The phased rollout of India’s Digital Personal Data Protection (DPDP) Rules officially began on November 14, 2025, marking the full operationalization of the DPDP Act, 2023. While organizations have an eighteen-month window for phased compliance, the complexity of managing digital identities means you must act now to avoid penalties that go as high as ₹250 crore.
Here is your technical roadmap for operationalizing the new mandates:
Enforce “Reasonable Security Safeguards” (Rule 6)
Rule 6 defines exactly what “reasonable security safeguards” look like, requiring you to protect personal data – including data handled by third-party processors – through:
Meet Higher Obligations for Significant Data Fiduciaries (Rules 13 and 15)
If your organization handles massive volumes of data and is classified as an SDF (significant data fiduciaries), you must:
As a full-stack Identity and Access Management (IAM) platform, we:
Talk to us today to find out how Akku can help your organization achieve full DPDP compliance.
Introduction RBI 2023 Master Direction Clause 19 is the most technically detailed access control provision in the framework. It establishes…
Introduction SEBI CSCRF's Protect function contains the Access Authentication sub-category PR.AA, which runs from PR.AA.S1 through PR.AA.S17 and represents the…
Introduction DPDPA Clause 6 sets specific conditions for consent as a lawful basis for processing personal data. Consent must be…
Introduction Most IT teams at regulated organisations experience compliance audits as events. A notice arrives. A scramble begins. Access records…
Introduction IRDAI ICS Annexure III Item 14 requires that all access to organisational systems be authenticated through a centralised authentication…
Indian companies with EU customers, EU operations, or EU-based employees are subject to the General Data Protection Regulation regardless of…