DPDP Act Compliance

What Every Business Handling Customer Data, Must Do Now
Most businesses that collect a customer’s phone number, email address, or payment detail assume data privacy law is something that applies to tech giants and hospitals, not to them. India’s Digital Personal Data Protection Act changes that assumption completely. If your business processes the digital personal data of anyone in India — a customer database, an employee HR system, a marketing list, a delivery app’s location logs — you are a data fiduciary under this law, regardless of your size, sector, or turnover.
Where the Rollout Actually Stands
The DPDP Act itself was passed back in 2023, but a law without implementing rules is largely aspirational, and it’s the rules that turn broad principles into obligations a business can actually be held to. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and they set out a phased rollout rather than a single switch-on date — which matters, because it means different obligations become enforceable at different times, and treating the whole thing as one distant deadline is a common and costly mistake.
The first phase took effect immediately on notification: the Data Protection Board of India, the body that will handle complaints and enforcement, began being constituted, and digital filing of proceedings started. If your business hasn’t started thinking about DPDP compliance at all, this is the phase you’re already behind on, though the practical consequences of that lag haven’t landed yet.
The second phase lands on 13 or 14 November 2026 (sources differ by a day depending on how the twelve-month period from notification is counted), when the Consent Manager framework under Rule 4 becomes operational. Consent Managers are registered intermediaries — companies incorporated in India with a minimum net worth of ₹2 crore — that give individuals a single interoperable dashboard to grant, review, and withdraw consent across different businesses that hold their data, without the Consent Manager itself being able to read the underlying information. Businesses that rely on third-party consent infrastructure, or whose customer base will expect to manage consent through these platforms, need their systems ready to integrate by this date, not starting the integration after it.
The third and largest phase arrives on 13 May 2027, when the remaining substantive obligations become enforceable all at once, with no indication of a further grace period. This is the phase that actually governs day-to-day operations for most businesses: notice and consent standards, reasonable security safeguards, breach notification timelines, data retention and erasure limits, data principal rights fulfilment, and — for businesses designated as Significant Data Fiduciaries based on the volume, sensitivity, or systemic risk of the data they handle — a heavier set of additional obligations again.
What “Full Compliance” Actually Requires
Stripped of the regulatory language, the DPDP framework asks a business to be able to answer a handful of concrete questions about the personal data it holds, and to have systems in place that make those answers true rather than aspirational.
Can you show, for every piece of personal data you hold, that you collected it with a clear, purpose-specific notice the individual actually understood — in English or any of the 22 Indian scheduled languages, not just the language your business defaults to? Can an individual withdraw consent as easily as they gave it, and does that withdrawal actually stop the downstream uses of their data rather than just switching off a flag somewhere in a database nobody checks? If a breach happens, does your business have a tested process for notifying the Data Protection Board and every affected individual promptly, followed by a detailed report within the required timeline — or would that process be improvised for the first time during an actual crisis? Is personal data deleted once its stated purpose is fulfilled, or does it sit indefinitely in a system that was never built with a retention limit in mind?
These aren’t abstract governance ideals. They’re the specific, auditable requirements the Rules translate the Act into, and a business that can’t answer them concretely today has real work to do before 2027, not a compliance box that can be ticked in a weekend once the deadline gets closer.
Why the Penalty Structure Changes the Calculation
Non-compliance penalties under the DPDP Act can reach ₹250 crore per violation. That figure alone should reframe how this gets prioritised internally — this isn’t a fine on the scale of a delayed regulatory filing that a business can reasonably absorb and move on from. It’s structured to be proportionate to genuinely large organisations and genuinely serious lapses, but the ceiling itself signals how seriously the framework is meant to be taken, and smaller businesses shouldn’t assume the number doesn’t apply to them simply because it sounds disproportionate to their size — the Act doesn’t carve out a separate, gentler penalty scale for smaller data fiduciaries.
Beyond the direct financial exposure, there’s a commercial dimension that’s easy to underweight. Enterprise buyers, particularly in regulated sectors like banking, healthcare, and financial services, are increasingly building DPDP readiness into their vendor due diligence — asking suppliers and partners to demonstrate their own compliance posture before signing a contract. A business that can show a genuine data governance programme closes those deals faster than one that can only offer assurances. Treated well, DPDP compliance becomes a competitive differentiator rather than purely a defensive cost.
Building Toward Compliance Without Panicking
The businesses that will struggle most with the 2027 deadline are the ones that wait until late 2026 to start, because the underlying work isn’t something that compresses well into a short window. It starts with a data inventory — a genuine mapping of what personal data the business actually collects, where it’s stored, who has access to it, and which third parties it gets shared with, since most businesses discover during this exercise that they’re holding more personal data, in more scattered places, than anyone realised.
From there, the priority is building consent architecture that’s granular and purpose-specific rather than a single blanket checkbox, and making sure vendor contracts with any data processor acting on the business’s behalf include the security and accountability clauses the Rules require — a legal workstream that typically takes longer than the technical one, because renegotiating existing vendor agreements takes time businesses often underestimate. Security safeguards — encryption, access controls, logging, monitoring, and backups — need to extend not just to the business’s own systems but to every processor handling data on its behalf.
Where the volume or sensitivity of data justifies it, appointing a Data Protection Officer, whether hired in-house or engaged through outsourced privacy counsel, gives the compliance programme an actual owner rather than leaving it distributed across departments that each assume someone else is responsible. And because this is a live regulatory area rather than a settled one — the Consent Manager ecosystem is still being built out, and enforcement posture will likely sharpen as the Data Protection Board matures — DPDP compliance isn’t a project with a defined end date so much as an ongoing governance function that needs periodic review as the framework itself continues to develop.
The businesses treating 2026 as the year to build this properly, rather than the year to start worrying about it, are the ones that will find May 2027 uneventful. Everyone else will find it expensive.