Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 7 October 2026. Methodology

Archive

Articles and updates, page 5

56 articles on the DPDP Act 2023 and the DPDP Rules 2025, newest first. Every legal claim cites the official source it rests on.

Applicability

Does DPDP apply to foreign companies?

Section 3(b), not in force yet, reaches processing outside India in connection with any activity related to offering goods or services to people in India. The Act creates no local presence duty beyond the India based Data Protection Officer of a notified Significant Data Fiduciary, and section 37 blocking, in the same 18 month group, is the route against a company with no Indian assets.

Applicability

Does the DPDP Act apply to startups? No size test, and 3 places size counts

Section 3 carries no turnover, headcount or user threshold, so a 2 person company is inside the Act once section 3 commences on a computed 13 May 2027. That date is interpretation until officially confirmed. Size still decides which duties bite, in 3 named places, and section 17(3) names startups without exempting a single one.

Penalties

From complaint to penalty: how the Data Protection Board process works

The Board complaint route is not open yet: sections 28 to 34 commence on a computed 13 May 2027, interpretation until officially confirmed. What starts an inquiry under section 27, the 6 month inquiry clock, the section 33(2) factors and the 60 day appeal.

Breach response

DPDP data breach reporting: what Rule 7 actually requires

DPDP Rule 7, not in force yet, starts 2 clocks on awareness of a breach: intimation without delay, then detailed information to the Board within 72 hours. Computed commencement is 13 May 2027, interpretation until officially confirmed, and the intimation goes to each affected Data Principal and to the Board.

Compliance

DPDP compliance checklist for CTOs

The DPDP obligations belong to your organisation and not to the CTO, and none of these rules is in force yet: all are computed to commence 13 May 2027. That date is interpretation until officially confirmed. Engineering usually leads the technical half: safeguards, retention timers, breach detection, consent withdrawal paths and rights machinery, with the cross functional dependencies made explicit.

Compliance

DPDP compliance checklist for startups

A small team's path through the DPDP framework: settle applicability, map your data, and build the 5 duty clusters in dependency order while the runway lasts.