The Digital Personal Data Protection Act, 2023 received presidential assent in August 2023, but sat largely dormant until the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. That notification set a phased rollout: the Data Protection Board of India became operational immediately, the Consent Manager registration framework opens on 13 November 2026, and every data fiduciary, including early-stage startups, must be fully compliant by 13 May 2027. For founders who have treated privacy as a “later” problem, later now has a date on the calendar.
Unlike sector-specific rules founders may already know, such as the RBI’s KYC norms, the DPDP Act applies horizontally to any entity that determines the purpose and means of processing digital personal data of individuals in India, with no exemption keyed to revenue, funding stage or headcount. A two-person SaaS startup collecting email addresses through a signup form is a “data fiduciary” in the same way a bank is. That breadth is why compliance with the DPDP Act becomes pertinent not only for large enterprises but also early stage startups.
The compliance with the DPDP Act should not only be on paper but should organically be built in to your product, processes and workflow. In this checklist, we will focus on the practical aspects of complying with the DPDP Act:
The Data Protection Board is already operational and can act on complaints today, even though the full compliance deadline is 13 May 2027, and the Consent Manager framework, described in this Hogan Lovells briefing, opens for registration in November 2026. Startups raising funding in this window should expect data protection questions in investor due diligence well before the deadline. Getting consent, notice and vendor-contract basics right now is materially cheaper than a retrofit under regulatory or investor pressure later.
The DPDP Act rewards startups that build privacy into their product from the outset rather than bolting it on later. None of the steps above require an enterprise compliance budget. They require a founder or in-house counsel willing to sit down with the text of the Act and the Rules and match it against how the product actually collects and uses data. Done early, that exercise is among the cheapest insurance a startup will buy this year.