Compliance software · India

DPDP Act and GRC compliance software for Indian businesses

India's Digital Personal Data Protection Act, 2023 and its Rules bring consent, notices, breach reporting and heavy penalties to every business that handles digital personal data — while CERT-In expects cyber incidents reported within six hours. AI Pazz Govnex gives an Indian SME an affordable, per-organization way to get ready.

In short

Every business that processes digital personal data in India will need to follow the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, whose main duties are phased in over the months after their notification in 2025: notice and consent, security safeguards, breach reporting and grievance handling. CERT-In also requires specified cyber incidents to be reported within six hours. Govnex keeps both as control sets, with owners and evidence.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in India

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

DPDP Act

Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025

Track it with your own controls
Regulator
Data Protection Board of India (Ministry of Electronics and Information Technology)
Who it applies to
Every data fiduciary processing digital personal data in India, and processing abroad that offers goods or services to people in India.
If you fall short
Up to INR 250 crore for failing to take reasonable security safeguards; other breaches carry penalties up to INR 200 crore.
What it asks of you
  • A clear notice and free, specific, informed consent — or another legitimate use
  • Reasonable security safeguards to prevent personal data breaches
  • Report a personal data breach to the Data Protection Board and to each affected person
  • Answer data principals' rights and grievances, and erase data when its purpose is served
  • Verifiable parental consent for children's data; a DPO in India, DPIAs and audits for Significant Data Fiduciaries

The DPDP Rules were notified in November 2025 with most obligations taking effect in phases over the following 18 months.

Source: meity.gov.in

CERT-In Directions

CERT-In Directions of 28 April 2022

Track it with your own controls
Regulator
Indian Computer Emergency Response Team (CERT-In)
Who it applies to
Service providers, intermediaries, data centres, body corporates and government organisations.
If you fall short
Penalties and prosecution under the Information Technology Act, 2000.
What it asks of you
  • Report specified cyber security incidents to CERT-In within six hours of noticing them
  • Keep ICT system logs for 180 days within India
  • Synchronise system clocks and designate a point of contact

Source: cert-in.org.in

RBI / SEBI / IRDAI

Sector rules: RBI, SEBI and IRDAI

Track it with your own controls
Regulator
Reserve Bank of India, Securities and Exchange Board of India, Insurance Regulatory and Development Authority
Who it applies to
Banks, NBFCs and payment firms (RBI); listed and market entities (SEBI's Cybersecurity and Cyber Resilience Framework); insurers (IRDAI).
If you fall short
Supervisory action by each regulator.
What it asks of you
  • IT governance, cyber security and resilience frameworks, audits and incident reporting

Source: rbi.org.in

Standards India buyers ask for

How AI Pazz Govnex helps in India

What you needHow Govnex does itModule
DPDP readinessAdd the DPDP Act and Rules as your own control set, assign owners and track readiness as each phase begins.
Notice, consent and data inventoryA register of the personal data you hold, purposes, owners and processors.
Breach reporting to the Board and CERT-InEach incident an issue with its six-hour and Board notification deadlines, owner and actions.
ISO 27001 and SOC 2 for customersReady-made control sets with owners, evidence and internal audit before certification.
Policies staff acknowledgePrivacy and security policies, versioned, with acknowledgement tracked.

Your first 90 days

  1. 1Map the digital personal data you hold, why and with whom it is shared.
  2. 2Add the DPDP obligations as controls, and plan them against the phased start dates.
  3. 3Rewrite your notices and consent flows, and set up grievance handling.
  4. 4Put six-hour CERT-In and DPDP breach reporting in place.
  5. 5Adopt ISO 27001 or SOC 2 if customers ask, and report readiness to management.

Start with what applies to you

Adopt the control sets that fit, add your own for the rest, and give every control an owner. The first months are free.

Start free

Compliance in India: questions and answers

When does the DPDP Act apply?
The Act was passed in 2023 and the DPDP Rules were notified in November 2025. The Data Protection Board provisions started first; most obligations on businesses take effect in phases over the following 18 months.
Does the DPDP Act apply to small businesses?
Yes — it applies to any data fiduciary processing digital personal data, whatever its size. Only some duties, such as those of Significant Data Fiduciaries, are limited to larger or riskier processing.
What are the penalties under the DPDP Act?
Up to INR 250 crore for failing to take reasonable security safeguards against a personal data breach, and up to INR 200 crore for failing to notify a breach or for children's data failures.
How quickly must cyber incidents be reported to CERT-In?
Within six hours of noticing a specified incident, under CERT-In's April 2022 directions.
Is Govnex affordable for Indian SMEs?
Govnex is priced per organization, not per user or per standard, with a free period to start — so a whole team can take part without per-seat costs.
Is the DPDP Act in the Govnex Library?
Not yet as a ready-made set — add its obligations as your own controls. ISO 27001, SOC 2, NIST CSF and the GDPR are ready-made.

Modules India teams start with

Every plan

Compliance management software

Compliance and Control Tracker

Track recurring compliance obligations, assign owners and record the evidence, cycle by cycle.

  • Adopt controls from the Compliance Library — ISO 27001, SOC 2, GDPR, Sri Lanka PDPA and more — as your own editable copies
  • Cycles and assessments whose scope is fixed the moment they open
  • Coverage and maturity scoring, withheld below a coverage floor you set
More about Compliance and Control Tracker
Small business and up

Data protection compliance software

Data Compliance Tracker

What you hold data about and what you do with it: entities and their records with a business owner and a data owner for each, and Records of Processing Activities with a compliance checklist answered item by item.

  • Entities — Customer, Employee, Supplier — each with a business owner and a data owner
  • A RoPA for each activity: its purpose, its owners, and the records it processes — what they hold read beside it
More about Data Compliance Tracker
Small business and up

Regulatory change management software

Regulatory Change

The regulations, standards and frameworks that apply to you — who owns each, whether it is still applicable, and the work to comply with it tracked in its own issue register.

  • Add a regulation from the Compliance Library — its issuer, jurisdiction and editions come with it — or type in one the library does not carry
  • An owner, a status and a rationale for every entry, with the units and jurisdictions it applies to
  • Create an implementation register in Issue & Remediation from the regulation in one click, or link one you already run
More about Regulatory Change