ComplianceStackLegal & contracts

The DPDP Act: What Indian Startups Must Do About Data Protection Now

the compliance control room25 July 2026 · ComplianceStack

India's Digital Personal Data Protection Act is here — the Rules were notified on 13 November 2025, with the core obligations in force from 13 May 2027 and penalties up to ₹250 crore. Here's what startups must start doing about data protection.

India's Digital Personal Data Protection (DPDP) Act is now real: the DPDP Rules, 2025 were notified on 13 November 2025, the Data Protection Board is being constituted, and the core compliance obligations for businesses handling personal data come into force on 13 May 2027 — with penalties up to ₹250 crore for serious failures. If your startup collects personal data (and almost every startup does), you have a defined runway to get ready. Here's what the Act means and what to start doing now.

Where things stand (as of 2026)

The DPDP Act, 2023 finally has operative rules. Rule 1 of the DPDP Rules, 2025 (G.S.R. 846(E)) staggers commencement from the date of publication:

  • 13 Nov 2025: the Rules are notified. The provisions establishing the Data Protection Board of India take effect immediately (the Board itself is being constituted).
  • 13 Nov 2026: the Consent Manager registration framework comes into force (one year on).
  • 13 May 2027: the substantive obligations on Data Fiduciaries — notice, consent, security safeguards, breach reporting, children's data, Significant Data Fiduciary duties — come into force (eighteen months on).

Until the core provisions bite, the older IT Act rules still govern — but the direction and the dates are now fixed, and the eighteen-month runway from November 2025 is meant for getting ready, not waiting.

What the Act requires (the shape of it)

If your company decides how and why personal data is processed, you're a Data Fiduciary with obligations including:

  • Consent and notice — collect personal data only with clear, informed consent for a stated purpose, and give a plain-language notice.
  • Purpose limitation and minimisation — use the data only for what you collected it for; don't hoard.
  • Data-principal rights — let individuals access, correct, and erase their data, and withdraw consent.
  • Security safeguards — implement "reasonable security" to prevent breaches.
  • Breach notification — notify the Board and affected individuals of a personal-data breach.
  • Children's data — extra protections (verifiable parental consent) for users under 18.
  • Grievance redressal — a mechanism, and (for larger "Significant Data Fiduciaries") extra duties like a Data Protection Officer and audits.

Why startups should not wait

Two reasons the runway is a trap if you sit on it:

  1. The penalties are severe — up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to notify a breach and for breaching the children's-data obligations, and up to ₹50 crore for any other violation.
  2. It's a diligence and enterprise-sales gate. Investors and enterprise customers already ask about data-protection posture. A startup that can show DPDP readiness (consent flows, a privacy policy, security safeguards) clears a check that an unprepared competitor stumbles on — the same way the security posture shows up in diligence.

What to start now

Get ahead of the 13 May 2027 deadline with a readiness plan — see the practical DPDP readiness checklist. The early moves: map what personal data you hold and why, fix your consent and notice flows, update your privacy policy, and put basic security and breach-response in place.

Track DPDP readiness alongside your compliance

DPDP is a new, dated compliance surface with real penalties — exactly the kind of obligation to track deliberately rather than discover late. ComplianceStack helps you keep data-protection readiness (privacy policy, consent, security artifacts) as evidenced items alongside the rest of your compliance. Get your free compliance health check.

FAQs

Is the DPDP Act in force?
The DPDP Rules, 2025 were notified on 13 November 2025 and commencement is phased: the Data Protection Board provisions took effect at once, the Consent Manager framework follows on 13 November 2026, and the core business obligations come into force on 13 May 2027. Until then the older IT Act rules still apply.
Does the DPDP Act apply to startups?
Yes — any company that decides how and why personal data is processed is a Data Fiduciary with obligations, regardless of size. Almost every startup collecting user or customer data is covered.
What are the penalties under the DPDP Act?
Up to ₹250 crore for failing to take reasonable security safeguards; up to ₹200 crore each for failing to notify a breach and for breaching the obligations around children's data; and up to ₹50 crore for any other violation of the Act or Rules.
What should a startup do now?
Use the runway: map the personal data you hold, fix consent and notice, update your privacy policy, and implement reasonable security and breach response — ahead of the 13 May 2027 deadline.

This article is general information, not tax, legal or accounting advice. Statutory timelines and thresholds change by notification — confirm applicability and interpretation with your CA, CS, or lawyer before acting.

Know exactly what applies to you

ComplianceStack builds your applicable GST, TDS, PF/ESI, ROC and legal calendar from a short questionnaire — and keeps the evidence in one place. Your first health check is free.

Get your free health check