a tidy desk
2

It gives people rights.

People can ask what data you hold about them, ask you to fix or delete it, and complain if you do not. You need a way to answer them, on time.

The rights people get
An IT security lead holds a tablet in a server room corridor
3

It has big penalties.

Up to 250 crore rupees for weak security. Up to 200 crore rupees for not reporting a breach. The Data Protection Board already exists.

See every penalty

/Key dates

Three dates to remember.

The law arrives in phases. The next one is 13 November 2026, 65 days from today.

In force

The law wakes up.

The Rules are notified. The Data Protection Board exists. Definitions and the Board's powers are live.

19 sections of the Act · 7 rules

65 days to go

Consent Managers arrive.

Consent Managers can register with the Board under rule 4. Section 6(9) and section 27(1)(d) start.

2 sections of the Act · 1 rule

246 days to go

Everything else starts.

Notices, consent, people's rights, security duties, breach reporting and penalties all apply from this day. This is the date to plan for.

23 sections of the Act · 15 rules

A finance manager marks a date on a large wall planner

246 days until the main duties apply.

Most companies need three to six months to get ready. Start now and the deadline is comfortable. Start late and it is not.

/Who we help

Sound like you?

DPDP touches every team that keeps information about people. These are the people who call us most.

Portrait of a Chief Financial Officer in a glass office

Chief Financial Officer

Vendor data, payment data, audits. You want one clean answer for the board.

Portrait of a Head of HR with a warm smile

Head of HR

Employee files, payroll, background checks. You hold more personal data than anyone.

Portrait of a Chief Information Officer in front of a data centre wall

CIO or CTO

Systems, access, backups, cloud. Security safeguards land on your desk.

Portrait of a young startup founder in a coworking space

Founder

You are growing fast. You want to get this right without a big team.

Portrait of a compliance officer with folders behind him

Compliance Officer

You need a map, a plan and proof that it all works.

Portrait of a hospital administrator in a bright reception

Hospital Administrator

Patient records are personal data at its most sensitive.

Portrait of a school principal in a school corridor

School Principal

Children's data has extra rules. Consent from parents is a must.

Portrait of an e-commerce operations head in a warehouse

E-commerce Operations Head

Customer data, marketing, delivery partners. Consent and notices everywhere.

Talk to us about your role

/How it works

Five simple steps. No jargon.

You do not need to understand the law to start. That is our job. You need one call.

  1. Two professionals shake hands across a desk at a first meeting
    01

    Talk

    30 minutes, free

    A short call. We listen. You tell us about your business, your systems and your worries. We tell you honestly what we see.

  2. A workshop team places colourful sticky notes on a glass wall
    02

    Map

    2 to 4 weeks

    We map your personal data and compare it with the law. You get a gap report and a roadmap with dates and owners.

  3. A consultant and an IT engineer work side by side at a laptop
    03

    Fix

    1 to 3 months

    Policies, notices, contracts, controls. We do the writing and the checking. Your team does the approving.

  4. A consultant explains to a small group of employees around a table
    04

    Train

    Half a day

    Your people learn what to do with personal data. Short sessions, real examples, a record for your file.

  5. A compliance lead and a client review a report together over coffee
    05

    Keep

    Ongoing

    Audits, updates when the law changes, and a team to call when something happens. We stay with you.

See how an engagement runsBook the first call

/Why MYND

A compliance partner, not a consultant who leaves.

A payroll team works together at screens

We have handled personal data with care for 25 years.

MYND runs payroll for 6 million payslips a year and processes 20 million transactions. Employee and vendor data has flowed through our systems for a quarter of a century. We know what it takes to keep it safe.

Consultants and a client team work together around a table with a laptop and printed documents

We have done compliance for 1,000+ companies.

Statutory filings, labour law, tax, vendor compliance. Across 50+ countries. DPDP is one more law we help you keep, with the same discipline.

A professional pauses to think at her laptop

We explain things in plain English.

We built the DPDP Wiki: every section, rule and notification, word for word, with simple explanations. It is free. Our advice reads the same way.

A leader briefs the board in a glass boardroom

One partner for law, process and people.

Most firms give you a legal opinion and leave. We stay to fix the process, train the team and check it stuck.

/Industries

We work across every sector that holds personal data.

Which is every sector. Here are the ones we see most.

Bank branch staff at work behind a modern counter

Banking & finance

Account data, credit data, KYC records.

A clinic receptionist checks in a patient at a bright front desk

Healthcare

Patient records, test results, insurance claims.

A university administrator helps a student with paperwork

Education

Student and parent data, most of it about children.

A retail store manager checks stock on a tablet

Retail & e-commerce

Customer profiles, orders, loyalty and marketing.

A software team works at desks with code on screens

IT & software

Client data in your systems, often from abroad.

A factory HR office with a manager and a worker in a hi-vis vest

Manufacturing

Thousands of employee and contractor records.

A hotel front desk team welcomes a guest

Hospitality

Guest identity documents, bookings, preferences.

A young startup team in a coworking space

Startups

Fast growth, new products, investors asking questions.

A professional reads a clean white web page on a laptop with a cup of tea beside it

/Free resource

Want to read the law yourself? We built the DPDP Wiki for that.

Every section of the Act, every rule and every notification, word for word from the Government of India. With plain-English explanations, key dates, a glossary, free tools and a question box. No sign-up. No cost.

Open the DPDP Wiki

/FAQ

Questions people ask us

Does the DPDP Act apply to my company?

Almost certainly yes, if you handle personal data in digital form in India, or offer goods or services to people in India. Size does not matter. Use the free checker on the wiki to be sure. Read more on the wiki

When do I need to be ready?

The Data Protection Board has existed since 13 November 2025. Consent Manager rules start on 13 November 2026. The main duties for every business, including notices, consent, rights and penalties, start on 13 May 2027. Read more on the wiki

What are the penalties?

Up to 250 crore rupees for failing to keep reasonable security safeguards. Up to 200 crore rupees for not reporting a breach. Other breaches carry their own limits. The wiki lists every one. Read more on the wiki

What is a Data Fiduciary?

The organisation that decides why and how personal data is used. If you collect data from customers or employees, that is you. Read more on the wiki

How much does this cost?

It depends on your size and how much personal data you handle. The first call is free. After it we give you a fixed quote. No surprises.

Is this legal advice?

No. MYND is a compliance and back-office partner, not a law firm. We work with your lawyers whenever you need a legal opinion. The official text of the law is on the wiki. Read more on the wiki

The deadline is fixed. Your start date is not.

One call is enough to know where you stand. It is free, it takes 30 minutes, and you leave with a clear next step.

A consultant and a client team shake hands after a workshop

/Talk to a person

Tell us where you are. We will tell you what to do next.

Fill in the form. A compliance lead (a real person, not a sales queue) replies within one working day. The first call is free and takes 30 minutes.

A friendly consultant smiles at the camera from his desk during a video call
  • 25 yearsof payroll, finance and statutory compliance
  • 1,000+clients across 50+ countries
  • 6M+payslips a year, personal data handled with care
  • 99%compliance accuracy across engagements
How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.
Email usTalk to us