DPDP Act: what to actually do in 2026

By S. Sridhar Thewar · 7 min read · Published August 2026
Short version: the rules are final, 2026 is the build year, and 13 May 2027 is when it stops being advisory. Surveys suggest more than 80% of Indian organisations have not started. Most of the work is infrastructure, not paperwork.

Compliance deadlines have a way of feeling distant right up until they are not, and DPDP is following the usual script.

India’s Digital Personal Data Protection Act, with rules finalised in November 2025, is the country’s first comprehensive framework for how digital personal data is collected, processed, stored and moved. The published timeline treats 2026 as a build-and-test year, with full accountability arriving in 2027. 13 May 2027 is the date most commentary converges on for hard enforcement.

The penalties are not symbolic. Serious violations can reach ₹250 crore per instance, and they stack per obligation category rather than per incident - so one badly handled breach that touches several obligations at once compounds rather than caps.

Almost nobody has started

An EY survey found close to 70% of professionals were not very familiar with the Act and Rules, more than 81% had not drafted or updated a DPDP-aligned privacy policy, and over 83% had not begun implementation in any comprehensive sense.

That matches what we see. When we scope network work for an Indian business and ask where personal data lives, the honest answer is usually a shrug and a guess. Not negligence - nobody ever had to know before.

The part that is engineering, not legal

DPDP gets discussed as a legal exercise, which is how it ends up as a policy document nobody implements. A large share of it is infrastructure work, and infrastructure work has lead times.

Know where the data is

Every other obligation depends on this one. Consent, retention limits, breach notification, deletion on request - none are possible if you cannot say which systems hold personal data. This is a discovery exercise across file servers, databases, backups, that one spreadsheet on a shared drive, and the SaaS tools bought without IT.

Segment it once you find it

If your network is flat, personal data is reachable from every compromised laptop in the building. Segmentation is the difference between an incident that touches one workstation and one you have to report. This is the single largest risk reducer on the list, and it takes weeks, not days.

Control and review access

Who can reach the systems holding personal data, and when was that last checked? Access lists accumulate. People change roles, contractors finish, nobody removes anything. A quarterly review is unglamorous and effective.

Keep logs you can actually use

Breach notification requires knowing what happened and what was touched. That requires logs that exist, are retained long enough, and are searchable. Logs that roll over after seven days will not answer a regulator’s question. Centralised log collection with defined retention is the fix, and it is worth doing before you need it rather than during.

Decide retention and enforce deletion

“We keep everything forever” stops being a storage decision and becomes a liability one. Every record retained past its purpose is exposure carrying no business value.

A realistic sequence for the time remaining

What we would not do

We would not buy a “DPDP compliance platform” as step one. Tooling applied to an environment nobody has mapped produces a dashboard, not compliance. Map first, fix the infrastructure, then decide whether tooling adds anything.

We would also not treat this as purely a legal engagement. A privacy policy written without knowing what the network actually does is a document that describes a company you do not run.

The businesses that will find May 2027 uneventful are the ones doing discovery and segmentation now, in 2026, while it is still optional.

Most of DPDP readiness is infrastructure work

Segmentation, access control, logging and retention are engineering problems before they are legal ones. That part we can help with.

Talk to an engineer