Nobody owes a DPO yet: section 10(2)(a) commences on a computed 13 May 2027, interpretation until officially confirmed. Only a notified Significant Data Fiduciary will owe one. Every other Data Fiduciary will owe a published contact person instead, under section 8(9) and Rule 9, which commence on the same date.
The DPDP duties on a business in 6 groups, none of them in force yet: the 2 grounds, notice, consent, section 8, rights, children, SDF and transfers. Every one is cited to the Gazette.
Only notified Significant Data Fiduciaries need a DPDP audit, and the duty has not started: section 10(2)(b) and Rule 13 commence on a computed 13 May 2027. That date is interpretation until officially confirmed. The independent auditor, the 12 month cycle, and the significant observations report.
Section 10 adds an India based DPO, an independent auditor and a 12 month Rule 13 DPIA and audit cycle once notified: all 3 commence on a computed 13 May 2027. That date is interpretation until officially confirmed. The DPO answers to the board of directors, and Rule 13 adds algorithmic due diligence and conditional localisation.
Only a notified Significant Data Fiduciary will owe a DPIA, and section 10 and Rule 13 both commence on a computed 13 May 2027. That date is interpretation until officially confirmed. What section 10(2)(c)(i) defines, the 12 month Rule 13 cycle, and the GDPR habits that do not carry.
Section 7(i), not in force yet, lets employers process employee personal data for the purposes of employment without consent; the ground is purpose based. Computed commencement for section 7 is 13 May 2027, interpretation until officially confirmed, so this is a planning window: it is not a blanket for everything HR touches, and the general obligations still apply.
There is no small business exemption in the DPDP Act's application section, so a small Indian business works the same 10 steps. Section 17(3), computed to commence 13 May 2027, interpretation until officially confirmed, lets the Central Government notify classes including startups as exempt from specified provisions only. Map your data, pick the ground for each purpose, fix your notice and consent, prepare for breaches and rights requests, each step cited to the exact provision.
The DPDP obligations belong to your organisation and not to the CTO, and none of these rules is in force yet: all are computed to commence 13 May 2027. That date is interpretation until officially confirmed. Engineering usually leads the technical half: safeguards, retention timers, breach detection, consent withdrawal paths and rights machinery, with the cross functional dependencies made explicit.
A small team's path through the DPDP framework: settle applicability, map your data, and build the 5 duty clusters in dependency order while the runway lasts.
No Significant Data Fiduciary duty is in force yet: section 10 commences on a computed 13 May 2027, interpretation until officially confirmed. SDF status will arrive by government notification against the section 10 factors, not by crossing a user count. The real numbers in the framework, the duties that follow, and the vendor thresholds that do not exist.
The provisions these articles point to
Each page carries the official text of the provision, its commencement status and the sources behind it.