The era has begun

For years, “India's data protection law” was a document in draft — debated, delayed, and easy to defer. That era is over. The Digital Personal Data Protection Act (DPDP Act) was passed in 2023, and on 13 November 2025 the government notified the DPDP Rules 2025, giving the framework its operational detail and, crucially, a date: full compliance is due by 13 May 2027.

Eighteen months can feel comfortable. It isn't. A meaningful data protection programme — understanding your data, fixing how it is handled, and reaching a state you could defend to a regulator — typically takes nine to twelve months to build. Read those two numbers together and the conclusion is uncomfortable but clear: organisations that begin now will be ready in time; those that wait will not.

Why a policy is not compliance

Here is the trap we see most often. An organisation drafts a privacy policy, publishes it, files it away, and considers the matter closed. It is a natural instinct — and a costly one.

A policy is a statement of intent. Compliance is what happens when your organisation actually starts doing what that policy says — in a structured, consistent way — across everything you do with personal data: what you collect, why, on what lawful basis, who you share it with, how you secure it, how long you keep it, and what you do when something goes wrong. No document delivers that on its own. The DPDP Act does not ask whether you have written the right words; it asks whether your operations match them.

This is the shift from policy to practice — from data protection as paperwork to data protection as something built into systems, processes, and the daily decisions of the people who handle personal data. It is harder than drafting. It is also the only version that survives scrutiny.

What “ready” actually looks like

Preparing for the DPDP era is not a single task but a connected set of them. In our experience, genuine readiness rests on the following foundations.

  • Know your data. You cannot account for what you cannot see. The starting point is always a record of the personal data you hold: what it is, where it lives, why you have it, who it flows to, and how long you keep it. This record — a Record of Processing Activities (RoPA) — is the map everything else is built on. Most organisations are surprised by how much data they hold, and how little of it they had documented.
  • Get consent and lawful basis right. Under the DPDP Act, consent must be free, specific, informed, unambiguous, and given by a clear affirmative action — accompanied by a notice in plain language setting out what you collect and why. Pre-ticked boxes, bundled permissions, and consent buried in lengthy terms will not hold. Where the Act permits processing without consent for certain legitimate uses, those grounds must be applied deliberately, not assumed.
  • Honour data principal rights. Individuals have the right to access a summary of their data, to have it corrected and erased, to grievance redressal, and to nominate someone to act on their behalf. Rights on paper mean little without a process behind them: a way to receive a request, verify it, act within time, and record what was done.
  • Secure the data — as an obligation, not an afterthought. The Act requires reasonable security safeguards. This is where data protection and information security meet — but they are not the same discipline. Security protects data from breaches; data protection governs whether you should hold and use that data at all, and on what terms. You need both, and you should not mistake one for the other.
  • Be ready for a breach before one happens. The Rules set a demanding notification process. On becoming aware of a personal data breach, you must inform the Data Protection Board without delay, tell affected individuals in plain language, and provide the Board a detailed account within 72 hours. You cannot assemble that response for the first time during the incident. Readiness — a data map, an incident plan, named roles, a drafted notification — is decided long before anything goes wrong.
  • Put someone in charge. Accountability cannot be diffuse. Significant Data Fiduciaries face specific obligations, including appointing a Data Protection Officer and conducting Data Protection Impact Assessments and audits. Smaller organisations still need a clear owner — internally, or through a DPO-as-a-service arrangement.
  • Look down your supply chain. Your obligations do not end at your own systems. Where processors and vendors handle personal data on your behalf, your contracts and oversight must reflect the Act's requirements. A gap in a vendor is a gap in you.

Where organisations go wrong

The failures we anticipate are rarely exotic. They are predictable — and therefore avoidable. Treating the privacy policy as the finish line. Mapping data once and never again as systems change. Collecting consent that would not withstand a second look. Assuming a security certification equals data protection compliance. And, most commonly, waiting — trusting that eighteen months is plenty, until it isn't.

A path that works

The work is substantial, but it is not mysterious. A programme that reaches readiness tends to move through four stages:

  • Discover — map your data, obligations, and current maturity, so you know where you actually stand.
  • Prioritise — assess your exposure and build a practical, risk-based roadmap, rather than trying to do everything at once.
  • Implement — put the policies, processes, controls, contracts, training, and governance in place, and make them real in day-to-day operations.
  • Evolve — monitor, review, and strengthen the programme as the law, the regulator's expectations, and your own business change.

Done this way, compliance stops being a scramble against a deadline and becomes something more durable: an operating discipline that makes the organisation more trustworthy. And in a data-driven economy, trust is not a compliance cost — it is a competitive advantage.

The bottom line

India has entered its data protection era, and the deadline is fixed. The organisations that come through it well will not be the ones with the most polished policy documents. They will be the ones that did the harder, quieter work of turning those documents into practice — and started early enough to finish.

This article is for general information and does not constitute legal advice. For guidance on your organisation's specific obligations under the DPDP Act and the DPDP Rules, 2025, speak with a data protection lawyer.