How to read this guide
Part A explains the law in plain words. Part B is five steps to fix your website. Part C covers fines, a deadline checklist and a map of sources.
In every table, "Act" means the DPDP Act, 2023 and "Rule" means the DPDP Rules, 2025. Links to all the original documents are in the source map at the end.
Part A. Understand the law
Key dates
| Date | What happens | Where it is mentioned |
|---|---|---|
| 13 Nov 2025 | Rules notified. Data Protection Board established. Definitions and Board provisions start. | Rule 1 (Rules, G.S.R. 846(E)); G.S.R. 844(E); G.S.R. 843(E) |
| 13 Nov 2026 | Consent Manager registration starts (Rule 4, Act Section 6(9)). | Rule 1; G.S.R. 843(E) |
| 13 May 2027 | Notice, consent, rights, security, breach reporting, children's data and penalties apply in full. | Rule 1 (Rules 3, 5 to 16, 22, 23); G.S.R. 843(E) (Act Sections 3 to 5, 6(1) to 6(8), 6(10), 7 to 17, 28 to 34) |
Is it personal data?
Personal data is any data about an individual who can be identified by or in relation to that data (Act Section 2(t)). Name, phone number and email address count in the same way as PAN and Aadhaar. A simple contact form that asks for name, phone and email needs the same care as a KYC form.
| Data | Counts as personal data? | Where it is mentioned |
|---|---|---|
| Name, phone number, email address | Yes | Act Section 2(t); Section 3 (digital personal data). |
| PAN, Aadhaar, bank or transaction details | Yes | Act Section 2(t). |
| IP address, device ID, cookie ID | Likely, when they can be linked to a person | Not listed by name. This follows from the wording of Section 2(t). Ask legal if you rely on the difference. |
Two legal bases for using the data. Most website data needs the person's consent (Section 6). One exception helps with simple forms: if a person gives you their name, phone or email for a specific purpose, such as asking for a callback, and does not object, Section 7(a) can allow you to use it for that purpose without a separate consent. Using the same data for marketing, or sharing it with partners, still needs consent. Confirm with legal which route applies to each form.
Part B. Fix your website in five steps

Step 1
Step 1. Know your data
You cannot protect or explain data you have not mapped. List every place your website collects personal data, then fill in one row per item. This table becomes the base for your notices, privacy policy and retention schedule.
| Where collected | Data | Why | Legal basis | Shared with | Keep for |
|---|---|---|---|---|---|
| Contact form | Name, phone, email | Reply to the enquiry | Section 7(a) or consent | CRM, email tool | To be set (see Step 4) |
| Sign-up and KYC form | Name, PAN, Aadhaar | Verify identity | Consent (Section 6) | Partner bank, KYC provider | RBI KYC period |
| Cookie banner | Cookie ID, IP | Analytics, ads | Consent (Section 6) | Analytics and ad vendors | Cookie lifespan |
| Newsletter box | Send updates | Consent (Section 6) | Email tool | Until unsubscribe |
Example only. Replace each row with your own facts.
Not sure what your site collects today? A DPDP website audit checks which cookies and tags load before consent and how each form asks for it.
Step 2
Step 2. Fix the website itself
2.1 Cookie banner and tracking
The law has no cookie-specific rule. A banner is treated as a request for consent, so the consent rules apply to it.
| What to do | Where it is mentioned |
|---|---|
| Do not load analytics or marketing trackers until the user says yes. Essential cookies, such as login or payment security, can load. | Act Section 6(1): consent must be free, specific, informed, unconditional and unambiguous, shown by a clear affirmative action. |
| Offer separate choices (for example analytics on, marketing off). No pre-ticked boxes. | Act Section 6(1): consent is specific and covers only the data necessary for the stated purpose. |
| Make Reject as easy as Accept, and keep a visible link so users can change their mind. | Act Section 6(4): withdrawing consent must be as easy as giving it. Rule 3: the notice must include a link to withdraw. |
| Write the banner in plain language, with English or any of the 22 Eighth Schedule languages available on request. | Act Sections 5(3) and 6(3). |
| Keep a record of each consent and the notice version shown. | Act Section 6(10): the company must prove that notice was given and consent was valid. Logging itself is good practice. |
- One Accept button, no way to say no
- Trackers load before any choice
- Vague wording, no link to change later
- Reject is as easy as Accept
- Separate choices, nothing pre-ticked
- Plain words and a link to change later
We do this work as a service: DPDP cookie consent banner setup, and Google Consent Mode v2 and GTM tag gating for the trackers behind it.
2.2 Sign-up and KYC forms
| What to do | Where it is mentioned |
|---|---|
| Show a short notice next to the form: what data, for what purpose, and how to withdraw or complain. | Act Section 5(1). Rule 3: an itemised list of the data, the specific purpose, and links to withdraw consent, use rights and complain to the Board. |
| Ask only for what the service needs. Remove optional fields such as marital status or social profile links. | Act Section 6(1): consent is limited to the personal data necessary for the stated purpose. |
| Keep the Terms of Service separate from data-sharing consent. Both boxes start unticked. | Act Section 6(1). Rule 3: the notice is presented on its own, in clear and plain language. |
| Do not make optional marketing consent a condition of using the basic service. | Act Section 6(1): consent must be unconditional. |
| Name the partners you share data with and say why. | Rule 3. Act Section 11: users can ask who their data was shared with. |
- Asks for more than the service needs
- One pre-ticked box bundles Terms, data and marketing
- No notice saying what is collected or why
- Only the fields the service needs
- A short notice next to the form
- Separate boxes, all unticked, marketing optional
We do this work as a service: DPDP consent for website forms.
2.3 Rights and complaints
| What to do | Where it is mentioned |
|---|---|
| Give users a way to see a summary of their data and who it was shared with. | Act Section 11. |
| Let users correct, complete, update and erase their data. | Act Section 12. Act Section 8(7): erase data when consent is withdrawn or the purpose ends. |
| Run a visible complaints channel and answer on time. | Act Section 13. Rule 14: how rights are exercised. Rule 14(3): not more than 90 days. |
| Let users nominate someone to use their rights for them. | Act Section 14. |
| Publish a contact point for questions. A named Data Protection Officer is required only for large ("significant") companies. | Act Section 8(9) and Rule 9 (contact). Act Section 10(2)(a) (Data Protection Officer). |
2.4 Children
If your website may be used by people under 18, get verifiable consent from a parent or guardian before processing their data. Do not track them, monitor their behaviour or target advertising at them.
| What to do | Where it is mentioned |
|---|---|
| Treat anyone under 18 as a child and get verifiable parental consent first. | Act Section 9(1) and Section 2(f). Rule 10: how parental consent is verified. |
| Do not track, monitor or target ads at children. | Act Section 9(3). |
| Check the exemptions in Rule 12 and the Fourth Schedule before relying on them. | Rule 12; Fourth Schedule. |
Step 3
Step 3. Write your three pages
The law does not require a privacy policy, a Terms page or a cookie policy by name. It requires a notice at the point where you ask for data (Section 5, Rule 3) and a published contact for questions (Section 8(9), Rule 9). In practice you should update all three pages, because each has a different job.
| Where | Update it? | What to put on it | Where it is mentioned |
|---|---|---|---|
| Notice at the form and the banner | Yes. This is the legal core. | What you collect (name, phone, email and so on), why, and links to withdraw consent, use rights and complain to the Board. It must stand on its own. | Act Section 5. Rule 3. |
| Privacy policy page | Yes. The full detail lives here. | All the data you collect and why; who receives it; how long you keep it; how to see, correct, erase and withdraw; how to complain, including to the Board; the contact for questions; the languages offered. | Act Sections 5, 8(9) and 11 to 14. Rules 3, 9 and 14. |
| Terms page | Yes, a small update. | Keep it about the service. Do not put data consent inside it. Add a line pointing to the privacy policy, and state that marketing consent is optional. | Act Section 6(1). Rule 3. |
| Cookie policy page | Yes, if you use analytics, ads or other trackers. | A table of each cookie: name, provider, purpose, lifespan and category. How to change or withdraw choices. A link to it from the banner. | Not required by name. It supports Act Sections 5, 6(1) and 6(4) and Rule 3. |
Example rows for the data table in your privacy policy (replace the wording with your own facts):
| Data | Why we collect it | Who receives it | How long we keep it |
|---|---|---|---|
| Name, phone number, email address | To reply to your enquiry and to set up your account | Our CRM and email tools (name each one) | 12 months after your last contact, unless you become a customer |
| PAN, Aadhaar | To verify your identity for a loan | Our partner bank and KYC provider (name them) | As the RBI KYC rules require |
We draft the privacy policy and cookie policy pages as a service, for your legal contact to approve: DPDP privacy policy and cookie policy drafting.
What the law does not say
Some online checklists present these as legal requirements. They are good practice, not law:
- No cookie-specific rule. Cookies are covered by the general consent rules.
- Consent does not have to expire automatically after a set period.
- A Data Protection Officer is only for significant data fiduciaries (Section 10(2)(a)). Everyone must publish a contact point (Section 8(9)).
- The notice must be available in English or any one of the 22 languages on request, not all 22 at once (Sections 5(3), 6(3)).
- Logging each consent is not named, but Section 6(10) puts the burden of proof on you, so logging is the safest route.
- A privacy policy, Terms page and cookie policy are not required by name.
- There is no single retention period for general data (see Step 4).
Step 4
Step 4. Set retention and deletion
The law does not set one fixed period for general data such as name, phone and email. The rule is based on purpose: keep the data only while the purpose you stated is still being served, then erase it. You choose the period, write it down and be ready to explain it. A few Rules and sector laws set specific periods.
| Situation | How long | Where it is mentioned |
|---|---|---|
| General rule (enquiry forms, sign-ups, newsletters) | Erase when the user withdraws consent, or when it is reasonable to assume the purpose has ended, whichever comes first. The user can also ask for erasure. | Act Section 8(7) and Section 12(3). |
| A law requires you to keep it | Keep it for the period that law sets, then erase. | Act Sections 8(7) and 12(3). |
| Regulated financial entities: KYC and transactions | Transaction records: 5 years from the date of the transaction. Identity and address records: at least 5 years after the customer relationship ends. This is an RBI rule, not a DPDP rule. | RBI Master Direction, Know Your Customer Direction 2016, paragraph 46. |
| Logs of access to personal data | Keep the logs for one year. | Rule 6(1)(e). |
| Purposes listed in the Seventh Schedule | Keep personal data, traffic data and logs for at least one year for those purposes, then erase unless a law requires longer. | Rule 8(3). |
| Large e-commerce, online gaming and social media platforms | Erase 3 years after the user last contacted you (or after the Rules start, if later), with at least 48 hours' warning, unless a law requires keeping it. Most company websites are not in these classes. | Rules 8(1) and 8(2). The classes and user thresholds are in the Third Schedule. Check the PDF for the current thresholds. |
| Consent records | Keep them as long as you rely on that consent, so you can prove it. The exact period is good practice, not stated in the law. | Act Section 6(10). |
Suggested starting point (good practice, not from the law). Agree your own periods with legal:
- Enquiry and demo forms that never became customers: review after 12 months with no contact, then delete or ask again.
- Newsletter list: keep until the person unsubscribes.
- Customers: keep for the relationship plus the sector retention period, then delete.
- Set up an automatic delete job and publish the periods in your privacy policy.
Step 5
Step 5. Secure the data and plan for breaches
| What to do | Where it is mentioned |
|---|---|
| Put reasonable security safeguards in place: encryption or masking, access controls, activity logs and backups. | Act Section 8(5). Rule 6: the minimum safeguards. |
| Have a breach plan with a named owner: tell each affected user without delay, tell the Board without delay, and send the Board a detailed report within 72 hours. | Act Section 8(6). Rule 7. |
| Remember you stay responsible for data handled by vendors (analytics, CRM, KYC, email tools). Use written contracts with each one. | Act Sections 8(1) and 8(2). Rule 6 (safeguards extend to processors). |
| Large companies the government designates as significant data fiduciaries have extra duties (Data Protection Officer, audits, impact assessments). | Act Section 10. |
Part C. Penalties, checklist and sources
Penalties
The Data Protection Board decides penalties after hearing the company. Each amount is a maximum, not a fixed fine.
| Failure | Maximum | Where it is mentioned |
|---|---|---|
| Not keeping personal data secure | ₹250 crore | Schedule to the Act, read with Section 8(5) |
| Not reporting a breach to the Board and users | ₹200 crore | Schedule, read with Section 8(6) |
| Breaking the rules for children's data | ₹200 crore | Schedule, read with Section 9 |
| Not meeting extra duties of a significant data fiduciary | ₹150 crore | Schedule, read with Section 10 |
| Any other breach of the Act or the Rules (including notice and consent) | ₹50 crore | Schedule to the Act. Penalties are imposed under Section 33. |
Checklist by deadline
| Done | Task | Suggested by | Source |
|---|---|---|---|
| Map every form, cookie and tool that collects personal data (Step 1) | Dec 2026 | Act Section 5 | |
| Decide the legal basis and retention period for each item (Steps 1 and 4) | Dec 2026 | Act Sections 6, 7, 8(7) | |
| Replace the cookie banner with one that blocks trackers until the user agrees | Feb 2027 | Act Section 6 | |
| Rewrite notices at each form, separate from the Terms | Feb 2027 | Rule 3 | |
| Update the privacy policy, Terms page and cookie policy (Step 3) | Mar 2027 | Act Sections 5, 8(9) | |
| Build rights and complaints handling, with a 90 day answer limit | Mar 2027 | Act Sections 11 to 14; Rule 14 | |
| Sign contracts with vendors and review safeguards (Step 5) | Apr 2027 | Act Section 8; Rule 6 | |
| Write the breach plan with the 72-hour Board report and test it | Apr 2027 | Act Section 8(6); Rule 7 | |
| Set up automatic deletion jobs; check RBI record rules with legal first | Apr 2027 | Act Section 8(7); Rule 8 | |
| Final review. Full duties apply. | 13 May 2027 | Rule 1 |
Suggested dates are planning targets, not legal deadlines. The only legal date is 13 May 2027.
A website keeps changing after the checklist is done. A monthly DPDP Care Plan rescans the site, reviews new cookies and tags and retests the banner.
Source map and original documents
Use this table to jump to the exact place in the original text.
| Topic | Act | Rules | Other |
|---|---|---|---|
| Personal data definition | Section 2(t) | ||
| Notice | Section 5 | Rule 3 | |
| Consent and withdrawal | Section 6 | Rule 3 | |
| Voluntarily provided data | Section 7(a) | ||
| Security and breach | Section 8(5), 8(6) | Rules 6, 7 | |
| Erasure and retention | Sections 8(7), 12(3) | Rule 8 | RBI KYC para 46 |
| Contact and complaints | Sections 8(9), 8(10), 13 | Rules 9, 14 | |
| Children | Section 9 | Rules 10, 12 | |
| User rights | Sections 11 to 14 | Rule 14 | |
| Significant data fiduciary | Section 10 | Rule 13 | |
| Penalties | Section 33; Schedule |
- Act: DPDP Act, 2023 (MeitY PDF), Gazette copy
- Rules: DPDP Rules, 2025, G.S.R. 846(E), 13 Nov 2025
- Commencement dates: G.S.R. 843(E), 13 Nov 2025
- Data Protection Board: G.S.R. 844(E), 13 Nov 2025
- Financial record retention: RBI Master Direction, Know Your Customer Direction 2016
- Government explainers: PIB press release, 14 Nov 2025, PIB backgrounder
Before you quote an exact wording or number, read the rule in the PDF. In particular, confirm the Third Schedule thresholds and the Seventh Schedule purposes used in Rule 8, and the Rule 12 and Fourth Schedule exemptions for children's data. This guide is a summary and not legal advice.
