
Most Indian businesses still treat data protection as a legal footnote. That window is closing. The Digital Personal Data Protection (DPDP) Act, 2023, paired with the DPDP Rules notified in November 2025, is now a live regulatory system with real deadlines and real penalties — up to ₹250 crore per violation. If your business collects a customer's name, phone number, or email address digitally, you are a "Data Fiduciary" under the Act, and the clock is already running.
This isn't a one-time filing. DPDP compliance touches your consent flows, your breach response process, your vendor contracts, and how your engineering team stores and deletes personal data. Getting DPDP readiness right means treating it as an operational build, not a checkbox exercise. Here's what the law actually requires, what's changing through 2026 and 2027, and how to approach DPDP Act compliance without derailing your product roadmap.
The DPDP Rules 2025 rolled out enforcement in three phases. Phase one took effect in November 2025 with the constitution of the Data Protection Board of India. Phase two lands on 13 November 2026, when the Consent Manager framework becomes operational, a system that lets users manage and withdraw consent across services through interoperable platforms. Phase three, the hard deadline, is 13 May 2027, when full substantive compliance across notice, consent, breach reporting, and data principal rights becomes enforceable with no announced grace period.
The DPDP Rules 2025 rolled out enforcement in three phases. Phase one took effect in November 2025 with the constitution of the Data Protection Board of India. Phase two lands on 13 November 2026, when the Consent Manager framework becomes operational, a system that lets users manage and withdraw consent across services through interoperable platforms. Phase three, the hard deadline, is 13 May 2027, when full substantive compliance across notice, consent, breach reporting, and data principal rights becomes enforceable with no announced grace period.
Strip away the legal language, and DPDP compliance comes down to seven operational buckets:
Historical data isn't exempt either. Regulators expect legacy datasets collected before the Act to be backed by valid consent or a lawful basis, a gap that trips up more companies than the day-to-day flows do.
Two patterns show up repeatedly. First, treating DPDP as a legal-team problem instead of an engineering one. Consent capture, breach detection, and data deletion are code, not clauses, they live in your application architecture, your database retention jobs, and your incident response runbooks. Second, underestimating legacy data. Auditing years of accumulated customer records for lawful basis is slower and messier than building new-user consent flows from scratch, and it's exactly the area regulators are watching first as the "soft enforcement" phase ends.
Start with a data inventory: what personal data you hold, where it lives, who touches it, and why. Map that against the seven obligation buckets above to find your real gaps, not assumed ones. From there, prioritize by risk and deadline: consent and notice infrastructure first, Consent Manager compatibility ahead of November 2026, then breach response and retention automation. Build the technical controls into your existing systems rather than bolting on a separate "compliance layer" that engineering will quietly ignore. Finally, document everything, audits, DPO appointments, and impact assessments aren't just internal hygiene; they're what you'll need to show the Data Protection Board if it comes calling.
DPDP compliance fails most often at the handoff between legal requirements and actual systems, the consent banner that doesn't talk to the database, the deletion policy with no automation behind it, the breach plan nobody has tested. Leapcodes closes that gap directly. Our DPDP compliance consulting services start with a full data inventory and gap assessment, then our engineering and infrastructure teams build the consent management, breach detection, and data rights workflows into your actual product, not as a separate layer bolted on before an audit. Whether you need a one-time DPDP readiness assessment or ongoing managed support through the 2027 deadline, Leapcodes builds the systems, not just the paperwork.
There isn't one single date. The Consent Manager framework becomes mandatory on 13 November 2026, and full substantive compliance across all obligations is due by 13 May 2027. Some provisions from the November 2025 notification are already in force.
Yes. If a foreign company offers goods or services to people in India, or profiles Indian residents, it falls under the Act — location doesn't create an exemption.
Every business processing personal data digitally is a Data Fiduciary. A Significant Data Fiduciary is a subset facing added duties — a Data Protection Officer, regular audits, and impact assessments — based on how much data they process and how sensitive or risky that processing is.
Penalties under the Act can reach ₹250 crore per violation, and officials have indicated there's no planned grace period once phase three takes effect. Non-compliance also carries breach and reputational risk well before any fine is issued.
Start with a data inventory and a gap analysis against the seven obligation areas — notice, consent, security, breach response, data principal rights, retention/erasure, and SDF status. You can't fix what you haven't mapped.