Practice · Service · India, EU and the UAE

DPDP compliance for startups, with the GDPR and UAE PDPL legs run as one programme.

The DPDP Rules 2025 bring the consent-manager rule into force on 13 November 2026 and every operating obligation on 13 May 2027. Infinilex builds the programme against those dates, with the GDPR and UAE PDPL legs alongside.

A DPDP compliance consultant in India builds the programme the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 require of a Data Fiduciary: the data map, the itemised consent notice, the security safeguards, the breach playbook, children’s consent, the rights process and the transfer position. Infinilex runs that programme for startups and SaaS exporters against the dates that matter, 13 November 2026 and 13 May 2027, and carries it into the GDPR and the UAE PDPL where your users sit there.

DPDP appears elsewhere on this site inside the fractional general counsel retainer scope; this page is the programme itself. Infinilex’s own privacy policy is a DPDP-era notice.

Three dates, three phases

The DPDP Rules 2025 were notified by MeitY as G.S.R. 846(E) on 13 November 2025 under section 40 of the DPDP Act 2023 (Act 22 of 2023); Rule 1 phases them in.

Schedule A: DPDP Rules 2025 commencement phases, as at 25 September 2026
DateRules in forceWhat it means for a startupProgramme work
13 November 2025Rules 1, 2 and 17 to 21: the Data Protection BoardThe Board is a digital office (Rule 20); no operating duty on a Data Fiduciary yetData map, applicability, gap assessment
13 November 2026Rule 4: Consent Manager registrationAn Indian company with net worth of at least Rs 2 crore may register as a Consent ManagerConsent architecture, notice, processor contracts
13 May 2027Rules 3, 5 to 16, 22 and 23: notice, safeguards, breach intimation, retention, children, Significant Data Fiduciary duties, rights, transfers, appealsEvery operating obligation appliesRollout, breach drill, retainer upkeep

Dates are computed from Rule 1. The Schedule to the Act caps penalties at Rs 250 crore for failing to take reasonable security safeguards (section 8(5)) and Rs 200 crore for failing to notify a breach (section 8(6)) or under the children’s-data duties (section 9): statutory ceilings.

What the DPDP compliance programme covers

  • The data map and the applicability call. Section 3(b) reaches processing outside India connected with offering goods or services to people in India. Section 17(1)(d) switches most of the Act off where data of people outside India is processed in India under a foreign contract, though sections 8(1) and 8(5) still apply. Section 17(3) lets the Central Government exempt notified classes, including startups.
  • The consent notice, rebuilt to Rule 3. Understandable on its own, in plain language, with an itemised description of the personal data and the purposes, and links to withdraw consent as easily as it was given, exercise rights and complain to the Board.
  • Security safeguards and processor contracts. Rule 6 sets the minimum: encryption, obfuscation, masking or virtual tokens; access controls; logs, monitoring and review; backups; one-year log retention; and contractual safeguards with every Data Processor, engaged only under a valid contract (section 8(2)).
  • The breach playbook. Rule 7 requires intimation of each affected Data Principal and of the Board without delay, with detailed facts, causes, mitigation and findings to the Board within seventy-two hours of becoming aware unless it allows longer.
  • Retention, erasure and children’s data. Section 8(7) requires erasure on withdrawal of consent or once the purpose is served, unless another law requires retention; the Third Schedule deems the purpose spent three years after last engagement for the largest e-commerce, social media and gaming intermediaries (Rule 8). A child is anyone under eighteen; Rule 10 requires verifiable parental consent.
  • Rights, grievance and Significant Data Fiduciary readiness. Rule 9 requires a published contact for data questions; Rule 14 a rights route answered within ninety days. A company notified under section 10 must appoint a Data Protection Officer based in India and an independent data auditor, and run an impact assessment and audit every twelve months (Rule 13).
  • The cross-border transfer position. Rule 15 allows transfer outside India subject to requirements the Central Government may specify, with no adequacy list and no standard-clause mechanism; section 16 lets it restrict transfers to notified countries.

DPDP, GDPR, UAE PDPL and the financial free zones compared

An Indian startup with users in the EU or the UAE meets three or four regimes at once. The GDPR column states the obligations generally; the specifics are confirmed with EU local counsel on your facts.

Schedule B: obligations compared across four regimes, as at 25 September 2026
ObligationDPDP (India)GDPR (EU)UAE PDPL (federal)DIFC and ADGM
Instrument and reachDPDP Act 2023 and Rules 2025 (section 3)The EU GDPR, where it applies to youFederal Decree-Law No. 45 of 2021, in force 2 January 2022; free zones with their own data law carved out (Art. 2)DIFC Law No. 5 of 2020 (Art. 6(3)); ADGM Data Protection Regulations 2021 (s.3(1))
Consent and noticeItemised stand-alone notice (Rule 3); verifiable parental consent under eighteen (Rule 10); Consent Managers from 13 November 2026Lawful basis and consent for the personal data you collectNo processing without the data owner’s consent, save stated exceptionsDIFC controllers register their processing with the Commissioner (Art. 14(7)); ADGM controllers notify the Commissioner and pay the Data Protection Fee before or as soon as practicable after processing starts (s.24)
Breach notificationUsers and the Board without delay; detail to the Board within 72 hours (Rule 7)A breach-notification process that exists before there is a breachTo the Data Office immediately on becoming aware, per the Executive Regulations (Art. 9)DIFC: as soon as practicable (Art. 41); ADGM: where feasible within 72 hours (s.32(1))
DPO and impact assessmentOnly for a notified Significant Data Fiduciary: DPO based in India, annual DPIA and audit (section 10, Rule 13)Confirmed with EU local counsel on your factsDPO for high-risk, sensitive or large-volume processing, inside or outside the UAE (Art. 10); DPIA for high-risk processing (Art. 21)DIFC: for High Risk Processing (Arts. 16, 20); ADGM: s.35(1) and s.34
Cross-border transferSubject to requirements the Central Government may specify (Rule 15); no adequacy list or standard clausesCross-border transfer of user data handled lawfully between your entitiesTo Data Office-approved countries (Art. 22) or under a binding contract (Art. 23)DIFC: adequacy (Art. 26) or standard clauses (Art. 27); ADGM: adequacy decisions (s.41(1))

Sources: u.ae and uaelegislation.gov.ae for the PDPL; the DIFC law and the ADGM Regulations. DIFC fines run per Schedule 2 item (USD 50,000 for no DPO) plus a general fine (Art. 62); ADGM fines are capped at USD 28 million (s.55(1)). Mainland and commercial free-zone companies, DMCC and IFZA under DIEZ included, sit under the PDPL.

How a DPDP compliance engagement is staged

Fixed-scope stages, mapped on a free discovery call. Stage one is the data map and gap assessment, which stands on its own. Stage two is the build: notice and consent flow, control list, processor contracts, breach playbook, retention schedule, rights process and transfer memo, with the GDPR and UAE legs in the same pass. Stage three is the rollout ahead of 13 May 2027, with the consent-manager decision taken before 13 November 2026; the retainer then keeps it current. The project or retainer choice is on how engagements work.

Who signs what on DPDP compliance work

No statute names a signatory for a consent notice, a processor contract, a breach playbook or an impact assessment, so this is drafting and programme work. Infinilex counsel qualified in India draft and run the DPDP leg; Infinilex counsel qualified in the UAE draft and run the PDPL, DIFC and ADGM legs. Acts a statute puts on the company stay there: the Data Fiduciary publishes the notice, intimates the Board (Rule 7) and appoints its Data Protection Officer and independent data auditor once notified (section 10). For the GDPR leg Infinilex scopes the work, builds the fact record and briefs the EU local counsel who advise on it; they are brought into the engagement explicitly and named to you before they act.

Frequently asked questions

Does GDPR compliance for an Indian SaaS company already satisfy the DPDP Act?

Not on its own. A GDPR programme gives you lawful basis and consent, a breach-notification process and a lawful transfer position, all reused. The DPDP Act and Rules 2025 add India-specific items: an itemised consent notice that stands on its own (Rule 3), verifiable parental consent under eighteen (Rule 10), detailed breach information to the Data Protection Board within seventy-two hours (Rule 7), a Data Protection Officer based in India for a notified Significant Data Fiduciary, registered Consent Managers, and a transfer rule with no adequacy list or standard clauses.

What must a startup do before 13 May 2027 under the DPDP Rules?

Rules 3, 5 to 16, 22 and 23 come into force on 13 May 2027, eighteen months after publication on 13 November 2025. By then a Data Fiduciary needs a plain-language consent notice with an itemised description of the data and purposes, the Rule 6 safeguards (encryption or masking, access controls, one-year logs, backups, processor contracts), a breach playbook that reaches users and the Board without delay, a published contact for data questions, a rights process answered within ninety days, and an erasure routine. The consent-manager rule starts on 13 November 2026.

Does the DPDP Act apply to an Indian SaaS company whose users are all outside India?

Only in part. Section 17(1)(d) switches off most of Chapters II and III and section 16 where personal data of people not in India is processed in India under a contract with a person outside India, the standard offshore SaaS arrangement. Sections 8(1) and 8(5), responsibility for compliance and reasonable security safeguards, still apply. Once the product is offered to users in India, the section 17(1)(d) carve-out no longer covers that data and the full Act applies under section 3, while the laws where your foreign users sit govern theirs.

Who can help with DPDP compliance before May 2027, and who has to sign?

No statute names a signatory for a consent notice, a processor contract, a breach playbook or an impact assessment, so a consultancy can run the programme. Infinilex does that with its counsel qualified in India, and its counsel qualified in the UAE for the PDPL, DIFC and ADGM legs. Acts a statute puts on the company stay there: the Data Fiduciary publishes the notice, intimates the Board and appoints its Data Protection Officer once notified. For the GDPR leg Infinilex scopes the work and briefs EU local counsel, named to you before they act.

Next step

Tell us what the product collects and where the users sit.

Send the one-paragraph version: the data you hold, where your users are, which entity contracts with them, and whether anyone under eighteen uses the product. We will tell you which regimes reach you and what the gap list looks like.

Further reading

The Web3 legal-readiness checklist · The FY 2026-27 India compliance calendar · DMCC vs ADGM vs IFZA from India · Founder FAQ

Related services: Fractional general counsel retainer · Contracts and IP · India subsidiary setup · How engagements work

Infinilex is a consultancy. This page is general information about the service, not legal advice for your specific business, and no outcome is guaranteed. DPDP, PDPL, DIFC and ADGM provisions, dates and penalty ceilings are stated as at 25 September 2026 from the texts cited above; the GDPR only at the level of this site’s live checklist; no notification under sections 10, 16 or 17(3) is assumed. Scope and the professionals involved are confirmed on the discovery call.