Executive and board
Start with current deadlines and product boundaries.
OpenDPDP is a research corpus and implementation specification for organisations preparing for India’s Digital Personal Data Protection framework. It translates primary-source law into product controls, evidence, workflows, APIs, connector behavior and deployment choices.
Software cannot certify a customer as legally compliant. The customer remains accountable for its processing, configuration, organisational measures and legal decisions.
Executive and board
Start with current deadlines and product boundaries.
Privacy and legal
Use the current-status ledger, source method and control matrix.
Product and engineering
Read the module specification, system architecture and API contracts.
CISO and operations
Work from the threat model, security architecture and breach runbook.
Sector owners
Apply the relevant sector playbook without flattening regulator-specific retention, outsourcing and incident duties.
Buyers and partners
Review India segmentation and packaging and the pilot design.
The Act’s Board and machinery cohort is in force. The Consent Manager accountability provision and Rule 4 are scheduled for 13 November 2026. Most processing duties and operational Rules are scheduled for 13 May 2027. These dates are controlled by G.S.R. 843(E) and G.S.R. 846(E), not by press summaries.