Skip to content

Legal & Compliance for Business

The data protection law is already notified. Most of your duties start in 2027.

The Digital Personal Data Protection Act, 2023 and the Rules made under it in November 2025 apply to the personal data most small businesses hold: customer lists, enquiry forms, staff records, delivery addresses. The Rules give businesses time, and the main duties are phased in over eighteen months. This session explains what the law says in plain language, which dates are fixed and which are still to be confirmed, and what an owner can start doing now. It is awareness, not legal advice.

An adviser and business owner review a contract using notes and removable page tabs.
Explore this page6 sections

Phased does not mean optional. It means you have time to do it properly.

The Act sets out duties for anyone who decides why and how personal data is processed, and rights for the individuals the data is about. The Rules, notified in November 2025, say how: what a notice must contain, what safeguards are expected, when a breach must be reported. Dates have been staggered so that businesses can prepare.

As of October 2026, we are in the middle of that period. This session helps a small business use it. This session is general information for awareness. It is not legal advice, and it does not replace a qualified lawyer, company secretary or chartered accountant, who should be consulted about a specific situation.

What the session covers

40 topics across 7 areas. Seven parts, from what the law is to what to do first. 6 apply to almost any business; the rest only in a particular case.

Where the Law Stands: Dates to CheckWhat the Rules say, and what we have not been able to confirm.6
  • The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology in November 2025
  • Rule 1 puts some rules into force on publication, including those on the Data Protection Board
  • Rule 4, on registration of Consent Managers, applies one year after publication, around November 2026
  • Rules 3 and 5 to 16 and 22 and 23, which include notice, safeguards, breach intimation and rights, apply eighteen months after publication, around May 2027
  • In January 2026 the press reported that the ministry was considering shortening some timelines; we have not found a notified change, and government statements since have described the eighteen-month schedule
  • Check the MeitY website and the Gazette for the current position before you plan around any date

The Act's own provisions were brought into force on a matching timetable. Confirm the current notification with a professional.

Who the Law CoversProbably more of your business than you assume.6
  • A Data Fiduciary is whoever decides why and how personal data is processed; a Data Processor handles it on its behalf; a Data Principal is the individual
  • The Act applies to digital personal data, and to data collected on paper and later digitised
  • Personal or domestic use by an individual is outside it
  • The Act does not set a general exemption for small businesses
  • It allows the Government to notify exemptions from some duties for particular classes, including startups; check whether any notification covers you
  • Employee data is covered too, with employment-related uses treated as a legitimate use
Know What You HoldYou cannot protect, or explain, what you have not listed.6

A one-page list of what you collect, why, where it sits and who can see it is the most useful single preparation step, and nothing in the law prevents you from starting it now.

  • Customer names, phone numbers, addresses, order histories
  • Enquiry and registration forms, including on paper
  • Staff and candidate records
  • Photos, KYC copies and payment details
  • Where each is kept: spreadsheets, accounting software, phones, cloud tools
  • Which vendors handle each, and who in your business can open it
Notice and ConsentTell people clearly, ask clearly, and be able to show you did.7
  • Consent must be free, specific, informed, unconditional and unambiguous, by a clear affirmative action, and limited to the data necessary for the stated purpose
  • A notice must accompany or precede the request, saying what data, for what purpose, how to exercise rights, and how to complain to the Board
  • Rule 3 asks for a notice that is understandable on its own, in clear and plain language, with an itemised description of the data and the specific purpose
  • People must be told how to withdraw consent, and withdrawal must be as easy as giving it
  • Notices must be available in English or a language listed in the Eighth Schedule to the Constitution
  • The business must be able to prove that notice was given and consent obtained
  • The Act also lists legitimate uses, such as using data a person voluntarily gave for the purpose they gave it
Safeguards, Breaches and PenaltiesThe part with the largest penalties in the law.5
  • Rule 6 lists minimum safeguards, such as encryption or masking, access control, logs and monitoring, backups, and contract terms with processors, plus retention of certain logs for one year
  • On becoming aware of a breach, a business must tell each affected person without delay, and tell the Board without delay and with more detail within seventy-two hours, or longer if the Board permits
  • The Schedule to the Act sets maximum penalties, for example up to two hundred and fifty crore rupees for failing to take reasonable security safeguards and up to two hundred crore rupees for failing to give breach notice
  • These are ceilings, not usual outcomes: the Board must weigh gravity, duration, mitigation and proportionality
  • A breach plan on one page, and knowing who to call, is cheaper than any penalty

Penalty figures are from the Schedule to the Act and the Government's November 2025 explainer. Check the current text.

People's Rights and Your Contact PointBe ready to answer when somebody asks.5
  • Rights to access a summary of data, to correct and update it, to erase it, to grievance redressal and to nominate someone to act for them
  • Rule 9 requires the business to publish a contact person for questions on processing
  • Rule 14 requires the business to publish how to make a request and to respond to grievances within a stated period, which may not exceed ninety days
  • Erasing data once consent is withdrawn or the purpose is served, unless another law requires you to keep it
  • Telling your processors to erase it too
Children's DataIf it appliesOnly for businesses that deal with under-18s.5
  • A child is anyone under eighteen
  • Verifiable consent of a parent or guardian is needed before processing a child's data
  • Tracking, behavioural monitoring and targeted advertising directed at children are barred
  • The Rules exempt some classes, such as certain clinics and educational institutions, for stated purposes
  • Coaching centres, schools, sports academies and children's retailers should take advice

A first-quarter preparation list

  • Write the one-page list of what you hold
  • Read your privacy notice against it and fix the gaps
  • Name the person who will answer data questions
  • List your vendors who see personal data
  • Draft a one-page breach response plan
  • Ask your professional which dates and duties apply to you

What this session is not

  • Not a compliance certificate or audit
  • Not legal advice about whether you are a Significant Data Fiduciary or exempt
  • Not a promise that these dates will not change
  • Not a substitute for reading the Act and Rules on the official site
  • Not a software or consultant recommendation

How the session runs

Led by a facilitator, with a qualified lawyer or data-protection professional where the topic needs one. It uses made-up examples, clearly labelled, such as a clinic's appointment sheet or a shop's loyalty list, to show how notice, consent and breach duties would work. Participants draft their one-page list of what they hold. The facilitator gives the official sources for the Act, the Rules and the commencement notifications, and participants are asked to check them before acting, since dates and clarifications may change.

What your students leave with

  • A plain understanding of the terms Data Fiduciary, Data Principal and Data Processor
  • The phasing of the Rules, with the dates to check on the official site
  • A list of the personal data their own business holds, and why
  • What a notice, consent request and breach response should look like
  • A short preparation plan they can start this quarter
  • The questions to take to a lawyer or chartered accountant

Scheduled sessions

Nothing scheduled yet

Sessions are arranged with a college once a date is agreed. Ask us and we will find the right person for it.

A student rather than a college? See what is coming up, or ask your placement team to host this.

You have until about May 2027 to prepare. A one-page list is a good place to begin.

Tell us who your students are and what stage they are at. Sessions are free for participants.