KyaTax
Legal

DPDP Rules 2025 Notified: What Every Indian Business Should Start Doing Now

Updated 2026-08-03 · By KyaTax · 8 min read · expert-explainer
Blog › Legal

The Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, moving India's data-protection law into execution. It applies to almost any organisation processing digital personal data while offering goods or services in India — any size, any sector.

0
max penalty
Nov 26
consent-manager rules
May 27
most obligations

Phased timeline

PhaseWhatWhen
ImmediateData Protection Board set-upFrom Nov 2025
~12 monthsConsent-manager provisionsBy Nov 2026
~18 monthsMost substantive obligationsFrom May 2027

Start now

🧮 Worked example

A small e-commerce store collects names, phone numbers, addresses and payment info.

Under DPDP it must: tell customers why it collects each field, take clear consent, store data securely, delete it when no longer needed, and be ready to handle a "delete my data" request. Start with a data map + a compliant privacy policy — the rest builds on that.

👩‍💼 Expert view

Don't wait for May 2027 — the useful work (knowing what data you hold and why) takes months and pays off immediately in customer trust. A privacy policy is the start, not the finish; for a full programme, use the runway now and take specialised advice before enforcement bites.

⚠️ Please read: This article is general information based on laws and notifications current as of August 2026. It is not legal, tax, accounting or professional advice or opinion and must not be relied upon for any decision. Rules change frequently and their application depends on your specific facts. Verify the latest position and connect with a KyaTax expert or your advisor before acting.
💬

Not sure how this applies to you?

Rules change and the answer depends on your exact numbers. Get a qualified professional to review DPDP Rules 2025 readiness for your business for your case — before you act.

Talk to a KyaTax expert →

Frequently asked questions

Does DPDP apply to small businesses?

Broadly yes — any organisation processing digital personal data to offer goods/services in India. Obligations scale with your role, but small businesses aren't automatically exempt.

When must I fully comply?

Most substantive obligations around May 2027; consent-manager provisions around November 2026.

Is a privacy policy enough?

It's a start, not the whole programme — data mapping, consent, security and breach processes also matter. Get specialised advice.

Related: Privacy Policy Generator · More guides · Our expert panel