About the DPDP Act
8 questionsThe DPDP Act 2023 got signed off on by the President on August 11th 2023, and the DPDP Rules 2025 were posted on November 13th 2025 (G.S.R. 846(E)). That made the operational details for enforcing the act finally available — so now businesses are staring at the possibility of getting hit with penalties up to ₹250 crore per category of violation — ones that haven't put their compliance in place yet need to treat that as an immediate priority, not something that's down the road.
Any entity that processes digital personal data of Indian residents — whether inside India or outside India — must comply. This includes Indian businesses of all sizes, foreign companies with Indian users, government bodies, and non-profits. There is no small-business exemption in the DPDP Act. Data Processors (vendors processing data on behalf of Data Fiduciaries) also have obligations.
The Schedule to the DPDP Act specifies penalties by violation category:
• Up to ₹250 Crore — failure to implement adequate security safeguards
• Up to ₹200 Crore — failure to notify the Data Protection Board of a breach
• Up to ₹200 Crore — failure to notify data principals of a breach
• Up to ₹150 Crore — failure to fulfil children's data obligations
• Up to ₹50 Crore — other violations
Penalties are per violation category and are assessed by the Data Protection Board of India.
• Up to ₹250 Crore — failure to implement adequate security safeguards
• Up to ₹200 Crore — failure to notify the Data Protection Board of a breach
• Up to ₹200 Crore — failure to notify data principals of a breach
• Up to ₹150 Crore — failure to fulfil children's data obligations
• Up to ₹50 Crore — other violations
Penalties are per violation category and are assessed by the Data Protection Board of India.
A Data Fiduciary is pretty much anyone who is responsible for deciding how and why personal data gets processed — that's companies, state bodies, individuals, or any other organisation for that matter. If your organisation is the one that makes the decisions about what data to collect, how to store it, and what to do with it, then you're basically a Data Fiduciary. And being a Data Fiduciary means you've got a bunch of responsibilities under DPDP: getting people's consent before using their data, keeping their data secure, dealing with requests from people whose data you are handling, and notifying them if you have to disclose any kind of breach.
A Data Principal is the individual whose personal data you are dealing with — whether that's your customers, users, employees, or anybody else's data your company holds onto. Under the DPDP Act, Data Principals get five core rights: access to information about the data you hold on them, right to make corrections and have it erased, a way to take their grievances to someone in power, the right to nominate someone else (that's in Section 14 of the act), and the right to withdraw their consent at any time — businesses need to have systems in place to make sure all five rights are respected.
Key differences include: (1) No legitimate interest basis — DPDP has no Article 6(1)(f) equivalent; all processing requires consent or a Section 7 exemption; (2) CERT-In 6-hour breach rule — GDPR's 72-hour window is significantly longer; (3) Right to nominate(Section 14) is unique to Indian law; (4) Children's threshold is under 18 in DPDP vs under 16 in GDPR; (5) DPDP penalties are fixed amounts rather than percentage of global revenue. Read our full comparison: DPDP Act vs GDPR.
Significant Data Fiduciaries (SDFs) are the companies identified by the Central Government under Section 10 of the DPDP Act — and that's only if they meet certain criteria: namely, handling a huge amount of sensitive personal data, posing a significant risk to people whose data they are handling, posing any kind of threat to national security, and/or affecting the democratic process. If a company is put on the list of SDFs, they have to meet some pretty tough requirements: having an in-house Data Protection Officer based in India, getting their data handled by an independent auditor, doing regular Data Protection Impact Assessments, and going through regular audits to ensure compliance. But at the moment, the final list of SDFs hasn't been published — as of mid-2026 at least.
The DPDP Act follows a data subject-based jurisdiction model: it applies to processing of personal data of Indian residents regardless of where the processing happens. A foreign company with no physical presence in India but which targets Indian users — e.g., an e-commerce website selling to India, a SaaS product with Indian subscribers — must comply with DPDP. The Act applies to "any person" who processes digital personal data "in the course of any activity related to the offering of goods or services" to persons in India.
About Consiva.ai
6 questionsConsiva.ai is India's purpose-built DPDP compliance platform, developed by Swaran Soft Pvt. Ltd. It provides: DPDP-compliant cookie consent banners in 22 Indian languages, consent record storage with full audit trail, CERT-In 6-hour breach tracker with auto-generated reports, Data Principal Rights portal (all 5 DPDP rights), AI-powered data discovery, automated ROPA generation, and DPIA workflows. It is built specifically for the DPDP Act 2023 — not retrofitted from a GDPR tool.
The free plan gets you: 1,000 cookie consent events per month, one domain, DPDP compliant cookie pop up, 30-day consent records kept on file, 3 cookie categories to play with, a basic privacy policy generator and email support — but no CERT-In breach tracking, Data Principal Rights portal, 22-language support or AI data discovery. Check out the full plan comparison for more details.
Installation takes under 5 minutes. After signing up, you receive a JavaScript snippet to paste before the closing
</head> tag. For WordPress, install the Consiva plugin and connect it with your account API key. For Shopify, the Consiva app is available on the Shopify App Store. The banner auto-detects browser language and serves the appropriate Indian language content.Yes. All personal data processed by Consiva — consent records, breach logs, Data Principal Rights requests, and audit trails — is stored exclusively on servers located in India. Our infrastructure is ISO 27001 certified. Enterprise customers can deploy within their own private cloud on Indian infrastructure for maximum control and data sovereignty.
The Consiva WordPress plugin lets you hook your WordPress website up with your Consiva account in one go — it automatically throws in the DPDP compliant consent pop-up, blocks any non-essential scripts until the user gives consent, and syncs up the consent records with your Consiva dashboard. Plus it's compatible with all the major WP themes, WooCommerce and all the popular analytics plugins too. And as a bonus it's free in the WordPress plugin directory to grab.
Yes. Monthly plans can be cancelled at any time with no penalty — you retain access until the end of your billing period. Annual plans are non-refundable after 30 days but can be cancelled before the next renewal. Your consent records and data remain accessible for 90 days after cancellationfor export purposes. No lock-in, no hidden cancellation fees.
Technical & Implementation
6 questionsWhen a user visits your site, Consiva's script loads before any non-essential tracking scripts. It checks for an existing consent record (stored as a first-party cookie). If no valid consent exists, the banner displays. The user's choice is recorded with a timestamp, IP hash, and user agent. Non-essential scripts are blocked until the corresponding category is consented to. Consent records are transmitted to Consiva's India-hosted servers for audit trail storage.
CERT-In mandates that all cybersecurity incidents — including personal data breaches — must be reported within 6 hours of detection. This applies to all businesses, government bodies, and intermediaries in India. The report must be filed on CERT-In's portal. Consiva's breach tracker starts a countdown the moment an incident is logged and auto-generates a CERT-In-formatted report draft. Full CERT-In guide →
Data discovery is the process of automatically scanning your IT environment — databases, cloud storage, SaaS applications, email systems, and APIs — to identify where personal data exists, what type it is, who has access, and how it flows. You cannot comply with DPDP if you don't know what personal data you hold. Data discovery is the foundational step before building a ROPA, conducting a DPIA, or responding to Data Principal Rights requests. Full guide →
A Record of Processing Activities (ROPA) is a document listing all personal data processing activities — what data is collected, from whom, for what purpose, the legal basis, retention period, and who it is shared with. While GDPR explicitly mandates ROPAs under Article 30, the DPDP Act does not use the term "ROPA" but requires Significant Data Fiduciaries to maintain records for audits. Maintaining a ROPA is best practice and practically necessary for audit readiness. Learn how to automate your ROPA →
For most websites, the basic DPDP-compliant consent banner is live within 10 minutes of signing up. Full setup — cookie scan, banner customisation, consent policy generation, CERT-In breach tracker, and Data Principal Rights portal — typically takes 2–4 hours. Enterprise integrations (API, SSO, custom deployments) are handled by our onboarding team over 1–3 business days. Book a setup call →
A mandatory DPO is only required for Significant Data Fiduciaries notified by the Central Government under Section 10 of the DPDP Act. For most businesses (non-SDFs), a DPO is not legally mandatory but is strongly recommended if you process large volumes of sensitive personal data. Consiva's platform automates many DPO functions — consent governance, rights fulfilment, breach response, and audit reporting — reducing the burden even without a dedicated DPO.
Still Have Questions?
Our compliance team is happy to help. Contact us for a free DPDP compliance assessment tailored to your business.