
It is a law about people's data.
If you keep information about people, such as names, phone numbers, salaries or health records, the DPDP Act applies to you. Even if your company is small.
Who does the Act apply to?/India's Digital Personal Data Protection Act, 2023
India's new data law applies to almost every business. The main duties start on 13 May 2027. MYND's compliance team helps you get ready, step by step, in plain English.
25 years of compliance work1,000+ clientsReply within one working day

25years
of payroll, finance and compliance work1,000+clients
across 50+ countries trust MYND6M+payslips
a year, full of personal data, kept safe99%accuracy
on compliance across our engagements/DPDP in 60 seconds
DPDP stands for Digital Personal Data Protection. Three things to know.

If you keep information about people, such as names, phone numbers, salaries or health records, the DPDP Act applies to you. Even if your company is small.
Who does the Act apply to?
People can ask what data you hold about them, ask you to fix or delete it, and complain if you do not. You need a way to answer them, on time.
The rights people get
Up to 250 crore rupees for weak security. Up to 200 crore rupees for not reporting a breach. The Data Protection Board already exists.
See every penalty/Key dates
The law arrives in phases. The next one is 13 November 2026, 65 days from today.
The Rules are notified. The Data Protection Board exists. Definitions and the Board's powers are live.
19 sections of the Act · 7 rules
Consent Managers can register with the Board under rule 4. Section 6(9) and section 27(1)(d) start.
2 sections of the Act · 1 rule
Notices, consent, people's rights, security duties, breach reporting and penalties all apply from this day. This is the date to plan for.
23 sections of the Act · 15 rules

Most companies need three to six months to get ready. Start now and the deadline is comfortable. Start late and it is not.
/What we do
Start with an assessment if you are new to this. Or go straight to the service you need.

We check where you stand today and give you a clear plan to get compliant.
Learn more
A privacy expert on call. Ask us anything about DPDP, any time.
Learn more
Building an app, website or platform? We review it for privacy before it goes live.
Learn more
Clear policies for your website, your staff and your vendors. Written so people actually read them.
Learn more
Sending data outside India? We tell you what is allowed and how to do it safely.
Learn more
A data breach, a complaint or a notice from the Board? We stand with you.
Learn more
Regular checks that your policies, controls and people are still doing what they should.
Learn more
New technology, new cloud, new AI tool? We assess the privacy risk first and help you reduce it.
Learn more
Short, practical training so your people know what to do with personal data.
Learn more/Who we help
DPDP touches every team that keeps information about people. These are the people who call us most.

Vendor data, payment data, audits. You want one clean answer for the board.

Employee files, payroll, background checks. You hold more personal data than anyone.

Systems, access, backups, cloud. Security safeguards land on your desk.

You are growing fast. You want to get this right without a big team.

You need a map, a plan and proof that it all works.

Patient records are personal data at its most sensitive.

Children's data has extra rules. Consent from parents is a must.

Customer data, marketing, delivery partners. Consent and notices everywhere.
/How it works
You do not need to understand the law to start. That is our job. You need one call.

30 minutes, free
A short call. We listen. You tell us about your business, your systems and your worries. We tell you honestly what we see.

2 to 4 weeks
We map your personal data and compare it with the law. You get a gap report and a roadmap with dates and owners.

1 to 3 months
Policies, notices, contracts, controls. We do the writing and the checking. Your team does the approving.

Half a day
Your people learn what to do with personal data. Short sessions, real examples, a record for your file.

Ongoing
Audits, updates when the law changes, and a team to call when something happens. We stay with you.
/Why MYND

MYND runs payroll for 6 million payslips a year and processes 20 million transactions. Employee and vendor data has flowed through our systems for a quarter of a century. We know what it takes to keep it safe.

Statutory filings, labour law, tax, vendor compliance. Across 50+ countries. DPDP is one more law we help you keep, with the same discipline.

We built the DPDP Wiki: every section, rule and notification, word for word, with simple explanations. It is free. Our advice reads the same way.

Most firms give you a legal opinion and leave. We stay to fix the process, train the team and check it stuck.
/Industries
Which is every sector. Here are the ones we see most.

Account data, credit data, KYC records.

Patient records, test results, insurance claims.

Student and parent data, most of it about children.

Customer profiles, orders, loyalty and marketing.

Client data in your systems, often from abroad.

Thousands of employee and contractor records.

Guest identity documents, bookings, preferences.

Fast growth, new products, investors asking questions.

/Free resource
Every section of the Act, every rule and every notification, word for word from the Government of India. With plain-English explanations, key dates, a glossary, free tools and a question box. No sign-up. No cost.
/FAQ
Almost certainly yes, if you handle personal data in digital form in India, or offer goods or services to people in India. Size does not matter. Use the free checker on the wiki to be sure. Read more on the wiki
The Data Protection Board has existed since 13 November 2025. Consent Manager rules start on 13 November 2026. The main duties for every business, including notices, consent, rights and penalties, start on 13 May 2027. Read more on the wiki
Up to 250 crore rupees for failing to keep reasonable security safeguards. Up to 200 crore rupees for not reporting a breach. Other breaches carry their own limits. The wiki lists every one. Read more on the wiki
The organisation that decides why and how personal data is used. If you collect data from customers or employees, that is you. Read more on the wiki
It depends on your size and how much personal data you handle. The first call is free. After it we give you a fixed quote. No surprises.
No. MYND is a compliance and back-office partner, not a law firm. We work with your lawyers whenever you need a legal opinion. The official text of the law is on the wiki. Read more on the wiki
One call is enough to know where you stand. It is free, it takes 30 minutes, and you leave with a clear next step.

/Talk to a person
Fill in the form. A compliance lead (a real person, not a sales queue) replies within one working day. The first call is free and takes 30 minutes.
