The DPDP Rules started an eighteen-month clock in November 2025. Most of the work is engineering, not legal.
Almost everything written about the Digital Personal Data Protection Act has been written by lawyers, which is useful for understanding your obligations and close to useless for discharging them. Consent, erasure, breach reporting and data principal rights are all features somebody has to build into systems that were never designed for them. This is the engineering half: what has to change in your tenant, your applications and your logs before substantive compliance falls due in May 2027.

- May 2027Substantive compliance due
- 72 hoursDetailed breach report
- 90 daysTo answer a rights request
- 1 yearMinimum log retention
Seven obligations, and what each one costs you in engineering.
Give notice that stands on its own
Rule 3 requires a notice in clear, plain language that works as a standalone document rather than a clause buried in terms of service, and it must carry an itemised list of the personal data you collect and the specific purpose for each. Itemised is the operative word. A notice saying you collect information to improve services does not survive this test. Producing a genuine itemised notice forces the data inventory, which is why most businesses discover they need a data map at the notice stage rather than earlier.
Collect consent you can prove and unwind
Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and withdrawal has to be as easy as giving it was. That last clause is where systems break. Most applications can record a yes; comparatively few can record which specific purpose it applied to, produce that record two years later on demand, and cascade a withdrawal through every downstream system and processor that received the data.
Apply safeguards that are proportionate and evidenced
Rule 6 asks for technical and organisational measures proportionate to the sensitivity and volume of what you process, and names the shape of them: encryption, obfuscation, masking or virtual tokens mapped to the personal data, and role-based access control that restricts access to authorised personnel. It also requires that logs and associated traffic data be retained for at least one year so a breach can be detected, investigated and remediated. Log retention is the requirement most estates fail on today, quietly, because default retention windows are shorter than a year.
Report a breach on the clock
On becoming aware of a personal data breach you inform the Data Protection Board without delay with the nature, extent, timing and location of the breach and its likely impact, and you inform affected data principals without delay too. Within seventy two hours you provide the Board an updated account: the circumstances that led to the breach, the remedial and mitigation measures taken, and your findings on who caused it. Extensions exist but must be requested in writing. Seventy two hours is not long enough to build a process from scratch, which is the entire argument for having one already.
Erase when the purpose is finished
Rule 8 permits retention only for as long as the specified purpose is being served, after which the data must be erased. For the classes listed in the Third Schedule, erasure follows a defined period, currently three years, unless the data principal re-engages, and you must give advance notice before erasing. Purpose limitation is the obligation that clashes hardest with how Indian businesses actually operate, because the prevailing default is to keep everything forever in case it is useful.
Answer data principal requests
Individuals can ask for a summary of the personal data you hold about them, ask you to correct or complete what is inaccurate, and ask for erasure. You have a maximum of ninety days to respond. Ninety days sounds generous until you try it: answering honestly requires querying every system that holds personal data, which is a different problem from having a policy that says you will.
Handle children and guardianship properly
Processing the personal data of anyone under eighteen requires verifiable consent from a parent or lawful guardian, and the same applies to persons with disability who have a lawful guardian. Targeted advertising and behavioural profiling directed at minors are prohibited outright. If your service is not intended for children, the engineering task is proving that: age assurance, and a documented basis for the assurance you chose.
Carry the extra load if you are designated significant
A Significant Data Fiduciary, designated by the government on the volume and sensitivity of what it processes and the risk it presents, takes on more: a Data Protection Officer based in India and answerable to the board, a Data Protection Impact Assessment, and an independent compliance audit, the latter two on a twelve month cycle. Most businesses will not be designated. Those that might should build assuming they will be, because retrofitting a DPIA discipline onto a live estate is materially harder than starting with one.
What is already in force, and what is coming.
- 01In force now· Since November 2025
The Data Protection Board exists
The rules establishing the Board and its procedures took effect on notification. The adjudicating body is standing up while the substantive obligations are still phasing in, which is the normal sequence and means the enforcement machinery will be operational well before the compliance deadline arrives.
- Board constituted and procedural rules live
- No substantive obligations enforceable yet
- The right window for gap assessment and remediation
- 02November 2026· Twelve months from notification
Consent Manager registration begins
Rule 4 comes into force, allowing registered, India-based, independent Consent Managers to operate an interoperable platform where an individual gives, reviews, manages and withdraws consent across multiple data fiduciaries from one place. Most businesses will never be a Consent Manager. Every business will eventually have to interoperate with one.
- Consent Manager registration framework live
- Consent architecture needs to be interoperable, not bespoke
- Consent records must be exportable and purpose-scoped
- 03May 2027· Eighteen months from notification
Substantive compliance falls due
Notice, consent, security safeguards, breach reporting, retention and erasure, data principal rights and the Significant Data Fiduciary obligations all become enforceable together. There is no indication of a general grace period beyond the eighteen months already given, and penalties at the top of the scale run into the hundreds of crores per violation.
- Rules 3 and 5 to 16 enforceable
- Full notice, consent, retention and rights machinery live
- Breach reporting process operational and tested
We do the half your law firm hands back.
We start with discovery, not with templates
Every DPDP engagement we run starts by finding the personal data, because every other obligation depends on that answer and because the answer is always more surprising than the client expects. Exports in shared drives, a former employee mailbox nobody closed, a test database seeded with production records, a vendor portal holding customer identity documents. Templates cannot find those. Discovery can.
Microsoft Partner, so the controls are ones you already own
For estates on Microsoft 365, a large share of Rule 6 is achievable with entitlements already held: sensitivity labels and encryption, data loss prevention, retention policies that actually delete, Entra role-based access control and unified audit logging extended past its default window. We check what your licences already include before recommending anything new, and we regularly find businesses paying separately for a capability sitting unused in their tenant.
We plan back from the lead times, not forward from today
Log retention only evidences a year of history after a year has passed. Data mapping gates four other obligations. Consent rework needs to be in place before Consent Managers arrive. We sequence the programme against those constraints so the slow items start first, rather than delivering a tidy plan that runs out of calendar.
We are explicit about where we stop
We are not lawyers and this is not legal advice. We do not draft your notice, determine your lawful basis, or advise on whether you are likely to be designated a Significant Data Fiduciary. We build and evidence the controls, and we work alongside your counsel rather than around them. Being clear about the boundary is worth more to you than a vendor claiming to cover both.
Sectors with the most to change.
Healthcare and diagnostics
High-sensitivity data, long clinical retention requirements that genuinely conflict with purpose limitation, and shared counter logins that make record access unattributable. The retention conflict is resolvable but has to be reasoned and documented rather than assumed.
BFSI and fintech
Already carrying sectoral obligations from RBI and SEBI, so the controls largely exist. The work is mapping what is already built onto the DPDP obligations, closing the gaps that sectoral rules do not cover, and avoiding a second parallel compliance programme.
Retail and consumer brands
Loyalty databases, marketing lists of uncertain provenance, and consent captured years ago in ways nobody can now evidence. Frequently the largest volume of personal data and the weakest record of why it was collected.
Education
Processing children data at scale, which pulls in verifiable parental consent and the prohibition on targeted advertising and profiling of minors. Age assurance and guardian verification are engineering problems most institutions have not started on.
Manufacturing and logistics
Workforce data, contractor records, biometric attendance and vehicle telematics. Often the least mature identity and access management, with attendance and CCTV systems sitting outside IT governance entirely.
GCCs and SaaS
Processing on behalf of overseas parents or customers, so the contractual chain matters as much as the technical controls. Existing SOC 2 or ISO 27001 work covers a useful share of Rule 6 and none of the consent, notice or rights machinery.
The gap between having a policy and being able to do the thing.
| Feature | Obligation | What most businesses have | What the Rules require |
|---|---|---|---|
Notice | A privacy policy on the website, written once, describing categories of data in general terms | A standalone, plain-language notice with an itemised list of data collected and the specific purpose for each | |
Consent | A checkbox recorded as a boolean, with no record of which purpose it covered | Purpose-scoped, provable consent with withdrawal as easy as granting, cascading to processors | |
Data inventory | Institutional memory, plus a spreadsheet somebody made for an audit and did not maintain | A current record of what personal data exists, where, why, who can reach it and how long it stays | |
Access control | Shared logins at reception, clinic counters and tills, and broad access granted at joining and never reviewed | Role-based access restricting personal data to authorised personnel, attributable to an individual | |
Logs | Default retention, typically ninety days or less, and frequently not centralised | Logs and traffic data retained at least a year, sufficient to detect, investigate and remediate | |
Erasure | A retention policy describing deletion, with nothing implementing it | Erasure once the purpose is served, on schedule, with notice given in advance where required | |
Rights requests | An email address in the privacy policy that nobody has ever received a request on | A process that queries every system holding personal data and answers within ninety days | |
Breach response | An incident response plan covering availability, written with ransomware in mind | Immediate notification to the Board and affected individuals, detailed report inside seventy two hours |
The deadline to plan against is not May 2027.
Substantive compliance falls due in May 2027, so that is the date everyone quotes. It is the wrong one to plan against, because two of the seven obligations have lead times measured in quarters rather than weeks. Log retention has to be extended and then has to actually accumulate a year of history before it evidences anything. Data mapping across a mid-sized estate is a discovery exercise, not a form-filling one, and it gates the notice, the rights process and the erasure schedule behind it.
- Working back from May 2027, log retention changes need to land by roughly May 2026 to have a full year of history
- Data mapping gates notice, consent, retention and rights, so it is the first task rather than one of them
- Consent architecture needs to be interoperable before Consent Managers go live in November 2026
- Breach response is the one obligation you cannot build after you need it
Five stages, sequenced by lead time.
- 1
Discover what personal data you hold
Systems, applications, file shares, mailboxes, SaaS tools, vendor platforms, backups and the places nobody lists. We build the record of what exists, where it lives, why you have it, who can reach it and how long it stays. This gates everything downstream, so it goes first and it gets done properly rather than quickly.
- 2
Assess against the seven obligations
Each obligation scored against what your estate can currently do, not against what your policies say. The output is a gap register with an owner, an effort estimate and a dependency chain for every item, and an explicit note where an obligation is a legal determination rather than an engineering one so it routes to your counsel.
- 3
Fix the long-lead items first
Log retention extended and centralised so a year of history starts accumulating. Access control tightened, shared accounts eliminated, joiner-mover-leaver made real. Encryption, labelling and data loss prevention configured on the entitlements you already hold. These take time to take effect, which is why they cannot be last.
- 4
Build the machinery for consent, rights and erasure
Consent capture reworked to be purpose-scoped, provable and interoperable. A rights request process that can actually query every system inside ninety days. Retention schedules implemented as something that deletes rather than something that describes deletion. This is the largest block of application work and it depends on stage one being right.
- 5
Test breach response, then keep it warm
A tabletop exercise against the seventy two hour clock: who declares, who assesses scope, who drafts the Board notification, who tells affected individuals, and how you evidence what you did. Then a review cadence, because an estate drifts and a control nobody re-checks is a control you no longer have.
DPDP compliance, answered plainly.
Go deeper on any one obligation.
DPDP data mapping
The discovery exercise every other obligation depends on: finding personal data across systems, mailboxes, file shares, SaaS and backups, and turning it into a record you can maintain.
Learn moreConsent architecture readiness
What purpose-scoped, provable, withdrawable consent has to look like before Consent Managers go live in November 2026, and how to rework capture that records only a boolean.
Learn moreData breach response plan
The seventy two hour clock, the decision tree that routes an incident to the Board, to CERT-In or to both, and the tabletop that proves the process works before you need it.
Learn moreFind out how far you actually are.
Most businesses are further from DPDP compliance than their policy documents suggest, and closer than the panic in the market implies. A readiness review tells you which, with a gap register you can plan and budget against. Remote-first from Hyderabad, serving all of India, and we will tell you plainly if the honest answer is that you have less to do than you feared.
Related Services
Explore more solutions that work great with this service