State · Gujarat

DPDPA Compliance in Gujarat

From 13 May 2027 the remaining DPDPA duties apply across Gujarat. If you decide why and how digital personal data is processed, you need a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. That is one state map — not an Ahmedabad-only policy PDF.

Last reviewed: 9 September 2026

Why DPDPA compliance matters in Gujarat specifically

Gujarat's files sit in more than one GIDC. Surat diamond and textile floors hold worker and buyer KYC. Ahmedabad pharma and chemical plants keep contractor IDs. Vadodara refinery gates log visitors. Mundra and Kandla CFS firms hold driver Aadhaar packs. Dairy cooperatives keep member rolls. A state GST or municipal vendor still needs a Section 8(2) contract. Processor copies stay personal data.

What Gujarat businesses should prepare first

  • Map Ahmedabad, Surat, Vadodara and port CFS files on one sheet — system, purpose, processor, owner.
  • Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
  • Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
  • Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — GIDC IT, cooperative core, port CFS, payroll.

Frequently asked questions

We have units in Surat and Vadodara. Do DPDPA rules differ by city?

No. The DPDPA is a central Act. One fiduciary framework covers the whole Gujarat operation. What changes is the file map: diamond-floor KYC, refinery visitor logs, and CFS driver packs are different purposes. Keep one notice and grievance process.

If a Kandla CFS or GIDC vendor file leaks, who do we tell and by when?

Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.

Does every Gujarat NBFC or cooperative need a Rule 13 pack?

No. Rule 13 annual DPIA and audit start only after a Section 10 Significant Data Fiduciary notice. Most still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Section 8(5) security failures sit under the ₹250 crore Schedule slab.

Official sources

Get a DPDPA readiness walkthrough for your Gujarat business

Book 30 minutes to map Surat, GIDC and port CFS files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.