AI Consulting

Your data protection deadline is three dates, and the first one has gone.

India’s data protection law stopped being a draft in November 2025. Most owner-led businesses are holding a single date somewhere in 2027 and treating everything before it as spare time. Here is what is actually on the record, with the notification numbers, so you can check it yourself.

The rules were notified, with a gazette number and a date, and they are not a draft any more.

13 Nov 2025

MeasuredThe Digital Personal Data Protection Rules, 2025, notified by MeitY via G.S.R. 846(E) dated 13 November 2025, under the DPDP Act 2023 (Act 22 of 2023).

Commencement is in three stages, not one, and the earliest has already passed.

3 stages

MeasuredRule 1(2) fixes periods, not dates: some rules on publication, Rule 4 one year after publication, and the substantive rules eighteen months after publication. Published commentary splits over whether a period computed "after" a date lands on the anniversary or the day following it, so the days below are given as a pair. The eighteen months is not in doubt, and that is the part a plan depends on.

How ready owner-led businesses actually are.

not measured

Not measuredWe have not audited a population and will not publish a readiness figure we have not counted. This paper reports the law, not anybody’s compliance.

Before seat belts were required, the motor industry’s position was that safety regulation was unnecessary, that drivers were the problem, and that any mandate would be ruinous.3 After it was required, the cost turned out to be small and nobody proposed going back. The expensive part was never the belt. It was the decade spent arguing about whether the belt was coming.

Data protection in India is at the same point in the same arc, and most owner-led businesses are still in the arguing phase without having noticed that the arguing ended.

What is actually on the record

The Digital Personal Data Protection Act was passed as Act 22 of 2023 and dated 11 August 2023.1For a long time that was all there was: an Act with no rules under it, which is why so many people reasonably filed it as “coming eventually.”

That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, by gazette notification G.S.R. 846(E).2 Rules exist. They have a number. You can look it up.

And it does not all commence at once. Rule 1(2) fixes three periods rather than three dates, each measured from publication: some rules on the day of publication itself, the Consent Manager framework one year after, and the substantive rules - notice, consent, security, breach reporting, erasure, children’s data - eighteen months after.2

So the days land on 13 November 2025, 13 or 14 November 2026 and 13 or 14 May 2027. The later two are written as a pair on purpose. Published commentary splits over whether a period computed “after” a date lands on the anniversary or the day following it, we are not the body that settles that, and nothing you would actually do changes by one day. The eighteen months is not in doubt, and the eighteen months is the part your plan depends on.

The single 2027 date most people are holding is the last one, not the only one. The first has already gone.

11 Aug 2023the Act13 Nov 2025Rules notified · stage one13/14 Nov 2026stage two · one year13/14 May 2027stage three · 18 monthsbehind youwhat people think the whole thing is
Three commencement stages. The conversation almost everybody is having concerns the one on the right.

Why “we are too small” is the wrong first question

The Act places duties on whoever decides the purpose and the means of processing personal data.1 That is a description of a role, not of a size. It is also, for most readers of this paper, a description of them.

The Act does allow the Central Government to notify exemptions for certain classes. Whether any of that reaches your business is a question for a lawyer with your facts in front of them, and I am not going to guess at it in either direction. What I will say is that “we are too small for this” is a conclusion people reach without checking, and it is the same sentence the motor industry used.

The useful first question is not whether you are exempt. It is what you are holding.

What you are holding, which is more than you think

Sit down and list every place your business keeps information about a person. Not systems you bought for that purpose. Every place.

  • Customer names and phone numbers in a billing system.
  • Years of WhatsApp conversations, including photographs people sent.
  • A staff attendance device, which may hold fingerprints or faces.
  • CCTV, and however long it keeps.
  • A booking sheet, a delivery list, a spreadsheet of complaints.
  • Whatever your last web developer set up to collect enquiries.

Almost nobody has this list. Making it is free, takes an afternoon, and is the single most useful hour of work available on this subject - because every question anyone will ever ask you about data protection starts with it, and no lawyer can make it for you.

Four things worth doing before you spend money

  1. Make the list above. On paper is fine. For each entry: what is in it, who can see it, and how long it has been there.
  2. Find anything you cannot justify still having. The cheapest data protection work in existence is deleting what you did not need to keep. It costs nothing and reduces every future obligation.
  3. Ask how each system would answer “show me everything you hold about this person, and now remove it.” If the honest answer is that nobody could do it, that is an engineering fact you can act on today, whatever your legal position turns out to be.
  4. Take the two notification numbers in this paper to a lawyer. Act 22 of 2023 and G.S.R. 846(E). Ask specifically what applies to a business of your shape, and what the three dates mean for you.

Steps one to three are useful whatever the answer to step four is. That is the whole reason to start with them: they are the part that does not depend on advice you have not received yet.

How this paper was made

THIS IS NOT LEGAL ADVICE AND WE ARE NOT YOUR LAWYERS. It is engineering guidance about what a system has to be able to do, written from the primary sources named below and read on 26 August 2026. Your own obligations depend on facts about your business that this paper knows nothing about. Take the dates and the notification numbers to a lawyer or your company secretary and ask about your position specifically.

Every date and every number in this paper comes from the Act and the notified Rules, cited below. Where we could not verify something to that standard, it is not in the paper. In particular: the Act allows the Central Government to notify exemptions for certain classes of data fiduciary, so whether any exemption reaches you is a question for counsel and not one we answer here.

We have not audited any business’s compliance for this paper, and we describe no client. Nothing here reports a finding about any real organisation.

On the date at the top of this page. This paper is dated 31 August 2026 because that is its slot in the series. The writing and the working were done on 26 August 2026, when the series was compiled ahead of its slot. We would rather say that here than have you find it in the page history.

References

  1. Parliament of India (2023). The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Government of India, 11 August 2023. The Act itself. Duties attach to the person who determines the purpose and means of processing personal data.
  2. Ministry of Electronics and Information Technology (2025). The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)). Government of India, notified 13 November 2025. The operative rules, and the notification that fixed the three enforcement dates.
  3. Nader, R. (1965). Unsafe at Any Speed: The Designed-In Dangers of the American Automobile. Grossman Publishers. An industry insisting regulation was unnecessary, then discovering it was cheap. The arc repeats.