← All posts

1 Sep 2026

DPDP Compliance in India by State and City: Where Your Exposure Actually Differs

Quick answer: DPDP compliance by state and city is a question of exposure, not of different law. The DPDP Act applies identically in every Indian state — there is no Maharashtra DPDP law or Karnataka variant. What changes by location is your exposure: the sectors around you, the languages your customers read consent in, the sector regulator already auditing you, and how ready your vendors are. ProtectComply covers all of India from one platform with consent in 22 Indian languages and India data residency, which is why the same product fits a Chennai hospital and a Gurugram NBFC.

What changes by state under DPDP: sector mix, notice language, regulator overlap and ecosystem readiness, while the Act, Rules and deadlines never change
There is no state-level DPDP law. Four things still differ by where you operate.

DPDP compliance by state and city: what changes and what does not

So if a consultant tells you your state has its own data protection rules, end the conversation. The Digital Personal Data Protection Act, 2023 is central law. The DPDP Rules, 2025 were notified on 13 November 2025 under G.S.R. 846(E), the Data Protection Board was constituted the same day, and every obligation in the Act applies the same way in Patna as in Bengaluru. Moreover, it also applies extraterritorially, so a Kochi company serving overseas users is covered, and so is an overseas company serving Indian users.

In addition, four things do change with where you operate, and they are what makes DPDP compliance by state and city worth mapping at all.

Similarly, your sector mix. However, Section 9 children’s data is an edtech problem, not a steel plant problem. Section 10 Significant Data Fiduciary designation is a Gurugram fintech risk long before it is a Jaipur hotel risk. In short, location is a proxy for sector, and sector is what drives which sections bite.

Moreover, the language your notices need. A Section 5 notice has to be understandable to the person giving consent, and the Act contemplates Indian languages. For example, a Tamil Nadu hospital collecting patient data from walk-in patients cannot rely on an English-only consent screen the way a Bengaluru B2B SaaS product can.

Regulator overlap and local readiness

As a result, the regulator already watching you. Mumbai and Gurugram financial firms answer to RBI, SEBI or IRDAI on data handling before DPDP enters the picture. Still, those overlapping obligations change your sequencing, not your DPDP duties.

Furthermore, your ecosystem’s readiness. In a GCC-heavy city like Hyderabad or Bengaluru, you are often a Data Processor for a foreign Data Fiduciary and the pressure arrives through client contracts. By contrast, in a Tier-2 manufacturing cluster it arrives through a large customer’s vendor questionnaire.

Tier-1 cities

CityData-heavy sectorsSharpest DPDP pressure pointNotice languagesPage
DelhiGovt contractors, edtech, healthcare chains, e-commerce HQs, mediaPublic-sector processing; children’s data in edtechHindi, Punjabi, UrduPlanned
Noida / Greater NoidaIT services, BPO/KPO, edtech, logistics, mediaProcessor obligations; cross-border for offshore clients; call-recording consentHindiConsultants · Companies
GurugramFintech, NBFCs, insurance, BPO, MNC back-offices, SaaSSignificant Data Fiduciary risk; RBI and DPDP overlap; breach response SLAsHindi, HaryanviPlanned
MumbaiBanking, NBFC, insurance, capital markets, media, pharma HQsRBI/SEBI/IRDAI overlap; SDF designation; high-value breach exposureMarathi, Gujarati, HindiPlanned
PuneIT services, auto and manufacturing, engineering R&D, edtechEmployee data via HRMS; vendor risk across supply chainsMarathi, HindiPune guide
BengaluruSaaS, product startups, GCCs, biotech, e-commerce, fintechConsent built into APIs and SDKs; GCC processor role; DPIA practiceKannada, Tamil, Telugu, HindiPlanned
HyderabadPharma and life sciences, IT services, GCCs, aerospace, fintechHealth and clinical-trial data; processor agreementsTelugu, Urdu, HindiPlanned
ChennaiHealthcare and medical tourism, auto, IT services, fintechPatient data; grievance workflows; Tamil-language noticesTamilPlanned
KolkataBanking back-offices, FMCG, healthcare, education, ITPaper-to-digital consent gaps; Bengali noticesBengali, HindiPlanned
Ahmedabad / GIFT CityPharma, chemicals, textiles, fintech (GIFT IFSC), diamondsIFSC cross-border data; MSME readinessGujarati, HindiPlanned
Chandigarh / Mohali / PanchkulaIT parks, pharma, education, govtTricity SME readiness; Punjabi noticesPunjabi, HindiPlanned
JaipurTourism, hospitality, jewellery e-commerce, BPO, educationGuest and booking consent; SME capacityHindi, RajasthaniPlanned
Kochi / ThiruvananthapuramIT (Infopark, Technopark), healthcare, tourism, fintechMalayalam notices; healthcare dataMalayalamPlanned
IndoreIT, pharma, education, agri-techCost-conscious Tier-2 buyers; lean compliance teamsHindiPlanned

States

State / regionMain business citiesDominant sectorsOfficial language(s)Page
MaharashtraMumbai, Pune, Nagpur, NashikFinancial services, IT, auto, pharmaMarathiPlanned
KarnatakaBengaluru, Mysuru, MangaluruSaaS, GCCs, biotech, aerospaceKannadaPlanned
TelanganaHyderabad, WarangalPharma, IT services, GCCsTelugu, UrduPlanned
Tamil NaduChennai, Coimbatore, MaduraiHealthcare, auto, textiles, ITTamilPlanned
Delhi NCRDelhi, Noida, Gurugram, Faridabad, GhaziabadEdtech, fintech, BPO, e-commerce, mediaHindiPlanned
Uttar PradeshNoida, Lucknow, Kanpur, VaranasiIT services, manufacturing, education, govtHindi, UrduPlanned
HaryanaGurugram, Faridabad, PanipatFintech, auto, textiles, BPOHindi, PunjabiPlanned
GujaratAhmedabad, Surat, Vadodara, GIFT CityPharma, chemicals, textiles, IFSC fintechGujaratiPlanned
West BengalKolkata, Siliguri, DurgapurBanking back-offices, FMCG, educationBengaliPlanned
KeralaKochi, Thiruvananthapuram, KozhikodeIT parks, healthcare, tourismMalayalamPlanned
RajasthanJaipur, Jodhpur, UdaipurTourism, jewellery, BPO, educationHindiPlanned
Madhya PradeshIndore, Bhopal, GwaliorIT, pharma, education, agri-techHindiPlanned
PunjabMohali, Ludhiana, Amritsar, JalandharIT, textiles, agri-processing, sports goodsPunjabiPlanned
Andhra PradeshVisakhapatnam, Vijayawada, TirupatiPharma, agri-processing, ports, govt ITTeluguPlanned
OdishaBhubaneswar, Cuttack, RourkelaIT services, steel and mining, educationOdiaPlanned
BiharPatna, MuzaffarpurAgri, education, govt services, retailHindi, UrduPlanned
JharkhandRanchi, Jamshedpur, DhanbadSteel, mining, heavy engineeringHindiPlanned
ChhattisgarhRaipur, BhilaiSteel, power, agriHindiPlanned
UttarakhandDehradun, Haridwar, RudrapurPharma manufacturing, auto components, tourismHindiPlanned
Himachal PradeshShimla, Baddi, SolanPharma manufacturing, tourism, hydroHindiPlanned
GoaPanaji, Verna, MargaoTourism and hospitality, pharma, ITKonkaniPlanned
AssamGuwahati, DibrugarhTea, oil and gas, govt services, retailAssamesePlanned

How to read the state table

In practice, the rows above cover north-eastern states other than Assam, and Union Territories other than Delhi and Chandigarh, rather than giving each a separate guide. Although obligations there are identical, the practical difference is sector mix and scale.

In addition, state IT and startup policy names change between revisions, so each state guide names and dates the current policy rather than repeating one from an old page.

The dates, read against your company type

First, penalties and Consent Manager registration begin 13 November 2026. Full compliance is due 13 May 2027. What that means depends on what you are.

A Bengaluru or Hyderabad GCC acting as a Data Processor is usually driven by the client’s contract date, not the statutory one. Indeed, those clauses are landing now.

A Mumbai or Gurugram regulated financial firm should assume Significant Data Fiduciary designation is plausible under Section 10 and plan for DPIAs, an appointed DPO and audits rather than hoping to stay out of scope.

Meanwhile, a Tier-2 manufacturer or hospital typically has the longest gap between “we should look at this” and “we have a RoPA”, because there is no existing privacy function to build on. Therefore ten weeks is enough for consent, notice and grievance; it is not enough to also discover and map every system.

Similarly, on breaches, be precise about what the Rules require: you must intimate the Board and affected data principals without delay, and file a detailed report with the Board within 72 hours. It is not “you get 72 hours to tell anyone”. As a result, getting that wrong is what turns a contained incident into a ₹200 crore exposure for failure to notify. Security-safeguard failures carry up to ₹250 crore. Our breach notification guide sets out the sequence.

How to use this page

Moreover, find your row, then work in this order. Treating DPDP compliance by state and city as a shortcut to your own risk list is the point of this table.

  1. Run a free readiness check to see which obligation areas you are actually exposed on. It takes about ten minutes.
  2. Second, scan your public website. Cookie banners and contact forms are where most DPDP problems are visible from outside, and our Website Scanner runs 60+ checks.
  3. Work the DPDP compliance checklist against your own systems.
  4. Read Section 5 on notice and Section 13 on grievance redressal. Those two shape most of what your customers will see.
  5. Finally, decide your route: platform, consultant, or both.

Platform, consultant, or law firm

In practice, most companies need two of the three, and the split is fairly consistent regardless of city.

A platform carries the work that repeats forever: consent capture and revocation, a RoPA that stays current, DSR intake and clocks, grievance logging, breach workflow, policy versioning. This is where ProtectComply fits, and where 22-language consent matters most. A Kochi hospital and a Ludhiana exporter need the same machinery in different languages.

By contrast, a consultant carries the one-time judgement calls: scoping, gap assessment, DPIA facilitation, vendor renegotiation. Our Noida and Delhi NCR consultants guide is the model for how to evaluate one, and the criteria travel to any city.

Finally, a law firm carries positions you may have to defend: SDF designation risk, cross-border structures under Section 16, disputes. Certainly you do not need one for consent screens.

As a result, indicative fee bands differ by city and firm size. ProtectComply plans start at ₹4,999/month (Startup), with Protect Pro, Protect Max and Enterprise above it. For how the platform tiers map to obligations, see Best DPDP Platform in India, our national comparison, and the DPDP primer if you are starting from scratch.

Start with your own numbers

Furthermore, take the free 10-minute readiness check and the free Website Compliance Scanner at protectcomply.com/signup. So you will get a picture of where you actually stand against the November and May dates rather than a generic checklist. If your exposure is sector-specific — patient data, children’s data, financial data — talk to sales and we will walk through the consent flows built for it.

Frequently asked questions

Is there a separate DPDP law for my state?

In practice, no. The DPDP Act, 2023 and the DPDP Rules, 2025 are central law and apply identically across India. Instead, your state changes your sector exposure and notice languages, not your obligations.

Is there a Data Protection Board office in Mumbai or Bengaluru?

In addition, the Data Protection Board was constituted on 13 November 2025 under the Rules. However, check its office locations and any regional presence against the current official notification.

Do privacy notices in Marathi, Tamil or Bengali count?

Similarly, yes, and in many consumer-facing settings they work better. Under Section 5 the notice must be understandable to the person consenting, and the Act contemplates Indian languages. In other words, English-only notices are a weak position if your customers do not transact in English.

Do IT companies in Pune or Bengaluru need a DPO?

A Data Protection Officer is mandatory for Significant Data Fiduciaries under Section 10. Many mid-size IT firms will not be designated, but if you are a processor for a large client, expect the DPO requirement to arrive through contract. See our DPO guide.

We are a GCC in Hyderabad processing data for a foreign parent. Are we a Fiduciary?

Usually a Data Processor, with the parent as Data Fiduciary. Nevertheless, the Act applies to you either way, and your processor obligations flow from the contract. Section 16 governs cross-border movement.

Our customers are outside India. Does DPDP still apply?

If you process the personal data of data principals in India, yes, including from outside India. Conversely, if you process only foreign data, your DPDP duties are mainly as a processor under your client’s instructions.

What happens on 13 November 2026?

Penalties become enforceable and Consent Manager registration opens. Then you must reach full compliance by 13 May 2027.

Which module should a Tier-2 SME start with?

Start with Consent Management and the AI Policy Generator, in that order, because they map to the first questions you will be asked. Together, they produce the artefacts a customer or auditor asks for first.

One takeaway on DPDP compliance by state and city: your postcode does not change your obligations, but it is a good shortcut to which ones will hurt first. Find your row, run the readiness check, and work from your own gaps rather than a generic list.

This is general guidance on the DPDP Act and Rules, not legal advice. Verify statutory dates and Board notifications against primary sources: the Ministry of Electronics and Information Technology, the Gazette of India and PIB.