Data protection

India’s DPDP Rules: the compliance calendar nobody is reading

The Digital Personal Data Protection Act finally has operating rules. The obligations are staged, the lead times are uneven, and the sensible response is to sequence the work rather than panic about all of it at once.

18 July 2026 · 8 min read · StellarStart GLOBAL

India’s Digital Personal Data Protection Act, 2023 sat on the shelf for months waiting for its operating rules. Now that the rules are in force, most businesses are reading the wrong part first. The instinct is to start with the penalty schedule. The better starting point is the calendar, because the obligations do not all bite at once, and the ones with the longest lead times are not the ones getting the attention.

Start with consent notices, because everything depends on them

The Act is consent-first in a way the GDPR is not. Legitimate interests, as EU practitioners know it, has no direct equivalent; the closest analogue, “certain legitimate uses”, is a closed list. That means the consent notice is not one compliance artefact among many. It is the foundation the rest of your processing sits on.

A compliant notice must be presented in clear, plain language, available in English and the languages listed in the Eighth Schedule of the Constitution, and must describe the personal data, the purpose, and the manner of exercising rights. Rebuilding consent flows across a product takes a quarter for most teams, not a sprint. Start here.

Verifiable parental consent is the long pole

If any part of your user base can be under eighteen, the Act requires verifiable parental consent before processing a child’s data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. There is no grace here for platforms that simply did not ask ages. Age assurance architecture, whether declaration plus verification or token-based approaches through Digital Locker style infrastructure, is an engineering project with vendor selection, integration and testing. Six months is a realistic runway.

Breach notification is where speed matters most

The rules require notification to the Data Protection Board and to each affected data principal, and the operative timelines are short. Unlike the GDPR’s harm threshold, the Indian regime as drafted does not let you decide a breach was too trivial to report. That makes the internal playbook, who decides, who drafts, who notifies, through which channel, the thing to build now, because it cannot be built during an incident.

What can wait, deliberately

Significant Data Fiduciary obligations, the DPO appointment, data protection impact assessments and annual audits, apply only once you are designated or clearly within the notified thresholds. Retention-driven erasure of long-dormant accounts also has defined trigger periods for the largest platforms. These matter, but they are sequenced after the foundations above, not before.

The order of work

Map processing and identify child-facing surfaces first. Rebuild consent notices second. Stand up the breach playbook third. Contract updates with processors, and grievance redressal mechanics, run alongside. If you do only one thing this quarter, make it the notice rebuild, because every other obligation assumes it exists.

This is general commentary, current at its publication date, and not legal advice for any specific matter. Rules in this area change quickly. If any of it touches your situation, book a free call and we will look at the specifics.