Before seat belts were required, the motor industry’s position was that safety regulation was unnecessary, that drivers were the problem, and that any mandate would be ruinous.3 After it was required, the cost turned out to be small and nobody proposed going back. The expensive part was never the belt. It was the decade spent arguing about whether the belt was coming.
Data protection in India is at the same point in the same arc, and most owner-led businesses are still in the arguing phase without having noticed that the arguing ended.
What is actually on the record
The Digital Personal Data Protection Act was passed as Act 22 of 2023 and dated 11 August 2023.1For a long time that was all there was: an Act with no rules under it, which is why so many people reasonably filed it as “coming eventually.”
That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, by gazette notification G.S.R. 846(E).2 Rules exist. They have a number. You can look it up.
And it does not all commence at once. Rule 1(2) fixes three periods rather than three dates, each measured from publication: some rules on the day of publication itself, the Consent Manager framework one year after, and the substantive rules - notice, consent, security, breach reporting, erasure, children’s data - eighteen months after.2
So the days land on 13 November 2025, 13 or 14 November 2026 and 13 or 14 May 2027. The later two are written as a pair on purpose. Published commentary splits over whether a period computed “after” a date lands on the anniversary or the day following it, we are not the body that settles that, and nothing you would actually do changes by one day. The eighteen months is not in doubt, and the eighteen months is the part your plan depends on.
The single 2027 date most people are holding is the last one, not the only one. The first has already gone.
Why “we are too small” is the wrong first question
The Act places duties on whoever decides the purpose and the means of processing personal data.1 That is a description of a role, not of a size. It is also, for most readers of this paper, a description of them.
The Act does allow the Central Government to notify exemptions for certain classes. Whether any of that reaches your business is a question for a lawyer with your facts in front of them, and I am not going to guess at it in either direction. What I will say is that “we are too small for this” is a conclusion people reach without checking, and it is the same sentence the motor industry used.
The useful first question is not whether you are exempt. It is what you are holding.
What you are holding, which is more than you think
Sit down and list every place your business keeps information about a person. Not systems you bought for that purpose. Every place.
- Customer names and phone numbers in a billing system.
- Years of WhatsApp conversations, including photographs people sent.
- A staff attendance device, which may hold fingerprints or faces.
- CCTV, and however long it keeps.
- A booking sheet, a delivery list, a spreadsheet of complaints.
- Whatever your last web developer set up to collect enquiries.
Almost nobody has this list. Making it is free, takes an afternoon, and is the single most useful hour of work available on this subject - because every question anyone will ever ask you about data protection starts with it, and no lawyer can make it for you.
Four things worth doing before you spend money
- Make the list above. On paper is fine. For each entry: what is in it, who can see it, and how long it has been there.
- Find anything you cannot justify still having. The cheapest data protection work in existence is deleting what you did not need to keep. It costs nothing and reduces every future obligation.
- Ask how each system would answer “show me everything you hold about this person, and now remove it.” If the honest answer is that nobody could do it, that is an engineering fact you can act on today, whatever your legal position turns out to be.
- Take the two notification numbers in this paper to a lawyer. Act 22 of 2023 and G.S.R. 846(E). Ask specifically what applies to a business of your shape, and what the three dates mean for you.
Steps one to three are useful whatever the answer to step four is. That is the whole reason to start with them: they are the part that does not depend on advice you have not received yet.
How this paper was made
THIS IS NOT LEGAL ADVICE AND WE ARE NOT YOUR LAWYERS. It is engineering guidance about what a system has to be able to do, written from the primary sources named below and read on 26 August 2026. Your own obligations depend on facts about your business that this paper knows nothing about. Take the dates and the notification numbers to a lawyer or your company secretary and ask about your position specifically.
Every date and every number in this paper comes from the Act and the notified Rules, cited below. Where we could not verify something to that standard, it is not in the paper. In particular: the Act allows the Central Government to notify exemptions for certain classes of data fiduciary, so whether any exemption reaches you is a question for counsel and not one we answer here.
We have not audited any business’s compliance for this paper, and we describe no client. Nothing here reports a finding about any real organisation.
On the date at the top of this page. This paper is dated 31 August 2026 because that is its slot in the series. The writing and the working were done on 26 August 2026, when the series was compiled ahead of its slot. We would rather say that here than have you find it in the page history.
References
- Parliament of India (2023). The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). Government of India, 11 August 2023. The Act itself. Duties attach to the person who determines the purpose and means of processing personal data.↩
- Ministry of Electronics and Information Technology (2025). The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)). Government of India, notified 13 November 2025. The operative rules, and the notification that fixed the three enforcement dates.↩
- Nader, R. (1965). Unsafe at Any Speed: The Designed-In Dangers of the American Automobile. Grossman Publishers. An industry insisting regulation was unnecessary, then discovering it was cheap. The arc repeats.↩