Data privacy · DPDP Act 2023 · DPDP Rules 2025

DPDP compliance for startups,
done before 13 May 2027.

India's Digital Personal Data Protection Act now has its Rules, and most duties apply from 13 May 2027 with penalties of up to ₹250 crore. We find your gaps, fix them with documents your team can actually run, and stay on call afterwards, at fixed fees.

Main deadline 13 May 2027 Penalties up to ₹250 crore Fixed fees from ₹25,000
What is DPDP compliance? DPDP compliance means handling the personal data of people in India the way the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 require: a clear notice and valid consent, reasonable security safeguards, breach reporting to the Data Protection Board and to affected users, erasure once the purpose ends, and a working route for people to exercise their rights.
Scope

Who has to comply with the DPDP Act?

The Act applies to any business that processes digital personal data in India, whether it was collected online or collected on paper and digitised later. It also reaches businesses outside India that process personal data to offer goods or services to people in India, which covers most foreign SaaS and consumer brands selling here.

If your startup collects names, phone numbers, email addresses, locations, payment details, health or learning data from customers, users or employees, you are a Data Fiduciary for that data. Your cloud host, CRM and payroll provider process it on your behalf as Data Processors, and you remain responsible for what they do with it.

The Act lets the government exempt certain startups from some duties by notification (section 17(3)). Treat that as possible relief, not a plan: check the current notifications before relying on it.

Startups we typically help
  • SaaS and B2B platforms
  • D2C and e-commerce brands
  • Fintech and lending apps
  • Healthtech and wellness apps
  • Edtech and apps used by children
  • HR-tech, staffing and marketplaces
Timeline

The DPDP Rules 2025 timeline

The Rules came into force in three phases, counted from their notification on 13 November 2025.

DateWhat comes into forceWhat it means for you
13 Nov 2025Rules 1, 2 and 17 to 21: the Data Protection Board and how it worksThe enforcement body's framework is live. Start your gap assessment now.
13 Nov 2026Rule 4: registration and obligations of Consent ManagersConsent Managers can register with the Board.
13 May 2027Rules 3, 5 to 16, 22 and 23: notice, security, breach reporting, retention, children's data, Significant Data Fiduciaries, rights and cross-border transfersYour notices, consent, security, breach plan and rights process must be running.

Source: Digital Personal Data Protection Rules, 2025, rule 1 (Gazette notification G.S.R. 846(E), 13 November 2025). Month-by-month plan in our DPDP Rules 2025 timeline guide.

What the law asks

Six things every Data Fiduciary must get right

Notice & consent

Tell people, then ask properly

A standalone notice in plain language that itemises the data you collect and why, and consent that is free, specific and informed, and as easy to withdraw as it was to give.

Sections 5 and 6 · Rule 3
Security

Reasonable security safeguards

Encryption or masking, access control, logs and monitoring, backups, and contracts that hold your processors to the same standard.

Section 8(5) · Rule 6
Breaches

Report breaches, fast

Tell affected users and the Board without delay, then give the Board a detailed report within 72 hours of becoming aware of the breach.

Section 8(6) · Rule 7
Retention

Erase when the purpose ends

Delete personal data once it is no longer needed, keep processing logs for at least one year, and in listed sectors warn users 48 hours before erasure.

Section 8(7) · Rule 8
Rights

Answer people who ask

Publish how users can access, correct or erase their data, publish a contact for privacy questions, and resolve grievances within 90 days.

Sections 11 to 14 · Rules 9 and 14
Children

Verifiable parental consent

Before processing the data of anyone under 18, obtain verifiable consent from a parent, and do not track, profile or target advertising at children.

Section 9 · Rule 10

Significant Data Fiduciaries notified by the government carry more: a Data Protection Officer based in India, an independent data auditor and a Data Protection Impact Assessment every year (section 10, rule 13).

Services

Three steps to DPDP compliance

Start with the check, fix everything with the pack, keep it working with Privacy Care. Each fee is fixed in writing before work starts.

Step 1 · 7 to 10 working days

DPDP Readiness Check

We map the personal data you hold and test it against the Act and the Rules. You get a gap register ranked by risk and a practical fix plan.

From ₹25,000
What the check covers →
Step 2 · 4 to 6 weeks

DPDP Compliance Pack

Notices, consent records, policies, a retention schedule, a breach playbook, processor contracts and team training, drafted for your product and rolled out with your team.

From ₹1,50,000
What the pack includes →
Step 3 · Ongoing

Privacy Care

A named privacy contact for your users, rights and grievance handling within the legal time limits, breach support, and quarterly reviews as your product changes.

From ₹10,000 per month
How Privacy Care works →
Add-ons: a Processor Pack for B2B platforms that process personal data for their own clients, and a Children's Data Module (from ₹50,000) for products used by under-18s. Your final fee depends on the size of your data footprint and is agreed in writing before we begin.
Penalties

What non-compliance can cost

BreachMaximum penalty
Failing to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failing to notify the Board or affected users of a personal data breach₹200 crore
Breaching the additional obligations for children's data₹200 crore
Breaching the additional obligations of a Significant Data Fiduciary₹150 crore
Breaching any other provision of the Act or the Rules₹50 crore
Breaching the duties of a Data Principal (an individual)₹10,000

Schedule to the DPDP Act, 2023. The Board sets each amount case by case, weighing the gravity and duration of the breach, the data affected and how quickly you acted to limit the damage. More in our DPDP penalties guide.

Why Legismith

Privacy advice from the team that already protects your IP

Partner-led

Led by our partners

The practice is led by Amar Gite, Founder & Managing Partner, and Santosh Sangle, Co-founder & Partner. They review your work themselves.

Fixed fees

No hourly surprises

Every engagement carries a fixed fee agreed in writing before we start, the same way we run patent and trademark work.

Practised here

We run it on our own site

legismith.com carries a notice at every form, a consent banner with a real reject option, and a published privacy and grievance contact.

Fundraising

One diligence story

Investors now ask about data as well as IP. We cover both, so your data room tells one consistent story.

IP for fundraising →
FAQs

DPDP compliance: common questions

Yes, if you process digital personal data of individuals in India, or process it outside India to offer goods or services to people in India. Company size does not change that. The government can exempt some startups from certain duties by notification, so check the current position before relying on it.

Most obligations under the DPDP Rules, 2025 apply from 13 May 2027, eighteen months after the Rules were notified on 13 November 2025. The Consent Manager rules apply from 13 November 2026, and the provisions on the Data Protection Board are already in force.

Up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore each for failing to report a breach or breaching the rules on children's data, up to ₹150 crore for a Significant Data Fiduciary's extra duties, and up to ₹50 crore for any other breach.

Only Significant Data Fiduciaries notified by the government must appoint a Data Protection Officer based in India. Every other business must still publish the business contact of a person who can answer questions about how it processes personal data.

Our readiness check takes 7 to 10 working days and the compliance pack usually 4 to 6 weeks, depending on how many products, vendors and data flows you have. Starting in 2026 leaves time for product changes before the May 2027 deadline.

At Legismith the readiness check starts from ₹25,000, the compliance pack from ₹1,50,000 and ongoing Privacy Care from ₹10,000 per month. The exact fixed fee depends on your data footprint and is agreed in writing before work starts.

No. They share ideas such as notice, security and breach reporting, but the DPDP Act relies mainly on consent and a short list of legitimate uses, treats anyone under 18 as a child, and sets its own breach reporting timelines. GDPR compliance helps, but it does not make you DPDP compliant.

No. The Rules require a standalone notice that lets people give specific and informed consent, plus security safeguards, a breach response process, erasure schedules and a way to handle rights requests and grievances. A privacy policy page is only one piece.

Start with a readiness check.

Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote and the first gaps we expect to find.

    Send Us Your Enquiry

    Fill in the form below and our team will respond within 24 hours.

    Prefer chat? WhatsApp us.

    General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.

    Scroll to Top