Take a 15-bed nursing home in Mysuru. Patient names and phone numbers get written down at the front desk. Lab reports go out on WhatsApp. Billing runs on software from a local vendor, and insurance forms go to TPAs. Nobody there thinks of themselves as a "data business". But under the Digital Personal Data Protection Act, 2023, that nursing home is a Data Fiduciary, and from May 2027 it has real legal duties.
The same goes for a coaching institute with 300 students, a CA firm's own client files, or a SaaS startup with a few thousand users. This post covers what you need in place, by when, and where to start.
When do the DPDP Act's obligations actually start?
The Act was passed in August 2023, but most of it only bites once the DPDP Rules are in force. The Rules were notified in November 2025 and come in three steps:
| When | What happens |
|---|---|
| November 2025 | Rules notified. The Data Protection Board of India is set up and can act. |
| November 2026 | Rules for registering Consent Managers come into force. |
| May 2027 | Most obligations apply: notices, security safeguards, breach reporting, rights requests, retention and children's data. |
In January 2026, MeitY discussed shortening the 18-month window, mainly for large companies. As of September 2026, no such change has been notified, so May 2027 stands. But if the timeline moves at all, it's more likely to get shorter than longer. Don't plan around a grace period either. None has been announced.
Does the DPDP Act apply to a small business?
Almost certainly, yes. If you collect personal data from people in India in digital form, the Act applies to you. There's no general exemption based on size or turnover.
The government does have the power to exempt some classes of businesses, including startups, from specific provisions. It hasn't used that power broadly. So a clinic, a coaching centre or a 20-person trading company should plan on the full set of core duties.
What falls outside: purely personal or household use, and data that people have made public themselves.
What do you need in place by May 2027?
Here's the practical list. None of it needs a big team. It does need someone to own it.
| Obligation | What it means for you | Where it comes from |
|---|---|---|
| Know your data | A written map of what personal data you hold, why, where it sits and who you share it with. | Needed to meet every other duty |
| Clear notice | Before you collect data, tell people what you collect, why, and how to withdraw consent or complain. It must stand on its own, not be buried in terms of service. | Section 5, Rule 3 |
| Consent or a lawful basis | Consent must be free, specific, informed and given by a clear action. Some uses, like a medical emergency or a legal requirement, don't need consent. | Sections 6 and 7 |
| Security safeguards | Reasonable protection: access control, encryption or masking where it matters, backups, and logs kept for at least a year. | Section 8, Rule 6 |
| Breach plan | Tell affected people without delay, and send a detailed report to the Data Protection Board within 72 hours of finding out. | Section 8, Rule 7 |
| Vendor contracts | Anyone processing data for you (software vendors, labs, payroll firms) needs a contract that covers it. | Section 8 |
| Delete when done | Erase data once its purpose is over, unless another law says to keep it. | Section 8 |
| A named contact | Publish the contact details of someone who can answer questions about your data handling. | Section 8, Rule 9 |
| Rights and grievances | A way for people to ask for access, correction or erasure, or to complain, with answers within 90 days at most. | Sections 11 to 13, Rule 14 |
| Children's data | For anyone under 18, verifiable parental consent, and no tracking or targeted ads aimed at them. | Section 9 |
If the government notifies you as a Significant Data Fiduciary, you'll have extra duties on top of these, like appointing a DPO based in India and running periodic audits. Most small and mid-sized businesses won't be in that group.
What happens if you're not ready?
The Data Protection Board can impose penalties, and the maximums are large. They go up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a breach or breaking the rules on children's data, and up to ₹50 crore for other breaches.
Those are ceilings, not fixed fines. The Board looks at how serious the breach was, how long it went on and what you did to fix it. But even a fraction of those numbers would end a small business.
The more immediate risk is commercial. Larger clients are starting to ask their vendors about DPDPA readiness. If a patient or parent complains to the Board, you'll need to show what you did and when. A business that can't produce a data map, a notice and a breach plan has nothing to show.
How long does getting ready take?
Longer than most people expect. The paperwork isn't the slow part. The slow part is finding out what data you actually hold, and getting vendors to sign updated contracts.
If you start in October 2026, a realistic path to May 2027 looks like this:
| Period | Focus |
|---|---|
| October to November 2026 | Map your data: every form, system, spreadsheet and WhatsApp group that holds personal data. |
| December 2026 to January 2027 | Fix your notices and consent flows. Send updated contracts to vendors. |
| February to March 2027 | Tighten security: who can access what, log retention, backups, encryption for sensitive data. |
| April 2027 | Test your breach plan with a dry run. Set up the rights request process and publish your contact. |
The step people skip is the first one. It's tempting to download a privacy notice template and call it done. But a notice that doesn't match what your front desk actually collects is a written record that you said one thing and did another.
Where should you start this month?
Five things you can do without buying anything:
- List your data sources. Walk through the business and write down every place personal data enters: forms, apps, phone calls, WhatsApp, email, walk-ins. The free DPDPOne assessment walks you through the same questions.
- Name an owner. One person who's responsible for DPDPA work and will be the published contact.
- List your vendors. Everyone who touches your customers' or patients' data on your behalf.
- Read your current privacy notice. Check it against what you actually collect. Many won't match.
- Write down what you'd do in a breach. Who finds out, who decides, who informs people, who files with the Board. Even a one-page draft beats nothing.
Run the full DPDPOne readiness assessment for free. The free plan shows your scores for three areas, so you can see where you stand before you spend anything.
The short version
May 2027 is fixed, it applies to small businesses, and the work takes months, not days. Start with the data map. Once you know what you hold, the notice, the security work and the breach plan all follow from it.
