State · Madhya Pradesh
DPDPA Compliance in Madhya Pradesh
Madhya Pradesh organisations that process digital personal data must meet remaining DPDPA duties from 13 May 2027: a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. Pithampur contractor packs and mandi KYC will not wait for an Indore-only banner.
Last reviewed: 23 September 2026
Why DPDPA compliance matters in Madhya Pradesh specifically
Madhya Pradesh's exposure is industrial and administrative. Pithampur and Mandideep auto and engineering units hold worker and contractor IDs. Indore pharma and IT seats process client data as Data Processors; those copies stay personal data. Bhopal secretariat and BHEL-adjacent vendors keep citizen and staff files. Soybean mandi traders hold buyer KYC. A state e-district vendor still needs a Section 8(2) contract.
What Madhya Pradesh businesses should prepare first
- Map Indore, Bhopal, Pithampur and Mandideep files on one sheet — system, purpose, processor, owner.
- Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
- Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
- Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — plant IT, pharma LIMS, e-district vendor, payroll.
Frequently asked questions
We have a Pithampur plant and a Bhopal sales desk. Do the rules differ by city?
No. The DPDPA is a central Act. One fiduciary framework covers the whole Madhya Pradesh operation. What changes is the file map: plant contractor KYC, Indore client copies, and e-district packs are different purposes. Keep one notice and grievance process.
If a Mandideep vendor or e-district copy leaks, who do we tell and by when?
Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.
Does every Madhya Pradesh factory need a Rule 13 audit?
No. Rule 13 annual DPIA and independent audit start only after a Section 10 Significant Data Fiduciary notice. Most still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Software is not your Section 10(2)(b) auditor. Section 8(5) security failures sit under the ₹250 crore Schedule slab.
Get a DPDPA readiness walkthrough for your Madhya Pradesh business
Book 30 minutes to map Pithampur, Indore and Bhopal vendor files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.