Skip to content
ZenoCloud Call
DPDP compliance services

DPDP readiness for your infrastructure.

From 13 May 2027 the DPDP Rules put real duties on your systems. Check where you stand, then close the gaps.

Rules notified Data Protection Board provisions in force
Consent Managers Registration of Consent Managers begins
Main obligations Safeguards, breach intimation, erasure, rights, penalties

Under 8 months until the main obligations start. Source: MeitY commencement notification

Free self-assessment

How DPDP-ready are your systems?

12 questions. Your answers stay in your browser.

  1. 1Do you have a current map of where personal data lives: databases, buckets, backups, logs and SaaS tools? Foundation for Rules 6 and 8

  2. 2Is personal data encrypted, masked or tokenised at rest and in transit? Rule 6(1)(a)

  3. 3Do admins use named accounts with MFA, with no shared logins? Rule 6(1)(b) · our recommendation

  4. 4Do you review who has access at least every quarter? Rule 6(1)(b) · quarterly is our recommendation

  5. 5Are access logs collected centrally and reviewed? Rule 6(1)(c)

  6. 6Are logs and relevant personal data kept for at least one year? Rule 6(1)(e), Rule 8(3)

  7. 7Are backups taken and a restore tested in the last 90 days? Rule 6(1)(d) · 90 days is our recommendation

  8. 8Do contracts with your processors and vendors include security obligations? Rule 6(1)(f)

  9. 9Could you detect a breach and tell affected users and the Board without delay? Rule 6(1)(c), Rule 7

  10. 10Could you produce a detailed breach report within 72 hours of becoming aware? Rule 7

  11. 11Do you erase personal data when consent is withdrawn or its purpose ends, including in backups? Act s. 8(7), Rule 8

  12. 12Could you show evidence of all this to a customer or auditor today? Evidence

0 of 12 answered

Businesses we’ve hosted and supported since 2009

  • RR Kabel
  • PC Jeweller
  • Impresario
  • Loom
  • Bhima Gold
Rule 6, clause by clause

The seven safeguards, and the evidence for each.

ClauseThe rule asks forThe controlEvidence to keep
6(1)(a)Protect the dataEncryption, obfuscation, masking or tokenisation of personal data.Encryption at rest and in transit; masked data in staging.Encryption settings, key ownership
6(1)(b)Control accessAppropriate access control on the computer resources that process it.Named accounts, MFA, least privilege, access reviews.Access review records
6(1)(c)See who accessed itVisibility of access through logs, monitoring and review.Central logging, alerting and a review routine.Log samples, review notes
6(1)(d)Keep runningContinued processing if confidentiality, integrity or availability is hit, such as backups.Backups off the server, restores tested.Restore test reports
6(1)(e)Keep the trailRetain logs and personal data for one year from processing, to detect and investigate, unless the law requires otherwise.Log retention of at least one year, then erasure.Retention settings
6(1)(f)Bind processorsSecurity safeguards written into contracts with Data Processors.Security terms your counsel puts in each processor contract, backed by a sub-processor list.Executed processor contracts with security terms
6(1)(g)Organise itAppropriate technical and organisational measures to keep safeguards working.Runbooks, owners and a review calendar.Runbooks, owner list

Source: DPDP Rules 2025, Rule 6 (MeitY). Commences 13 May 2027.

Rule 7 · breach clocks

The clocks that start at a breach.

  1. Without delayOnce you become aware: tell each affected user and send the Board a description.
  2. 72 hoursWithin 72 hours of becoming aware, unless the Board allows longer on written request: facts, mitigation, any findings on who did it, steps to prevent a repeat, and the user notices sent.
  3. 6 hoursIn force today: CERT-In’s 2022 Directions require listed cyber incidents to be reported within 6 hours of noticing them or being told.

Sources: Rule 7 · CERT-In Directions, 28 Apr 2022

Act Schedule · penalties

Penalties run up to ₹250 crore.

Failing to take reasonable security safeguardsup to ₹250 crore
Failing to notify the Board or users of a breachup to ₹200 crore
Breaching obligations for children’s dataup to ₹200 crore
Breaching Significant Data Fiduciary obligationsup to ₹150 crore
Breaching a voluntary undertaking (s. 32)up to the cap for the original breach
Breaching any other provisionup to ₹50 crore
Data Principal breaching their dutiesup to ₹10,000

The Board sets the amount, weighing gravity, duration, repetition and mitigation. Source: DPDP Act 2023, s. 33 and Schedule

Get it right

DPDP myths we keep seeing.

“There is a DPDP certification.”

There isn’t. The Act and Rules create no certification for organisations. What you can show is evidence.

“DPDP means hosting data in India.”

Not by default. Transfers abroad are allowed unless the Government restricts them (s. 16, Rule 15). Sector rules, such as RBI’s, may still apply.

“You have 72 hours before telling anyone.”

Users and the Board must hear without delay. The 72 hours is for the detailed report to the Board.

“Small companies are exempt.”

Not from security safeguards. The Government may exempt notified startups from some duties (s. 17(3)), but not from protecting the data.

“Enforcement has already started.”

The main obligations start on 13 May 2027. Board provisions came into force on 13 Nov 2025.

Illustration of a company's systems with the databases, backups and logs that hold personal data glowing gold
Why an infrastructure team

The Rules name cloud providers as processors. We are one.

Under Rule 8 you must make your processors, such as a cloud provider, keep data and logs for a year.

We do
Data map, access control, encryption, 1-year logs, tested backups, erasure jobs, breach evidence, VAPT.
Your counsel does
Legal advice, notices, consent, processor contracts, DPO and Board filings.
DPDP gap assessment

From data map to evidence pack.

Discover
Map where personal data lives in your systems.
Assess
A gap report against Rules 6, 7 and 8.
Fix
Close the infrastructure gaps, on servers we run or yours.
Evidence
An evidence pack your counsel and customers can use.

Need application security testing too? Add a VAPT with retest. Watching it afterwards: security monitoring.

DPDP gap report · Rules 6–8

yourstore.com · 4 servers, 2 databases, 1 bucket

6(1)(e)
Gap Application logs kept 30 days. Rule needs at least 1 year.
6(1)(b)
Gap Three shared admin logins on the database. Move to named accounts with MFA.
6(1)(d)
Partial Daily backups, restore tested in September. Continuity plan not yet written.
s.8(7), R.8
Gap No rule for erasing deleted accounts from backups. Add one, in line with required retention.
Evidence
Data map, access review, retention schedule, restore test, sub-processor list.
For agencies

Sell DPDP readiness to your clients.

Partner programme
Your name on it
Gap reports and evidence packs under your agency’s brand.
Your margin
Partner pricing. You set what your client pays.
Our team
We do the infrastructure work. You keep the client.
Pricing

DPDP readiness pricing.

Readiness review

Discovery and gap report

Scoped quoteone time

Book a review

Remediation and evidence

Close gaps, build the evidence pack

Scoped quoteper scope

Get a quote

Ongoing monitoring

Keep controls watched

From ₹9,999in Managed Server, per VM a month

See monitoring
Common questions

What is DPDP readiness?

Preparing the systems that hold personal data for the DPDP Act and Rules: knowing where the data is, securing it, keeping logs, handling breaches and erasure, and having evidence to show. We do the infrastructure side, alongside your counsel.

Is there a DPDP certification?

No. Neither the Act nor the Rules create a certification for organisations. What you can show is evidence: controls, logs, restore tests, access reviews and a VAPT report.

When do DPDP obligations start?

The main obligations, including security safeguards, breach intimation and erasure, start on 13 May 2027, 18 months after the Rules were notified. Consent Manager registration starts 13 November 2026.

Do we have to host our data in India?

Not under DPDP by default. Transfers abroad are allowed unless the Government restricts them, though sector rules (such as RBI) can require local storage, and Rules 13(4) and 15 already allow restrictions for certain data.

How long must we keep logs?

At least one year. The Rules require personal data, associated traffic data and processing logs to be kept for at least one year from processing, then erased unless the law needs them longer. You must make your processors, such as cloud providers, keep them too.

Does this replace our lawyer?

No. We handle technical controls and evidence. Your counsel handles legal interpretation, notices, consent and contracts. This page is general information, not legal advice.

Primary sources

Last reviewed 4 October 2026. Status as of October 2026. General information about technical controls, not legal advice; confirm obligations with your counsel.

Get started

Book a DPDP readiness review.

Tell us what you run and your deadline. We reply within one business day with a scoped quote.

Prefer to talk? Call India +91 99991 08033 or US +1 714 242 5683

Add details (optional)

We reply within one business day.

Quote request

What should we quote?

Describe the configuration or problem, location and timing.