“There is a DPDP certification.”
There isn’t. The Act and Rules create no certification for organisations. What you can show is evidence.
From 13 May 2027 the DPDP Rules put real duties on your systems. Check where you stand, then close the gaps.
Under 8 months until the main obligations start. Source: MeitY commencement notification
12 questions. Your answers stay in your browser.
Businesses we’ve hosted and supported since 2009
| Clause | The rule asks for | The control | Evidence to keep |
|---|---|---|---|
| 6(1)(a)Protect the data | Encryption, obfuscation, masking or tokenisation of personal data. | Encryption at rest and in transit; masked data in staging. | Encryption settings, key ownership |
| 6(1)(b)Control access | Appropriate access control on the computer resources that process it. | Named accounts, MFA, least privilege, access reviews. | Access review records |
| 6(1)(c)See who accessed it | Visibility of access through logs, monitoring and review. | Central logging, alerting and a review routine. | Log samples, review notes |
| 6(1)(d)Keep running | Continued processing if confidentiality, integrity or availability is hit, such as backups. | Backups off the server, restores tested. | Restore test reports |
| 6(1)(e)Keep the trail | Retain logs and personal data for one year from processing, to detect and investigate, unless the law requires otherwise. | Log retention of at least one year, then erasure. | Retention settings |
| 6(1)(f)Bind processors | Security safeguards written into contracts with Data Processors. | Security terms your counsel puts in each processor contract, backed by a sub-processor list. | Executed processor contracts with security terms |
| 6(1)(g)Organise it | Appropriate technical and organisational measures to keep safeguards working. | Runbooks, owners and a review calendar. | Runbooks, owner list |
Source: DPDP Rules 2025, Rule 6 (MeitY). Commences 13 May 2027.
Sources: Rule 7 · CERT-In Directions, 28 Apr 2022
| Failing to take reasonable security safeguards | up to ₹250 crore |
| Failing to notify the Board or users of a breach | up to ₹200 crore |
| Breaching obligations for children’s data | up to ₹200 crore |
| Breaching Significant Data Fiduciary obligations | up to ₹150 crore |
| Breaching a voluntary undertaking (s. 32) | up to the cap for the original breach |
| Breaching any other provision | up to ₹50 crore |
| Data Principal breaching their duties | up to ₹10,000 |
The Board sets the amount, weighing gravity, duration, repetition and mitigation. Source: DPDP Act 2023, s. 33 and Schedule
“There is a DPDP certification.”
There isn’t. The Act and Rules create no certification for organisations. What you can show is evidence.
“DPDP means hosting data in India.”
Not by default. Transfers abroad are allowed unless the Government restricts them (s. 16, Rule 15). Sector rules, such as RBI’s, may still apply.
“You have 72 hours before telling anyone.”
Users and the Board must hear without delay. The 72 hours is for the detailed report to the Board.
“Small companies are exempt.”
Not from security safeguards. The Government may exempt notified startups from some duties (s. 17(3)), but not from protecting the data.
“Enforcement has already started.”
The main obligations start on 13 May 2027. Board provisions came into force on 13 Nov 2025.

Under Rule 8 you must make your processors, such as a cloud provider, keep data and logs for a year.
Need application security testing too? Add a VAPT with retest. Watching it afterwards: security monitoring.
yourstore.com · 4 servers, 2 databases, 1 bucket
Preparing the systems that hold personal data for the DPDP Act and Rules: knowing where the data is, securing it, keeping logs, handling breaches and erasure, and having evidence to show. We do the infrastructure side, alongside your counsel.
No. Neither the Act nor the Rules create a certification for organisations. What you can show is evidence: controls, logs, restore tests, access reviews and a VAPT report.
The main obligations, including security safeguards, breach intimation and erasure, start on 13 May 2027, 18 months after the Rules were notified. Consent Manager registration starts 13 November 2026.
Not under DPDP by default. Transfers abroad are allowed unless the Government restricts them, though sector rules (such as RBI) can require local storage, and Rules 13(4) and 15 already allow restrictions for certain data.
At least one year. The Rules require personal data, associated traffic data and processing logs to be kept for at least one year from processing, then erased unless the law needs them longer. You must make your processors, such as cloud providers, keep them too.
No. We handle technical controls and evidence. Your counsel handles legal interpretation, notices, consent and contracts. This page is general information, not legal advice.
Last reviewed 4 October 2026. Status as of October 2026. General information about technical controls, not legal advice; confirm obligations with your counsel.