State · Madhya Pradesh

DPDPA Compliance in Madhya Pradesh

Madhya Pradesh organisations that process digital personal data must meet remaining DPDPA duties from 13 May 2027: a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. Pithampur contractor packs and mandi KYC will not wait for an Indore-only banner.

Last reviewed: 23 September 2026

Why DPDPA compliance matters in Madhya Pradesh specifically

Madhya Pradesh's exposure is industrial and administrative. Pithampur and Mandideep auto and engineering units hold worker and contractor IDs. Indore pharma and IT seats process client data as Data Processors; those copies stay personal data. Bhopal secretariat and BHEL-adjacent vendors keep citizen and staff files. Soybean mandi traders hold buyer KYC. A state e-district vendor still needs a Section 8(2) contract.

What Madhya Pradesh businesses should prepare first

  • Map Indore, Bhopal, Pithampur and Mandideep files on one sheet — system, purpose, processor, owner.
  • Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
  • Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
  • Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — plant IT, pharma LIMS, e-district vendor, payroll.

Frequently asked questions

We have a Pithampur plant and a Bhopal sales desk. Do the rules differ by city?

No. The DPDPA is a central Act. One fiduciary framework covers the whole Madhya Pradesh operation. What changes is the file map: plant contractor KYC, Indore client copies, and e-district packs are different purposes. Keep one notice and grievance process.

If a Mandideep vendor or e-district copy leaks, who do we tell and by when?

Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.

Does every Madhya Pradesh factory need a Rule 13 audit?

No. Rule 13 annual DPIA and independent audit start only after a Section 10 Significant Data Fiduciary notice. Most still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Software is not your Section 10(2)(b) auditor. Section 8(5) security failures sit under the ₹250 crore Schedule slab.

Official sources

Get a DPDPA readiness walkthrough for your Madhya Pradesh business

Book 30 minutes to map Pithampur, Indore and Bhopal vendor files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.