This stopped being a "someday" law in November 2025
The Digital Personal Data Protection Act got presidential assent in August 2023, but it sat without operative rules for two years. That changed on 14 November 2025, when the DPDP Rules were notified with a phased, 18-month rollout: the Data Protection Board of India became operative immediately, Consent Manager integration becomes mandatory on 13 November 2026, and full substantive compliance is due by 13 May 2027. Regulators are expected to move from guidance and warnings toward active supervision starting November 2026, roughly the point most of this article's readers will be at when they're re-reading it.
The number that gets everyone's attention is the penalty range: ₹10,000 to ₹250 crore per violation, assessed per instance, not per company, per year. A single lapse, missed consent records, an undernotified breach, personal data shared without authorization, can be penalized on its own, and the Data Protection Board can find more than one violation in the same inquiry.
Consent managers protect your website. What protects your registers?
Search for "DPDP Act compliance software" and almost everything you find is a consent-manager, cookie-banner, or data-subject-access-request tool, built to handle the personal data a company collects from its customers through its website and apps. That's real and necessary. It's also not the whole picture.
A company's own governance records hold just as much personal data: a director's address and PAN in the statutory registers, an employee's bank details in HR records, a vendor's contact information in the finance module, a shareholder's identity in the members' register. None of that arrived through a cookie banner, and none of it is covered by a consent-management platform. It's exactly the kind of record a Company Secretary, not a marketing team, is responsible for keeping accurate, complete, and now, secure under a law with ₹250 crore penalties attached. It's no coincidence that India's own Company Secretary institute has started publishing on the CS's role as a central figure in DPDP governance inside the boardroom, not a bystander to a website-compliance project run by someone else.
A cookie banner protects data your company collects. It does nothing for the data your company has already been holding for years, in a register that predates the DPDP Act by a decade.
Masked by default, unmasked only by authorization, logged either way
This is the gap eFilix, our on-premise corporate compliance platform, is built to close. Every personal-data field it stores, director details, employee records, vendor and banker contacts, is masked by default across the system. A user only sees the underlying value if they're explicitly authorized to unmask it, and unmasking is itself a logged, audited action, recorded with who, when, and which record, the same way every edit already is.
That's paired with a dedicated Data Protection Office workspace: a real place for whoever your organization designates to own personal-data handling, consent records, grievance response, and breach workflow, instead of a policy document nobody reopens after the audit. Access history is retained for future review, not just recent activity, so there's an actual record to show a regulator or an internal audit committee, not a gap where one should be.
On-premise-first because we were handling sensitive records before this law existed
This isn't a feature we added to chase a new regulation. Data has run on-premise, security-first systems handling real, sensitive personal data at government scale for over two decades: RajSevaDwar, the Government of Rajasthan's data-exchange layer connecting 40+ departments since 2015, IFMS 3.0, the state's treasury and disbursement system handling financial data for roughly 32,000 Drawing & Disbursing Officers, and IHMS, our hospital-systems engagement integrating with RGHS, Chiranjeevi, Jan Aadhaar, and e-Aushadhi. Data that sensitive doesn't get a second chance if it leaks; the discipline behind eFilix's masking and audit trail is the same discipline that's already been protecting government-scale personal data for years, not a compliance checkbox added for this law specifically.
Common questions on the DPDP Act and company records
Yes. Any record that identifies an individual, a director's address, phone number, or PAN, for example, is personal data under the Act, regardless of whether it's customer-facing or purely internal governance data. The same obligations around security safeguards and purpose limitation apply to it.
Only organizations classified as Significant Data Fiduciaries are required to appoint a formal DPO based in India, reporting to the Board. Other data fiduciaries can instead designate a person to handle data-related queries, but every fiduciary has to publish that person's contact details.
The DPDP Rules were notified 14 November 2025 with an 18-month phased rollout. Consent Manager integration becomes mandatory 13 November 2026, and full substantive compliance is due 13 May 2027. Enforcement is expected to move from guidance toward active supervision from November 2026 onward.
Financial penalties range from ₹10,000 to ₹250 crore per violation, assessed per instance. The Data Protection Board of India sets the amount based on the severity of the violation, the volume of data affected, and whether it's a repeat issue.
It covers customer- and website-facing data flows, but not the personal data already inside a company's own internal records, statutory registers, HR files, and vendor or banker contacts, which are personal data under the Act too and need the same protection.
Want your statutory registers, board records, and HR files DPDP-ready, not just your website? Our eFilix page covers the full platform: board governance, ROC filings, and the Data Protection Office workspace, masking, unmask authorization, and audit trails, built in from the start.

