Talk to Expert

DPDP Act Compliance for Indian Businesses: The IT Team’s Checklist Before May 2027

India’s Digital Personal Data Protection Act has stopped being a legal-team problem. The DPDP Rules were notified on 13 November 2025, the eighteen-month runway ends in May 2027, and almost every obligation in the Act eventually lands on someone in IT — the person who knows where the data actually sits.

This guide is written for that person: the IT manager, sysadmin or infrastructure lead at an Indian business who has been handed “sort out DPDP” with no privacy team behind them. It covers what the Act requires, which parts are genuinely technical work, and a realistic sequence for getting there.

Who actually has to comply

The Act uses the term data fiduciary — any person or organisation that decides why and how personal data gets processed. That is deliberately broad. If you run a website with a contact form, an HRMS holding employee records, a CRM, or a billing system with customer phone numbers, you are a data fiduciary.

There is no revenue threshold and no employee-count exemption. A forty-person manufacturing company in Noida with a Tally install and a WhatsApp Business number is in scope. So is a Series B SaaS company. The difference is proportionality, not applicability — the Act expects safeguards “appropriate” to your scale, but it does not let small businesses opt out.

A subset of large processors will be designated Significant Data Fiduciaries and carry extra duties: a named Data Protection Officer based in India, independent audits and periodic impact assessments. Most SMEs will not be designated, but if you process data at volume or handle sensitive categories, plan as though you might be.

The dates that matter

  • 13 November 2025 — Rules notified. The Data Protection Board’s constitution and operating provisions took effect immediately.
  • 12 November 2026 — Consent manager registration provisions become operative. If you intend to work through a registered consent manager, this is the gate.
  • May 2027 — Eighteen months from notification, the substantive obligations bite: notice and consent, data principal rights, breach reporting, cross-border transfer conditions, retention limits.

May 2027 sounds distant. It is not, for one specific reason: most of the work is not writing a policy, it is finding out what personal data you hold and where it flows. On a mid-sized estate with a decade of accumulated systems, that discovery exercise alone routinely takes three to six months.

What non-compliance costs

Penalties under the Act are financial and substantial. Failure to take reasonable security safeguards that results in a breach carries up to ₹250 crore. Failure to notify a breach carries up to ₹200 crore. Breaches of obligations relating to children’s data carry up to ₹200 crore, and failures against Significant Data Fiduciary duties up to ₹150 crore. General non-compliance carries up to ₹50 crore.

These are ceilings, not tariffs — the Board weighs the nature of the breach, its gravity, whether it was repetitive, and what you did to mitigate. But note the shape of it: the largest single penalty attaches to security safeguards. That is an IT line item, not a legal one.

The seven things IT owns

1. Knowing what personal data you hold

Every downstream obligation depends on this. You cannot honour an erasure request, set a retention period or scope a breach if you do not know which systems hold personal data. Build a record of processing activities: system, data categories, purpose, lawful basis, retention period, who it is shared with, where it is stored.

Start with the obvious estate — HRMS, CRM, payroll, ticketing, marketing automation, backups — then chase the shadow IT. Spreadsheets on shared drives and exported CSVs in someone’s Downloads folder are where most Indian estates actually leak.

2. Notice and consent capture

Consent under DPDP must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and tied to a notice in plain language. Pre-ticked boxes and bundled consent do not survive. The notice must be available in English and in the Eighth Schedule languages on request, which for consumer-facing businesses means a translation pipeline, not a static PDF.

Withdrawal has to be as easy as giving consent — that is an explicit requirement, and it is the one most homegrown implementations fail. If signing up takes one click and withdrawing takes an email to support, you are not compliant.

3. Data principal rights

Individuals can ask for access to a summary of their data, correction, completion, updating, erasure, and can nominate someone to exercise rights on their behalf. You need an intake route, identity verification, a way to fan the request out across every system in your inventory, and an audit trail proving what you did and when.

Doing this by email and spreadsheet works until you receive your fourth simultaneous request.

4. Grievance redressal

You must publish contact details for a person who can answer questions about your processing, and provide a grievance mechanism. Refusals must state reasons. Unresolved grievances escalate to the Data Protection Board, and the Board will look at your response record.

5. Breach notification

On becoming aware of a personal data breach, you must intimate the Board and every affected data principal without delay, and follow up with a detailed report to the Board within 72 hours. “Without delay” is not “after we finish the RCA.”

Practically, this means your incident response runbook needs a privacy branch: who decides it is reportable, who drafts the principal-facing notice, who files with the Board, and where the evidence lives. If you already run managed detection and response or a SOC, this is a process change, not a new tool.

6. Retention and erasure

Personal data must be erased once the purpose is served and retention is no longer required by law. That means retention schedules per data category, and — the hard part — erasure that actually reaches backups, log stores, analytics warehouses and third-party processors.

7. Processor and vendor contracts

You remain liable for processing done on your behalf. Every vendor touching personal data needs a contract with processing terms, security commitments, breach notification obligations and deletion-on-termination. Build the vendor register alongside your data inventory — they answer the same question from two directions.

The security safeguards clause

The Rules name specific technical measures rather than leaving “reasonable security” undefined: encryption, obfuscation or masking of personal data; access controls; logging and monitoring sufficient to detect unauthorised access; measures for continued processing after a compromise; and retention of logs and personal data for one year for detection purposes unless law requires longer.

Read that list again — it is a standard security baseline. If you have already invested in identity and access management, SIEM and reliable backup, most of the safeguards clause is already satisfied. What is usually missing is the evidence: being able to show the Board, eighteen months later, that the control was operating on the day of the incident.

A realistic sequence

Months 1–2: discovery. Data inventory and RoPA. Vendor register. Identify your highest-risk stores — anything holding Aadhaar, PAN, bank details, health data or children’s data.

Months 2–3: gap assessment. Score current state against each obligation. This is also where you decide whether you are likely to be designated a Significant Data Fiduciary.

Months 3–5: consent and notice. Rebuild consent capture on the website and in the product. Multi-language notices. Withdrawal flows. Cookie banner that actually blocks scripts before consent rather than after.

Months 4–6: rights and grievance. Stand up the DSR intake portal, verification, SLA timers and audit trail. Publish grievance contact details.

Months 5–7: security and breach. Close safeguard gaps found in the assessment. Add the privacy branch to incident response. Run a tabletop exercise against the 72-hour report.

Ongoing: evidence. Every control needs a trail. Retrofitting evidence after an incident is not possible.

Build it or buy it

Consent records, RoPA, DSR workflows, breach registers and grievance logs can all be run on spreadsheets and shared inboxes. Plenty of businesses will try. The failure mode is predictable: the spreadsheet is current for four months, then a system changes, nobody updates the register, and the audit trail has a hole in exactly the period you need it.

The alternative is a purpose-built DPDP compliance platform that anchors each module to the section of the Act it satisfies and keeps the evidence chain intact automatically. ProtectComply is one such platform built specifically for the Indian Act rather than retrofitted from GDPR tooling — consent capture, a readiness assessment, RoPA and data mapping, a data principal rights portal, grievance and breach workflows, and translation into the official Indian languages. For teams without a dedicated privacy function, that shortcut is usually cheaper than the headcount.

Whichever route you take, the sequencing does not change. Inventory first, controls second, evidence throughout.

Frequently asked questions

Does the DPDP Act apply to small businesses in India?

Yes. There is no turnover or headcount threshold. Any organisation that determines the purpose and means of processing digital personal data is a data fiduciary. Obligations scale with risk, but they do not disappear.

What is the DPDP compliance deadline?

The substantive obligations take effect eighteen months after the Rules were notified on 13 November 2025 — May 2027. Consent manager registration provisions become operative from 12 November 2026.

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore for failing to take reasonable security safeguards where that failure leads to a personal data breach. Other categories range from ₹50 crore to ₹200 crore.

How quickly must a data breach be reported?

The Board and every affected data principal must be intimated without delay, with a detailed report to the Board within 72 hours of becoming aware.

Do we need a Data Protection Officer?

Only Significant Data Fiduciaries must appoint a DPO based in India. Every data fiduciary, however, must publish contact details for someone able to answer questions about its processing.

Getting help

Novotron works with businesses across Delhi NCR on the infrastructure and security side of this: data discovery across on-premise and cloud estates, access control and logging gaps, backup and retention design, and incident response runbooks that hold up under a 72-hour reporting clock. If you want a view of where your environment stands before the deadline, talk to our team.

Get A Quote

Scroll to Top