What should my business do about the DPDPA?
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are now in force in phases, and the compliance clock is running. This page is a working resource for business leaders. Start with the decision you are actually trying to make, not with three hundred pages of statute.

Where Things Stand
The DPDP Rules, 2025 have been notified, and core obligations under the DPDPA framework will become fully binding in May 2027, following a phased commencement over roughly eighteen months. That runway is short for the amount of work most businesses have to do.
Most of the real work mapping your data, fixing notices and consent, sorting vendor contracts, tightening security, setting up breach response takes several quarters. Businesses that start now arrive at enforcement with defensible systems. The ones that wait until 2027 end up rebuilding under live scrutiny.
13 Nov 2025 · RULES NOTIFIED
Foundational provisions under the DPDP Rules take effect and the framework for the Data Protection Board and Consent Managers is established.
Around 13 Nov 2026 · CONSENT MANAGERS & FURTHER OBLIGATIONS
Consent Manager registration and related obligations begin, and more operational provisions come into force.
13 May 2027 · FULL COMPLIANCE WINDOW
The main obligations on consent, notice, security safeguards, breach response, and data-principal rights become binding for covered Data Fiduciaries.tcsa+1
You are here: mid-2026. This is build time.
Decision Finder
Start with your business question.
Pick the decision you are trying to make. Each answer is a plain starting point from our team. Where your situation needs proper advice, it says so.
Marketing
1. Can I use customer WhatsApp numbers for promotions?
Sometimes. It depends on why you collected the numbers and what people agreed to at the time. A number someone gave you to confirm a delivery was not necessarily given to you for marketing, and using it that way may not match the original basis. Check what your records actually say before you run anything.
Next step: Check your consent records before you send a campaign.
2. Can I send marketing emails under the DPDPA?
Often you can, provided you have a defensible basis for each list and a working way for people to opt out. The trouble tends to start with vague consent and unsubscribe links that do not do anything in practice.
Next step: Confirm your basis for each list and test that unsubscribe works.
3. Can I buy customer databases?
In most cases, buying customer databases is high-risk and difficult to defend from a consent standpoint. Bought lists almost never carry consent that clearly transfers to you, and if the data was collected improperly, the exposure becomes yours when you start using it.
Next step: Build your own opted-in list instead of buying one.
4. Can I use website cookies and analytics?
It depends on what the cookies collect and what you tell visitors. Basic traffic analytics sits at the lower end of the risk. Tracking that ties back to identifiable people, or that builds profiles across services, sits higher and needs clearer notice and basis.
Next step: Read your own cookie notice against what your tools actually collect.
5. Can I collect leads from LinkedIn?
Public does not mean fair game. A profile being visible is not the same as that person agreeing to sit in your outreach list. Scraping and cold messaging carry more risk than most people assume, especially when they involve large volumes of personal data.
Next step: Confirm your lawful basis for processing before you build the list.
Human Resources
1. Can employees ask us to delete their records?
Some of it, yes. Some of it, no. Payroll and statutory records often have to be kept for a set period under other laws. Other data may be deletable on request if you no longer have a good reason to keep it. The answer depends on the record, not only on who is asking.
Next step: Sort your employee records into what you must keep and what you can remove.
2. Can we monitor company email?
Often you can, if you have a clear policy, you have told staff in advance, and the monitoring is proportionate to a real purpose such as security or compliance. Quiet or blanket monitoring is where firms tend to get into trouble.
Next step: Put a written monitoring policy and a staff notice in place first.
3. Can we hold on to resumes?
Keeping every CV forever is hard to defend. Recruitment records should run to a stated retention period you can point to, and you should clear out what you no longer need.
Next step: Set a retention period for recruitment records and hold to it.
4. Can we use biometric attendance?
Biometric data is more sensitive than a swipe card, and it should be treated that way. You need a genuine reason for using it, stronger security around it, and usually an alternative for staff who object or cannot use the system.
Next step: Test whether you truly need biometrics, and what protects them, before rolling it out.
AI & Technology
1. Can I upload contracts to AI tools like ChatGPT?
You should be cautious. Contracts carrying personal or commercially sensitive detail should not go into consumer AI tools without safeguards, because you often cannot control where that data sits, how it is used, or who can access derivative outputs.
Next step: Agree an internal AI usage policy before anyone uploads client material.
2. Can employees use AI tools at work?
Yes, within some rules. The tool is rarely the problem on its own. The real risk is staff pasting client data or confidential documents into it without thinking through where that information goes.
Next step: Publish an AI usage policy and a list of approved tools.
3. Can AI process customer information?
It can, where you have a lawful basis and appropriate protections around it. The details that matter are the vendor’s terms, where the data sits, how it is secured, and who can see it, including any human review of outputs.
Next step: Read the tool’s terms and confirm your basis before feeding it customer data.
4. Can Copilot-style assistants access confidential documents?
An assistant can see whatever it has permission to see. If your file permissions are loose, sensitive material can surface in places it should not. Turning on document-aware AI without cleaning up access can expose more than you realise.
Next step: Tighten document access before switching on document-aware AI.
Vendors & Contracts
1. Do I need Data Processing Agreements? · FOUNDATIONAL
In most cases, yes, wherever a vendor handles personal data for you. A data processing agreement is one of the first things to get in place, because a good deal of your other protection depends on it.
Next step: Put data processing agreements in place with the vendors that need them.
2. What happens if my vendor suffers a data breach?
Their failure can still be your problem. As the business that chose to use them, you may remain accountable for the personal data in question. Your contract terms and your due diligence are what stand between you and that exposure.
Next step: Keep vendor due diligence current and have a breach response plan ready.
3. Can vendors transfer customer data overseas?
Moving data out of the country is not automatically unlawful, but it needs looking at first, not after. The contract terms, the regulatory position on cross-border transfers, and the security around the transfer all matter.
Next step: Review the transfer terms and applicable rules before any data leaves India.
4. Who is responsible for a vendor’s mistakes?
Often, you are. That is exactly why the contract and the processing agreement carry so much weight. Outsourcing the work does not outsource the responsibility with it; you may still remain the Data Fiduciary for the data.
Next step: Set out liability and obligations clearly in every vendor contract.
By Sector
Same law, different data, different fixes.
What you hold, and the risk attached to it, depends on what you do. Sector guides are being added. Start where your business sits.
- Healthcare & Diagnostics
Patient records, reports over WhatsApp, telemedicine, insurance coordination. - SaaS & Technology
User accounts, analytics, APIs, AI platforms, cross-border data. - Education
Admissions, student and parent data, LMS platforms, alumni engagement. - E-Commerce & D2C
Customer accounts, payments, marketing pixels, loyalty programmes. - HR & Corporate
Recruitment, payroll, employee records, attendance systems. - Fintech & NBFC
KYC, PAN and Aadhaar, credit profiling, partner and agent access.
Compliance Roadmap
Eight steps, in order.
A practical sequence most businesses can work through from the top.
- Identify every type of personal data your business collects.
- Map where the data is stored and who can reach it.
- Review your privacy notice and how you take consent.
- Assess the third-party vendors handling personal data.
- Strengthen your technical and organisational safeguards.
- Train staff on handling data responsibly.
- Write a breach response plan before you need one.
- Review the whole programme regularly and improve it.
Why Upscale Legal
Practical guidance for business decisions.
A lot of legal advice tells you what the law says and stops there. That part is important, but the harder and more useful question is what your particular business should do about it, and that is the part we work on with you. Our team focuses on turning statutory obligations into concrete steps, with commercial sense attached, so you leave with something you can put into practice.
Common Questions
1. Does the DPDPA apply to startups and small businesses?
If your business handles digital personal data, the Act can apply whatever your size. What you actually have to do depends on your activities and on any government notifications that apply to you, including exemptions or special treatment for certain categories of Data Fiduciaries.
2. When is the DPDP compliance deadline?
The DPDP Rules were notified in November 2025 and commence in phases. Current guidance reflects an eighteen-month runway to full obligations, with core substantive duties on consent, notice, security safeguards, breach response, and data-principal rights becoming fully binding around 13 May 2027.
3. Do we need a Data Protection Officer?
That depends on your business, the kind of processing you do, and whether the additional obligations for larger or Significant Data Fiduciaries apply to you. If you hold large volumes of sensitive data or perform high-risk processing, this is something that needs a specific assessment rather than a generic answer.
4. What are the penalties under the DPDPA?
Penalties are imposed by the Data Protection Board under the DPDP framework and can reach ₹250 crore per violation for a failure to take reasonable security safeguards, with lower but still significant caps for other kinds of failures. They are assessed per violation, so a single incident can add up
Speak With Us
No two businesses hold data the same way.
Whether you are putting a privacy programme together, checking your contracts, or bringing in AI tools, a conversation can help you prioritise work and take a fair amount of avoidable risk off the table before it becomes a problem.
This is an enquiry, not a request for advice on specific facts. Getting in touch does not create a lawyer–client relationship.
Disclaimer: Everything here is general information about the DPDPA, not legal advice. What you have to do depends on your own facts. For guidance on your situation, talk to a lawyer.












