State · Karnataka

DPDPA Compliance in Karnataka

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 set one date for remaining duties: 13 May 2027. From then, any organisation that decides why and how digital personal data is processed must show a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. For firms across Karnataka, that work is a state file map — not a Bengaluru cookie banner.

Last reviewed: 3 September 2026

Why DPDPA compliance matters in Karnataka specifically

Karnataka's exposure sits outside one IT park. Mysuru pharma and electronic-city suppliers hold worker and clinical-trial vendor IDs. Mangaluru port, refinery and contractor gates keep sailor and driver KYC. Hubballi-Dharwad auto MSMEs run ESI and piece-rate rolls. Kodagu estates hold seasonal labour Aadhaar. Seva Sindhu and municipal vendors process citizen applications as Data Processors; those copies are still personal data and need a Section 8(2) contract.

What Karnataka businesses should prepare first

  • Map Bengaluru plus Mysuru, Mangaluru and Hubballi files on one sheet — system, purpose, processor, owner.
  • Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
  • Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
  • Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — payroll, clinic software, port CFS, e-governance vendor.

Frequently asked questions

We only have a Mysuru or Mangaluru unit, not a Bengaluru HQ. Does DPDPA still apply?

Yes. The Act has no city or turnover floor. If you decide the purpose and means for digital personal data — worker IDs, patient files, port contractor KYC — you are a Data Fiduciary. Size and pin code are not carve-outs. Section 8(5) security failures sit under the ₹250 crore Schedule slab.

If a Hubballi MSME or Seva Sindhu vendor copy leaks, who do we tell and by when?

Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.

Do Karnataka schools and coaching centres need a Rule 13 pack?

Not unless the Central Government notifies you as a Significant Data Fiduciary under Section 10. Rule 13 annual DPIA and audit are SDF-only. You still owe notices, grounds, security, dual-clock reporting, erasure, and processor contracts. Children's data needs verifiable parental consent under the Act — that is not Rule 13.

Official sources

Get a DPDPA readiness walkthrough for your Karnataka business

Book 30 minutes to map Mysuru, Mangaluru and Hubballi files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.