Skip to content
Kanoons.®
Resource Center All Services Industries Calculators Due Dates Knowledge Contact Us
Notifications

Create an account Forgot password?

Practice Areas

Startup & Compliances GST, tax & notices IP Rights All Services

Resources

Resource Center Industries Calculators Due Dates Knowledge FAQs Contact Us
Esc

DPDP Act 2023 and DPDP Rules 2025 for small and mid-size Indian businesses — phased commencement (Consent Manager ~Nov 2026; core notice/safeguard rules ~May 2027), consent notices, breach duties and a practical readiness checklist.

By Kanoons Editorial Team · 13 min read · Last verified 2026-10-06

SummaryShow summaryHide summary

Summary

India’s Digital Personal Data Protection Act, 2023 is no longer a Bill on a shelf. Parliament enacted it in August 2023; MeitY notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025 (G.S.R. 846(E)) with a phased commencement. For an SME the job is not to memorise every schedule — it is to know when notices, consent, security safeguards and breach duties actually bite, and to clean your customer / employee data map before those dates. Verified against the Rules text and MeitY explanatory material on 6 October 2026.

  • Rules notified 13 Nov 2025; Consent Manager framework ~13 Nov 2026; core notice / safeguard / breach rules ~13 May 2027 (18 months after publication).
  • You are usually a Data Fiduciary for customer and employee personal data you control.
  • Rule 3 notices must be standalone, itemised and linked to withdrawal / rights / Board complaint.
  • Breach: notify individuals without delay; Board update within 72 hours.
  • Service path: Legal Agreements (privacy / consent / processor terms).

Commencement map (do not skip)

SliceTiming (from 13 Nov 2025 gazette)What SMEs feel
Rules 1, 2, 17–21From publicationDefinitions / machinery
Rule 4 Consent Manager+ 1 year (~13 Nov 2026)Ecosystem registration — most SMEs are consumers of this, not registrants
Rules 3, 5–16, 22, 23+ 18 months (~13 May 2027)Notices, State processing standards, security safeguards, breach intimation, rights mechanics, etc.

Use these dates for programme planning; re-read the gazette if MeitY issues corrigenda.

Practical SME checklist (start now)

1. Data map — what personal data you hold (customers, leads, employees, vendors), where it lives, and why you process it. 2. Purpose inventory — one processing purpose per consent ask; stop bundling “marketing + account + sharing with everyone”. 3. Notice rewrite — draft Rule 3-ready notices (itemised data + purposes + uses enabled + withdrawal / rights / Board links). 4. Consent UX — affirmative action; withdrawal as easy as grant; keep versioned logs (you may need to prove consent). 5. Processor contracts — payroll, CRM, cloud, WhatsApp BSP, email ESP — flow-down security and instruction terms. 6. Security baseline — Rule 6 themes: encryption / access control / logs / backups / processor clauses / one-year log retention ideas. 7. Breach runbook — who calls whom in the first hour; Board + individual intimation templates (Rule 7). 8. Rights desk — contact person for access / correction / erasure / nomination / grievance (90-day grievance themes in practitioner summaries — confirm live Rule text for your obligations). 9. Children / verifiable consent — if you actually target children, read Rules 10–11 early; do not improvise. 10. Vendor and cookie hygiene — marketing pixels and scraped lead lists are where SME programmes usually fail first.

Mid-article CTA: Update privacy notices and data-processing terms → Cross-sell: Website / app policies via legal agreements, Startup legal stack, Contact.

Consent notice — Rule 3 in one breath

The notice must be understandable without reading your Terms of Service. At minimum it itemises personal data, states each purpose and the goods/services/uses enabled, and gives means to:

  • withdraw consent (comparable ease)
  • exercise rights under the Act
  • complain to the Data Protection Board

English or an Eighth Schedule language your users actually read.

What “good” looks like before May 2027

  • Privacy / notice pages match real data flows (not copied EU text with “GDPR” left in)
  • Lead forms record purpose + timestamp + notice version
  • Employee / CCTV / visitor processing has a lawful narrative and access rules
  • Breach tabletop exercise run once with engineering + founder
  • Board / founder note acknowledging the May 2027 compliance cliff

Related reading on this site

  • Startup legal agreements checklist
  • E-commerce seller GST / TCS compliance
  • How to send a legal notice
  • POSH compliance employer guide

Primary sources

  • Digital Personal Data Protection Act, 2023
  • Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E) (13 November 2025) — commencement in Rule 1(2)–(4)
  • MeitY explanatory note on the DPDP Rules, 2025
  • PIB / MeitY releases on Rules notification (Nov 2025)

How Kanoons can help

DPDP readiness for SMEs is mostly notices, contracts and breach hygiene — not an enterprise GRC suite on day one. Kanoons helps rewrite privacy / consent notices, align processor and employment terms, and build a practical checklist against the Rules’ phased dates.

Primary: Privacy notices and data-processing agreements

Also relevant:

  • Startup legal agreements checklist services
  • HR policies for employee-data narratives
  • Legal notices if a vendor / customer dispute is already live
  • Contact the Kanoons team for a scoped readiness review

Questions about your facts before you publish new notices? Contact the Kanoons team.

Disclaimer

General information only — not legal advice. Kanoons is not a law firm. DPDP commencement, Significant Data Fiduciary duties, cross-border transfer mechanisms and penalty exposure are fact-specific and evolving; confirm against the live Act, Rules and Board directions before relying on any date or control. See our Disclaimer.

Frequently asked questions

Are the DPDP Rules in force?

The Digital Personal Data Protection Rules, 2025 were notified around 13 November 2025 (G.S.R. 846(E)). Commencement is phased: Rules 1, 2 and 17–21 from publication; Rule 4 (Consent Manager registration) one year after publication (~13 November 2026); Rules 3, 5–16, 22 and 23 eighteen months after publication (~13 May 2027). Always re-check the gazette dates before promising a go-live to your board.

Does DPDP apply to small businesses?

Yes, if you determine purposes and means of processing digital personal data as a Data Fiduciary (or process for someone who is). Size may affect how heavy your programme looks, but “we are an SME” is not an exemption from consent, notice, security safeguards or breach intimation once the relevant rules apply. Significant Data Fiduciary designations add extra duties for notified classes.

What must a consent notice contain under Rule 3?

An independent, plain-language notice with an itemised description of personal data, the specified purpose(s) and the goods/services/uses enabled by that processing, plus links / means to withdraw consent, exercise rights and complain to the Data Protection Board — with withdrawal as easy as giving consent.

What are the breach timelines under the Rules?

On becoming aware of a personal data breach, intimate affected Data Principals without delay (content prescribed in Rule 7) and intimate the Board without delay with an initial description, followed by a detailed update within 72 hours (or longer if the Board allows on written request).

Do I need to become a Consent Manager?

No. Consent Managers are a specialised registered role (Rule 4 / First Schedule) from the one-year commencement. Most SMEs will remain Data Fiduciaries that honour consents — including those managed through a registered Consent Manager — rather than registering as one.

Home / Knowledge / …
Verified

Digital Personal Data Protection Act for SMEs: Consent, Notices and Practical Steps

On this page

    Related guides

      How Kanoons can help

      Filing, objections and compliance calendars — get a clear next step from the team.

      Talk to Kanoons Browse services
      Related

      More on this topic

      Article not found. Browse the knowledge centre.

      Kanoons.®

      Kanoons Law and Tax Consultants Private Limited — advisory, documentation, business registration, taxation, compliance management and IP filings for Indian businesses.

      Due-date reminders by email.

      Practice Areas
      Startup & Compliances GST, tax & notices IP Rights Industries
      Resources
      Resource Center Knowledge Centre Calculators Due Date Reminders FAQs Client Portal
      Company
      Contact Us Client Portal Disclaimer Privacy Policy Terms & Conditions Refund & Returns Policy
      Contact us

      #404, MQ Splendor, Above HDFC Bank, Pillar No. 210, Airport Road, Upperpally, Hyderabad, Telangana, India

      +91 90000 13560 / 90 support@kanoons.com
      © 2026 Kanoons Law and Tax Consultants Private Limited. All rights reserved.

      Kanoons.com is owned and operated by Kanoons Law and Tax Consultants Private Limited, a registered consultancy providing services in advisory, documentation, business registration, taxation, compliance management and intellectual property filings across India. Kanoons is not a law firm or accounting firm and does not offer legal representation, statutory audits, attestation or certification services — all specialised professional work is coordinated through authorised, independently qualified professionals in accordance with applicable Indian laws.

      All content on this website is intended for general informational purposes only and should not be interpreted as legal, financial or tax advice. Use of this website or communication through it does not create any attorney–client, accountant–client or other professional relationship with the company. Users are encouraged to seek independent professional advice before making decisions based on content or services provided herein. We are committed to safeguarding user information in accordance with applicable data protection laws, including the Information Technology Act, 2000, and rules thereunder.

      Your access to and use of this website is subject to our Terms & Conditions, Privacy Policy, Refund and Returns Policy and Disclaimer. By continuing to browse or interact with the site, you acknowledge and agree to these terms. The wordmark “Kanoons®”, its logo and all related brand assets are the exclusive intellectual property of Kanoons Law and Tax Consultants Private Limited; unauthorised use, imitation or reproduction is strictly prohibited and may lead to civil or criminal action.