The phased rollout of India’s Digital Personal Data Protection (DPDP) Rules officially began on November 14, 2025, marking the full operationalization of the DPDP Act, 2023. While organizations have an eighteen-month window for phased compliance, the complexity of managing digital identities means you must act now to avoid penalties that go as high as ₹250 crore.
Here is your technical roadmap for operationalizing the new mandates:
Enforce “Reasonable Security Safeguards” (Rule 6)
Rule 6 defines exactly what “reasonable security safeguards” look like, requiring you to protect personal data – including data handled by third-party processors – through:
Meet Higher Obligations for Significant Data Fiduciaries (Rules 13 and 15)
If your organization handles massive volumes of data and is classified as an SDF (significant data fiduciaries), you must:
As a full-stack Identity and Access Management (IAM) platform, we:
Talk to us today to find out how Akku can help your organization achieve full DPDP compliance.
Introduction Every compliance audit, regardless of framework, arrives at the same point: the auditor requests evidence that specific controls operated…
Introduction DPDPA Chapters II and III establish six rights for Data Principals. Each right creates a corresponding technical obligation for…
Introduction GDPR Article 25 requires that data protection be built into system architecture by design and that data minimisation be…
Introduction ISO 27001:2022 Annex A.8.15 requires that logs recording user activities, exceptions, faults, and security events be produced, kept, and…
Introduction Every compliance audit, regardless of framework, arrives at the same point: the auditor requests evidence that specific controls operated…
Introduction SOC 2 CC6 is the Logical and Physical Access Controls criterion cluster and is where the majority of IAM-relevant…