DPDP Act 2023 + Rules 2025: What Startups Must Do by 2027
Published on 1 July 2026

May 13, 2027 isn’t a suggestion. It’s the hard deadline for full DPDP Act compliance, and unlike most Indian regulatory rollouts, there’s no extended grace period baked in this time. If your startup collects a customer’s email, phone number, or even a device ID, this law already applies to you — whether you’ve got 200 users or 2 lakh.
Most founders think this is a “big company” problem. It isn’t. Penalties run up to ₹250 crore per violation, and they stack.
What You’ll Learn
- What the DPDP Act and DPDP Rules 2025 actually require of startups
- The exact phased timeline — November 2025, November 2026, and May 2027
- What “Significant Data Fiduciary” means and whether it applies to you
- A practical, founder-friendly compliance checklist
What Is the DPDP Act 2023 and Why the Rules 2025 Change Everything
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive data privacy law, rooted in the Supreme Court’s Puttaswamy judgment that recognised privacy as a fundamental right. For years it sat unenforced because the government hadn’t notified the operational rules.
That changed on November 13, 2025, when the Ministry of Electronics and Information Technology (MeitY) notified the final DPDP Rules 2025, which convert the Act’s broad principles into specific, enforceable obligations.
Here’s the thing: the Act calls your startup a Data Fiduciary the moment you decide why and how personal data is collected — even if a third-party tool actually stores it.
Your users are Data Principals, and any vendor processing data on your behalf (your CRM, your analytics tool, your cloud host) is a Data Processor. You stay accountable for what they do with that data, not them.
The Compliance Timeline: Three Phases Every Founder Should Have on Their Calendar
What most founders miss: the DPDP rollout isn’t a single deadline — it’s a phased 18-month clock that started ticking the day the Rules were notified

- Phase 1 — November 13, 2025 (already live): The Data Protection Board of India (DPB) is operational and accepting complaints. Procedural provisions are in force.
- Phase 2 — November 13, 2026: Consent Manager registration opens. If you plan to rely on a third-party consent platform, vendor due diligence needs to start well before this.
- Phase 3 — May 13, 2027 (the real deadline): Every remaining obligation kicks in at once — consent notices, breach reporting, data principal rights, retention and erasure rules, and grievance redressal.
The short answer: 2026 is your build year. Waiting until early 2027 to start means compressing a 12–18 month compliance programme into a few months — and rebuilding consent flows or data architecture under pressure rarely goes well.
What Your Startup Must Actually Do Before May 2027
Let’s break this down into what actually needs building, not just legal language.
1. Redesign your consent flow
Consent under DPDP must be free, specific, informed, and given through a clear affirmative action — not inferred from continued app use. A standalone privacy notice separate from your Terms of Service is mandatory, and withdrawing consent must be as easy as giving it.
2. Map every place personal data flows through your systems
You can’t protect what you haven’t inventoried. Map every entry point — signup forms, payment gateways, support tickets, analytics SDKs — and log which vendors touch that data.
3. Build breach notification protocols
Under Section 8(6) of the Act and Rule 7 of the Rules, a breach must be reported to the Data Protection Board without unreasonable delay, followed by a detailed report within 72 hours. If your startup doesn’t have an incident response checklist today, this is the moment to write one.
4. Set retention and erasure policies
Data must be deleted once its purpose is served or consent is withdrawn. Erasure requests must be honoured within 90 days, and this applies to data sitting with your processors too — not just your own servers.
5. Handle children’s data with extra care
If your product could reasonably be used by anyone under 18, verifiable parental consent is required, and behavioural tracking or targeted advertising to minors is prohibited outright.
If your startup is still setting up its legal foundation, organize your core business legal documentation first. A clear entity structure and well-drafted contracts make it much easier to create privacy policies and consent frameworks.
Penalties: What Happens If You Don’t Comply
The short answer: this isn’t a slap-on-the-wrist regime. Failure to maintain reasonable security safeguards can attract penalties up to ₹250 crore. Delayed breach notification and violations involving children’s data can each attract penalties up to ₹200 crore.

General non-compliance can still cost up to ₹50 crore. Since penalties are imposed per violation, a single incident can trigger multiple penalty categories at the same time.
For example, a startup that suffers a data breach may delay reporting it. If it also has weak security safeguards, one incident could lead to three separate penalty categories. There’s no small-business carve-out in the fine structure — the DPB assesses based on the violation, not your headcount.
Does “Significant Data Fiduciary” Status Apply to You?
What most founders miss here: the Act distinguishes between ordinary Data Fiduciaries and Significant Data Fiduciaries (SDFs), a tier the government notifies based on the volume of data you process, its sensitivity, and potential for harm.
SDFs carry heavier obligations — appointing a Data Protection Officer based in India, conducting annual Data Protection Impact Assessments, and independent audits.
Most early-stage startups won’t be classified as SDFs at launch. But if you’re scaling fast — particularly in fintech, healthtech, or any platform handling sensitive personal data at volume — it’s worth tracking MeitY notifications closely, since SDF status can change your compliance obligations overnight.
Startups formalising their MSME registration as they scale should build this monitoring into their broader compliance calendar.
A Practical DPDP Compliance Checklist for Indian Startups
- Appoint a privacy lead or focal point, even if it’s a founder wearing multiple hats
- Map all personal data flows across your product, team, and vendors
- Draft a standalone privacy notice, separate from your Terms of Service
- Rebuild consent capture so it’s affirmative, specific, and easily withdrawable
- Set up a grievance redressal mechanism with a published contact point
- Encrypt stored and transferred data, and review access controls
- Review every vendor contract for DPDP-compliant data processing clauses
- Define retention and deletion timelines for every data category you hold
India’s startup ecosystem is already responding — as Inc42 reported, a wave of privacy-tech startups and platforms are building consent management and compliance tooling specifically for this law, which tells you how seriously the market is treating the May 2027 deadline.
Frequently Asked Questions
A: No. There is currently no statutory revenue or user-count exemption for startups or MSMEs under the DPDP Act. If you collect personal data such as names, emails, or phone numbers, core compliance obligations apply regardless of your size.
A: May 13, 2027 is the full compliance deadline, 18 months after the DPDP Rules were notified on November 13, 2025. Some provisions, like Consent Manager registration, become active earlier, in November 2026.
A: The Data Protection Board of India can impose penalties of up to ₹250 crore depending on the violation, and these penalties can stack if a single incident breaches multiple provisions. There is no grace period built into the penalty framework after May 2027.
A: Only if the government designates your startup as a Significant Data Fiduciary. Other Data Fiduciaries need a grievance redressal mechanism and a clear contact point for data principals, but not a formally appointed DPO.
A: Yes. The Act has extra-territorial application and covers any organisation processing personal data in connection with offering goods or services to individuals located in India, regardless of where the company itself is incorporated.
A: Neither the Act nor the Rules explicitly mention cookies, but personal data is defined broadly enough to include any data relating to an identifiable individual. Where cookies can be linked back to a person, directly or combined with other data, they likely fall within scope.
Lawizer’s experts handle everything — privacy policy drafting, consent framework design, and compliance documentation — fully online, starting at just ₹4,999. No CA visit needed.
