पाठशाला Pathshala · नियम Niyam, Law and compliance · Lesson 11 · Build
The DPDP Act: what it requires of your product
India’s data protection law is in force in stages and its main duties begin on 13 May 2027. Most of what it asks for is product work, and product work takes longer than a policy.
Pathshala, The Founder Library · 11 October 2026 · 7 min read

A founder asks the lawyer for a privacy policy compliant with the new data protection law and receives one in a week. Six months later a customer’s procurement team sends a questionnaire: show us the consent screen, the withdrawal flow, the erasure log, the breach runbook and the processor contracts. None of them exists, because none of them is a document. They are features, and nobody put them on the roadmap.
This lesson explains where the Digital Personal Data Protection Act stands on 10 October 2026, who it applies to and in what role, and then what it requires of a product, in the order a user meets it: notice, consent, rights, security, breach and deletion. The checklist turns it into sixteen pieces of work to schedule before the main duties begin.
Where the law stands, and the dates that matter
Parliament passed the Digital Personal Data Protection Act 2023 in August 2023, leaving its commencement to notification. The government notified the Digital Personal Data Protection Rules 2025 in November 2025, with an eighteen-month period for phased compliance. On the reading of the law firm Khaitan and Co, three stages follow. The definitions and the provisions setting up the Data Protection Board took effect at once. The registration and obligations of consent managers commence on 13 November 2026. The core duties of data fiduciaries, notice, consent, security, breach intimation, rights, retention and the duties of significant data fiduciaries, commence on 13 May 2027.
Two qualifications, both checked on 10 October 2026. In early 2026 MeitY consulted industry on shortening the timeline, by six months for significant data fiduciaries; a proposal is not an amendment, and a September 2026 analysis still reads 13 May 2027 as the date. And until that date the older regime under section 43A of the Information Technology Act and its 2011 rules on sensitive personal data continues to apply; section 44(2) of the new Act omits section 43A when the core provisions commence. So a company today has two sets of duties: the old ones now, the new ones in about seven months. The second is the larger build.
Who you are under the Act
The Act applies to the processing of digital personal data within India, and to processing outside India connected with offering goods or services to people in India. The person the data is about is the data principal. The company that decides why and how data is processed is the data fiduciary, and nearly every startup is one for its own users and staff. A vendor processing data on its behalf, a cloud provider, a CRM, a support tool, an analytics service, is a data processor, and under section 8 the fiduciary remains responsible for compliance whatever its processors do. The government may designate some fiduciaries as significant data fiduciaries by volume and sensitivity of data; they must appoint a data protection officer, have an independent data audit and, under the Rules, carry out a data protection impact assessment every year.

Two consequences for a product team. First, every vendor that touches personal data needs a contract that limits it to your purpose, requires security and breach notice, and makes it delete on instruction; that is a procurement task and a long one. Second, the Act’s duties attach to digital personal data whether you collect it online or digitise it later, so the paper forms scanned into a shared drive count.
Notice and consent, built into the screens
Section 5 requires a notice before or alongside every request for consent, stating the personal data and the purpose, how to withdraw consent and exercise rights, and how to complain to the Data Protection Board. The Rules add that the notice must be understandable on its own, presented independently of other information such as the terms of service, and give an itemised description of the data, the specified purposes, and the goods, services or uses each enables. A privacy policy linked from the footer does not meet that standard. A short notice on the screen where data is collected does.
Section 6 sets the standard for consent: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to what is necessary for the purpose. In product terms that means one toggle per purpose rather than one checkbox for everything, nothing pre-ticked, and no service withheld because a user declined something the service does not need. The data principal may withdraw consent at any time, and section 6(4) requires withdrawal to be as easy as giving consent was; on withdrawal section 8(7) requires the fiduciary to erase the data unless a law requires it to be kept. Section 6(10) puts the burden of proving that notice was given and consent obtained on the fiduciary, which is why the consent log in the checklist is not optional. Not everything needs consent: section 7 lists legitimate uses, including data a person voluntarily provides for a specified purpose and processing for employment.
Children change the design. Section 2 defines a child as anyone who has not completed eighteen years, and section 9 requires verifiable consent from a parent or lawful guardian before processing a child’s data, and forbids processing likely to harm a child’s well-being, tracking, behavioural monitoring and targeted advertising directed at children. A consumer product that cannot rule out minors needs an age gate and a parental consent flow; one that is plainly for adults should say so and design for it.
A privacy policy is a document. Compliance with this Act is a set of screens, logs and deletion jobs, and those take a quarter to build.
Rights the product must answer
Sections 11 to 14 give every data principal the right to a summary of the personal data processed and the processing activities, with the identities of other fiduciaries and processors it was shared with; the right to correction, completion, updating and erasure; the right to grievance redressal, which must be exhausted before going to the Board; and the right to nominate someone to act on their behalf in the event of death or incapacity. The Rules require fiduciaries to publish how each right can be exercised and set ninety days as the outer limit for responding. Build these as self-service flows in the account settings, with a ticket queue behind them for anything the flow cannot handle, and track the age of every request.
Security, breach and the 72 hours
Section 8(5) requires reasonable security safeguards to prevent personal data breaches, and the Schedule makes failure here the most expensive breach of the Act, with a penalty of up to ₹250 crore. Section 8(6) requires the fiduciary to inform the Board and each affected data principal of a breach. The Rules set the clock: affected people are told without delay, in plain language, what happened, the likely consequences and what is being done; the Board is told without delay and then receives a detailed report within 72 hours of the fiduciary becoming aware, covering the facts, the mitigation, the findings on who was responsible, the steps to prevent a recurrence and the notices sent. Failing to notify carries a penalty of up to ₹200 crore, the same as breaching the duties towards children; breaching a significant data fiduciary’s duties up to ₹150 crore; anything else up to ₹50 crore.
Seventy-two hours is not long enough to write a process. Write it now: who declares a breach, who investigates, who drafts the user notice, who files with the Board, and the templates for both. The Rules also require logs and related data to be kept for at least a year, so that there is something to investigate with.
Retention and deletion
Section 8(7) requires erasure once consent is withdrawn or the purpose is no longer served, unless another law requires retention, and processors must erase too. The Rules add a hard limit for large platforms: e-commerce entities and social media intermediaries with two crore or more registered users in India, and online gaming intermediaries with fifty lakh or more, must erase data three years after a user’s last interaction, with 48 hours’ notice to the user first. A startup below those thresholds still needs a retention schedule per data type and a deletion job that runs on it. Keeping everything forever was always a security risk; under this Act it is also a breach.
A quarterly privacy review
Name one owner, a founder or the head of product, and hold a forty-five-minute review on the first Monday of each quarter. Walk the checklist and move the open items into the next sprint. Read any notification under the Act or Rules issued in the quarter, and any order of the Data Protection Board. Check the age of every rights request and grievance against the ninety-day limit. Add any new vendor to the inventory with its contract. Run a tabletop breach drill twice a year and time it against the 72 hours. Then send the founders a single paragraph: what changed in the law, what shipped, what is late. Only three quarterly reviews fit between now and 13 May 2027, so the first should be this month.
Nothing here is legal or tax advice; confirm the current rule with a chartered accountant or lawyer before acting.
Sources
- The Digital Personal Data Protection Act 2023: sections 2, 5 to 9, 11 to 14, 33 and 44 and the Schedule of penalties, MeitY
- Press Information Bureau, Digital Personal Data Protection Rules 2025: fact sheet, November 2025 (eighteen-month phased compliance, ninety days, penalties)
- Khaitan and Co, ERGO: Digital Personal Data Protection Rules, 15 November 2025 (commencement stages, 72-hour report, retention thresholds, one-year logs)
- King Stubb and Kasiva, What happens to the SPDI Rules after DPDP enforcement, September 2026 (section 44(2) and 13 May 2027)
- S.S. Rana and Co, MeitY plans to cut short the DPDP compliance timeline, 13 February 2026 (proposal under consultation)