KyaTax
Blog › Legal
Legal

DPDP Rules 2025 Notified: What Every Indian Business Should Start Doing Now

Updated 2026-08-02 · By KyaTax · 8 min read

The Digital Personal Data Protection (DPDP) Rules, 2025 were notified in November 2025, moving India's data-protection law into the execution phase. The law applies to almost any organisation processing digital personal data while offering goods or services in India — regardless of size or sector.

Phased timeline

PhaseWhatWhen
ImmediateData Protection Board of India set-up provisionsFrom Nov 2025
~12 monthsConsent-manager provisionsBy Nov 2026
~18 monthsMost substantive obligationsFrom May 2027

What to start now

Penalties are significant — up to ₹250 crore for failing to maintain reasonable security safeguards. Start with a data map and a compliant privacy policy; escalate to specialised counsel for a full programme.
Important: This article is general information based on laws, notifications and public sources current as of August 2026. It is not legal, tax, accounting or professional advice or opinion, and must not be relied on for any decision. Tax and legal rules change frequently and their application depends on your specific facts. Please verify the latest position and connect with a KyaTax expert or your professional advisor before acting.

Rules change often and how they apply depends on your exact numbers and facts. Don't guess on DPDP Rules 2025 readiness for your business — get a qualified professional to review your case.

💬 Talk to a KyaTax expert →

Frequently asked questions

Does DPDP apply to small businesses?

It broadly applies to any organisation processing digital personal data to offer goods/services in India. Obligations scale with your role and data, but small businesses are not automatically exempt. Assess your exposure.

When must I fully comply?

Most substantive obligations are set to apply around May 2027, with consent-manager provisions around November 2026. Use the runway to prepare.

Is a privacy policy enough?

A compliant privacy policy is a start, not the whole programme. Data mapping, consent, security and breach processes also matter. Get specialised advice for a full roll-out.

Related: Privacy Policy Generator · More guides · Our expert panel