Almost every business in India now collects personal data: names and phone numbers from enquiry forms, addresses from online orders, health details in clinic apps, location data in delivery apps, and conversations in CRMs and WhatsApp. For years, the rules on how that data could be used were thin. That has changed. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 create a full data protection regime, with a phased deadline that is now close. DPDP Act compliance is no longer a future project; it is a 2026 and 2027 roadmap item.
Much of the work is not legal paperwork. It is software. Consent has to be captured and recorded in your forms and apps, users need a way to access and erase their data, old data has to be deleted on schedule, breaches have to be detected and reported quickly, and access to personal data has to be controlled and logged. If those features are not built into your website, app, CRM and integrations, policies alone will not make you compliant.
This guide explains the DPDP framework in plain language, the deadlines, what changes in your product, and a practical checklist and roadmap. It is general information for business and product teams, not legal advice; work with a qualified lawyer on your specific obligations.
DPDP Act Compliance at a Glance
Quick answer: DPDP Act compliance means processing digital personal data in India lawfully: with valid notice and consent (or another permitted ground), only for stated purposes, with reasonable security safeguards, honouring users' rights, deleting data when it is no longer needed, protecting children's data and reporting breaches. The DPDP Rules were notified on 13 November 2025 with an 18-month phased rollout, so most obligations apply by May 2027.
- Phase 1 (November 2025): the Data Protection Board of India and related provisions.
- Phase 2 (November 2026): the consent manager framework.
- Phase 3 (May 2027): the main obligations, including notice, consent, security safeguards, breach reporting and data principal rights.
- Breaches: inform affected users and the Board without delay, with a detailed report to the Board within 72 hours.
- Penalties: up to โน250 crore for failing to take reasonable security safeguards, and up to โน200 crore for breach-notification and children's data failures.
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's law on how organisations collect, use, store, share and delete digital personal data. The DPDP Rules, 2025 add the operational detail: how notices must look, how consent managers work, how breaches are reported, how long certain data can be kept, and how children's data is handled.
Three terms appear everywhere:
- Data Principal: the person the data is about, such as your customer, user, patient or employee.
- Data Fiduciary: the organisation that decides why and how personal data is processed, usually your business.
- Data Processor: a company that processes data on your behalf, such as a cloud host, CRM provider or software vendor. You remain responsible for what processors do with your data.
DPDP Rules 2025: The Deadlines
The Ministry of Electronics and Information Technology notified the DPDP Rules on 13 November 2025, with an 18-month phased implementation:
| Phase | When | What starts |
|---|---|---|
| Phase 1 | November 2025 | Data Protection Board of India and related provisions |
| Phase 2 | November 2026 | Consent manager registration and obligations |
| Phase 3 | May 2027 | Main obligations: notice, consent, security safeguards, breach reporting, retention and data principal rights |
Eighteen months sounds generous, but software changes, vendor contracts, data clean-up and testing all take time. Teams that start in late 2026 will be building under pressure; teams that start now can phase the work alongside normal releases.
Who Must Comply
The DPDP Act applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to people in India. In practice, that covers:
- startups, SMEs and enterprises with websites, apps or online services used by people in India;
- e-commerce, fintech, healthcare, education, travel, real estate and gaming businesses;
- B2B companies that hold customer and lead data in CRMs and marketing tools;
- employers processing employee data digitally;
- software vendors and SaaS providers, as processors for their clients and as fiduciaries for their own customers.
Some entities may be designated as Significant Data Fiduciaries based on factors such as the volume and sensitivity of data. They face additional duties, including data protection impact assessments and audits.
Key Obligations in Plain Language
- Give a clear notice. Before or when you collect data, tell people what data you collect, why, and how they can exercise their rights and complain.
- Get valid consent where consent is your basis: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and as easy to withdraw as to give.
- Use data only for the stated purpose, and collect only what you need.
- Keep data accurate and secure with reasonable security safeguards such as encryption, access control, logging and backups.
- Honour user rights: access to information about their data, correction, completion, updating and erasure, grievance redressal and nominating someone to act for them.
- Delete data when the purpose is served or consent is withdrawn, unless law requires you to keep it.
- Report breaches to affected people and the Data Protection Board.
- Protect children's data with verifiable parental consent and limits on tracking and targeted advertising.
- Manage processors through contracts and oversight.
What Changes in Your App or Website
Here is how those obligations translate into product and engineering work:
| Area | What to build or change |
|---|---|
| Forms and sign-up | Plain-language notices, separate consent for separate purposes (no pre-ticked boxes), links to privacy information |
| Consent records | A record of who consented to what, when, through which version of the notice, and when consent was withdrawn |
| User account | Self-service options to view, correct and delete data and withdraw consent, or a clear request flow |
| Marketing | Consent-based email, SMS and WhatsApp lists, with withdrawal honoured across every tool |
| Data storage | An inventory of where personal data lives, encryption, role-based access and access logs |
| Retention | Retention rules per data type and automated deletion or anonymisation jobs |
| Integrations | Mapping of data sent to CRMs, analytics, payment, messaging and AI tools, with contracts and minimal data sharing |
| Security operations | Monitoring, alerting and an incident process that supports reporting within the required timelines |
| Children | Age checks where relevant and a verifiable parental consent flow |
CRMs and WhatsApp tools deserve special attention because they often hold the most personal data with the least control. Our WhatsApp CRM guide and CRM integration guide cover how these systems connect.
Personal Data Breach Reporting
Under Rule 7 of the DPDP Rules, when a Data Fiduciary becomes aware of a personal data breach, it must:
- inform each affected Data Principal without delay, in clear language, including what happened, the likely consequences, the steps taken and what they can do to protect themselves;
- inform the Data Protection Board without delay; and
- send the Board a detailed report within 72 hours of becoming aware, covering the facts, mitigation measures, findings about who caused the breach and steps to prevent recurrence, unless the Board allows longer.
You cannot meet a 72-hour deadline without preparation. You need monitoring that detects incidents, logs that show what data was affected, a contact channel for every user, and a tested response plan with named owners.
Data Retention and Deletion
Many businesses keep personal data forever by default: old leads in the CRM, closed accounts in the database, years of chat history and form submissions in email inboxes. Under the DPDP framework, personal data should be erased once the purpose it was collected for is no longer being served, or when consent is withdrawn, unless another law requires you to keep it.
The DPDP Rules go further for certain large platforms. The Third Schedule sets a three-year retention limit for listed classes of e-commerce entities, online gaming intermediaries and social media intermediaries above specified user thresholds, counted from the last time the user approached the platform or exercised their rights. At least 48 hours before erasure, the platform must tell the user their data will be deleted unless they log in or make contact.
Even if your business is not on that list, the practical lesson is the same: decide how long each type of data is needed, write it down, and automate deletion. Useful steps include:
- setting retention periods per data type, such as leads, customers, invoices, support tickets and chat logs;
- separating data you must keep for tax, accounting or other legal reasons from data you no longer need;
- building scheduled jobs that delete or anonymise expired records across the database, CRM and file storage;
- making sure backups and exports follow the same rules within a reasonable period;
- logging deletions so you can show what was removed and when.
Vendors, Processors and Integrations
Modern businesses share personal data with many tools: hosting and cloud providers, CRMs, email and SMS platforms, WhatsApp providers, payment gateways, analytics, support desks and, increasingly, AI services. Under the DPDP Act, your business remains responsible for personal data that processors handle on your behalf, so these relationships need the same attention as your own systems.
- Map every data flow. List which personal data goes to which vendor, through which integration, and why.
- Minimise what you share. Send only the fields each tool needs; many integrations copy entire records by default.
- Update contracts. Make sure processors are bound to process data only on your instructions, protect it, support rights requests and delete it when the work ends.
- Propagate withdrawals and deletions. When a user withdraws consent or asks for erasure, the change must reach every connected system, not just your main database.
- Review AI tools carefully. Check whether personal data sent to AI services is stored or used for training, and configure them accordingly.
Integration work is often the hardest part of DPDP compliance, because data is copied between systems that were never designed to stay in sync. Clean, documented APIs make rights requests and deletions far easier to honour.
Children's Data
Under the DPDP framework, a child is anyone under 18. Before processing a child's personal data, you must obtain verifiable consent from a parent or lawful guardian, and you must not undertake tracking, behavioural monitoring or targeted advertising directed at children, subject to limited exemptions. Education, gaming, social, health and e-commerce platforms with younger users should review sign-up flows, analytics and advertising set-ups early.
Penalties for Non-Compliance
The Data Protection Board can impose significant financial penalties under the Act's schedule. The largest include up to โน250 crore for failing to take reasonable security safeguards to prevent a personal data breach, and up to โน200 crore each for failing to notify a breach and for failing to meet obligations relating to children. Beyond penalties, breaches damage customer trust, partnerships and fundraising.
DPDP Act Compliance Checklist
- Create a data inventory: what personal data you collect, where, why, where it is stored and who it is shared with.
- Confirm the legal basis for each purpose, with legal advice.
- Rewrite privacy notices in plain language and show them at the point of collection.
- Rebuild consent capture so it is specific, unbundled and easy to withdraw, and store consent records.
- Build a user rights process for access, correction and erasure requests, with response tracking.
- Set retention periods and automate deletion or anonymisation.
- Strengthen security safeguards: encryption, role-based access, multi-factor login for staff, logging and backups.
- Prepare a breach response plan that can meet the 72-hour Board report.
- Review vendors and processors and update contracts.
- Check children's data flows and parental consent.
- Appoint a clear owner and publish grievance contact details.
- Train staff who handle customer data, including sales and support teams.
A Roadmap to May 2027
Now to December 2026: Discover and design
- Complete the data inventory and gap assessment across website, apps, CRM and integrations.
- Prioritise high-risk systems: those with sensitive, large-volume or children's data.
- Design the consent, rights and retention features and agree vendor changes.
January to March 2027: Build
- Ship consent capture, consent records and updated notices.
- Build user rights flows and automated retention jobs.
- Improve access control, logging and monitoring.
April to May 2027: Test and operate
- Run a breach simulation against the 72-hour timeline.
- Test rights requests end to end, including data held by vendors.
- Train teams and document processes for ongoing compliance.
What DPDP Compliance Costs
The cost of DPDP Act compliance depends on your systems, not just your size. The main factors are:
- Number of systems holding personal data: website, apps, CRM, ERP, analytics, messaging and support tools.
- Data volume and sensitivity, especially financial, health and children's data.
- Technical debt: older systems without clear data models or logging take more work. Our legacy modernization guide explains how to approach them.
- Custom vs off-the-shelf software: custom systems need development; SaaS tools need configuration and vendor review.
- Legal advice, security testing and ongoing operations.
A short assessment usually pays for itself by showing which systems need changes and which are already in good shape.
Frequently Asked Questions
What is DPDP Act compliance?
DPDP Act compliance means meeting the requirements of India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 when processing digital personal data: notice and consent, purpose limitation, security safeguards, user rights, retention limits, children's data protection and breach reporting.
When do the DPDP Rules come into force?
The DPDP Rules were notified on 13 November 2025 with an 18-month phased rollout: Board provisions from November 2025, the consent manager framework from November 2026, and the main obligations by May 2027.
Does the DPDP Act apply to small businesses and startups?
Yes. The Act applies to organisations that process digital personal data, regardless of size, although some entities may have additional duties if designated as Significant Data Fiduciaries. Startups should build compliance into their products early, when it is cheapest.
How quickly must a data breach be reported under the DPDP Rules?
Affected individuals and the Data Protection Board must be informed without delay, and a detailed report must be sent to the Board within 72 hours of becoming aware of the breach, unless the Board allows longer.
What are the penalties under the DPDP Act?
Penalties can reach โน250 crore for failing to take reasonable security safeguards, and โน200 crore for failures relating to breach notification or children's data, among other amounts in the Act's schedule.
What is a consent manager?
A consent manager is a registered entity that gives people a single platform to give, manage, review and withdraw consent across organisations. The consent manager framework starts in November 2026.
Is this guide legal advice?
No. It is general information to help business and product teams plan. Please consult a qualified lawyer for advice on your specific situation.
How can CodeBase Coders help with DPDP Act compliance?
CodeBase Coders handles the technology side of DPDP Act compliance, working alongside your legal advisers. We start with an IT and data audit that maps where personal data lives across your website, apps, CRM and integrations. Then our software development team builds what the law requires: consent capture and records, privacy notices, user rights requests, retention and deletion jobs, access controls, logging and breach alerts, in your web applications, mobile apps and CRM. For AI features, our AI governance consulting covers responsible use of personal data. Book a free DPDP readiness review.
Sources
- Press Information Bureau: DPDP Rules, 2025 notified (November 2025)
- DLA Piper: Data Protection Laws of the World, India (phased implementation and penalties)
- DPDP Rules 2025, Rule 7: Intimation of personal data breach
- Wikipedia: Digital Personal Data Protection Rules, 2025
Work With CodeBase Coders
DPDP Act compliance is mostly built in software: consent, rights, retention, security and breach response. CodeBase Coders helps businesses turn ideas into scalable digital products and improve existing processes through software, automation, AI, integrations and modern web technologies. We map your personal data, build the features the law requires, and keep your systems ready for audits.
- IT & Data Audit
- Custom Software Development
- Web Application Development
- Mobile App Development
- Custom CRM Development
- AI Governance Consulting
Not sure how ready your systems are? Book a free DPDP readiness review with CodeBase Coders and we will map where personal data lives in your website, apps and tools and give you a prioritised build plan. Explore everything we build at codebasecoders.com.
Rohan Verma
Founder, CodeBase CodersRohan Verma is the founder of CodeBase Coders. He helps startups, SMEs and enterprises turn ideas into scalable digital products and improve business processes through custom software, AI, automation, integrations and modern web technologies.