Business setup8 min read
India's DPDP Act: what a small company has to do
The Digital Personal Data Protection Act, 2023 was brought into force in stages from 13 November 2025. What the consent notice must say, what the security rules require, the 72-hour breach report, the rules on children's data, and the penalty ceilings.
You & Me VenturesPublished 18 September 2026 · sources checked, full verification in progressIndia · Data protection · Compliance · Regulation
The Digital Personal Data Protection Act, 2023 received the President's assent on 11 August 2023 and then sat dormant for two years. Section 1(2) let the Central Government bring it into force in pieces, and no piece was notified until 13 November 2025, when the Ministry of Electronics and Information Technology published G.S.R. 843(E), fixing the commencement dates, and G.S.R. 846(E), the Digital Personal Data Protection Rules, 2025.
The commencement is staggered, and the stagger is the first thing a small company should read. The provisions constituting the Data Protection Board of India, sections 18 to 26, took effect on the date of publication. Sections 3 to 17, which hold every obligation a business actually carries, take effect eighteen months from publication. Eighteen months from 13 November 2025 is 13 May 2027. Section 33, the penalty provision, arrives that day.
When each part switches on
| From | Act provisions | Rules |
|---|---|---|
| 13 November 2025, the date of publication | s.1(2), s.2, ss.18 to 26, ss.35, 38 to 43, s.44(1) and (3) | Rules 1, 2 and 17 to 21 |
| One year from publication | s.6(9), s.27(1)(d) | Rule 4 |
| Eighteen months from publication | ss.3 to 5, s.6(1) to (8) and (10), ss.7 to 10, ss.11 to 17, s.27 other than (1)(d), ss.28 to 34, 36, 37, s.44(2) | Rules 3, 5 to 16, 22 and 23 |
The one-year bucket is narrow. It concerns Consent Manager registration only, and Part A of the First Schedule sets the conditions, including incorporation in India and a net worth of not less than two crore rupees. A company with no intention of operating as a Consent Manager passes that date without effect.
Who has to comply
Section 3 sets the reach. The Act applies to digital personal data processed within India, whether collected in digital form or digitised afterwards. It also applies to processing outside India where that processing is connected with offering goods or services to data principals in India. It does not reach personal data processed by an individual for a personal or domestic purpose, nor personal data the individual has herself made publicly available.
There is no turnover threshold and no headcount threshold. A two-person firm holding a customer list is a data fiduciary on the same terms as a bank. Section 17(3) gives the Central Government power to exempt classes of data fiduciaries, startups included, from the notice, from parts of section 8 and from sections 10 and 11. The Rules notified on 13 November 2025 do not exercise that power.
The notice
Consent is one of two lawful bases. The other is the set of certain legitimate uses in section 7, which covers personal data a person voluntarily provided for a specified purpose without indicating that she objects, and processing for the purposes of employment or to safeguard the employer from loss or liability. Most commercial processing falls back on consent, and consent requires a notice under section 5. Rule 3 is short and unusually prescriptive.
be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary
The notice must give, at a minimum, an itemised description of the personal data and the specified purpose, with a specific description of the goods or services to be provided. It must carry the communication link for the website or app, and any other means by which the person can withdraw consent, exercise her rights and complain to the Board. Section 5(3) adds a language obligation: English or any language specified in the Eighth Schedule to the Constitution. Section 6(10) settles who proves what. Where a question about consent arises in a proceeding, the data fiduciary must prove that notice was given and consent obtained.
Duties the business carries
Section 8(1) makes the data fiduciary responsible irrespective of any agreement to the contrary, and irrespective of the data principal failing her own duties. Handing the work to a vendor does not move the liability. Under section 8(2), a data processor may be engaged only under a valid contract.
- Section 8(3): where personal data is likely to be used for a decision affecting the person, or disclosed to another data fiduciary, it must be complete, accurate and consistent.
- Section 8(7): erase the personal data once consent is withdrawn, or as soon as it is reasonable to assume the specified purpose is no longer served, unless a law requires retention.
- Rule 9: publish prominently on the website or app the business contact information of the Data Protection Officer, where applicable, or of a person who can answer questions about the processing, and repeat it in every response to a rights request.
- Rule 14(3): publish a grievance redressal system that responds within a period not exceeding ninety days.
Section 10 applies only to a data fiduciary the Central Government notifies as a Significant Data Fiduciary, judged on the volume and sensitivity of data processed and the risk to data principals. Rule 13 then requires a Data Protection Impact Assessment and an audit every twelve months, with significant observations reported to the Board.
Security safeguards, written as a list
Rule 6 names a floor rather than a principle. Encryption, obfuscation, masking or virtual tokens mapped to the personal data. Access control over the computer resources used. Logs and monitoring that give visibility on who accessed the data. Backups or equivalent measures for continued processing after a loss. A contractual term obliging the processor to take reasonable safeguards. Rule 6(e) requires those logs and the personal data to be retained for one year, unless another law requires otherwise.
Rule 8(3) is separate and applies whatever the size of the business: personal data, associated traffic data and other logs of the processing must be kept for a minimum of one year from the date of processing, for the purposes set out in the Seventh Schedule, before erasure, even if the data principal deletes her account sooner. A longer, three-year erasure rule in the Third Schedule applies only to an e-commerce entity or social media intermediary with two crore or more registered users in India, or an online gaming intermediary with fifty lakh or more.
Breach notification has no threshold
Rule 7 sets no materiality test and no minimum number of affected people. On becoming aware of any personal data breach, the data fiduciary must intimate each affected data principal without delay, through her user account or a mode of communication she registered, describing the breach and its nature, extent and timing, the consequences likely to arise for her, the measures taken to mitigate risk, the safety measures she can take herself, and contact details for a person who can answer her questions.
The Board receives two communications. Without delay, a description of the breach including its nature, extent, timing, location and likely impact. Then, within seventy-two hours of becoming aware, a fuller account: the facts and circumstances that led to the breach, mitigation measures, any findings about the person who caused it, remedial measures against recurrence, and a report on the intimations given to affected individuals. That deadline extends only on a written request the Board allows.
Children
A child, under section 2(f), is an individual who has not completed eighteen years. Section 9(1) requires verifiable consent of the parent or lawful guardian before any processing of a child's personal data. Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at them. Section 9(2) prohibits processing likely to cause a detrimental effect on a child's well-being.
Rule 10 describes the diligence expected: checking that the individual identifying herself as the parent is an identifiable adult, by reference to identity and age details the fiduciary already holds, details supplied voluntarily, or a virtual token issued by an authorised entity such as a Digital Locker service provider. Part A of the Fourth Schedule switches off sections 9(1) and 9(3) for named classes, among them clinical establishments, educational institutions and crèches. Part B does the same for named purposes, including a user account limited to email and locating a child in the interests of her safety.
The penalty ceiling
| Breach | Penalty may extend to |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach, s.8(5) | ₹250 crore |
| Failure to give the Board or an affected data principal notice of a breach, s.8(6) | ₹200 crore |
| Breach of the additional obligations relating to children, s.9 | ₹200 crore |
| Breach of the additional obligations of a Significant Data Fiduciary, s.10 | ₹150 crore |
| Breach of the duties of a data principal, s.15 | ₹10,000 |
| Breach of a voluntary undertaking accepted by the Board, s.32 | The extent applicable to the breach proceeded against |
| Breach of any other provision of the Act or the Rules | ₹50 crore |
Section 33(2) lists what the Board must weigh before fixing an amount: the nature, gravity and duration of the breach, the type of personal data affected, whether it was repetitive, whether a gain was realised or a loss avoided, and what mitigation was attempted. Penalties are credited to the Consolidated Fund of India under section 34.
The asymmetry in the Schedule is worth reading twice. A data fiduciary that fails to take reasonable security safeguards faces a ceiling of two hundred and fifty crore rupees. An individual who breaches her own duties under section 15 faces ten thousand rupees.
The work between now and 13 May 2027 is dull and specific. Start by writing out every field of personal data the business collects, one line per field, with the purpose beside it. That list is the substance of the rule 3 notice, and nothing else can be drafted until it exists.
Sources
- Gazette of India — The Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
- Ministry of Electronics and Information Technology — commencement notification G.S.R. 843(E), 13 November 2025
- Ministry of Electronics and Information Technology — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025
- Press Information Bureau, Ministry of Electronics & IT — DPDP Rules, 2025 notified, 14 November 2025
Figures are as published on the date above. Rules and fees change. Each source above has been confirmed to exist and resolve; a second pass checking every figure in this article against what its source states is still in progress. This is general information, not professional advice for your situation.