Data Protection

The DPDP countdown: what Indian businesses must do before 14 May 2027

By Adv. K J Muhammed Aslam · Advocate, High Court of Kerala

Published 16 August 2026 · Last reviewed 16 August 2026

Indian businesses must comply with the core obligations of the Digital Personal Data Protection Act, 2023 by 14 May 2027, when its consent, notice, security, breach-reporting and erasure provisions — and penalties of up to ₹250 crore — become enforceable. The DPDP Rules, 2025 were published in the Gazette of India on 14 November 2025 and phase in over eighteen months. One earlier date matters for a narrow group: the Consent Manager framework under Rule 4 takes effect on 14 November 2026. This article sets out the verified timeline, the obligations that bite, and a realistic nine-month plan to meet them.

When exactly does the DPDP Act apply to my business?

It already partly applies. The commencement notification, G.S.R. 843(E), is dated 13 November 2025 but was published in the Gazette on 14 November 2025, together with the Rules, and the phased periods run from publication. The PIB backgrounder confirms the 14 November 2025 notification date.

Date What takes effect
14 November 2025 Definitions (s. 2), Data Protection Board provisions (ss. 18–26), rule-making and miscellaneous provisions (ss. 35–43); Rules 1, 2 and 17–21
14 November 2026 Consent Manager registration: s. 6(9), s. 27(1)(d) and Rule 4 with the First Schedule
14 May 2027 Everything else: ss. 3–5, s. 6(1)–(8) and (10), ss. 7–17, ss. 28–34, 36 and 37; Rules 3, 5–16, 22 and 23; the s. 33 penalty regime

Two practical notes. First, the Data Protection Board of India exists on paper — a four-member, fully digital body whose enabling provisions are in force — but it was not yet functioning as an operational adjudicator as of August 2026. Second, the runway may shrink. In January 2026 MeitY floated compressing the eighteen-month window to twelve months for key obligations, seeking industry feedback by early February 2026. No amending notification had been gazetted as of August 2026, so 14 May 2027 remains the operative date — but a business that plans to finish in April 2027 is betting against a proposal already on the table. Treat late 2026 as the safer internal target.

Is my business a Data Fiduciary under the DPDP Act?

Almost certainly, if it has an app, a website with sign-ups, or a CRM. Section 2(i) defines a Data Fiduciary as any person who, alone or with others, “determines the purpose and means of processing of personal data”. A company deciding what customer data to collect and why is a fiduciary. A vendor processing that data purely on the company’s instructions is a Data Processor under s. 2(k) — but the fiduciary remains responsible for the processor’s compliance under s. 8(1).

The Act applies to digital personal data processed within India, and to processing abroad connected with offering goods or services to people in India (s. 3). It does not apply to purely personal or domestic processing, or to data the individual has themselves made publicly available. There is no small-business turnover threshold. Section 17(3) allows the Central Government to exempt notified classes of fiduciaries — expressly including DPIIT-recognised startups — from some obligations such as notice, data-sharing disclosures and s. 11 access requests, but no such notification had been issued as of August 2026. Plan on full compliance and treat any startup exemption as a bonus.

From 14 May 2027, every consent request must be accompanied or preceded by a standalone notice that a reader can understand without hunting through a privacy policy. Under s. 5 of the Act and Rule 3, the notice must:

  1. Itemise the personal data being collected — not “we collect your information”, but the actual list.
  2. State the specific purpose of processing, and describe the goods, services or uses enabled by it.
  3. Give a direct communication link, and plain-language instructions, for withdrawing consent.
  4. Explain how the user can exercise their rights and complain to the Data Protection Board.
  5. Be available in English or any of the twenty-two Eighth Schedule languages the user opts for.

Consent itself must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action (s. 6(1)). Bundled consent fails: the Act’s own illustration invalidates a telemedicine app demanding contact-list access. The parity rule in s. 6(4) is the one most product teams miss — withdrawing consent must be as easy as giving it was. A one-tap sign-up paired with an email-us-to-withdraw flow will not survive scrutiny. Under s. 6(10), the burden of proving notice and consent sits on the fiduciary, which is why consent logs matter as much as consent screens.

What security safeguards does Rule 6 actually require?

Section 8(5) requires “reasonable security safeguards”, and Rule 6 converts that into a named minimum floor. Every fiduciary must have, at least:

  1. Encryption, obfuscation, masking, or virtual tokens mapped to the personal data.
  2. Access controls on the computer resources used for processing.
  3. Logs, monitoring and review giving visibility into who accessed personal data, to detect and investigate unauthorised access.
  4. Retention of those logs for one year, unless another law requires longer.
  5. Data backups and measures for continued processing if confidentiality, integrity or availability is compromised.
  6. Contract clauses obliging every Data Processor to maintain the same safeguards.

This is the obligation carrying the Act’s highest penalty — up to ₹250 crore — so it deserves the earliest engineering attention. Notably, s. 44(2) of the DPDP Act omits s. 43A of the Information Technology Act, 2000, the old compensation provision for negligent data handling; the DPDP regime replaces it. The IT Act’s offence provisions continue to operate separately — see the IT Act offences explained.

What happens after a data breach — and what is the 72-hour rule?

Rule 7 sets a two-track intimation duty, and it runs on awareness, not convenience. On becoming aware of a personal data breach:

  1. Affected users, without delay. Each affected Data Principal must be informed through their user account or registered contact details, in concise, clear and plain language: what happened, the likely consequences for them, mitigation measures taken, safety steps they can take, and a contact person.
  2. The Board, without delay. An initial intimation describing the breach’s nature, extent, timing and likely impact.
  3. The Board, within 72 hours. A detailed report covering the facts, circumstances, causes, mitigation, findings on the person responsible, remedial steps to prevent recurrence, and a summary of the intimations sent to users. The Board may allow a longer period only on a written request.

Note the design: there is no materiality threshold and no “risk of harm” filter in the text — the definition of personal data breach in s. 2(u) is wide, covering unauthorised processing and accidental disclosure or loss of access. Failing to notify carries a penalty of up to ₹200 crore, separate from the ₹250 crore exposure for the underlying safeguard failure. A written breach-response runbook, with the 72-hour clock built in and owners named, is the only realistic way to comply at 2 a.m. on a holiday.

How long can I keep customer data, and when must I erase it?

The default rule in s. 8(7) is purpose-based: erase personal data once consent is withdrawn or the specified purpose is no longer served, unless retention is required by another law — RBI KYC record-keeping, tax and company-law retention periods being common examples. Rule 8 then adds a hard clock for large platforms via the Third Schedule:

Class of Data Fiduciary Threshold (registered users in India) Erasure trigger
E-commerce entity 2 crore or more 3 years from the user’s last engagement
Online gaming intermediary 50 lakh or more 3 years from the user’s last engagement
Social media intermediary 2 crore or more 3 years from the user’s last engagement

At least 48 hours before erasure, the fiduciary must tell the user their data will be deleted unless they log in or otherwise engage. Rule 8 also requires retention of personal data, traffic data and processing logs for a minimum of one year for specified state purposes. Smaller businesses are not off the hook — the purpose-based erasure duty in s. 8(7) applies to everyone from 14 May 2027, so every business needs a written retention schedule and a working deletion job, not just a policy PDF.

What are the rules for users under 18?

Section 9 treats everyone under eighteen as a child. Before processing a child’s data, a fiduciary must obtain verifiable consent of a parent or lawful guardian. Rule 10 specifies how verification works: relying on identity and age details the fiduciary already holds, or details voluntarily provided and checked through means such as Digital Locker or a virtual token issued by an authorised entity. Rule 11 applies a parallel scheme for persons with disabilities who have lawful guardians.

Three conduct rules follow. Processing likely to cause detrimental effect on a child’s well-being is prohibited (s. 9(2)). Tracking, behavioural monitoring and targeted advertising directed at children are prohibited (s. 9(3)). The Fourth Schedule, via Rule 12, exempts narrow classes and purposes — healthcare, education, real-time safety and similar — from the consent and tracking bars. For everyone else building consumer apps, the practical question is age-gating architecture, and the penalty for getting it wrong is up to ₹200 crore.

What extra duties do Significant Data Fiduciaries have?

Section 10 lets the Central Government notify fiduciaries or classes of them as Significant Data Fiduciaries (SDFs), weighing volume and sensitivity of data, risk to individuals, and factors like electoral democracy and security of the State. No SDF class had been notified as of August 2026, though reporting around the January 2026 MeitY consultation indicated large technology, social media and financial-sector companies are the intended first wave.

Once notified, an SDF must, under s. 10 and Rule 13:

  1. Appoint a Data Protection Officer based in India, answerable to the board of directors, as the grievance contact point.
  2. Appoint an independent data auditor.
  3. Conduct a Data Protection Impact Assessment and an audit once every twelve months, with significant observations reported to the Board.
  4. Exercise due diligence to verify that its technical measures, including algorithmic software, do not pose risks to Data Principals’ rights.
  5. Keep any personal data and related traffic data specified by the Central Government, on a committee’s recommendation, within India.

Breach of SDF duties carries a penalty of up to ₹150 crore. Mid-size companies should watch the notification criteria: an SDF designation can arrive by class, and the MeitY proposal contemplates SDF obligations applying from the amendment’s notification rather than after a grace period.

What rights machinery must be in place for Data Principals?

Sections 11 to 14 give individuals rights to access a summary of their data and the identities of everyone it was shared with, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person to act on death or incapacity. Rule 14 requires the fiduciary to publish how these rights are exercised, and the government’s stated position is that requests must be answered within ninety days.

Under s. 13, every fiduciary needs a readily available grievance mechanism with published response timelines, and an individual must exhaust it before complaining to the Board. That makes the humble grievance inbox a genuine legal defence layer: a documented, timely response can end a matter that an ignored email escalates into a Board inquiry. The same discipline applies when a grievance arrives dressed as a lawyer’s letter — see how to respond to a legal notice.

What penalties apply, and who imposes them?

The Schedule to the Act, read with s. 33, sets ceilings per breach. The Board imposes penalties after inquiry and hearing, weighing gravity, duration, repetition, gains made, and mitigation under s. 33(2). Appeals lie to the TDSAT within sixty days (s. 29).

Breach Maximum penalty
Failure to take reasonable security safeguards — s. 8(5) ₹250 crore
Failure to notify the Board or affected users of a breach — s. 8(6) ₹200 crore
Breach of children’s data obligations — s. 9 ₹200 crore
Breach of Significant Data Fiduciary obligations — s. 10 ₹150 crore
Breach of a Data Principal’s duties — s. 15 ₹10,000
Breach of a voluntary undertaking accepted under s. 32 Up to the penalty for the underlying breach
Any other breach of the Act or Rules ₹50 crore

Section 32’s voluntary undertaking mechanism is worth remembering: the Board can accept a remediation commitment that bars further proceedings on the same facts, which will likely become the pragmatic exit for first-time, good-faith lapses.

What does a realistic 9-month compliance plan look like?

For a small or mid-size company starting now, three quarters of steady work is enough — provided each quarter has named owners and the work is documented as it happens, because s. 6(10) makes records the proof of compliance.

Quarter 1 (September–November 2026): know your data.

  1. Map every system holding personal data — app databases, CRM, analytics, payroll, marketing lists, spreadsheets.
  2. Record, for each dataset: what is collected, why, the lawful basis (consent or a s. 7 legitimate use), where it is stored, who accesses it, and which vendors touch it.
  3. Classify your role — fiduciary or processor — for each flow, and list every Data Processor contract.
  4. Run a gap analysis against ss. 5–13 and Rules 3–14, and fix the priority order.

Quarter 2 (December 2026–February 2027): rebuild the user-facing layer.

  1. Rewrite notices to the Rule 3 itemised standard, with Eighth Schedule language support scoped.
  2. Re-engineer consent flows for affirmative action, granular purposes, and withdrawal parity under s. 6(4), with consent logging.
  3. Stand up the grievance channel, publish response timelines, and publish the s. 8(9) contact point.
  4. Write the retention schedule, build the deletion jobs, and design age-gating and parental-consent flows if minors can use the service.

Quarter 3 (March–May 2027): harden and rehearse.

  1. Implement the Rule 6 floor — encryption or masking, access controls, logging with one-year retention, backups.
  2. Amend processor contracts to pass down security and erasure obligations.
  3. Adopt a breach-response runbook and run one tabletop drill against the 72-hour clock.
  4. Train customer-facing and engineering teams, and close the file with a dated compliance record before 14 May 2027.

Where do Kerala startups stand in all this?

Nothing in the Act turns on geography within India, but the practical exposure of Kerala’s technology cluster is real: SaaS, fintech and health-tech companies at Infopark Kochi and Technopark Thiruvananthapuram typically process data of users across India and abroad, which places them squarely within s. 3, and several already sit inside GDPR-driven contractual frameworks that make DPDP alignment an incremental project rather than a fresh build. In practice, I see the consent-withdrawal parity rule and the retention schedule cause the most rework, because both cut into product and infrastructure rather than paperwork. The constitutional footing is worth remembering too — the framework implements the privacy right recognised in Justice K.S. Puttaswamy v. Union of India. Where board-level sign-off or contract redrafting is needed, an advocate can map the obligations onto the company’s actual data flows and vendor stack; an overview of that kind of work is at data protection practice.

Primary sources

FAQ

Common questions

When does the DPDP Act become enforceable for businesses?
The core obligations — notice, consent, security safeguards, breach reporting, retention limits and Data Principal rights — become enforceable on 14 May 2027, eighteen months after the DPDP Rules, 2025 were published in the Gazette on 14 November 2025. The definitional and Data Protection Board provisions are already in force, and the Consent Manager registration framework under Rule 4 takes effect on 14 November 2026. The Section 33 penalty regime also begins on 14 May 2027.
What are the penalties for not complying with the DPDP Act?
The Schedule to the Act sets penalty ceilings for each breach: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify the Board or affected users of a data breach, up to ₹200 crore for breaching children's data obligations, and up to ₹150 crore for a Significant Data Fiduciary's breach of its additional duties. Any other breach of the Act or Rules can attract up to ₹50 crore. Penalties are imposed by the Data Protection Board after an inquiry and hearing, with appeals to the TDSAT within sixty days.
Does the DPDP Act apply to small businesses and startups?
Yes. Any business that decides why and how digital personal data is processed — which includes almost any company running an app, website, CRM or customer database — is a Data Fiduciary under Section 2(i), regardless of size. Section 17(3) lets the Central Government exempt notified classes of Data Fiduciaries, including recognised startups, from some obligations such as notice and data-sharing disclosures, but no such exemption notification had been issued as of August 2026.
What must a company do within 72 hours of a data breach under the DPDP Rules?
Rule 7 creates a two-track duty. Each affected user must be informed without delay, in plain language, through their user account or registered contact details, describing the breach, its likely consequences, mitigation steps and a contact person. The Data Protection Board must receive an initial intimation without delay and a detailed report within seventy-two hours of the company becoming aware of the breach, extendable only if the Board allows a written request.
Is parental consent required for users under 18 in India?
Yes. Section 9 of the DPDP Act defines a child as anyone under eighteen and requires verifiable consent of a parent or lawful guardian before processing a child's data, with verification done under Rule 10 using identity details already held, or identity and age details confirmed through means such as Digital Locker. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited, subject to narrow exemptions in the Fourth Schedule for purposes like health and education. Breaches attract penalties of up to ₹200 crore.
What is a Consent Manager and what happens on 14 November 2026?
A Consent Manager is an interoperable platform, registered with the Data Protection Board, through which individuals can give, manage, review and withdraw consent across Data Fiduciaries. Rule 4 and the First Schedule — which require a Consent Manager to be an Indian-incorporated company meeting conditions including a minimum net worth of ₹2 crore — take effect on 14 November 2026, twelve months after the Rules were published. Ordinary businesses do not need to register; only entities wanting to operate as Consent Managers do.

Get in touch

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. As required by the Bar Council of India, this website only provides information about Adv. K J Muhammed Aslam to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.