As at 29 September 2026, India's DPDP framework has a phased commencement. The core business obligations are scheduled for the later, eighteen-month phase following the November 2025 notification, broadly May 2027. Startups should use the preparation period to understand their data and build workable processes, while continuing to assess obligations already applicable under other laws and contracts.
A copied privacy policy will not tell you which vendor holds customer data, who can export it or how the business would respond to a deletion request.
Separate what has commenced from what comes later
The commencement notification brings specified institutional and other provisions into force first. A one-year phase, broadly November 2026, covers specified Consent Manager-related provisions; most core processing duties and individual rights follow in the eighteen-month phase. The Rules have a corresponding staged structure. [Sources 1 and 2]
Read these as phased provisions, not as a claim that the whole Act is either fully operational or irrelevant. This article is a preparation guide dated September 2026. Recheck the notification and any subsequent changes before using it as a current deadline guide.
The Act's omission of section 43A of the Information Technology Act is also placed in the later phase. The transition is therefore not a general pause on existing privacy and security responsibilities. [Source 1]
Map data before rewriting the notice
List the personal data the startup handles and the purpose for each use. Include website enquiries, trial accounts, paying users, applicants, employees, customer support and marketing tools. B2B businesses can still handle identifiable individuals' information.
For each activity, record where data comes from, where it is stored, who can access it, which vendors receive it and what determines retention. Include spreadsheets, shared inboxes and personal devices used for work, not just the production database.
For example, a startup may say it collects only names and email addresses while its support workflow also receives identity documents and screenshots containing customer information. A useful notice and security plan must reflect the workflow that actually exists.
Identify your role and the basis for processing
The DPDP Act distinguishes the party determining processing purposes and means from a processor acting on its behalf. Its processing framework includes consent and specified legitimate uses; those legitimate uses are not a general permission to process anything useful to the business. [Source 3]
Map roles by activity. A SaaS provider may process customer-uploaded data on instructions while deciding independently how it uses its own sales contacts. Avoid assigning one label to the entire company without examining the activity.
Where consent is relevant, design a process that can record the choice and handle withdrawal. Where another permitted basis is proposed, document the actual provision and facts supporting it. An existing GDPR document should be reviewed for Indian requirements rather than renamed.
Make notices match product behaviour
The notified notice rule calls for clear, understandable information about the personal data and purposes, with routes for withdrawal and rights-related action. It belongs to the later commencement phase. [Source 2]
As a preparation step, review each collection point. Can a user understand why an optional phone number is requested? Does the marketing choice match what the CRM will do? Can the support team act on the promises the notice makes?
Use plain wording, but do not omit a material use simply to keep the page short. Test the customer journey after the legal copy changes, including links, settings and contact channels.
Prepare vendors and incident handling
Identify the contracts and operational contacts for hosting, analytics, CRM, communications and outsourced support. Discuss permitted processing, security, subcontractors, incident assistance and return or deletion at the end of service.
The notified Rules address security safeguards and breach communications. Their future reporting sequence includes an initial notification without delay and subsequent detailed information to the Board within 72 hours, subject to the rule's extension mechanism. Do not describe that as permission to wait 72 hours before doing anything. [Source 2]
Run a practical exercise now: if an employee exports customer data to the wrong recipient, who investigates, who preserves evidence and who assesses the notifications already required under applicable law or contract? Keep that operational plan separate from an unsupported claim of full DPDP compliance.
Build a process that a small team can maintain
Assign an internal owner, an enquiry route and a register of requests and decisions. Set review points for new vendors, product features and changes in retention. Do not collect identity documents for every request without considering necessity and risk.
Assess higher-risk features early, including children's data. The Act does not make every startup a Significant Data Fiduciary or require every startup to appoint a statutory DPO. Equally, potential startup exemptions are not a blanket automatic exemption from the framework. [Source 3]
Frequently asked questions
Does every DPDP obligation apply today?
No. As at this article's research date, commencement is phased. Read the relevant provision and its commencement together.
Is a privacy policy enough?
No. The business also needs its collection, access, vendor, retention and response processes to match its actual responsibilities and promises.
Should a small startup wait until the main phase begins?
Preparation now can reveal product and vendor changes that take time. Prioritise a data map and actual workflows before buying a large compliance package.
Corpernicus can assist with privacy documentation and data-protection preparation. Book an introductory call to discuss the product and a proportionate scope of work.
Sources checked 29 September 2026
- Source 1: DPDP Act commencement notification GSR 843(E), November 2025.
- Source 2: DPDP Rules 2025 GSR 846(E), particularly rules 1, 3, 6 and 7, read with the December 2025 corrigendum GSR 892(E).
- Source 3: DPDP Act 2023, particularly sections 2, 4, 7, 9, 10 and 17.
General information about the September 2026 position. Sectoral, IT, employment, consumer and contractual requirements may apply separately.