DPDP Act Compliance — Privacy Notice, Consent, Breach Reporting and Website Terms for Indian Businesses

Quick answer: The Digital Personal Data Protection Act 2023 became operational through the DPDP Rules 2025, notified on 13–14 November 2025 in phases: the Data Protection Board and the definitions took effect at once, Consent Manager registration (Rule 4) follows at 12 months (about November 2026), and the substantive duties of every business that processes digital personal data — notice, consent, security safeguards, breach intimation, retention limits, children's data and data-principal rights — apply from about 13 May 2027, eighteen months after notification. Failure to take reasonable security safeguards can draw a penalty of up to ₹250 crore. A January 2026 MeitY consultation floated bringing dates forward; we found no notification doing so, but the commencement text is checked at each engagement.

Last verified 5 October 2026 — rules on this page checked against the current notifications. We update it the day a rule changes.

Timeline — measured from the November 2025 notification

WhenWhat applies
13–14 Nov 2025DPDP Rules 2025 notified (G.S.R. 846(E) as cited by commentators); Data Protection Board constituted; Act's definitions and Board provisions in force
About 13 Nov 2026 (12 months)Rule 4 — Consent Manager registration and obligations
About 13 May 2027 (18 months)Rules 3 and 5–16 — privacy notice, consent, security safeguards, breach intimation (72-hour detailed report), erasure and retention, children's data, Significant Data Fiduciary duties — the date most businesses must plan to
Check before you rely on a date: the day differs by one among commentators (13 or 14 of the month), and one consultation in January 2026 proposed an earlier cut-over. We found no notification advancing the 18-month date, so we plan to May 2027 and re-check the Gazette at each engagement.

What a business has to put in place

Website documents: privacy policy, terms and cookies

What we do

Dates, forms and thresholds are quoted from the governing Act, rules and official portals; where a figure changes by notification or year, the page says so and we confirm it at filing rather than estimate.

Talk to us before you file anything

Call for a free consultation

Frequently asked questions

Is the DPDP Act in force?

In phases: the Data Protection Board and definitions took effect on notification of the Rules in November 2025, consent-manager rules follow at 12 months, and the main duties of data fiduciaries apply about 18 months after notification, around 13 May 2027.

Does the DPDP Act apply to small businesses?

It applies to anyone who processes digital personal data in India, whatever the size; exemptions are limited, so even a small online seller or clinic with customer data must comply.

What is the penalty under the DPDP Act?

Up to ₹250 crore for failure to take reasonable security safeguards, with lower caps for other breaches set in the Act's Schedule.

Do we need a separate privacy notice?

Yes — a clear, itemised notice at or before data collection that states the purpose and how to withdraw consent and complain; a generic policy page is not enough.

How fast must a data breach be reported?

The Data Protection Board and affected individuals must be informed, with a detailed report to the Board within 72 hours of becoming aware.

What is a Consent Manager?

A registered entity that lets individuals give, manage and withdraw consent across businesses; registration opens under Rule 4 about 12 months after notification.

Is a website terms and conditions page mandatory?

Not by statute for every site, but it is the contract that limits liability and fixes payment, refund, intellectual-property and jurisdiction terms, and marketplaces and payment gateways ask for it.

Is the compliance date likely to change?

A January 2026 consultation floated an earlier date; we found no notification advancing it, so plan to May 2027 and verify the Gazette before relying on it.