DPDP Act Compliance — Privacy Notice, Consent, Breach Reporting and Website Terms for Indian Businesses
Quick answer: The Digital Personal Data Protection Act 2023 became operational through the DPDP Rules 2025, notified on 13–14 November 2025 in phases: the Data Protection Board and the definitions took effect at once, Consent Manager registration (Rule 4) follows at 12 months (about November 2026), and the substantive duties of every business that processes digital personal data — notice, consent, security safeguards, breach intimation, retention limits, children's data and data-principal rights — apply from about 13 May 2027, eighteen months after notification. Failure to take reasonable security safeguards can draw a penalty of up to ₹250 crore. A January 2026 MeitY consultation floated bringing dates forward; we found no notification doing so, but the commencement text is checked at each engagement.
Last verified 5 October 2026 — rules on this page checked against the current notifications. We update it the day a rule changes.
Timeline — measured from the November 2025 notification
| When | What applies |
|---|---|
| 13–14 Nov 2025 | DPDP Rules 2025 notified (G.S.R. 846(E) as cited by commentators); Data Protection Board constituted; Act's definitions and Board provisions in force |
| About 13 Nov 2026 (12 months) | Rule 4 — Consent Manager registration and obligations |
| About 13 May 2027 (18 months) | Rules 3 and 5–16 — privacy notice, consent, security safeguards, breach intimation (72-hour detailed report), erasure and retention, children's data, Significant Data Fiduciary duties — the date most businesses must plan to |
What a business has to put in place
- Itemised notice: a standalone, plain-language notice at or before collection — what data, for which purpose, how to withdraw consent, how to exercise rights and how to complain to the Board; a long marketing-style privacy policy alone does not meet this
- Valid consent: free, specific, informed, unambiguous, with a clear affirmative action and a withdrawal route as easy as giving consent; "legitimate uses" (such as employment or legal obligations) are listed in the Act
- Security safeguards and breach process: encryption or equivalent controls, access logs, a tested incident plan, intimation to the Board and affected people with the detailed report within 72 hours
- Retention and erasure: delete when the purpose ends, unless law requires retention; vendor (processor) contracts that bind the processor to the same duties
- Children: verifiable parental consent for under-18s and no tracking or targeted advertising directed at children
- Penalties: up to ₹250 crore for failure to take reasonable security safeguards; other breaches carry lower caps set in the Act's Schedule
Website documents: privacy policy, terms and cookies
- Privacy notice/policy rewritten to the DPDP structure, with a grievance contact and a purpose-by-purpose data map
- Website terms and conditions: the contract with users — scope of service, payment and refund terms, intellectual property, limitation of liability, governing law and jurisdiction (Delhi or Patna courts, as relevant), and intermediary due-diligence statements under the IT Act where you host user content
- Cookie banner and preference centre that records consent, not just displays a notice
What we do
- Data-flow mapping, gap assessment against the Rules, privacy notice, consent screens, breach playbook and vendor clauses
- Website terms and conditions and privacy policy drafting; board-level briefing note
- Pairs with POSH and HR policies, employment, vendor and NDA drafting and company compliance
Dates, forms and thresholds are quoted from the governing Act, rules and official portals; where a figure changes by notification or year, the page says so and we confirm it at filing rather than estimate.
Talk to us before you file anything
Frequently asked questions
Is the DPDP Act in force?
In phases: the Data Protection Board and definitions took effect on notification of the Rules in November 2025, consent-manager rules follow at 12 months, and the main duties of data fiduciaries apply about 18 months after notification, around 13 May 2027.
Does the DPDP Act apply to small businesses?
It applies to anyone who processes digital personal data in India, whatever the size; exemptions are limited, so even a small online seller or clinic with customer data must comply.
What is the penalty under the DPDP Act?
Up to ₹250 crore for failure to take reasonable security safeguards, with lower caps for other breaches set in the Act's Schedule.
Do we need a separate privacy notice?
Yes — a clear, itemised notice at or before data collection that states the purpose and how to withdraw consent and complain; a generic policy page is not enough.
How fast must a data breach be reported?
The Data Protection Board and affected individuals must be informed, with a detailed report to the Board within 72 hours of becoming aware.
What is a Consent Manager?
A registered entity that lets individuals give, manage and withdraw consent across businesses; registration opens under Rule 4 about 12 months after notification.
Is a website terms and conditions page mandatory?
Not by statute for every site, but it is the contract that limits liability and fixes payment, refund, intellectual-property and jurisdiction terms, and marketplaces and payment gateways ask for it.
Is the compliance date likely to change?
A January 2026 consultation floated an earlier date; we found no notification advancing it, so plan to May 2027 and verify the Gazette before relying on it.