DPDP Compliance Isn't a 2027 Problem — Here's What to Fix Now
- Consult Guild
- Aug 10
- 2 min read
India's Digital Personal Data Protection Act isn't a future law anymore — it's already in force, rolling out in phases. The Data Protection Board of India was established in November 2025, and the remaining obligations arrive on a fixed schedule through May 2027. For most businesses, the real risk isn't non-compliance today — it's still treating this as something to think about later.

The Rollout, in Plain Terms
The DPDP Rules were notified in November 2025 in three phases: the Data Protection Board became operational immediately, the Consent Manager framework is set to come online by November 2026, and the full set of substantive compliance obligations — along with the penalty regime — takes effect by May 2027. Eighteen months sounds like a long runway, but privacy notices, consent flows, and breach-response processes take real time to build properly.
Who This Actually Applies To
If your business collects digital personal data from anyone in India — customer names, phone numbers, emails, IDs collected through a website form, a booking system, or a CRM — you're a Data Fiduciary under the Act, regardless of your size or sector. There's no small-business exemption written into the framework.
What's Worth Starting Now
Three things tend to matter most in practice: a privacy policy that actually reflects what data you collect and why, a consent mechanism that's genuinely opt-in rather than buried in fine print, and a documented process for what happens if data is breached. None of these are complex individually — the risk is doing them under deadline pressure instead of methodically.
The Cost of Waiting
Penalties under the Act can reach up to ₹250 crore for serious violations. That figure is aimed at large-scale failures, not small businesses — but it signals how seriously the framework is meant to be enforced once the full regime is active in 2027.
Where Blackridge Fits In
Reviewing an existing privacy policy against DPDP requirements, drafting consent and notice language, and mapping out a breach-response process are all things Blackridge Law Group can help put in place — before the compliance window closes rather than after.




Comments