The DPDP Act and Rules, read by the people who have to build for them.
India's data protection law is in force in stages. The Rules arrived in November 2025, consent managers follow in November 2026, and the obligations that change how you collect, keep and erase personal data bite on 13 May 2027. This is what the law asks, in the order you will have to do it.
- Where the law stands today
- The three dates that matter
- Which of these you are
- Notice and consent
- Consent managers, and what they mean for you
- The rights you have to answer
Where the law stands today
The Digital Personal Data Protection Act was passed in 2023 and then waited for its Rules. Those were notified on 13 November 2025, and the Data Protection Board of India was constituted the same day. The law now arrives in stages rather than all at once, which is a gift: the substantive duties are known, and the date they bite is far enough away to build for properly and close enough that a business which starts next quarter will be late.
Nothing in the Act is exotic. Tell people what you are taking and why. Take only what the purpose needs. Keep it safe. Erase it when the purpose ends. Answer them when they ask. The work is not understanding it. The work is making a business that runs on spreadsheets and WhatsApp able to prove all five.
The three dates that matter
| Date | What happens | What it means for you |
|---|---|---|
| 13 November 2025 | The Rules were notified and the Data Protection Board of India was constituted. | The framework exists and the regulator is real. Nothing else was switched on that day. |
| 13 November 2026 | The consent manager provisions commence. | Registration with the Board opens. If your consent will be routed through a consent manager, the integration work has to be under way before this. |
| 13 May 2027 | The remaining substantive obligations come into force. | Notice, consent, rights, security safeguards, breach reporting, retention and the penalties behind them all apply. This is the date to plan back from. |
Plan back from May 2027, not forward from today. Discovery and cleanup of the data you already hold is the long pole, and it is the part nobody can do for you in a week.
Which of these you are
| Role | Who it is | What it carries |
|---|---|---|
| Data Fiduciary | Whoever decides why and how personal data is processed. Most businesses reading this. | Notice, consent, security, breach reporting, erasure, answering rights requests. |
| Data Processor | Anyone processing on a fiduciary's behalf, under contract. | What the contract says. The fiduciary stays answerable to the individual. |
| Data Principal | The individual. For a child, the parent or lawful guardian. | Rights of access, correction, erasure, grievance and nomination. |
| Consent Manager | An entity registered with the Board that lets a person give, manage, review and withdraw consent in one place. | Registration conditions, an India incorporation and a net worth of at least two crore rupees. |
| Significant Data Fiduciary | Those the government designates, by volume and sensitivity of data and risk to the country. | Everything above, plus a data protection impact assessment, an independent audit each year and a data protection officer based in India. |
Most businesses are a data fiduciary for their own customers and employees, and a processor for somebody else's data at the same time. Write down which hat you wear for each data set before you design anything.
Notice and consent
- Notice comes first, in plain language, itemised. What data, for what purpose, how to withdraw, how to complain to the Board.
- Consent has to be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data the purpose actually needs.
- Withdrawal has to be as easy as giving it was. When consent goes, processing stops, and the data goes unless another law requires you to keep it.
- Consent taken before the law applied does not carry over on its own. Where the original notice does not meet the standard, it is given again.
- Every notice version, every consent and every withdrawal has to be reconstructable later. If you cannot show what someone agreed to and when, you do not have consent, you have a record of a click.
There is a lawful basis besides consent, for certain legitimate uses such as a service a person has asked for, employment purposes, medical emergencies and obligations under other laws. It is narrower than people hope. Treat it as the exception you can defend in writing, not the default.
Consent managers, and what they mean for you
A consent manager is a registered intermediary. A person uses one to give, review and withdraw consent across the businesses they deal with, from a single place, and the business has to honour what arrives through it. Registration is with the Board, the applicant must be incorporated in India, must show a net worth of at least two crore rupees, and must satisfy the conditions in the First Schedule on governance, security and conflicts of interest. Those provisions commence in November 2026.
For almost every business reading this, the implication is not a registration project. It is an integration one. Your systems have to accept a consent or a withdrawal that originated somewhere else, apply it to the right purposes, stop the processing that depended on it, and be able to show afterwards that they did.
The rights you have to answer
| Right | What you have to be able to do |
|---|---|
| Access | A summary of the personal data you hold on the person and what you are doing with it, plus who else you have shared it with. |
| Correction and erasure | Correct, complete, update or erase on request, unless a law requires the data to stay. |
| Grievance | A published route to complain to you first, answered inside your own stated period, before the Board hears it. |
| Nomination | The person can nominate someone to exercise their rights if they die or become incapable. |
Publish the route and the contact. Put a clock on every request. The failure mode is not refusing a request, it is losing one in an inbox and having nothing to show when it is asked about.
Children and guardianship
For anyone under eighteen, consent comes from a parent or lawful guardian, and it has to be verifiable. Tracking children, monitoring their behaviour and advertising directed at them are off the table. The same protection extends to a person with a disability who has a lawful guardian.
If your service is not built for children but is used by them, age assurance stops being a product decision and becomes a compliance one. Decide how you will know, and write down what you do when you cannot.
Security, and a breach clock of 72 hours
The Rules ask for reasonable security safeguards in substance rather than a certificate: encryption or equivalent protection, access control, logs and monitoring that would let you detect and reconstruct an incident, continuity arrangements, and the same discipline contracted down to your processors.
When a breach happens, two clocks start. Tell the affected people without delay, in plain language: what happened, the likely consequences, what you have done, what they should do, and who they can contact. File with the Board within 72 hours of becoming aware, with the facts and the remediation. The 72 hours runs from awareness, not from certainty, and the penalties for staying quiet are among the heaviest in the schedule.
Retention and erasure
The general rule is purpose-bound: when the purpose is served, or consent is withdrawn, the data goes, unless another law requires it to stay. On top of that the Rules set a default for large consumer platforms. E-commerce and social media services above two crore registered users, and online gaming services above fifty lakh, erase personal data three years after the person last engaged, and have to tell the person at least 48 hours before the erasure so they can keep the account alive by using it.
Most businesses are under those thresholds, and it would be a mistake to read that as a licence to keep everything forever. Write the retention period for each data set, put it in the system, and make erasure a job that runs rather than a promise in a policy.
The next 90 days
- Find the personal data. Every system, every spreadsheet, every WhatsApp export. Who is in it, why you hold it, on what basis, and who else you sent it to.
- Rewrite the notice. Plain language, itemised, and offered in English and the languages of the Eighth Schedule where your users expect them.
- Rebuild consent as a record. Purpose by purpose, versioned, with withdrawal that actually stops the processing downstream.
- Stand up the rights desk. One route in, an owner, a clock, and evidence that each request was answered inside it.
- Write the retention rule down. For each data set: why you hold it, how long, and what triggers erasure. Then enforce it in the system, not in a policy document.
- Rehearse a breach. Who decides it is a breach, who tells the individuals, who files with the Board inside 72 hours, and where the evidence is kept.
- Fix your contracts. Processors, vendors and anyone you share data with. Instructions, security, breach reporting back to you, deletion at the end.
None of these is a purchase. Each one is a week or two of unglamorous work, and all seven have to be true at once before the law is satisfied.
Where NeauraPrivPro fits
NeauraPrivPro is the register of whose personal data you hold and on what basis. It checks consent before a message goes out, tracks every access, correction and erasure request against its legal window, enforces the retention rule you wrote instead of reminding you about it, and keeps the evidence an audit or a Board enquiry will ask for. It runs in your own region, on your cloud or your premises.
It sits alongside the rest of what we build, so consent taken at a counter, a form or a WhatsApp conversation lands in the same register as consent taken on your website, and a withdrawal reaches all of them.
Sources and a caveat
Last checked against the Act and the Rules: 27 September 2026. We review this page on a schedule and correct it when the law moves.
The authority is the Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025 as notified in the Gazette on 13 November 2025. Read them, and take the wording to your own counsel. This page is a working reading by the team that builds the systems, not legal advice, and dates and thresholds should be re-checked before you rely on them.
Answered
Do we need to become a consent manager?
Almost certainly not. A consent manager is a registered intermediary that acts for individuals across many businesses. What you need is a consent record of your own that is accurate, versioned and able to accept and honour consent and withdrawal that arrive from a consent manager.
Does the DPDP Act apply to business contact data?
It applies to digital personal data about an identifiable individual. A named person at a company is still a person. The exemptions are narrow and specific, so treat business contacts as in scope unless your counsel says otherwise.
We are outside India. Does it reach us?
If you process the personal data of people in India in connection with offering goods or services to them, yes.
How fast is breach reporting?
Tell the affected individuals without delay. File with the Board inside 72 hours of becoming aware, with what happened, the likely consequences, what you did about it and who they can contact.
What are the penalties?
The schedule to the Act sets caps by failure, up to two hundred and fifty crore rupees. The largest attach to failing to take reasonable security safeguards and to failing to report a breach.
Is this legal advice?
No. It is a working reading of the Act and the Rules by the team that builds the systems. Take the wording to your counsel before you rely on it.
Talk to us. If your project excites us, we’ll build a working MVP* — free.
No slide deck, a working screen. It shows you how we think before you sign anything.
*Scoped to about three focused days of work, and only for a project we genuinely find interesting — not every enquiry qualifies.