Skip to content

Make India privacy operations executable

OpenDPDP is a research corpus and implementation specification for organisations preparing for India’s Digital Personal Data Protection framework. It translates primary-source law into product controls, evidence, workflows, APIs, connector behavior and deployment choices.

Status
Research and product specification · reviewed
As of
29 July 2026
Owner
OpenDPDP maintainers
Scope
India-first; enterprise and SME
Foundational provisions in force Main duties start 13 May 2027 Readiness work now

Software cannot certify a customer as legally compliant. The customer remains accountable for its processing, configuration, organisational measures and legal decisions.

Sector owners

Apply the relevant sector playbook without flattening regulator-specific retention, outsourcing and incident duties.

Three product profiles, deliberately separated

Section titled “Three product profiles, deliberately separated”
  1. Data Fiduciary Privacy Operations — the default enterprise profile: inventory, purposes, notices, consent, rights, retention, breach, processors, evidence and sector overlays.
  2. Data Processor Compliance Plane — customer instructions, tenant-specific boundaries, subprocessors, incidents, deletion/return and evidence rooms.
  3. Statutory Consent Manager — an optional, legally and operationally separate profile. It must never be marketed as registered unless the operating entity has actually obtained Board registration.

The Act’s Board and machinery cohort is in force. The Consent Manager accountability provision and Rule 4 are scheduled for 13 November 2026. Most processing duties and operational Rules are scheduled for 13 May 2027. These dates are controlled by G.S.R. 843(E) and G.S.R. 846(E), not by press summaries.

Read what is verified and what remains open.