India's Digital Personal Data Protection Act now has its Rules, and most duties apply from 13 May 2027 with penalties of up to ₹250 crore. We find your gaps, fix them with documents your team can actually run, and stay on call afterwards, at fixed fees.
The Act applies to any business that processes digital personal data in India, whether it was collected online or collected on paper and digitised later. It also reaches businesses outside India that process personal data to offer goods or services to people in India, which covers most foreign SaaS and consumer brands selling here.
If your startup collects names, phone numbers, email addresses, locations, payment details, health or learning data from customers, users or employees, you are a Data Fiduciary for that data. Your cloud host, CRM and payroll provider process it on your behalf as Data Processors, and you remain responsible for what they do with it.
The Act lets the government exempt certain startups from some duties by notification (section 17(3)). Treat that as possible relief, not a plan: check the current notifications before relying on it.
The Rules came into force in three phases, counted from their notification on 13 November 2025.
| Date | What comes into force | What it means for you |
|---|---|---|
| 13 Nov 2025 | Rules 1, 2 and 17 to 21: the Data Protection Board and how it works | The enforcement body's framework is live. Start your gap assessment now. |
| 13 Nov 2026 | Rule 4: registration and obligations of Consent Managers | Consent Managers can register with the Board. |
| 13 May 2027 | Rules 3, 5 to 16, 22 and 23: notice, security, breach reporting, retention, children's data, Significant Data Fiduciaries, rights and cross-border transfers | Your notices, consent, security, breach plan and rights process must be running. |
Source: Digital Personal Data Protection Rules, 2025, rule 1 (Gazette notification G.S.R. 846(E), 13 November 2025). Month-by-month plan in our DPDP Rules 2025 timeline guide.
A standalone notice in plain language that itemises the data you collect and why, and consent that is free, specific and informed, and as easy to withdraw as it was to give.
Sections 5 and 6 · Rule 3Encryption or masking, access control, logs and monitoring, backups, and contracts that hold your processors to the same standard.
Section 8(5) · Rule 6Tell affected users and the Board without delay, then give the Board a detailed report within 72 hours of becoming aware of the breach.
Section 8(6) · Rule 7Delete personal data once it is no longer needed, keep processing logs for at least one year, and in listed sectors warn users 48 hours before erasure.
Section 8(7) · Rule 8Publish how users can access, correct or erase their data, publish a contact for privacy questions, and resolve grievances within 90 days.
Sections 11 to 14 · Rules 9 and 14Before processing the data of anyone under 18, obtain verifiable consent from a parent, and do not track, profile or target advertising at children.
Section 9 · Rule 10Significant Data Fiduciaries notified by the government carry more: a Data Protection Officer based in India, an independent data auditor and a Data Protection Impact Assessment every year (section 10, rule 13).
Start with the check, fix everything with the pack, keep it working with Privacy Care. Each fee is fixed in writing before work starts.
We map the personal data you hold and test it against the Act and the Rules. You get a gap register ranked by risk and a practical fix plan.
Notices, consent records, policies, a retention schedule, a breach playbook, processor contracts and team training, drafted for your product and rolled out with your team.
A named privacy contact for your users, rights and grievance handling within the legal time limits, breach support, and quarterly reviews as your product changes.
| Breach | Maximum penalty |
|---|---|
| Failing to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Failing to notify the Board or affected users of a personal data breach | ₹200 crore |
| Breaching the additional obligations for children's data | ₹200 crore |
| Breaching the additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breaching any other provision of the Act or the Rules | ₹50 crore |
| Breaching the duties of a Data Principal (an individual) | ₹10,000 |
Schedule to the DPDP Act, 2023. The Board sets each amount case by case, weighing the gravity and duration of the breach, the data affected and how quickly you acted to limit the damage. More in our DPDP penalties guide.
The DPDP Act and the GDPR overlap on notice, security and breach response, but they differ on the legal grounds for processing, breach reporting timelines and the age at which someone counts as a child. If your startup also serves users in the EU, our readiness check flags the gaps between the two regimes, so one set of documents can serve both wherever the law allows.
The practice is led by Amar Gite, Founder & Managing Partner, and Santosh Sangle, Co-founder & Partner. They review your work themselves.
Every engagement carries a fixed fee agreed in writing before we start, the same way we run patent and trademark work.
legismith.com carries a notice at every form, a consent banner with a real reject option, and a published privacy and grievance contact.
Investors now ask about data as well as IP. We cover both, so your data room tells one consistent story.
IP for fundraising →Yes, if you process digital personal data of individuals in India, or process it outside India to offer goods or services to people in India. Company size does not change that. The government can exempt some startups from certain duties by notification, so check the current position before relying on it.
Most obligations under the DPDP Rules, 2025 apply from 13 May 2027, eighteen months after the Rules were notified on 13 November 2025. The Consent Manager rules apply from 13 November 2026, and the provisions on the Data Protection Board are already in force.
Up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to report a breach or breaching the rules on children's data, up to ₹150 crore for a Significant Data Fiduciary's extra duties, and up to ₹50 crore for any other breach.
Only Significant Data Fiduciaries notified by the government must appoint a Data Protection Officer based in India. Every other business must still publish the business contact of a person who can answer questions about how it processes personal data.
Our readiness check takes 7 to 10 working days and the compliance pack usually 4 to 6 weeks, depending on how many products, vendors and data flows you have. Starting in 2026 leaves time for product changes before the May 2027 deadline.
At Legismith the readiness check starts from ₹25,000, the compliance pack from ₹1,50,000 and ongoing Privacy Care from ₹10,000 per month. The exact fixed fee depends on your data footprint and is agreed in writing before work starts.
No. They share ideas such as notice, security and breach reporting, but the DPDP Act relies mainly on consent and a short list of legitimate uses, treats anyone under 18 as a child, and sets its own breach reporting timelines. GDPR compliance helps, but it does not make you DPDP compliant.
No. The Rules require a standalone notice that lets people give specific and informed consent, plus security safeguards, a breach response process, erasure schedules and a way to handle rights requests and grievances. A privacy policy page is only one piece.
Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote and the first gaps we expect to find.
Prefer chat? WhatsApp us.
General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.
We use essential cookies to run this website and keep our enquiry forms secure. With your permission we would also like to use analytics cookies, to see how the site is used, and advertising cookies, to measure our Google Ads. These collect your IP address, device and browser details and the pages you visit, and share them with Google and Cloudflare. You can change or withdraw your choice at any time using Cookie settings at the bottom of every page, or write to [email protected].
Disclaimer: Under the Bar Council of India rules, advocates may not advertise or solicit work. This website only shares general information on intellectual property. It is not an advertisement, a solicitation or legal advice, and using it does not create a lawyer–client relationship.