nudgecompliant
Global compliance guide

India Technology Compliance — Plain English

Every regulation that applies to your business in India. Identified, tracked, verified.

Run your free India compliance audit

Why now

India's DPDP Act is reshaping data duties while CERT-In reporting and sector tech-risk rules already bite. Early evidence packs are a competitive advantage.

  • Digital Personal Data Protection Act duties rolling into force through rules and notifications
  • CERT-In directions impose tight cyber-incident reporting timelines
  • MEITY AI policy work is shaping buyer and government expectations
  • RBI technology-risk expectations remain material for fintechs and banks

1. Digital Personal Data Protection Act (DPDP)

What it is
India's framework for processing digital personal data, consent, legitimate uses, security, individual rights, and cross-border transfers.
Who it applies to
Organisations processing digital personal data in India and certain overseas organisations offering goods or services to people in India.
Key deadlines
Duties commence in stages through government notifications and rules — confirm which provisions are live for your processing.
Penalties when duties are not met
The statutory schedule allows penalties up to ₹250 crore for certain failures to take security safeguards.

Not sure if this applies to you? The free audit takes 4 minutes.

Find out where you stand →

2. CERT-In cybersecurity directions

What it is
Mandatory directions on incident reporting, log retention, and synchronised timing for covered entities and service providers.
Who it applies to
Service providers, intermediaries, data centres, companies, and government organisations covered by CERT-In directions.
Key deadlines
Certain cyber incidents must be reported within hours of awareness — build a runbook before you need it.
Penalties when duties are not met
Non-cooperation can attract action under the Information Technology Act framework and related orders.

Not sure if this applies to you? The free audit takes 4 minutes.

Find out where you stand →

3. India AI Policy framework (MEITY)

What it is
National AI policy and advisory work from MEITY covering responsible AI, innovation, and sector adoption.
Who it applies to
Public programmes and private organisations deploying AI in India, especially where government or critical services are involved.
Key deadlines
Policy milestones evolve; treat new MEITY publications as governance-review triggers.
Penalties when duties are not met
Policy frameworks are not always a direct fine schedule; sector and IT laws still apply.

Not sure if this applies to you? The free audit takes 4 minutes.

Find out where you stand →

4. RBI technology risk guidelines (fintechs)

What it is
Reserve Bank of India expectations for IT governance, cybersecurity, outsourcing, and operational resilience in regulated financial entities.
Who it applies to
Banks, NBFCs, payment operators, and fintechs supervised by the RBI or bound by RBI outsourcing rules.
Key deadlines
Supervisory expectations are ongoing; audit and board-review cycles should show continuous attention.
Penalties when duties are not met
RBI supervisory and enforcement actions apply under banking and payments frameworks.

Not sure if this applies to you? The free audit takes 4 minutes.

Find out where you stand →

FAQ

Is DPDP fully in force?
Key parts depend on notifications and rules. Assume privacy programmes must be ready, and track which duties have commenced for your processing.
Who must follow CERT-In directions?
A wide set of service providers and companies in India. If you run digital services or hold systems in India, check whether the directions name your category.
Do startups need RBI tech-risk controls?
If you are RBI-regulated or a material outsourced provider to a regulated entity, yes. Pure unregulated SaaS may still face contractual RBI-style clauses.
What is the fastest way to start?
Map personal data under DPDP, write a CERT-In incident runbook, and inventory AI systems used in India.
Is this legal advice?
No. It is general information only.

Operating across borders?

Operating across multiple jurisdictions? NudgeCompliant maps your obligations across all of them in one audit.

Related regulation hubs

Related reading

This guide is for information only, not legal advice. Requirements change, so confirm critical decisions with a qualified professional.

Other jurisdictions

Compare plain-English hubs for other markets.

Find out where you stand. About 4 minutes.

Tell us what technology you use and where you operate. Get a plain-English readout of what matters, and what doesn't.

Check my tools →

No account. No card. Start with the obligations that matter now.