India's Digital Personal Data Protection Act is not a future regulation. The rules were notified on November 13, 2025. Substantive obligations — consent, breach notification, data principal rights — come into force on May 13, 2027. That gives you roughly 18 months to get compliant. For most Indian startups, that timeline will go faster than expected.
Who DPDP applies to
Unlike sector-specific rules such as RBI's data localisation requirements or SEBI's cybersecurity framework, DPDP applies to any entity that processes the personal data of individuals in India — regardless of industry, revenue, or headcount. If you have employees, you are a data fiduciary. If you have customers, users, or vendors whose data you process, you are a data fiduciary.
There is no size threshold for basic obligations. A 10-person fintech handling employee Aadhaar and PAN numbers for payroll has the same core obligations as a 10,000-person enterprise. The obligations scale with data sensitivity and volume, not company size.
What DPDP actually requires
- Legal basis for processing: Every processing activity needs either verifiable consent from the data principal, or a "legitimate use" — employment contract, legal obligation, medical emergency, or state function. You cannot just process data because it is convenient.
- Data principal rights: Individuals can request access to their data, correction, erasure, and grievance redressal. You must be able to fulfil these requests. If you cannot locate the data, you cannot fulfil the right.
- Breach notification: Notify the Data Protection Board "without undue delay." Draft guidance puts this at 72 hours for the Board, with immediate notification to affected principals for high-risk breaches.
- Security safeguards: Implement "appropriate technical and organisational measures" to protect personal data. What counts as appropriate will be interpreted based on data sensitivity, volume, and available technology.
- Data minimisation: Only collect and retain personal data that is necessary for the stated purpose. Excessive collection is itself a violation.
The Significant Data Fiduciary threshold
The government can designate certain entities as Significant Data Fiduciaries based on volume of personal data processed, sensitivity of data, national security implications, or risk to data principals. SDFs face additional obligations: mandatory appointment of a Data Protection Officer (resident in India), mandatory Data Protection Impact Assessments, and periodic audits by certified auditors.
The specific thresholds for SDF designation are pending notification, but draft guidance suggests: 100+ employees whose data is processed, 10,000+ data principals in the system, or any entity that processes sensitive personal data such as health records, biometrics, or financial data at scale. If you are a fintech, healthtech, or edtech — assume you will be designated an SDF.
Penalties under DPDP reach ₹250 crore for data breaches where reasonable security safeguards were not implemented. That is not an abstract number — it is a figure that will appear in board discussions and investor due diligence.
The enforcement reality
The Data Protection Board of India is being constituted. Early enforcement will likely focus on large consumer platforms and SDFs — not on small startups. But enforcement typically cascades: large platforms build contractual obligations down their supply chains. If you sell to an enterprise that becomes subject to DPDP enforcement, they will require you to demonstrate compliance as a vendor.
B2B founders are already seeing this pattern. Enterprise procurement questionnaires increasingly include data protection requirements. The smart move is not to wait for direct regulatory enforcement — it is to use DPDP compliance as a sales signal, ahead of when your competitors get there.
Where to start
- 1Inventory what personal data you hold — employee data first, then customer data. You cannot protect or govern data you have not located.
- 2Map your processing activities to a legal basis. Employment data → legitimate use. Customer data → consent or contract. Marketing → consent.
- 3Check whether you meet the SDF threshold. If so, start the DPO search now — the market for qualified DPOs in India is thin.
- 4Implement breach detection and notification capability. The 72-hour window requires pre-built processes, not improvised responses.
- 5Generate your first data protection evidence artifact. The Board will ask for it. Investors will ask for it. Customers will ask for it.
Takeaway
DPDP is the most significant compliance shift for Indian businesses since GST. The companies that treat it as a detection and evidence problem — rather than a paperwork problem — will be the ones that emerge with a competitive advantage. The enforcement window is 18 months. The setup time for basic compliance is measured in days, not months, if you have the right tooling.