Deadline Readiness

What the DPDP Act needs from your business by May 2027

Mahadev Thukaram·30 September 2026·4 min read

Short answer

From May 2027, most businesses that handle digital personal data in India must meet the DPDP Act's core duties: a clear notice, consent or lawful basis, reasonable security, a breach plan with a 72-hour SLA to report to the Board, and a way to answer people's requests within 90 days. Size doesn't exempt you.

Key takeaways

  • →The main obligations under the DPDP Rules come into force in May 2027, 18 months after the Rules were notified in November 2025.
  • →There's no general exemption for small businesses. A 10-person Nursing homes/clinic has the same core duties as a large hospital chain.
  • →You'll need a clear notice, consent or another lawful basis, security safeguards, a breach plan and a process for people's requests.
  • →Breaches must be reported to the Data Protection Board within 72 hours, and requests answered within 90 days.
  • →Start with a map of the personal data you hold. Everything else builds on it.
Contents

Take a 15-bed nursing home in Mysuru. Patient names and phone numbers get written down at the front desk. Lab reports go out on WhatsApp. Billing runs on software from a local vendor, and insurance forms go to TPAs. Nobody there thinks of themselves as a "data business". But under the Digital Personal Data Protection Act, 2023, that nursing home is a Data Fiduciary, and from May 2027 it has real legal duties.

The same goes for a coaching institute with 300 students, a CA firm's own client files, or a SaaS startup with a few thousand users. This post covers what you need in place, by when, and where to start.

When do the DPDP Act's obligations actually start?

The Act was passed in August 2023, but most of it only bites once the DPDP Rules are in force. The Rules were notified in November 2025 and come in three steps:

When What happens
November 2025 Rules notified. The Data Protection Board of India is set up and can act.
November 2026 Rules for registering Consent Managers come into force.
May 2027 Most obligations apply: notices, security safeguards, breach reporting, rights requests, retention and children's data.

In January 2026, MeitY discussed shortening the 18-month window, mainly for large companies. As of September 2026, no such change has been notified, so May 2027 stands. But if the timeline moves at all, it's more likely to get shorter than longer. Don't plan around a grace period either. None has been announced.

Does the DPDP Act apply to a small business?

Almost certainly, yes. If you collect personal data from people in India in digital form, the Act applies to you. There's no general exemption based on size or turnover.

The government does have the power to exempt some classes of businesses, including startups, from specific provisions. It hasn't used that power broadly. So a clinic, a coaching centre or a 20-person trading company should plan on the full set of core duties.

What falls outside: purely personal or household use, and data that people have made public themselves.

What do you need in place by May 2027?

Here's the practical list. None of it needs a big team. It does need someone to own it.

Obligation What it means for you Where it comes from
Know your data A written map of what personal data you hold, why, where it sits and who you share it with. Needed to meet every other duty
Clear notice Before you collect data, tell people what you collect, why, and how to withdraw consent or complain. It must stand on its own, not be buried in terms of service. Section 5, Rule 3
Consent or a lawful basis Consent must be free, specific, informed and given by a clear action. Some uses, like a medical emergency or a legal requirement, don't need consent. Sections 6 and 7
Security safeguards Reasonable protection: access control, encryption or masking where it matters, backups, and logs kept for at least a year. Section 8, Rule 6
Breach plan Tell affected people without delay, and send a detailed report to the Data Protection Board within 72 hours of finding out. Section 8, Rule 7
Vendor contracts Anyone processing data for you (software vendors, labs, payroll firms) needs a contract that covers it. Section 8
Delete when done Erase data once its purpose is over, unless another law says to keep it. Section 8
A named contact Publish the contact details of someone who can answer questions about your data handling. Section 8, Rule 9
Rights and grievances A way for people to ask for access, correction or erasure, or to complain, with answers within 90 days at most. Sections 11 to 13, Rule 14
Children's data For anyone under 18, verifiable parental consent, and no tracking or targeted ads aimed at them. Section 9

If the government notifies you as a Significant Data Fiduciary, you'll have extra duties on top of these, like appointing a DPO based in India and running periodic audits. Most small and mid-sized businesses won't be in that group.

What happens if you're not ready?

The Data Protection Board can impose penalties, and the maximums are large. They go up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a breach or breaking the rules on children's data, and up to ₹50 crore for other breaches.

Those are ceilings, not fixed fines. The Board looks at how serious the breach was, how long it went on and what you did to fix it. But even a fraction of those numbers would end a small business.

The more immediate risk is commercial. Larger clients are starting to ask their vendors about DPDPA readiness. If a patient or parent complains to the Board, you'll need to show what you did and when. A business that can't produce a data map, a notice and a breach plan has nothing to show.

How long does getting ready take?

Longer than most people expect. The paperwork isn't the slow part. The slow part is finding out what data you actually hold, and getting vendors to sign updated contracts.

If you start in October 2026, a realistic path to May 2027 looks like this:

Period Focus
October to November 2026 Map your data: every form, system, spreadsheet and WhatsApp group that holds personal data.
December 2026 to January 2027 Fix your notices and consent flows. Send updated contracts to vendors.
February to March 2027 Tighten security: who can access what, log retention, backups, encryption for sensitive data.
April 2027 Test your breach plan with a dry run. Set up the rights request process and publish your contact.

The step people skip is the first one. It's tempting to download a privacy notice template and call it done. But a notice that doesn't match what your front desk actually collects is a written record that you said one thing and did another.

Where should you start this month?

Five things you can do without buying anything:

  1. List your data sources. Walk through the business and write down every place personal data enters: forms, apps, phone calls, WhatsApp, email, walk-ins. The free DPDPOne assessment walks you through the same questions.
  2. Name an owner. One person who's responsible for DPDPA work and will be the published contact.
  3. List your vendors. Everyone who touches your customers' or patients' data on your behalf.
  4. Read your current privacy notice. Check it against what you actually collect. Many won't match.
  5. Write down what you'd do in a breach. Who finds out, who decides, who informs people, who files with the Board. Even a one-page draft beats nothing.

Run the full DPDPOne readiness assessment for free. The free plan shows your scores for three areas, so you can see where you stand before you spend anything.

The short version

May 2027 is fixed, it applies to small businesses, and the work takes months, not days. Start with the data map. Once you know what you hold, the notice, the security work and the breach plan all follow from it.

Frequently asked questions

Is there a grace period after May 2027?

No grace period has been announced. The Data Protection Board has existed since November 2025, so plan on the obligations applying from day one.

Do I need to appoint a Data Protection Officer?

Only Significant Data Fiduciaries, which the government notifies, must appoint a DPO based in India. Every other business must publish the contact details of someone who can answer questions about how it handles personal data.

We're already GDPR compliant. Does that cover DPDPA?

It helps, but it isn't the same. The DPDP Act treats everyone under 18 as a child, handles lawful grounds for processing differently, and has its own breach reporting and notice rules. Check each obligation rather than assuming.

Does the DPDP Act cover paper records?

It covers personal data in digital form, including data you collect on paper and later digitise. Records that stay on paper only fall outside it. Most businesses digitise far more than they realise, for example scanned forms and WhatsApp photos.

Sources

Last reviewed on 30 September 2026 by Mahadev Thukaram

Mahadev Thukaram
Mahadev Thukaram

Founder, DPDPOne

Founder of DPDPOne. 25+ years in information security and IT service management, now building DPDP Act compliance software for Indian businesses and the CAs and lawyers who advise them.

50+ years in information security and IT service management · Security operations and GRC: SIEM/SOAR, NIST CSF 2.0, ITIL 4 · Active in the DPDP Act practitioner community (FDPPI sessions, industry panels) · Author - Advanced Malware Analysis · CISM, CDPO, GDPR CEP, ISO27001 Lead Auditor, ISO22301 Lead Auditor, ITIL Expert, Auhorized trainer for Forcepoint DLP & Netskope

Ready to check your DPDP readiness?

This article is general information about the DPDP Act, not legal advice. Check with a qualified professional before acting on it.