When does the DPDP Act apply to businesses?
The DPDP Rules were notified on 13 November 2025 with a phased start. The Data Protection Board works from notification, consent managers can register from 13 November 2026, and the duties most businesses must meet (notice, consent, security safeguards, breach reporting, rights and grievances) apply from 13 May 2027.
Does DPDP apply to a small business?
Yes, if it holds personal data in digital form, and almost every business does: customer records, website enquiries and staff payroll all count. There is no size threshold for the core duties. Extra duties apply only to organisations the government notifies as Significant Data Fiduciaries.
What are the penalties under the DPDP Act?
The Schedule to the Act sets ceilings: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach or for breaching the obligations on children's data, and up to ₹50 crore for breach of any other provision.
How fast must a personal data breach be reported?
Under Rule 7, the affected people and the Data Protection Board are to be told without delay, and the Board is to get a detailed report within 72 hours of the organisation becoming aware of the breach.
Do we need consent for employee data?
Not always. Section 7 lists legitimate uses that need no consent, including processing for employment purposes and to meet a legal obligation. Consent is needed where none of those applies, for example most marketing.
Is this check legal advice?
No. It is guidance based on the Act, the Rules and your own answers, which it cannot verify. Every item names the section it comes from, so a lawyer can check it against the text.