This guide walks through what the DPDP Act actually requires, where India stands on enforcement right now, and the concrete steps a business — small or large — should be taking to get its house in order.
Digital Personal Data Protection Act: What It Covers
The DPDP Act applies to any group that handles personal data of people in India, whether that happens within India or outside it. If you operate an app or a website that lets users sign up, you fall under it. HR tools and customer databases also count.
The law uses roles that sound familiar, but the terms are set by the Act. It calls you the "Data Fiduciary" if you collect and decide how data is used. It calls the user the "Data Principal" because that is whose data it is. It also uses the term "Significant Data Fiduciaries" for bigger groups or those seen as higher risk — those groups face extra duties, may need an India-based Data Protection Officer, and have to do periodic checks and audits.
In simple terms, DPDP compliance comes down to a short list. Get consent that is clear and specific before you gather personal data. Use the data only for the reason you collected it. Protect the data from loss or misuse. Remove or delete the data when you no longer need it. Also let people reach their data, fix it, or stop use by withdrawing consent.
Where the DPDP Rules Stand
This is where many people get stuck. The DPDP Rules were released on November 13, 2025. The government did not start everything at the same time — instead, it set up a plan with three phases for rollout.
- November 13, 2025 — The foundational, "machinery" provisions came into force. The Data Protection Board of India was formally constituted, and digital complaint filing became technically available, though the Board itself has been slow to staff up.
- November 13, 2026 — This is when Consent Manager registration and API integration become mandatory under Rule 4, and when the Board's enforcement and penalty powers formally switch on.
- May 13, 2027 — the key due date. You need real DPDP work done by then, not just plans on paper. That means consent and notice duties, rules for telling people about breaches, security steps, limits on how long you keep data, and how you erase it. It also covers extra duties for kids' data and the rights given to data principals.
One thing to keep in mind: in early 2026, the Ministry of Electronics and IT floated a proposal to cut the timeline for Significant Data Fiduciaries down from 18 months to 12 months. If that change comes to pass, the new deadline would shift from May 2027 to November 2026. Even with no official word that this is actually going to happen, planning for the sooner date will at least give you a cushion — so that's probably the way to go.
A Simple Way to Approach DPDP Compliance
- Get a grip on where personal data is hiding. You can't secure what you don't know exists. Check every system, spreadsheet, CRM, and third-party tool — note what kind of data is stored, what it's for, and how long you retain it. The usual problem spots are marketing tools, customer support logs, and old backup files.
- Get your consent act together. DPDP rules require that consent is real, clear, and easy to understand — specific, not hidden away as a pre-checked item in a lengthy terms page. Your notice needs to lay out exactly what data you collect, why, and how someone can opt out. Withdrawal needs to be just as easy as giving consent in the first place.
- Sort out your legal basis for processing. Consent isn't the only route — the Act also allows processing for "legitimate uses" in narrowly defined situations, such as an existing employment relationship or a voluntary disclosure for a specific purpose. Map each data flow to a lawful basis rather than assuming consent covers everything by default.
- Put security safeguards in writing and in practice. Rule 6 expects "reasonable security safeguards" — encryption, access controls, monitoring, and logging that can actually detect a breach. This overlaps heavily with general cybersecurity hygiene.
- Build a breach response plan you can actually execute. If a personal data breach occurs, you're expected to notify the Data Protection Board and affected individuals quickly, with the rules pointing toward a 72-hour window for a detailed report. Draft the plan, assign owners, and run it as a tabletop exercise before you ever need it for real.
- Set how long data stays and when it is removed. Do not keep personal data forever without a clear reason. Decide the time limit for each type of data, turn on automatic deletion or anonymising when you can, and apply the same rule to backups and old archives.
- Treat vendors and data processors with care. If someone else handles personal data for you, you still own the responsibility — payment providers, analytics services, cloud hosts included. Review vendor agreements so they match DPDP duties, and check that vendors can help with deletion and access requests.
- Set up a real way for users to act on their rights. People can ask to see their data, fix it, or delete it. You need a working procedure to receive these requests, verify the requester's identity, and respond within a fair time window. A shared inbox is not enough if it is not actually monitored.
- Plan for added duties if you meet the "Significant Data Fiduciary" bar. If your work involves large amounts of data or sensitive categories, you might be classed as a Significant Data Fiduciary — bringing tasks like naming a Data Protection Officer in India, doing Data Protection Impact Assessments regularly, and completing outside audits.
- Keep records of what you do. Regulators and auditors look for proof, not only written promises. Keep consent logs, DPIAs, vendor contracts, training records, and notes from incident response practice.
Get consent capture live first
A DPDP-ready consent banner can be live on your site in minutes — one domain, free, no credit card.
Start Free on Consiva.ai — No Credit Card →Why Waiting Is a Costly Bet
Penalties under the DPDP Act are steep — up to ₹250 crore for serious violations like failing to implement reasonable security safeguards. Even though the Board's full enforcement powers only activate in phases, businesses that start their DPDP compliance work in 2026 will have the breathing room to test processes, fix gaps, and train teams properly. Those that wait until the deadline is close will be rushing through consent redesigns and security audits under pressure — which tends to produce weaker, more expensive outcomes.
Frequently Asked Questions
The Act applies to any Data Fiduciary processing personal data of individuals in India, regardless of size. Smaller businesses do get some relief through exemptions the government can notify for specific categories, but as things stand, there's no blanket small-business carve-out. If you collect names, emails, phone numbers, or similar data, DPDP compliance applies to you.
Full compliance is set for 13 May 2027. However, the enforcement tools and penalties start on 13 November 2026. So if you only plan for the 2027 date, you still have months where you can be exposed. Also note this: some Significant Data Fiduciaries may be given an earlier date if the proposed 12 month move is officially issued.
You must appoint one only if you are a Significant Data Fiduciary. The officer has to be in India and should report straight to the board or the main governing body. If you do not fall in that group, there is no direct duty to appoint one. Still, many firms pick an internal privacy lead as a practical step.
Under the DPDP Act, penalties can reach ₹250 crore in serious cases. Examples include not putting in place reasonable security controls or mishandling a breach notification. The Data Protection Board can also order corrective steps that you must follow, in addition to any money penalty.
Start with a data inventory — you need to know exactly what personal data you hold, where it lives, and why, before any consent, security, or retention fix makes sense. From there, consent redesign and a breach response plan are usually the next most urgent items given how much rebuild work they typically involve.
Start Free — No Credit Card
One domain, 1,000 cookie consents a month, unmetered rights requests, no expiry.