Free · No signup · Works offline

DPDP Ready?

Answer three questions and see exactly which of India's Digital Personal Data Protection Rules, 2025 apply to you, when each one bites, and what to do in the first 72 hours of a breach. Every claim below cites its rule number and links the Gazette text.

The two dates that matter

13 November 2026
Rule 4 — Registration and obligations of Consent Managers comes into force (Rule 1(3)).
13 May 2027
Rules 3, 5–16, 22 and 23 — notice, consent, security safeguards, breach reporting and erasure come into force (Rule 1(4)).

Rules 1, 2 and 17 to 21 have been in force since publication in the Official Gazette on 13 November 2025 (Rule 1(2)). Countdowns run on your device clock.

Check what applies to you

Already did GDPR? Only these things are different

If you have a working GDPR programme, most of your muscle transfers. These are the gaps where GDPR habits will quietly put you out of compliance.

TopicGDPRDPDP Rules, 2025
Breach threshold Report only if the breach is likely to result in a risk to the rights and freedoms of individuals No threshold — every personal data breach is reportable (Rule 7)
Breach deadline 72 hours to the supervisory authority; without undue delay to individuals if high risk 72 hours to the Board for the detailed report, plus intimation on coming to know; without delay to every affected individual regardless of risk (Rule 7(1), 7(2))
Grievance response One month to respond to a data subject request Published timeline of not more than ninety days for grievance redressal (Rule 14)
Transfer mechanism Standard Contractual Clauses, adequacy decisions, BCRs No SCCs exist — transfer abroad is permitted subject to requirements the Central Government may specify by general or special order (Rule 15)
Small-org relief Some, e.g. records-of-processing exemption under 250 staff None — no small-business or startup exemption; obligations are uniform regardless of size
Consent middleman No equivalent role Consent Managers — registered with the Board, and must be companies incorporated in India (Rule 4, First Schedule)
Children's data Age of digital consent set by each member state, 13–16 Verifiable consent of a parent or lawful guardian for anyone under 18 (Rule 10), with limited exemptions (Rule 12)
Retention limit General storage-limitation principle, no fixed clock Fixed three-year erasure clock, but only for the classes listed in the Third Schedule, with 48 hours' notice before erasure (Rule 8)

On "Significant Data Fiduciary" thresholds

Rule 13 sets additional obligations for a Significant Data Fiduciary — an annual data protection impact assessment and audit, verification that algorithmic software does not pose a risk to Data Principals' rights, and localisation of personal data and traffic data designated on the recommendation of a government committee. No Significant Data Fiduciaries have been designated yet. You become one only when the Central Government notifies you. Turnover and user-count figures circulating in vendor decks as "SDF thresholds" are interpretation, not statute — this tool will not quote them.

If you've been quoted ₹15 lakh to ₹2 crore

Read the rule text first. Most of what the Rules ask a mid-sized company to do is process work you can staff internally: write a compliant notice (Rule 3), publish a contact for data questions (Rule 9), document your security measures (Rule 6), stand up a grievance route with a published timeline (Rule 14), and write the breach runbook (Rule 7). The heavy items — annual audits, DPIAs, algorithmic verification — sit in Rule 13 and apply only once you are notified as a Significant Data Fiduciary. Price the work against the rule numbers you actually fall under, and ask any vendor to point at the rule behind each line of their quote.

Official sources

Where this tool states a rule number, it was checked against the MeitY Gazette text linked above. Where a claim could not be tied to a specific rule number, the topic is cited without one.