There is no small business exemption in the DPDP Act's application section, so a small Indian business works the same 10 steps. Section 17(3), computed to commence 13 May 2027, interpretation until officially confirmed, lets the Central Government notify classes including startups as exempt from specified provisions only. Map your data, pick the ground for each purpose, fix your notice and consent, prepare for breaches and rights requests, each step cited to the exact provision.
Rule 7 of the DPDP Rules 2025 is not in force, and when it commences 2 clocks start the moment your organisation becomes aware of a personal data breach. Computed commencement is 13 May 2027, interpretation until officially confirmed. Contain and anchor the clock, run the 2 Rule 7 duties in parallel, file the 72 hour Board submission, then stabilise.
DPDP का फुल फॉर्म है Digital Personal Data Protection। DPDP Act 2023 भारत का डेटा संरक्षण कानून है और DPDP Rules 2025 इसे लागू करते हैं। यह कब से लागू है, किस पर लागू होता है और जुर्माने कितने हैं, आधिकारिक राजपत्र के संदर्भ के साथ।
India runs 2 breach clocks and only 1 is in force today: CERT In, 6 hours. DPDP Rule 7 gives 72 hours for the detailed Board submission, and its computed commencement is 13 May 2027, interpretation until officially confirmed, after which one organisation can be on both. Who reports what, to whom, on which clock.
DPDP and GDPR differ in machinery, and the DPDP duties compared here are not in force yet: computed commencement 13 November 2026 and 13 May 2027. Both dates are interpretation until officially confirmed. 2 grounds under section 4 against the longer list of lawful bases in GDPR Article 6(1), and fixed rupee caps in the Schedule, up to 250 crore rupees. Scope, Consent Managers, breach clocks, children's data, cross border transfers and DPIA triggers in one table, with the GDPR column given as orientation to the official EUR Lex text.
DPDP stands for Digital Personal Data Protection. The DPDP Act 2023 is India's data protection law and the DPDP Rules 2025 operationalise it, in force in phases from 13 November 2025.
Most ordinary businesses do not need to register as a Consent Manager, and Rule 4 is not in force yet. It commences on a computed 13 November 2026, interpretation until officially confirmed. A Consent Manager is a registered intermediary, not consent management software. What Rule 4 actually sets up.
One test decides it: who determines the purpose and means of the processing. The 8 engagements worked through, why one company holds both roles at once, what the test never asks, and why the Act says Fiduciary where other laws say controller.
Usually yes, in 2 roles at once. For your own users you are a Data Fiduciary with the full duty set. For customer data you are a Data Processor, and the framework never addresses you by that name.