DPDP Rules 2025 Notified: What Every Indian Business Should Start Doing Now
The Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, moving India's data-protection law into the execution phase. The law applies to almost any organisation processing digital personal data while offering goods or services in India — regardless of size or sector.
Phased timeline
| Phase | What | When |
|---|---|---|
| Immediate | Data Protection Board of India set-up provisions | From Nov 2025 |
| ~12 months | Consent-manager provisions | By Nov 2026 |
| ~18 months | Most substantive obligations | From May 2027 |
What to start now
- Map what personal data you collect, why, and where it is stored.
- Prepare clear consent notices and a lawful basis for processing.
- Plan breach notification, record-keeping and data-principal request handling.
- Note special protections for children and persons with disabilities.
Rules change often and how they apply depends on your exact numbers and facts. Don't guess on DPDP Rules 2025 readiness for your business — get a qualified professional to review your case.
💬 Talk to a KyaTax expert →Frequently asked questions
Does DPDP apply to small businesses?
It broadly applies to any organisation processing digital personal data to offer goods/services in India. Obligations scale with your role and data, but small businesses are not automatically exempt. Assess your exposure.
When must I fully comply?
Most substantive obligations are set to apply around May 2027, with consent-manager provisions around November 2026. Use the runway to prepare.
Is a privacy policy enough?
A compliant privacy policy is a start, not the whole programme. Data mapping, consent, security and breach processes also matter. Get specialised advice for a full roll-out.
Related: Privacy Policy Generator · More guides · Our expert panel