India now has a comprehensive data protection law, and for the first time it applies to almost every business that touches a customer's name, phone number, or email. The Digital Personal Data Protection Act, 2023 sat dormant for two years while the country waited on the operational detail. That detail arrived in November 2025, when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 and constituted the Data Protection Board of India. The regime is now live, and the clock on compliance is running.
This is a plain-English brief on what the law is, when its deadlines land, and why small and mid-sized businesses in particular cannot afford to treat it as a problem for "the big companies."
What the law actually does
The DPDP Act governs the processing of digital personal data — any information about an identifiable person, held or processed digitally, including data collected on paper and later digitised. If your systems hold names, contact details, online identifiers, or behavioural data, you are a Data Fiduciary under the Act: the entity that decides why and how that data is processed. The individuals whose data you hold are Data Principals, and the Act gives them enforceable rights over it.
In practice, the law asks four things of a business:
- Give clear notice and obtain valid consent before collecting personal data. Consent must be free, specific, informed, and unambiguous — a clear affirmative action. Pre-ticked boxes, bundled permissions, and dark patterns are not valid.
- Honour Data Principal rights — access, correction, and erasure of their data, with a defined process to withdraw consent as easily as it was given.
- Secure the data with reasonable technical and organisational safeguards, and notify both the Board and affected individuals if a breach occurs.
- Hold data only as long as needed, then erase it, and keep contracts with any downstream vendors who process data on your behalf.
The timeline that matters
The Rules use a staggered, roughly 18-month runway. Three dates define it:
- November 2025 — the regime goes live. The Act and Rules are in force, the Data Protection Board is constituted, and Data Principals can already file complaints. There is no compliance deadline yet, but the regulator exists and is receiving grievances.
- November 2026 — enforcement machinery activates. The Consent Manager registration framework opens, and the "soft" awareness phase is expected to give way to active supervision. Legacy data — anything collected before the Act that lacks valid notice and consent — comes into focus.
- 13 May 2027 — full compliance is mandatory. Notice and consent standards, Data Principal rights, security safeguards, breach reporting, retention limits, children's-data protections, and cross-border conditions all apply. Because the Board is already operational, no extended grace period is expected.
Eighteen months sounds generous. For a business without a privacy function, mapping every data flow, rebuilding consent, and standing up breach procedures will consume most of it.
Why "we're too small to matter" is the costly mistake
This is where SMEs get caught. Indian regulation usually comes with size-based relief — turnover floors, user thresholds, small-business carve-outs. The DPDP Act does not. It is built around the individual whose data is processed, not the size of the company processing it. A business collecting even a single customer's email is a Data Fiduciary and must comply.
There is a widely repeated myth that startups are exempt. The Act does contain a provision — Section 17(3) — that lets the government exempt certain classes of data fiduciaries, including recognised startups, from some obligations such as notice and retention limits. But that is a power the government may use, not one it has used. No such notification has been issued. Until one is, planning your compliance around a hypothetical future exemption is a gamble, not a strategy — every startup and small business remains subject to the full Act.
The one genuine relief for smaller players: unless the government designates you a Significant Data Fiduciary (a status reserved for high-volume or high-risk processors), you are not required to appoint a Data Protection Officer or run formal data-protection impact assessments. You do, however, need a published point of contact and a working grievance-redressal mechanism.
The cost of getting it wrong
The penalties are not calibrated to company size, and they are steep. The Schedule to the Act sets fixed-rupee ceilings, assessed per instance:
- Up to ₹250 crore — failure to take reasonable security safeguards that leads to a breach. This is the headline number, and it attaches to the most common failure in Indian industry.
- Up to ₹200 crore — failure to notify a breach, and, separately, failure to meet children's-data obligations.
- Up to ₹150 crore — additional obligations of Significant Data Fiduciaries.
- Up to ₹50 crore — any other contravention of the Act or Rules.
Two features make this sharper than the numbers first suggest. Penalties are fixed ceilings rather than a percentage of turnover, so there is no "small company, small fine" cushion — a modest business can face a disproportionate number. And they are cumulative: one incident that reveals inadequate safeguards and a missed notification and processing without consent can draw penalties across each category at once. The Board does weigh mitigating factors — self-disclosure, prompt remediation, a documented compliance record — so a real, evidenced compliance programme directly reduces exposure. Orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal.
The bottom line
DPDP is not a big-company problem with a long fuse. It is a whole-market obligation with a hard 2027 deadline, an already-operational regulator, and penalties indifferent to your size. The businesses that come through it cleanly will be the ones that started early — mapping what data they hold, rebuilding consent and notice, tightening security, and documenting the whole effort so that, if the Board ever asks, the answer is on file.
The first step is the cheapest: find out where you actually stand today. Knowing your specific gaps — before enforcement, before a complaint, before a breach — is what turns an abstract fear of ₹250 crore into a concrete, prioritised, and very manageable to-do list.