State · Maharashtra

DPDPA Compliance in Maharashtra

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 set one date for remaining duties: 13 May 2027. From then, any organisation that decides why and how digital personal data is processed must show a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. For firms across Maharashtra, that work is a state-wide map of files — not a Mumbai-only banner.

Last reviewed: 3 September 2026

Why DPDPA compliance matters in Maharashtra specifically

Maharashtra's exposure is not one city. MIDC estates from Pimpri-Chinchwad to Aurangabad and Nashik hold worker IDs, contractor KYC and visitor logs. Pune's Hinjewadi and Magarpatta units process client data as Data Processors; those copies stay personal data. Western Maharashtra sugar cooperatives and urban cooperative banks keep member KYC next to RBI-shaped NBFCs. JNPT-adjacent CFS and transport firms hold driver Aadhaar packs. A state GST or municipal vendor still needs a Section 8(2) contract.

What Maharashtra businesses should prepare first

  • Build one record-class map that covers Mumbai, Pune, Nagpur, Nashik and MIDC plants — not three local policies.
  • Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i); do not route them through consent you cannot honour if someone withdraws.
  • Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours, including processor copies at an LSP or payroll vendor.
  • Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — LOS, LMS, cooperative core, SEZ IT vendor.

Frequently asked questions

We have offices in Mumbai, Pune and Nashik. Do the DPDPA rules differ by city?

No. The DPDPA is a central Act. One fiduciary framework covers the whole Maharashtra operation. What changes is the file map: MIDC worker IDs, Hinjewadi client data, and cooperative KYC are different purposes. Keep one notice and grievance process, and make each location follow it.

If a Pune vendor or Nagpur NBFC file leaks, who do we tell and by when?

Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.

Does every Maharashtra NBFC need a Rule 13 audit before May 2027?

No. Rule 13 annual DPIA and independent audit start only after a Section 10 Significant Data Fiduciary notice. Most state NBFCs still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Software is not your Section 10(2)(b) auditor. Section 8(5) security failures sit under the ₹250 crore Schedule slab.

Official sources

Get a DPDPA readiness walkthrough for your Maharashtra business

Book 30 minutes to map MIDC, Pune IT and cooperative files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.