City · Delhi
DPDPA Compliance in Delhi
The Digital Personal Data Protection Act, 2023 applies to every business that processes personal digital data in India. Its rules were notified in November 2025, and the substantive obligations — notice, consent, security safeguards, breach reporting and grievance redressal — become enforceable on 13 May 2027. Delhi firms have that window to map data, fix consent and paper processor contracts.
Last reviewed: 25 August 2026
Why DPDPA compliance matters in Delhi specifically
Delhi's economy spans government contractors and PSUs in Connaught Place, a vast IT and consulting sector in Nehru Place and Gurugram-adjacent corridors, plus dense wholesale and export trading hubs in Karol Bagh, Chandni Chowk, and Okhla. This mix means DPDPA compliance in Delhi touches everyone from large system-integrators bidding on government data contracts to thousands of export-import SMEs handling customer and vendor data with little formal consent infrastructure — and none of that data sits in a special "sensitive" tier under the Act.
What Delhi businesses should prepare first
- Map government-contract and citizen-data touchpoints (PSU / tender work) and confirm lawful grounds before sharing with agencies.
- Document lawful grounds and consent records for each processing purpose.
- Name owners for all four breach lanes: CERT-In within 6 hours; Rule 7(1) to affected people without delay; Rule 7(2)(a) initial Board intimation without delay; Rule 7(2)(b) detailed Board report within 72 hours.
- Review vendor contracts for Section 8(2) processor terms, security and escalation clauses.
Frequently asked questions
Do government contractors and vendors in Delhi have extra DPDPA obligations?
Handling government or citizen records does not, by itself, make you a Significant Data Fiduciary. SDF status applies only where the Central Government notifies you under Section 10. Rule 13's DPO, annual audit and DPIA duties follow that notification. High-volume citizen data still needs the same baseline as any other personal data — notice, lawful ground, Section 8(5) security, breach reporting and a published Section 8(9)/8(10) grievance route — and DPDPA has no separate sensitive-data tier.
What counts as a reportable data breach for a Delhi-based trading or export business?
Any unauthorised processing of personal data that compromises confidentiality, integrity or availability — such as customer or vendor contact details — can trigger reporting. Four lanes run cumulatively: CERT-In within 6 hours of noticing a reportable cyber incident; Rule 7(1) intimation to affected Data Principals without delay; Rule 7(2)(a) initial Board intimation without delay; Rule 7(2)(b) detailed Board report within 72 hours.
Are small IT consulting firms in Delhi exempt from DPDPA because they're not SDFs?
No. Every Data Fiduciary must comply with baseline obligations like notice, consent, security safeguards and breach reporting, regardless of size. Only the extra Rule 13 obligations (India-resident DPO, audits, DPIA) are limited to Significant Data Fiduciaries notified under Section 10 — not the Act's core requirements.
Get a DPDPA readiness walkthrough for your Delhi business
Book a 30-minute call to map your consent architecture, vendor exposure, and breach posture against DPDPA.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.