State · Karnataka
DPDPA Compliance in Karnataka
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 set one date for remaining duties: 13 May 2027. From then, any organisation that decides why and how digital personal data is processed must show a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. For firms across Karnataka, that work is a state file map — not a Bengaluru cookie banner.
Last reviewed: 3 September 2026
Why DPDPA compliance matters in Karnataka specifically
Karnataka's exposure sits outside one IT park. Mysuru pharma and electronic-city suppliers hold worker and clinical-trial vendor IDs. Mangaluru port, refinery and contractor gates keep sailor and driver KYC. Hubballi-Dharwad auto MSMEs run ESI and piece-rate rolls. Kodagu estates hold seasonal labour Aadhaar. Seva Sindhu and municipal vendors process citizen applications as Data Processors; those copies are still personal data and need a Section 8(2) contract.
What Karnataka businesses should prepare first
- Map Bengaluru plus Mysuru, Mangaluru and Hubballi files on one sheet — system, purpose, processor, owner.
- Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
- Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
- Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — payroll, clinic software, port CFS, e-governance vendor.
Frequently asked questions
We only have a Mysuru or Mangaluru unit, not a Bengaluru HQ. Does DPDPA still apply?
Yes. The Act has no city or turnover floor. If you decide the purpose and means for digital personal data — worker IDs, patient files, port contractor KYC — you are a Data Fiduciary. Size and pin code are not carve-outs. Section 8(5) security failures sit under the ₹250 crore Schedule slab.
If a Hubballi MSME or Seva Sindhu vendor copy leaks, who do we tell and by when?
Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.
Do Karnataka schools and coaching centres need a Rule 13 pack?
Not unless the Central Government notifies you as a Significant Data Fiduciary under Section 10. Rule 13 annual DPIA and audit are SDF-only. You still owe notices, grounds, security, dual-clock reporting, erasure, and processor contracts. Children's data needs verifiable parental consent under the Act — that is not Rule 13.
Get a DPDPA readiness walkthrough for your Karnataka business
Book 30 minutes to map Mysuru, Mangaluru and Hubballi files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.