Compare BizTech
B2B Software

India’s DPDP Compliance for Businesses: A Practical Guide for 2026

DPDP Act compliance guide for Indian businesses covering consent, data security and breach rules

Somewhere in your company right now, a spreadsheet has customer phone numbers sitting in a shared drive nobody’s locked down. An old consent checkbox on your signup form still says “I agree to terms” and nothing else. Your HR system has resumes from three years ago that nobody’s ever going to delete. None of that felt like a legal problem last year. It does now.

DPDP compliance India isn’t a future-tense concern anymore, even though full enforcement doesn’t land until mid-2027. The rules are already notified, the penalties are already written into law, and the soft-enforcement grace period everyone’s leaning on gets shorter every month. So let’s walk through what the law actually asks of you, not the panic-inducing version, the working one.

What Is DPDP?

The Digital Personal Data Protection Act, 2023, or DPDP Act, is India’s first real data privacy law with actual enforcement muscle behind it. Parliament approved it back in August 2023, but it stayed inactive, a law on paper without operational rules, until the government finally notified the DPDP Rules on November 13, 2025.

That notification kicked off a phased rollout. A handful of provisions, setting up the Data Protection Board of India among them, took effect the same day. Consent manager registration arrives on November 13, 2026. And the bulk of what actually changes how you run your business, consent mechanics, breach notification, security obligations, becomes fully enforceable on May 13, 2027.

Until then, the older IT Act and its 2011 security rules technically still administer the space. But treating that as a reason to wait is a mistake. The Data Protection Board is expected to move from guidance mode to active supervision around November 2026, which gives you roughly a year of runway before the questions get pointed.

DPDP Act enforcement timeline from 2023 passage to full enforcement in May 2027

Applicability: Does This Even Apply to You?

Probably, yes. The DPDP Act applies to any business processing digital personal data of individuals in India, and it doesn’t care whether your company is registered here. A software company in Singapore selling to Indian customers falls under it just as much as a Mumbai retailer does, as long as the processing relates to offering goods or services to people in India.

here’s no small-business carve out either. Unlike some privacy laws that exempt companies below a certain revenue or headcount, DPDP applies the same core obligations to a five-person startup and a listed conglomerate. The penalty amounts might land harder on a small business proportionally, but the legal requirement doesn’t shrink to match your size.

One meaningful limit worth knowing: the Act only covers digital personal data, meaning data that’s either collected digitally or later digitized. If you’re still running paper forms that never touch a computer, that data technically sits outside DPDP’s scope for now. Most businesses don’t have that luxury anymore, and honestly, most shouldn’t want it.

Personal Data: What Actually Counts

The Act explains personal data broadly, any information that can identify a living person, directly or indirectly. Names, phone numbers, email addresses, addresses, employee IDs, IP addresses secured to a person, biometric data, financial details. If it can point back to a specific human being, it counts.

What trips people up is the indirect part. A customer ID number alone might look unidentified, but if you can cross-reference it against another database to recognize the person, it’s still individual data under the law. Businesses that assume “we don’t collect names, we’re fine” often notice they’re sitting on more recognizable data than they thought, once someone actually maps it out.

Data Fiduciaries: Who’s on the Hook

DPDP uses its own vocabulary, borrowed loosely from GDPR but not identical to it. Your business, if it decides why and how personal data gets processed, is a Data Fiduciary. That’s roughly what GDPR calls a controller. The individual whose data you’re processing is a Data Principal, not a “user” or “customer” in the legal sense, though obviously they’re both.

Being a Data Fiduciary means the legal responsibility sits with you, even when you hand data off to a vendor or an AI tool to do the actual processing. You can outsource the work. You can’t outsource the accountability. That single point trips up more businesses than almost anything else in the Act, because it means your compliance exposure doesn’t shrink just because a third party is technically doing the processing.

Diagram showing the relationship between Data Fiduciary, Data Processor and Data Principal under DPDP

Consent: The Foundation Everything Else Sits On

Consent is where DPDP gets genuinely strict, and it’s worth spending real time here because getting it wrong undermines everything downstream. Blanket “I agree to terms and conditions” checkboxes don’t cut it anymore. Consent has to be free, specific, informed, unrestricted and clear-cut, and it has to be tied to a clear, stated purpose. Bundling five different uses of someone’s data into one unclear agreement is exactly the pattern the law was written to stop.

Withdrawal matters just as much as collection. If someone can consent with one click, withdrawing has to be roughly that easy too, not buried three menus deep in account settings where nobody will find it. And once consent is withdrawn, you’re expected to stop processing that data going forward, subject to whatever you’re legally required to retain.

Consent Managers are a newer piece of the puzzle; registered intermediaries’ individuals can use to manage and track their consent across multiple businesses in one place. The registration framework for these goes live in November 2026, so this part of the ecosystem is still being built out. Worth watching, not yet something most businesses need to act on directly.

Notice: Telling People What You’re Actually Doing

Before you gather anyone’s personal data, DPDP requires a clear notice, separate from your general privacy policy, that spells out exactly what data you’re collecting, why, and how someone can exercise their rights or withdraw consent. It needs to be understandable, not lawyer-speak dressed up as transparency.

A lot of businesses already have a privacy policy and assume that covers it. It usually doesn’t. Privacy policies tend to be broad, permanent documents covering everything a company might ever do with data. DPDP notice requirements are narrower and more contextual, tied to the specific processing happening at that moment. If your signup form collects an email and a phone number, the notice at that point should say so plainly, not point to a 4,000-word policy written for a different audience entirely.

Rights: What Individuals Can Actually Demand from You

DPDP gives Data Principals four core rights, and it’s worth knowing upfront that this list is shorter than GDPR’s. There’s no right to data portability under Indian law, and no standalone right to object to processing the way GDPR grants one.

What you do have to honor: the right to access information about what data you’re processing and why, the right to correction and erasure of inaccurate, incomplete or outdated data, the right to grievance redressal if someone’s unhappy with how a request was handled, and the right to nominate someone else to exercise these rights on their behalf if they die or become incapacitated. That last one is actually unique to Indian law, not something GDPR or CCPA grant in the same form.

Grievance responses need to happen within a reasonable window the law caps at 90 days, though realistically, taking that long on a simple correction request is going to frustrate people and invite complaints to the Data Protection Board. Build a real process for this rather than treating it as a once-in-a-while email someone in legal handles whenever they get around to it.

Children’s Data: The Strictest Category in the Law

Anyone under 18 counts as a child under DPDP, a notably higher bar than GDPR’s 13-to-16 range depending on the country. Before processing a child’s data, you need verifiable parental consent, not a checkbox that says “I’m over 18,” but actual verification tied to identity and age details.

Rule 10 of the DPDP Rules lays out two accepted ways to verify this: cross-referencing identity and age details you already have on file, or using other government-approved verification mechanisms as they get defined. Beyond consent, the law flatly bans behavioral tracking, profiling and targeted advertising aimed at anyone under 18. There’s no exception carved out for engagement-driven business models here.

If your product serves a general audience and you’re not deliberately marketing to children, you still need an age-gating mechanism, because “we didn’t know they were a minor” isn’t much of a defense if your platform never asked.

Security: What “Reasonable Safeguards” Actually Means

The Act requires “reasonable security safeguards” without spelling out a rigid technical checklist, which sounds unclear until you look at what regulators actually expect: encryption of data at rest and in transit, access controls that restrict who inside your company can see what, audit logs tracking who accessed data and when, and a minimum one-year retention period for processing logs specifically.

This isn’t a set-it-and-forget-it requirement. It extends to your vendors too. If a third-party processor handling your data on your behalf gets breached because their security was compromised, you’re still exposed, since the obligation to implement reasonable safeguards travels with the data, not just the company that collected it originally.

Breach: The 72-Hour Clock You Don’t Want to Discover Mid-Crisis

If a breach happens, the clock starts the moment you become aware of it, not the moment you confirm every detail. You’re expected to give the Data Protection Board an initial intimation without delay, followed by a full report within 72 hours. Affected individuals need to be notified too, without delay, in plain language explaining what happened and what they can do about it.

The penalties here are steep enough to reorganize a company’s priorities overnight. Failing to implement reasonable security safeguards that leads to a breach carries a fine of up to ₹250 crore. Missing the notification window adds up to ₹200 crore on top of that, and these penalties stack, meaning one bad incident involving both a security failure and a late notification can hit you on both fronts simultaneously.

Worth noting too: this runs parallel to, not instead of, your existing CERT-In obligations under the IT Act, which require a 6-hour notification for cybersecurity incidents. Most real breaches trigger both, and filing with one authority doesn’t satisfy the other.

DPDP breach notification timeline showing 72-hour reporting deadline and penalty amounts up to ₹250 crore

Vendors: Your Compliance Doesn’t Stop at Your Own Walls

Every vendor touching personal data on your behalf, your CRM provider, your payroll software, your cloud host, the AI tool your marketing team uses, is effectively an extension of your compliance obligation. DPDP holds Data Fiduciaries responsible for how processors handle data, which means a vague terms-of-service agreement isn’t enough anymore for anything touching real customer or employee information.

Before signing up with a new vendor, check for a proper data processing agreement, ask where their servers are physically located, confirm how long they retain your data by default, and find out whether your data gets used for anything beyond the service you’re paying for, model training being the obvious example with AI tools. If a vendor can’t answer these clearly, that’s worth treating as a red flag rather than a minor gap to sort out later.

AI & DPDP: The Part Most Compliance Plans Skip

Generative AI tools create a specific kind of exposure DPDP wasn’t originally written with in mind, but the law still applies to it. The moment an employee pastes customer or employee data into ChatGPT, Gemini, Claude or Copilot to draft something faster, that tool potentially becomes a data processor, and you’re on the hook for whatever happens to that data next.

Free consumer tiers of most AI tools use your inputs to improve their models by default unless someone manually opts out, and retention windows of around 30 days apply even after opting out, mostly for abuse monitoring. Business and enterprise tiers generally offer better terms, no training on your data by default, proper data processing agreements, sometimes even zero data retention options. But “better” still means checking the actual policy rather than assuming a paid plan automatically means compliant.

If your team uses AI tools at all, and by 2026 almost every team does whether IT approved it or not, build this into your written policy explicitly. What can be pasted in, what can’t, which tools are approved for work touching real personal data, and who owns that decision.

A DPDP Compliance Checklist to Work Through

Think of this less as a legal document and more as a working DPDP compliance checklist you can actually hand to whoever owns this at your company.

DPDP compliance checklist covering consent, data mapping, security, vendor contracts and breach planning

– Rewrite consent language so it’s specific, plain, and separate from your general privacy policy

– Build a real process for handling access, correction and erasure requests within a reasonable timeframe

– Add age verification and parental consent mechanisms anywhere your product could realistically reach a minor

– Review vendor contracts for data processing agreements, retention terms and cross-border transfer details

– Map every place personal data enters your business, forms, apps, vendors, AI tools, and document it in one place

– Set up encryption, access controls and audit logging as a baseline, not an aspiration

– Draft a breach response plan now, including who notifies the Board and within what timeframe, before you need it

– Put someone in charge of AI tool approvals so employees aren’t making that call individually

Common Mistakes Businesses Are Making Right Now

The most common one is treating DPDP like a future problem because enforcement doesn’t fully land until May 2027. That gap is shrinking fast, and the businesses waiting until the deadline to start will be doing months of work under pressure instead of at a reasonable pace now.

Second is assuming an existing privacy policy already satisfies the notice requirement. It usually doesn’t, since DPDP wants something more specific and contextual than a broad, permanent policy document.

Third is forgetting that vendors extend your liability rather than absorbing it. A lot of companies assume that once data leaves their hands and goes to a processor, the risk goes with it. It doesn’t, not under this law.

And fourth, maybe the one growing fastest right now, is letting AI tool adoption outrun any real policy. Employees are using these tools daily whether or not anyone signed off, and every unmanaged use is a small, quiet gap in an otherwise reasonable data privacy India program.

FAQs

Q. When does DPDP actually become enforceable?

A. In phases. Foundational provisions took effect on November 13, 2025. Consent manager registration arrives November 13, 2026. Full enforcement, including the penalty schedule for most obligations, lands May 13, 2027.

Q. Is there a standard DPDP compliance checklist businesses can just follow?

A. There’s no single official document, since obligations vary by what data you handle and how. But the core building blocks are consistent across every business: clear consent, a proper notice, a working rights-request process, reasonable security safeguards, and vendor agreements that actually hold up.

Q. What happens if we’re not compliant by the 2027 deadline?

A. Penalties under the Act range from ₹10,000 for minor Data Principal duty violations up to ₹250 crore for serious security failures. The Data Protection Board is expected to move from guidance to active enforcement well before the hard deadline, so treating May 2027 as the actual start line is a risky bet.

Q. Do small businesses need to worry about DPDP, or is it just for large companies?

A. Everyone needs to worry about it. There’s no size-based exemption in the Act. A small business handling customer data carelessly through an AI tool or an unsecured vendor faces the same penalty structure as a large enterprise would.

Q. What’s the actual difference between a Data Fiduciary and a Data Processor?

A. A Data Fiduciary decides why and how data gets processed; that’s usually your business. A Data Processor handles data on the Fiduciary’s behalf, think your CRM provider or payroll vendor. The legal responsibility stays with the Fiduciary even when a processor is doing the actual work.

Related posts

What Y Combinator’s Top B2B Startups Know About Pricing That You Don’t

Team Compare BizTech

What Is Accounting Practice Management Software — And Do You Need It?

Praveen Kumar Panjiar

a16z’s Winning Strategies For Selling B2B Software In A Tough Market

Team Compare BizTech

Leave a Comment