Annexure · Founder resources · Data protection

The DPDP compliance checklist for startups: what to finish before 13 November 2026 and 13 May 2027

The DPDP Act compliance deadline for an ordinary startup is 13 May 2027, when every operating duty starts. 13 November 2026, when Consent Managers may apply to register, is the milestone for the notice and consent flow. This checklist sets out the DPDP Rules 2025 timeline and twelve items, each tied to the section or rule that asks for it, in build order. Print it or ask for the PDF.

Or get it by email
Verified as of 6 October 2026. Built from the official texts: the Digital Personal Data Protection Act 2023 (Act 22 of 2023, gazetted 11 August 2023), commencement notification G.S.R. 843(E) of 13 November 2025, the DPDP Rules 2025 (G.S.R. 846(E), 13 November 2025) and the Data Protection Board of India notifications G.S.R. 844(E) and G.S.R. 845(E). Laws move; confirm anything you rely on against current law, or ask us to.

Work through it in order: items 1 to 3 settle what applies, items 4 to 6 build the notice and consent flow before 13 November 2026, items 7 to 12 are the duties live on 13 May 2027. The programme behind it, with the GDPR and UAE PDPL legs, the DPO and Significant Data Fiduciary questions, the developer questions on intermediaries and LLM APIs, and who signs what, is on DPDP compliance.

Schedule A · DPDP Act and Rules 2025 commencement, and what to finish by each date, as at 6 October 2026
DateIn force (G.S.R. 843(E) and rule 1)What it means for a startupChecklist items
13 November 2025Act sections 1(2), 2, 18 to 26, 35, 38 to 43, 44(1) and (3); rules 1, 2 and 17 to 21The Board is established (G.S.R. 844(E)) and sized at four Members (G.S.R. 845(E)); no appointment located as at 6 October 2026. No operating duty on a startup yetItems 1 to 3, now
13 November 2026Act sections 6(9) and 27(1)(d); rule 4Consent Managers may apply to register (Indian company, net worth at least Rs 2 crore). Still no operating duty on a startupItems 4 to 6: our milestone, not a statutory deadline
13 May 2027Act sections 3 to 5, 6(1) to (8) and (10), 7 to 17, 27 except (1)(d), 28 to 34, 36, 37 and 44(2); rules 3, 5 to 16, 22 and 23Every operating duty applies; the Board can penalise under section 33; IT Act section 43A is omittedItems 7 to 12 live; the legacy-user notice goes out

Confirm the Act reaches you, and which parts

Section 3 decides who is in; two carve-outs decide how much.

  • Section 3(a) and (b): data processed in India, and processing abroad connected with offering goods or services to people in India, so a Delaware or Dubai entity with Indian users is in. Whether a foreign parent is lawfully held from India is on round-tripping under FEMA.
  • Section 17(1)(d) carves out an Indian entity processing foreign users’ data under a foreign contract, except sections 8(1) and 8(5). Section 17(3) could exempt notified startups; no notification was located as at 6 October 2026.

Map the data, the purposes and the processors

The duty stays with the Data Fiduciary, whoever processes.

  • List every data set, purpose and recipient. Section 8(1) keeps you responsible for your Data Processors; section 8(2) allows them only under a valid contract. Clauses sit with contracts and IP.
  • Each purpose rests on consent (section 6) or a legitimate use (section 7); section 4 allows nothing else, and there is no GDPR-style legitimate interests basis. Section 7(a) covers data a user volunteers, section 7(i) employee data for employment.

Keep the IT Act regime and the CERT-In clock running

Nothing switches off early.

  • Section 44(2)(a) omits section 43A of the IT Act 2000, but G.S.R. 843(E) brings section 44(2) into force only on 13 May 2027. The SPDI Rules 2011 regime applies until then.
  • CERT-In directions of 28 April 2022: Annexure I incidents reported within 6 hours, ICT logs kept 180 days in India. The DPDP Act does not replace them (item 8).

Rebuild the notice, and draft the one for existing users

Rule 3 makes the notice a product surface that stands alone.

  • Section 5(1): a notice with every consent request stating the data, the purpose, how to exercise rights and how to complain to the Board. Rule 3: plain language, an itemised list of data, purposes and goods or services, links to withdraw, exercise rights and complain. Sections 5(3) and 6(3): English or any Eighth Schedule language, at the user’s option.
  • Section 5(2): users who consented before commencement get a fresh notice as soon as reasonably practicable; processing continues until withdrawal. Draft it now for 13 May 2027.

Rebuild the consent flow and keep the log

Consent you cannot prove is consent you do not have.

  • Section 6(1): free, specific, informed, unconditional and unambiguous, by clear affirmative action, limited to the data the purpose needs. Pre-ticked boxes fail. Section 6(4): withdrawal as easy as consent.
  • Section 6(10) puts the burden of proving notice and consent on you, so the log is evidence. Section 6(6): on withdrawal, cease and make your Data Processors cease within a reasonable time.

Decide the Consent Manager question before 13 November 2026

A decision date for a startup, not a filing date.

  • Section 6(9) and rule 4 start on 13 November 2026 (G.S.R. 843(E)(b), rule 1(3)): an Indian company with net worth of at least Rs 2 crore may apply to register as a Consent Manager (First Schedule). Optional infrastructure, not a startup duty.
  • Integrate, become one, or neither: the answer shapes item 5. No Board appointment and no application format was located as at 6 October 2026; verify both first. The date sits in the India compliance calendar.

Put the rule 6 safeguards in place, with named owners

Section 8(5) makes reasonable security safeguards mandatory.

  • Rule 6(1) minimum: encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review; backups; one-year retention of logs and personal data for breach detection; a safeguards clause in every processor contract; organisational measures.
  • Map each measure to a system and a named owner. Sign the processor clauses before 13 May 2027.

Write the breach playbook with two clocks

Every breach is reportable; the Act sets no materiality threshold.

  • Section 2(u): accidental disclosure, alteration and loss of access count, so an exposed storage bucket is a breach. Section 8(6): intimate the Board and each affected user.
  • Rule 7(1): tell each affected user without delay through their account or registered channel. Rule 7(2): tell the Board without delay, then within seventy-two hours file the facts, causes, mitigation, findings, remedial steps and a report on the user intimations, unless the Board allows longer on a written request. CERT-In’s 6 hours run alongside.

Set retention and erasure in one schedule

Erase when the purpose ends; keep logs a year. Both apply.

  • Section 8(7): erase on withdrawal or once the purpose is reasonably assumed served, unless another law requires retention, and make processors erase. Rule 8(3): keep personal data, traffic data and logs one year from processing for Seventh Schedule purposes, even after the account is deleted.
  • Rule 8(1) and the Third Schedule: e-commerce with 2 crore or more registered users, gaming intermediaries with 50 lakh or more, social media with 2 crore or more erase three years from the later of the user’s last approach and “the commencement of” the Rules, with 48 hours’ notice (rule 8(2)). The Schedule does not say which commencement date counts; rule 8 itself starts 13 May 2027, so verify before scheduling deletions. Data kept so the user can reach the account, or a stored virtual token usable for money, goods or services, is carved out.

Gate children at eighteen and switch off tracking

A child is anyone under eighteen (section 2(f)).

  • Section 9(1): verifiable parental consent before processing a child’s data. Section 9(3): no tracking, behavioural monitoring or targeted advertising directed at children.
  • Rule 10: check the claimed parent is an identifiable adult using identity details already held, volunteered, or a Digital Locker virtual token. Rule 12 and the Fourth Schedule carve out health and education settings within limits, email account creation, real-time safety location and the age check itself.

Publish the contact, the rights route and the grievance period

The grievance desk becomes the Board’s front door.

  • Rule 9: publish prominently, and repeat in every rights response, the contact of the DPO or the person who answers data questions. Rule 14(1) and (3): publish how rights are exercised and a grievance response period of at most ninety days.
  • Sections 11 to 14: access, correction and erasure, grievance redressal, nomination; section 13(3) makes the user exhaust your route first. A DPO is required only of a notified Significant Data Fiduciary (section 10, rule 13); no notification was located as at 6 October 2026.

Settle where the data sits and what moves it

Transfers out are allowed until the Central Government says otherwise.

  • Section 16(1) lets the Central Government notify countries to which transfer is restricted; rule 15 makes transfers subject to any general or special order on making data available to a foreign State. No adequacy list, no standard clauses. No notification or order was located as at 6 October 2026.
  • Section 16(2) keeps stricter sectoral law: the RBI circular of 6 April 2018 (RBI/2017-18/153) requires payment system data stored only in India, the foreign leg also storable abroad. Intra-group paper is on intercompany agreements and transfer pricing.

What is at stake, as at 6 October 2026. Section 33 and the Schedule set maxima: up to Rs 250 crore for failing security safeguards (section 8(5)), Rs 200 crore for a breach not notified (section 8(6)) or for children’s-data duties (section 9), Rs 150 crore for Significant Data Fiduciary duties, Rs 50 crore otherwise; the Board weighs gravity, repetition, gain and mitigation. Section 37: on the Board’s written reference after penalties in two or more instances, the Central Government may, after a hearing, order public access to the service blocked in India. Appeals go to TDSAT within sixty days (section 29(2), rule 22). Upkeep after 13 May 2027 is the fractional general counsel retainer.

Frequently asked questions

What is the DPDP Act compliance deadline for startups?

13 May 2027 for every operating duty. G.S.R. 843(E)(c) brings sections 3 to 5, 6(1) to (8) and (10), 7 to 17, 27 (except 27(1)(d)), 28 to 34, 36, 37 and 44(2) of the Act into force eighteen months after 13 November 2025, and rule 1(4) brings rules 3, 5 to 16, 22 and 23 of the DPDP Rules 2025 in on the same day. 13 November 2026, when section 6(9) and rule 4 start and Consent Managers may apply to register, is a milestone for a startup, not a deadline.

Is there a startup exemption under the DPDP Act?

None located as at 6 October 2026. Section 17(3) lets the Central Government notify classes of Data Fiduciaries, including startups, to whom sections 5, 8(3), 8(7), 10 and 11 would not apply. The Act defines a startup as a private limited company, partnership firm or LLP incorporated in India and recognised as one under criteria the Central Government notifies; it names no department and sets no turnover test. Even a notification would leave consent, security safeguards and breach intimation in place. Plan for the full Act.

Does the DPDP Act apply to a Delaware or Dubai company with users in India?

Yes. Section 3(b) extends the Act to processing outside India connected with offering goods or services to Data Principals in India, so incorporating abroad does not take a company out. The mirror image is section 17(1)(d): a person in India processing foreign users' data under a contract with a person outside India is outside Chapters II and III and section 16, except sections 8(1) and 8(5).

What has to happen within 72 hours of a personal data breach under the DPDP Rules?

Rule 7(2): tell the Board without delay, then within seventy-two hours of becoming aware file the detailed facts, causes, mitigation, findings, remedial steps and a report on the user intimations, unless the Board allows longer on a written request. Rule 7(1) separately requires each affected user to be told without delay. Section 8(6) sets no materiality threshold, and the CERT-In directions of 28 April 2022 run their own 6-hour clock for Annexure I incidents.

Can I download this DPDP compliance checklist as a PDF?

Yes. Print the page, which is built for paper and carries the verification date, or email info@infinilex.io with the subject line PDF: DPDP startup compliance checklist for the current version and each update as the Act or the Rules move. Nothing here is gated.

The one principle under all twelve

Nothing here is new to anyone who has read the Act; what is new is a Board that can act on it from 13 May 2027. Consent you can prove, a notice that stands alone, a breach reported without delay and in detail inside seventy-two hours, erasure when the purpose ends, an age gate at eighteen. Build in this order and keep the file.

Next step

Want the open items marked for your product?

Send one paragraph: what the product collects, where the users sit, which entity contracts with them, whether anyone under eighteen uses it. We will say which of the twelve are open.

Thirty minutes with Prashant Sharma, the founder, who does the work himself. You leave with next steps either way. Email is read by the founder and answered within one working day.

The PDF

Want this as a PDF in your inbox?

Email us and we will send the current version, and the updated one each time the law moves. Or print the page: it is built for paper.

Email me the PDF

General information for founders and product teams, not legal advice for your business. No notification under sections 10, 16 or 17(3) or rule 15 is assumed; verify the Board’s appointments and portal before relying on either. Confirm every point against the current text.