Published 18 September 2026 · Dravincon Security Team
India's Digital Personal Data Protection Act, 2023 became operational when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 in November 2025. The Rules arrive in phases, and the longest runway — 18 months — covers most of the obligations businesses actually have to build. That window closes in 2027.
The three phases
- Immediately: definitions and the provisions that set up the Data Protection Board.
- After 12 months: registration and obligations of Consent Managers — the platforms that will let people give, manage and withdraw consent across services.
- After 18 months: notices, security safeguards, breach intimation, retention and erasure, children's data, rights of Data Principals and Significant Data Fiduciary duties.
The obligations that take the longest
1. Knowing where personal data lives
You cannot write an honest notice, delete data on time or report a breach accurately if you do not know which systems hold personal data. Data discovery across apps, databases, shared drives, spreadsheets, vendors and backups is the foundation — and typically the slowest step.
2. Notices and consent
Notices must be stand-alone, clear and plain, list the personal data and the specific purpose, and give a direct way to withdraw consent and to complain to the Board. Withdrawing consent must be as easy as giving it. Pre-ticked boxes and bundled "I agree to everything" checkboxes do not survive this standard.
3. Reasonable security safeguards
The Rules expect, at minimum, measures such as encryption, obfuscation or masking, access control, visibility through logs and monitoring, backups for continuity, and contracts that bind your processors to the same standard. Logs relating to processing must be kept for at least one year. Failing to take reasonable safeguards carries the Act's highest penalty — up to ₹250 crore.
4. Breach intimation
On becoming aware of a personal-data breach, you must inform each affected Data Principal and the Data Protection Board without delay, and send the Board a detailed report — facts, cause, mitigation and notifications made — within 72 hours. If you already report cyber incidents to CERT-In within 6 hours, align both processes now so one investigation feeds both.
5. Rights and grievances
People can ask for a summary of their data, correction, completion, updating and erasure, and can nominate someone to act for them. Publish how to make a request and respond to grievances within the period the Rules set — no more than 90 days.
A 90-day starter plan
- Weeks 1–4: appoint an owner, map personal data and processors, list every place you collect it.
- Weeks 5–8: rewrite notices, fix consent capture and withdrawal, define retention periods.
- Weeks 9–12: close security gaps on the systems holding the most sensitive data, write and rehearse the breach playbook.
Not sure where you stand? Our free DPDP check takes about five minutes and runs entirely in your browser.
This article is general information, not legal advice. Refer to the official text of the Act and Rules for your specific obligations.