The DPDP compliance checklist for startups: what to finish before 13 November 2026 and 13 May 2027
The DPDP Act compliance deadline for an ordinary startup is 13 May 2027, when every operating duty starts. 13 November 2026, when Consent Managers may apply to register, is the milestone for the notice and consent flow. This checklist sets out the DPDP Rules 2025 timeline and twelve items, each tied to the section or rule that asks for it, in build order. Print it or ask for the PDF.
Work through it in order: items 1 to 3 settle what applies, items 4 to 6 build the notice and consent flow before 13 November 2026, items 7 to 12 are the duties live on 13 May 2027. The programme behind it, with the GDPR and UAE PDPL legs, the DPO and Significant Data Fiduciary questions, the developer questions on intermediaries and LLM APIs, and who signs what, is on DPDP compliance.
| Date | In force (G.S.R. 843(E) and rule 1) | What it means for a startup | Checklist items |
|---|---|---|---|
| 13 November 2025 | Act sections 1(2), 2, 18 to 26, 35, 38 to 43, 44(1) and (3); rules 1, 2 and 17 to 21 | The Board is established (G.S.R. 844(E)) and sized at four Members (G.S.R. 845(E)); no appointment located as at 6 October 2026. No operating duty on a startup yet | Items 1 to 3, now |
| 13 November 2026 | Act sections 6(9) and 27(1)(d); rule 4 | Consent Managers may apply to register (Indian company, net worth at least Rs 2 crore). Still no operating duty on a startup | Items 4 to 6: our milestone, not a statutory deadline |
| 13 May 2027 | Act sections 3 to 5, 6(1) to (8) and (10), 7 to 17, 27 except (1)(d), 28 to 34, 36, 37 and 44(2); rules 3, 5 to 16, 22 and 23 | Every operating duty applies; the Board can penalise under section 33; IT Act section 43A is omitted | Items 7 to 12 live; the legacy-user notice goes out |
Confirm the Act reaches you, and which parts
Section 3 decides who is in; two carve-outs decide how much.
- Section 3(a) and (b): data processed in India, and processing abroad connected with offering goods or services to people in India, so a Delaware or Dubai entity with Indian users is in. Whether a foreign parent is lawfully held from India is on round-tripping under FEMA.
- Section 17(1)(d) carves out an Indian entity processing foreign users’ data under a foreign contract, except sections 8(1) and 8(5). Section 17(3) could exempt notified startups; no notification was located as at 6 October 2026.
Map the data, the purposes and the processors
The duty stays with the Data Fiduciary, whoever processes.
- List every data set, purpose and recipient. Section 8(1) keeps you responsible for your Data Processors; section 8(2) allows them only under a valid contract. Clauses sit with contracts and IP.
- Each purpose rests on consent (section 6) or a legitimate use (section 7); section 4 allows nothing else, and there is no GDPR-style legitimate interests basis. Section 7(a) covers data a user volunteers, section 7(i) employee data for employment.
Keep the IT Act regime and the CERT-In clock running
Nothing switches off early.
- Section 44(2)(a) omits section 43A of the IT Act 2000, but G.S.R. 843(E) brings section 44(2) into force only on 13 May 2027. The SPDI Rules 2011 regime applies until then.
- CERT-In directions of 28 April 2022: Annexure I incidents reported within 6 hours, ICT logs kept 180 days in India. The DPDP Act does not replace them (item 8).
Rebuild the notice, and draft the one for existing users
Rule 3 makes the notice a product surface that stands alone.
- Section 5(1): a notice with every consent request stating the data, the purpose, how to exercise rights and how to complain to the Board. Rule 3: plain language, an itemised list of data, purposes and goods or services, links to withdraw, exercise rights and complain. Sections 5(3) and 6(3): English or any Eighth Schedule language, at the user’s option.
- Section 5(2): users who consented before commencement get a fresh notice as soon as reasonably practicable; processing continues until withdrawal. Draft it now for 13 May 2027.
Rebuild the consent flow and keep the log
Consent you cannot prove is consent you do not have.
- Section 6(1): free, specific, informed, unconditional and unambiguous, by clear affirmative action, limited to the data the purpose needs. Pre-ticked boxes fail. Section 6(4): withdrawal as easy as consent.
- Section 6(10) puts the burden of proving notice and consent on you, so the log is evidence. Section 6(6): on withdrawal, cease and make your Data Processors cease within a reasonable time.
Decide the Consent Manager question before 13 November 2026
A decision date for a startup, not a filing date.
- Section 6(9) and rule 4 start on 13 November 2026 (G.S.R. 843(E)(b), rule 1(3)): an Indian company with net worth of at least Rs 2 crore may apply to register as a Consent Manager (First Schedule). Optional infrastructure, not a startup duty.
- Integrate, become one, or neither: the answer shapes item 5. No Board appointment and no application format was located as at 6 October 2026; verify both first. The date sits in the India compliance calendar.
Put the rule 6 safeguards in place, with named owners
Section 8(5) makes reasonable security safeguards mandatory.
- Rule 6(1) minimum: encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review; backups; one-year retention of logs and personal data for breach detection; a safeguards clause in every processor contract; organisational measures.
- Map each measure to a system and a named owner. Sign the processor clauses before 13 May 2027.
Write the breach playbook with two clocks
Every breach is reportable; the Act sets no materiality threshold.
- Section 2(u): accidental disclosure, alteration and loss of access count, so an exposed storage bucket is a breach. Section 8(6): intimate the Board and each affected user.
- Rule 7(1): tell each affected user without delay through their account or registered channel. Rule 7(2): tell the Board without delay, then within seventy-two hours file the facts, causes, mitigation, findings, remedial steps and a report on the user intimations, unless the Board allows longer on a written request. CERT-In’s 6 hours run alongside.
Set retention and erasure in one schedule
Erase when the purpose ends; keep logs a year. Both apply.
- Section 8(7): erase on withdrawal or once the purpose is reasonably assumed served, unless another law requires retention, and make processors erase. Rule 8(3): keep personal data, traffic data and logs one year from processing for Seventh Schedule purposes, even after the account is deleted.
- Rule 8(1) and the Third Schedule: e-commerce with 2 crore or more registered users, gaming intermediaries with 50 lakh or more, social media with 2 crore or more erase three years from the later of the user’s last approach and “the commencement of” the Rules, with 48 hours’ notice (rule 8(2)). The Schedule does not say which commencement date counts; rule 8 itself starts 13 May 2027, so verify before scheduling deletions. Data kept so the user can reach the account, or a stored virtual token usable for money, goods or services, is carved out.
Gate children at eighteen and switch off tracking
A child is anyone under eighteen (section 2(f)).
- Section 9(1): verifiable parental consent before processing a child’s data. Section 9(3): no tracking, behavioural monitoring or targeted advertising directed at children.
- Rule 10: check the claimed parent is an identifiable adult using identity details already held, volunteered, or a Digital Locker virtual token. Rule 12 and the Fourth Schedule carve out health and education settings within limits, email account creation, real-time safety location and the age check itself.
Publish the contact, the rights route and the grievance period
The grievance desk becomes the Board’s front door.
- Rule 9: publish prominently, and repeat in every rights response, the contact of the DPO or the person who answers data questions. Rule 14(1) and (3): publish how rights are exercised and a grievance response period of at most ninety days.
- Sections 11 to 14: access, correction and erasure, grievance redressal, nomination; section 13(3) makes the user exhaust your route first. A DPO is required only of a notified Significant Data Fiduciary (section 10, rule 13); no notification was located as at 6 October 2026.
Settle where the data sits and what moves it
Transfers out are allowed until the Central Government says otherwise.
- Section 16(1) lets the Central Government notify countries to which transfer is restricted; rule 15 makes transfers subject to any general or special order on making data available to a foreign State. No adequacy list, no standard clauses. No notification or order was located as at 6 October 2026.
- Section 16(2) keeps stricter sectoral law: the RBI circular of 6 April 2018 (RBI/2017-18/153) requires payment system data stored only in India, the foreign leg also storable abroad. Intra-group paper is on intercompany agreements and transfer pricing.
What is at stake, as at 6 October 2026. Section 33 and the Schedule set maxima: up to Rs 250 crore for failing security safeguards (section 8(5)), Rs 200 crore for a breach not notified (section 8(6)) or for children’s-data duties (section 9), Rs 150 crore for Significant Data Fiduciary duties, Rs 50 crore otherwise; the Board weighs gravity, repetition, gain and mitigation. Section 37: on the Board’s written reference after penalties in two or more instances, the Central Government may, after a hearing, order public access to the service blocked in India. Appeals go to TDSAT within sixty days (section 29(2), rule 22). Upkeep after 13 May 2027 is the fractional general counsel retainer.
Frequently asked questions
What is the DPDP Act compliance deadline for startups?
13 May 2027 for every operating duty. G.S.R. 843(E)(c) brings sections 3 to 5, 6(1) to (8) and (10), 7 to 17, 27 (except 27(1)(d)), 28 to 34, 36, 37 and 44(2) of the Act into force eighteen months after 13 November 2025, and rule 1(4) brings rules 3, 5 to 16, 22 and 23 of the DPDP Rules 2025 in on the same day. 13 November 2026, when section 6(9) and rule 4 start and Consent Managers may apply to register, is a milestone for a startup, not a deadline.
Is there a startup exemption under the DPDP Act?
None located as at 6 October 2026. Section 17(3) lets the Central Government notify classes of Data Fiduciaries, including startups, to whom sections 5, 8(3), 8(7), 10 and 11 would not apply. The Act defines a startup as a private limited company, partnership firm or LLP incorporated in India and recognised as one under criteria the Central Government notifies; it names no department and sets no turnover test. Even a notification would leave consent, security safeguards and breach intimation in place. Plan for the full Act.
Does the DPDP Act apply to a Delaware or Dubai company with users in India?
Yes. Section 3(b) extends the Act to processing outside India connected with offering goods or services to Data Principals in India, so incorporating abroad does not take a company out. The mirror image is section 17(1)(d): a person in India processing foreign users' data under a contract with a person outside India is outside Chapters II and III and section 16, except sections 8(1) and 8(5).
What has to happen within 72 hours of a personal data breach under the DPDP Rules?
Rule 7(2): tell the Board without delay, then within seventy-two hours of becoming aware file the detailed facts, causes, mitigation, findings, remedial steps and a report on the user intimations, unless the Board allows longer on a written request. Rule 7(1) separately requires each affected user to be told without delay. Section 8(6) sets no materiality threshold, and the CERT-In directions of 28 April 2022 run their own 6-hour clock for Annexure I incidents.
Can I download this DPDP compliance checklist as a PDF?
Yes. Print the page, which is built for paper and carries the verification date, or email info@infinilex.io with the subject line PDF: DPDP startup compliance checklist for the current version and each update as the Act or the Rules move. Nothing here is gated.
Nothing here is new to anyone who has read the Act; what is new is a Board that can act on it from 13 May 2027. Consent you can prove, a notice that stands alone, a breach reported without delay and in detail inside seventy-two hours, erasure when the purpose ends, an age gate at eighteen. Build in this order and keep the file.
Want the open items marked for your product?
Send one paragraph: what the product collects, where the users sit, which entity contracts with them, whether anyone under eighteen uses it. We will say which of the twelve are open.
Thirty minutes with Prashant Sharma, the founder, who does the work himself. You leave with next steps either way. Email is read by the founder and answered within one working day.
Want this as a PDF in your inbox?
Email us and we will send the current version, and the updated one each time the law moves. Or print the page: it is built for paper.
General information for founders and product teams, not legal advice for your business. No notification under sections 10, 16 or 17(3) or rule 15 is assumed; verify the Board’s appointments and portal before relying on either. Confirm every point against the current text.
Prepared by Infinilex Consultancy · infinilex.io · Published 6 October 2026 · Verified as of 6 October 2026. Printed copies date; check infinilex.io/resources/ for the current version.