Data protection
The Digital Personal Data Protection Act finally has operating rules. The obligations are staged, the lead times are uneven, and the sensible response is to sequence the work rather than panic about all of it at once.
18 July 2026 · 8 min read · StellarStart GLOBAL
India’s Digital Personal Data Protection Act, 2023 sat on the shelf for months waiting for its operating rules. Now that the rules are in force, most businesses are reading the wrong part first. The instinct is to start with the penalty schedule. The better starting point is the calendar, because the obligations do not all bite at once, and the ones with the longest lead times are not the ones getting the attention.
The Act is consent-first in a way the GDPR is not. Legitimate interests, as EU practitioners know it, has no direct equivalent; the closest analogue, “certain legitimate uses”, is a closed list. That means the consent notice is not one compliance artefact among many. It is the foundation the rest of your processing sits on.
A compliant notice must be presented in clear, plain language, available in English and the languages listed in the Eighth Schedule of the Constitution, and must describe the personal data, the purpose, and the manner of exercising rights. Rebuilding consent flows across a product takes a quarter for most teams, not a sprint. Start here.
If any part of your user base can be under eighteen, the Act requires verifiable parental consent before processing a child’s data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. There is no grace here for platforms that simply did not ask ages. Age assurance architecture, whether declaration plus verification or token-based approaches through Digital Locker style infrastructure, is an engineering project with vendor selection, integration and testing. Six months is a realistic runway.
The rules require notification to the Data Protection Board and to each affected data principal, and the operative timelines are short. Unlike the GDPR’s harm threshold, the Indian regime as drafted does not let you decide a breach was too trivial to report. That makes the internal playbook, who decides, who drafts, who notifies, through which channel, the thing to build now, because it cannot be built during an incident.
Significant Data Fiduciary obligations, the DPO appointment, data protection impact assessments and annual audits, apply only once you are designated or clearly within the notified thresholds. Retention-driven erasure of long-dormant accounts also has defined trigger periods for the largest platforms. These matter, but they are sequenced after the foundations above, not before.
Map processing and identify child-facing surfaces first. Rebuild consent notices second. Stand up the breach playbook third. Contract updates with processors, and grievance redressal mechanics, run alongside. If you do only one thing this quarter, make it the notice rebuild, because every other obligation assumes it exists.