DPDP Act 2023 and DPDP Rules 2025 for small and mid-size Indian businesses — phased commencement (Consent Manager ~Nov 2026; core notice/safeguard rules ~May 2027), consent notices, breach duties and a practical readiness checklist.
By Kanoons Editorial Team · 13 min read · Last verified 2026-10-06
SummaryShow summaryHide summary
Summary
India’s Digital Personal Data Protection Act, 2023 is no longer a Bill on a shelf. Parliament enacted it in August 2023; MeitY notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025 (G.S.R. 846(E)) with a phased commencement. For an SME the job is not to memorise every schedule — it is to know when notices, consent, security safeguards and breach duties actually bite, and to clean your customer / employee data map before those dates. Verified against the Rules text and MeitY explanatory material on 6 October 2026.
- Rules notified 13 Nov 2025; Consent Manager framework ~13 Nov 2026; core notice / safeguard / breach rules ~13 May 2027 (18 months after publication).
- You are usually a Data Fiduciary for customer and employee personal data you control.
- Rule 3 notices must be standalone, itemised and linked to withdrawal / rights / Board complaint.
- Breach: notify individuals without delay; Board update within 72 hours.
- Service path: Legal Agreements (privacy / consent / processor terms).
Commencement map (do not skip)
| Slice | Timing (from 13 Nov 2025 gazette) | What SMEs feel |
|---|---|---|
| Rules 1, 2, 17–21 | From publication | Definitions / machinery |
| Rule 4 Consent Manager | + 1 year (~13 Nov 2026) | Ecosystem registration — most SMEs are consumers of this, not registrants |
| Rules 3, 5–16, 22, 23 | + 18 months (~13 May 2027) | Notices, State processing standards, security safeguards, breach intimation, rights mechanics, etc. |
Use these dates for programme planning; re-read the gazette if MeitY issues corrigenda.
Practical SME checklist (start now)
1. Data map — what personal data you hold (customers, leads, employees, vendors), where it lives, and why you process it. 2. Purpose inventory — one processing purpose per consent ask; stop bundling “marketing + account + sharing with everyone”. 3. Notice rewrite — draft Rule 3-ready notices (itemised data + purposes + uses enabled + withdrawal / rights / Board links). 4. Consent UX — affirmative action; withdrawal as easy as grant; keep versioned logs (you may need to prove consent). 5. Processor contracts — payroll, CRM, cloud, WhatsApp BSP, email ESP — flow-down security and instruction terms. 6. Security baseline — Rule 6 themes: encryption / access control / logs / backups / processor clauses / one-year log retention ideas. 7. Breach runbook — who calls whom in the first hour; Board + individual intimation templates (Rule 7). 8. Rights desk — contact person for access / correction / erasure / nomination / grievance (90-day grievance themes in practitioner summaries — confirm live Rule text for your obligations). 9. Children / verifiable consent — if you actually target children, read Rules 10–11 early; do not improvise. 10. Vendor and cookie hygiene — marketing pixels and scraped lead lists are where SME programmes usually fail first.
Mid-article CTA: Update privacy notices and data-processing terms → Cross-sell: Website / app policies via legal agreements, Startup legal stack, Contact.
Consent notice — Rule 3 in one breath
The notice must be understandable without reading your Terms of Service. At minimum it itemises personal data, states each purpose and the goods/services/uses enabled, and gives means to:
- withdraw consent (comparable ease)
- exercise rights under the Act
- complain to the Data Protection Board
English or an Eighth Schedule language your users actually read.
What “good” looks like before May 2027
- Privacy / notice pages match real data flows (not copied EU text with “GDPR” left in)
- Lead forms record purpose + timestamp + notice version
- Employee / CCTV / visitor processing has a lawful narrative and access rules
- Breach tabletop exercise run once with engineering + founder
- Board / founder note acknowledging the May 2027 compliance cliff
Related reading on this site
- Startup legal agreements checklist
- E-commerce seller GST / TCS compliance
- How to send a legal notice
- POSH compliance employer guide
Primary sources
- Digital Personal Data Protection Act, 2023
- Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E) (13 November 2025) — commencement in Rule 1(2)–(4)
- MeitY explanatory note on the DPDP Rules, 2025
- PIB / MeitY releases on Rules notification (Nov 2025)
Disclaimer
General information only — not legal advice. Kanoons is not a law firm. DPDP commencement, Significant Data Fiduciary duties, cross-border transfer mechanisms and penalty exposure are fact-specific and evolving; confirm against the live Act, Rules and Board directions before relying on any date or control. See our Disclaimer.
Frequently asked questions
Are the DPDP Rules in force?
The Digital Personal Data Protection Rules, 2025 were notified around 13 November 2025 (G.S.R. 846(E)). Commencement is phased: Rules 1, 2 and 17–21 from publication; Rule 4 (Consent Manager registration) one year after publication (~13 November 2026); Rules 3, 5–16, 22 and 23 eighteen months after publication (~13 May 2027). Always re-check the gazette dates before promising a go-live to your board.
Does DPDP apply to small businesses?
Yes, if you determine purposes and means of processing digital personal data as a Data Fiduciary (or process for someone who is). Size may affect how heavy your programme looks, but “we are an SME” is not an exemption from consent, notice, security safeguards or breach intimation once the relevant rules apply. Significant Data Fiduciary designations add extra duties for notified classes.
What must a consent notice contain under Rule 3?
An independent, plain-language notice with an itemised description of personal data, the specified purpose(s) and the goods/services/uses enabled by that processing, plus links / means to withdraw consent, exercise rights and complain to the Data Protection Board — with withdrawal as easy as giving consent.
What are the breach timelines under the Rules?
On becoming aware of a personal data breach, intimate affected Data Principals without delay (content prescribed in Rule 7) and intimate the Board without delay with an initial description, followed by a detailed update within 72 hours (or longer if the Board allows on written request).
Do I need to become a Consent Manager?
No. Consent Managers are a specialised registered role (Rule 4 / First Schedule) from the one-year commencement. Most SMEs will remain Data Fiduciaries that honour consents — including those managed through a registered Consent Manager — rather than registering as one.