What does the DPDP Act actually require from your business
I've sat through a lot of "we'll deal with it later" conversations about India's data protection law. I get why. The Act passed back in 2023, the rules only showed up in November 2025, and the real deadlines still feel far off.
They're not as far off as they feel. Let me walk you through what this law actually requires, and what you should be doing about it right now.
Quick answer: the DPDP Act applies to any business that processes digital personal data connected to India, regardless of size, including foreign companies serving Indian customers. The rules were notified in November 2025 and roll out in three phases, with full substantive compliance required by May 13, 2027. There's no size exemption. A five-person startup and a 5,000-person company carry the same basic obligations. Penalties for serious violations can reach ₹250 crore per incident.
What is the DPDP Act, and who does it apply to?
It's India's first comprehensive data privacy law, and it applies to you if you handle any digital personal data connected to India, no matter how small your business is.
The Act covers any organisation that determines the purpose and means of processing personal data, called a Data Fiduciary in the law's terminology. That's roughly the same role GDPR calls a "controller." If you collect a customer's name, email, or phone number digitally, you're a Data Fiduciary, full stop.
Here's the part that catches foreign companies off guard. The DPDP law reaches beyond India's borders. If you're based anywhere in the world but offer goods or services to people in India and process their personal data in connection with that, you're covered too. There's no revenue threshold, no employee count cutoff, and no blanket small-business exemption that's been notified.
What's the actual compliance timeline?
Three phases spread across 18 months from when the rules were notified, with the real deadline landing in May 2027.
|
Phase |
Date |
What kicks in |
|
Phase 1 |
November 13, 2025 |
Data Protection Board established, penalty framework active |
|
Phase 2 |
November 13, 2026 |
Consent Manager registration opens |
|
Phase 3 |
May 13, 2027 |
Full substantive compliance mandatory |
Phase 3 is where the real work lands. Notices, consent mechanisms, security safeguards, breach reporting, and data principal rights all need to be fully operational by that date. There's talk of MeitY compressing this window from 18 months to 12, which would move the deadline earlier, but that hasn't been formally confirmed as of mid-2026.
My honest take here: treat 2026 as your build year regardless of whether that compression happens. Consent flows, data inventories, and vendor contracts take months to get right. Waiting for a confirmed deadline before starting is how companies end up in a scramble.
|
👉Must read: DPDP Compliance Checklist |
What do you actually have to do as a data fiduciary?
The core obligations come down to five things: notice, consent, security, breach handling, and honoring individual rights.
-
Give clear notice. Every data collection point needs a plain-language notice explaining what you're collecting and why.
-
Get valid consent. Free, specific, informed, and unconditional. No pre-checked boxes, no bundling multiple purposes into one blanket agreement.
-
Secure the data. Reasonable security safeguards proportionate to the sensitivity of what you're holding.
-
Report breaches within 72 hours. Both to the Data Protection Board and to affected individuals.
-
Honor data principal rights. Access, correction, and deletion requests need a real process behind them, not just a policy document.
If you use a vendor to process data on your behalf, that vendor is a Data Processor under the Act. Using one doesn't transfer your responsibility. You still need contracts in place with adequate safeguards, and you're still accountable if that vendor mishandles the data.
How is consent different under DPDP than what you're probably doing today?
It's stricter than most Indian businesses are used to, and there's no fallback option if consent isn't properly obtained.
This is the detail that surprises people most: unlike GDPR, the DPDP Act does not recognize "legitimate interest" as a basis for processing. Consent is essentially the primary path, alongside a narrow set of specifically defined "legitimate uses" that don't leave much room for interpretation.
That means the consent banner you've been running for years, the one with a pre-checked "I agree" box or a single blanket permission covering five different purposes, almost certainly doesn't hold up under this law. Consent has to be specific to each purpose, and the person has to be able to withdraw it as easily as they gave it.
What happens if there's a data breach?
You have 72 hours to notify affected people, and the notification has to include specific details, not a vague acknowledgment that something happened.
Once a breach occurs, the clock starts immediately. Your notification to affected Data Principals needs to cover what happened in plain language, what data was exposed, what protective steps they can take, and how to reach you with questions. The Data Protection Board also needs to be notified, and the completeness and speed of your report directly affects the penalty you might face.
This is worth testing before you need it. A breach response plan that only exists on paper tends to fall apart in the first real incident. Run through it once with your team so the 72-hour clock doesn't catch anyone off guard.
Are you a significant data fiduciary?
Possibly, if you process data at real scale or in sensitive categories, and the government hasn't published the official list yet, so the safest move is to prepare as if you might qualify.
The Central Government designates Significant Data Fiduciaries, or SDFs, based on the volume and sensitivity of data processed, the risk to individuals, and broader considerations like national security or impact on electoral processes. If you're designated, the obligations step up meaningfully:
-
Appoint a Data Protection Officer based in India, reporting to your board
-
Appoint an independent data auditor
-
Conduct regular Data Protection Impact Assessments
-
Undergo more frequent, more formal audits
As of mid-2026, that official SDF list still hasn't been published. High-volume platforms, fintechs, healthtechs, and large consumer businesses should assume they're likely candidates and prepare accordingly.
What can cross-border data transfer actually look like?
More flexible than you might expect. India didn't copy the strict data localization model some other countries use.
The DPDP Act runs on a negative-list approach. Transfers are allowed to any country except ones the government specifically restricts. No such restricted list has been published yet, so cross-border transfers are currently permitted broadly, subject to safeguards specified later.
This flexibility isn't permanent. SDFs may face additional restrictions on specific categories of data down the line, so map your cross-border data flows now.
What happens if you don't comply?
The penalties are steep enough to change how seriously most businesses treat this, and they stack per violation.
|
Violation type |
Maximum penalty |
|
Failure to maintain reasonable security safeguards |
₹250 crore |
|
Failure to notify a breach |
₹200 crore |
|
Children's data violations |
₹200 crore |
|
Significant Data Fiduciary obligation failures |
₹150 crore |
|
General non-compliance |
₹50 crore |
These aren't caps per company. They're per violation, and they can stack if multiple failures occur from the same incident.
What should you actually do right now?
Work through this in order, and you'll be in a genuinely strong position well before May 2027.
-
Map your data. Know what personal data you collect, where it lives, and who touches it, including vendors.
-
Appoint a responsible person. Even before you know if you'll be designated an SDF, someone needs clear ownership of this program.
-
Rebuild your consent flows. Audit every collection point for pre-checked boxes, bundled permissions, or vague language, and fix them now rather than in a rush later.
-
Put processor contracts in place. Confirm every vendor touching personal data has a contract with real security obligations attached.
-
Draft and test your breach response plan. Don't wait for an actual incident to find out it doesn't work.
What mistakes are businesses making with DPDP prep?
A few patterns show up again and again, and they're all avoidable with a bit of early effort.
-
Waiting for the SDF list before preparing. By the time it's published, you may already be behind. Prepare as if you qualify.
-
Treating consent as a one-time banner fix. Real compliance means every collection point, not just your homepage cookie notice.
-
Assuming vendor contracts are optional. Using a processor doesn't reduce your liability. It just adds another party you need a solid contract with.
-
Underestimating how long consent flow rebuilds actually take. This is engineering and legal work combined, and it rarely finishes in a sprint.
The bottom line
The DPDP Act isn't a distant regulation to worry about later. It applies broadly, the deadlines are real, and the penalties are large enough to matter to businesses of every size.
Start with your data map and your consent flows. Everything else on this list gets easier once those two are actually done. And given how much of this touches legal risk directly, it's worth having your compliance program reviewed by legal counsel familiar with the Act rather than relying on any single guide, including this one.


