Compliance deadlines have a way of feeling distant right up until they are not, and DPDP is following the usual script.
India’s Digital Personal Data Protection Act, with rules finalised in November 2025, is the country’s first comprehensive framework for how digital personal data is collected, processed, stored and moved. The published timeline treats 2026 as a build-and-test year, with full accountability arriving in 2027. 13 May 2027 is the date most commentary converges on for hard enforcement.
The penalties are not symbolic. Serious violations can reach ₹250 crore per instance, and they stack per obligation category rather than per incident - so one badly handled breach that touches several obligations at once compounds rather than caps.
Almost nobody has started
An EY survey found close to 70% of professionals were not very familiar with the Act and Rules, more than 81% had not drafted or updated a DPDP-aligned privacy policy, and over 83% had not begun implementation in any comprehensive sense.
That matches what we see. When we scope network work for an Indian business and ask where personal data lives, the honest answer is usually a shrug and a guess. Not negligence - nobody ever had to know before.
The part that is engineering, not legal
DPDP gets discussed as a legal exercise, which is how it ends up as a policy document nobody implements. A large share of it is infrastructure work, and infrastructure work has lead times.
Know where the data is
Every other obligation depends on this one. Consent, retention limits, breach notification, deletion on request - none are possible if you cannot say which systems hold personal data. This is a discovery exercise across file servers, databases, backups, that one spreadsheet on a shared drive, and the SaaS tools bought without IT.
Segment it once you find it
If your network is flat, personal data is reachable from every compromised laptop in the building. Segmentation is the difference between an incident that touches one workstation and one you have to report. This is the single largest risk reducer on the list, and it takes weeks, not days.
Control and review access
Who can reach the systems holding personal data, and when was that last checked? Access lists accumulate. People change roles, contractors finish, nobody removes anything. A quarterly review is unglamorous and effective.
Keep logs you can actually use
Breach notification requires knowing what happened and what was touched. That requires logs that exist, are retained long enough, and are searchable. Logs that roll over after seven days will not answer a regulator’s question. Centralised log collection with defined retention is the fix, and it is worth doing before you need it rather than during.
Decide retention and enforce deletion
“We keep everything forever” stops being a storage decision and becomes a liability one. Every record retained past its purpose is exposure carrying no business value.
A realistic sequence for the time remaining
- Now to end of 2026: discovery. Find the data. Write down what you hold, where, why, and for how long. Nothing else can be planned until this exists.
- Late 2026 to early 2027: the infrastructure work - segmentation, access review, logging and retention. This is the long pole; it needs maintenance windows and budget.
- Early 2027: policy, consent flows, notices, breach procedure. Faster to produce once the technical picture is known, and it will be accurate rather than aspirational.
- Before 13 May 2027: test it. Run a tabletop. Can you actually answer what was accessed, by whom, within the notification window?
What we would not do
We would not buy a “DPDP compliance platform” as step one. Tooling applied to an environment nobody has mapped produces a dashboard, not compliance. Map first, fix the infrastructure, then decide whether tooling adds anything.
We would also not treat this as purely a legal engagement. A privacy policy written without knowing what the network actually does is a document that describes a company you do not run.
The businesses that will find May 2027 uneventful are the ones doing discovery and segmentation now, in 2026, while it is still optional.