The Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, moving India's data-protection law into execution. It applies to almost any organisation processing digital personal data while offering goods or services in India — any size, any sector.
Phased timeline
| Phase | What | When |
|---|---|---|
| Immediate | Data Protection Board set-up | From Nov 2025 |
| ~12 months | Consent-manager provisions | By Nov 2026 |
| ~18 months | Most substantive obligations | From May 2027 |
Start now
- Map what personal data you collect, why, and where it's stored.
- Prepare clear consent notices and a lawful basis.
- Plan breach notification, record-keeping and data-principal requests.
- Note special protections for children and persons with disabilities.
A small e-commerce store collects names, phone numbers, addresses and payment info.
Under DPDP it must: tell customers why it collects each field, take clear consent, store data securely, delete it when no longer needed, and be ready to handle a "delete my data" request. Start with a data map + a compliant privacy policy — the rest builds on that.
Don't wait for May 2027 — the useful work (knowing what data you hold and why) takes months and pays off immediately in customer trust. A privacy policy is the start, not the finish; for a full programme, use the runway now and take specialised advice before enforcement bites.
Not sure how this applies to you?
Rules change and the answer depends on your exact numbers. Get a qualified professional to review DPDP Rules 2025 readiness for your business for your case — before you act.
Talk to a KyaTax expert →Frequently asked questions
Does DPDP apply to small businesses?
Broadly yes — any organisation processing digital personal data to offer goods/services in India. Obligations scale with your role, but small businesses aren't automatically exempt.
When must I fully comply?
Most substantive obligations around May 2027; consent-manager provisions around November 2026.
Is a privacy policy enough?
It's a start, not the whole programme — data mapping, consent, security and breach processes also matter. Get specialised advice.
Related: Privacy Policy Generator · More guides · Our expert panel