On 14 May 2027, most of the enforceable provisions of India's Digital Personal Data Protection Act come into force. If you run a business that holds customer data, and every MSME with a website, a Udyam registration, a WhatsApp order book or an email newsletter does, you are a Data Fiduciary under this law. The Rules have been published. The commencement dates are fixed. What is genuinely unclear is how much of the enforcement architecture will actually be operational by then. This article sets out what the Act requires of an MSME, what a business owner or their compliance advisor can start on today, and where the practical uncertainty still sits, so the next nine months are spent on the parts that will actually matter.
Why now: three shifts in the last eighteen months
Three developments have moved this out of the "regulation to watch" category and into "regulation to plan against".
First, the Digital Personal Data Protection Rules, 2025 were notified in the Gazette on 14 November 2025 (PIB Release ID 2190014). The commencement is staggered. Rules 1, 2 and 17 to 21 are in force from 14 November 2025. Rule 4, which governs Consent Managers, comes into force on 14 November 2026. The rest, including Rule 3 (consent notice), Rules 5 to 16 (all substantive obligations on Data Fiduciaries) and Rules 22 and 23 (enforcement), come into force on 14 May 2027. Read the dates carefully: this is not one deadline. It is three, and only the third one is the one most compliance briefs are talking about.
Second, the Data Protection Board of India, the body constituted to receive complaints and register Consent Managers, is still being staffed. MeitY invited applications for Board Members in May 2026, publicly listed on the MeitY and Digital India Corporation websites. The Digital India Corporation was still recruiting technical staff for the Board's operational office as of late July 2026, per its public recruitment listings. No Chairperson or Members have been appointed by name in the public record. In practical terms the Board cannot register a Consent Manager today because Rule 4 has not commenced.
Third, and least discussed, the ecosystem gap is real. No technical standard, API specification or reference implementation has been published for how a Data Fiduciary connects to a Consent Manager. The Rules only cross-refer to Part A (eligibility) and Part B (obligations) of the First Schedule. The RBI-regulated Account Aggregator framework has not been adopted as the technical basis. Whether a separate standard will emerge under Rule 4(1) is left to the Board and is currently unpublished. No MSME-specific guidance from MeitY exists.
What the Act actually asks of a Data Fiduciary
Who is who under the Act
Data Principal
The individual whose personal data is collected.
Data Fiduciary
The MSME. Every business holding customer data, whatever its size.
Data Processor
Third-party SaaS acting on the MSME's instructions. The Fiduciary stays liable.
Consent Manager
Registered intermediary for consent. Registration opens 14 November 2026.
Six obligations sit at the heart of the framework and will drive most MSME work.
Rules 3 to 8 at a glance
Consent notice
Itemised notice before collection, in English and an Eighth Schedule language.
Consent Managers
Registered intermediary. In force 14 November 2026.
State processing
Subsidies, benefits, licences. Read with the Second Schedule.
Security safeguards
Encryption in transit and at rest, access controls, logging, monitoring.
Breach notification
Notify the Board and affected individuals. The prescribed time is short.
Retention
No retention beyond the purpose. Explicit outer limits for some categories.
Rule 3: Consent notice
Every collection of personal data must be preceded by an itemised notice: what data, for what purpose, for how long, and to whom it will be shared. The notice must be available in English and in any of the languages listed in the Eighth Schedule to the Constitution that the data principal chooses. A generic privacy policy at the footer of a website will not satisfy this.
Rule 4: Consent Managers
A Consent Manager is a registered third party that intermediates consent between the data principal and the Data Fiduciary. The registration window opens 14 November 2026. Which MSMEs must route through a Consent Manager and for which categories of data will depend on Board notifications. Even where the routing is optional, the interoperability, portability and secure-withdrawal expectations set the direction the ecosystem is heading in.
Rule 5: State processing
Processing personal data for a subsidy, benefit, service, certificate, licence or permit issued by the State or its instrumentalities is governed by Rule 5 read with the Second Schedule. Ministry-facing rather than MSME-facing, but worth reading if the MSME operates a benefit-linked platform.
Rule 6: Reasonable security safeguards
Encryption in transit and at rest, access controls, logging, and monitoring. The text is general. The enforcement will be specific.
Rule 7: Breach notification
A personal-data breach must be notified to the Board and to affected individuals in the manner and within the time prescribed. The time prescribed in the Rules is short. Build the breach workflow before you need it.
Rule 8: Retention
Personal data cannot be retained beyond the period necessary for the purpose. For certain categories the Rules set explicit outer limits. An MSME that has been keeping every past customer's address for a decade will need to change that.
Beyond these, Rules 10 and 11 govern the processing of children's personal data and data of persons with disabilities, both requiring verifiable consent. Rule 12 empowers the Central Government to designate Significant Data Fiduciaries with additional obligations. Most MSMEs will not cross that threshold, but a fast-growing fintech or e-commerce MSME might.
The penalty ceiling for a failure to observe reasonable security safeguards is Rs 250 crore, adjudicated by the Board. This is a ceiling, not a per-violation figure, and the Schedule contains other ceilings for other categories of breach. It is still meaningful for an MSME.
What an MSME can actually start on today
The following is a nine-month plan built around the fixed dates, not around the Board's readiness.
The nine months, in three phases
- Data-touchpoint mapping
- Consent notice drafted, English plus one language
- Point of contact named
- Rule 6 safeguards implemented
- Rule 7 breach workflow built
- Rule 8 retention limits automated
- Vendor DPDP addenda requested
- Consent-notice UX live
- Grievance officer named with an SLA
- Cross-border list honoured
- Breach tabletop run once
By November 2026: data mapping and consent design
Enumerate every touchpoint where personal data is collected. Website forms, mobile app, WhatsApp Business, POS terminal, CRM, email marketing list, delivery-partner integration, feedback surveys, warranty registration. For each, categorise the data by type (name, phone, email, address, PAN, GSTIN, health data if applicable), by purpose, by retention need, and by the third parties it flows to.
Where personal data enters and where it goes
- Website forms
- Mobile app
- WhatsApp Business
- POS terminal
- CRM
- Email marketing list
- Feedback surveys
- Warranty registration
Data Fiduciary
- Shopify
- Zoho
- Razorpay
- Tally
- WhatsApp Business API
- Google Workspace
- Marketplaces
- Delivery-partner integration
Draft a consent notice per Rule 3 in English and in at least one Eighth Schedule language that matches the customer base. Name a Data Fiduciary point of contact within the business. If the MSME is too small for a dedicated compliance role, this can be the owner or an external advisor, but it has to be named.
By March 2027: implementation
Implement Rule 6 safeguards: encryption in transit and at rest, access controls, audit logs. Build the Rule 7 breach workflow: who is notified, who notifies the Board, in what timeframe. Implement Rule 8 retention limits by adding auto-delete or auto-archive to the systems that hold personal data.
If the MSME processes children's data (education, coaching, gaming, health), implement verifiable parental consent under Rule 10 well ahead of May.
Read every vendor contract for a clause that describes the vendor as processing personal data on behalf of the MSME. Absent that, ask for a DPDP addendum. Vendors that stall on this are a red flag.
By 14 May 2027
Consent-notice UX live on all customer-facing surfaces. Grievance officer named with a response SLA. Cross-border transfer restrictions honoured for the list of countries MeitY notifies. Breach workflow tested at least once through a tabletop exercise.
A timeline the MSME can plan against
Three milestones
Rules 1, 2, 17 to 21 in force
What you can start todayGovernance familiarisation across owner and IT lead
Rule 4 in force; Consent Manager registration window opens with the Board
What you can start todayData-touchpoint audit; consent-notice drafting; vendor-contract review
Rules 3, 5 to 16, 22 and 23 in force; full-compliance clock starts
What you can start todayRule 6 safeguards; Rule 7 breach workflow; Rule 8 retention limits; grievance officer named
Common mistakes
Waiting for the Board to be operational before starting internal audits. The Rules commence on the notified dates regardless of whether adjudications have begun.
Treating DPDP as an IT problem. It is a business-process problem with an IT layer. If the marketing team keeps a WhatsApp broadcast list without a consent record, no amount of database encryption fixes that.
Copying a GDPR privacy notice from a template. DPDP has different consent, retention and cross-border rules. A GDPR-derived notice will fail on multiple counts, most obviously on the Eighth Schedule language requirement.
Assuming small size means exemption. There is no MSME turnover threshold in the Act. There is only a Significant Data Fiduciary layer that sits on top of the base obligations. Every MSME with personal data is in scope from day one.
Relying on an interpretation of the Rules from a vendor sales deck. Read the Gazette notification directly. It is not long and it is not difficult.
A note on working with third-party platforms
Most MSMEs today run on third-party SaaS: Shopify, Zoho, Razorpay, Tally, the WhatsApp Business API, Google Workspace, one or two e-commerce marketplaces. Under DPDP, those vendors are Data Processors. The MSME, as the Data Fiduciary, remains liable for the vendor's conduct with the data it has been entrusted with.
Practical implication: existing vendor contracts almost certainly do not carry the flow-down clauses DPDP will require. Ask each material vendor for a DPDP addendum by end of the calendar year. Where the vendor is a global provider with a standard Data Processing Addendum written to GDPR, it will read as broadly compatible but not identical. A short review by counsel is worth the cost.
Where a vendor cannot or will not sign, the MSME faces a choice between accepting the residual risk (and documenting the decision) and migrating to a compliant alternative. That decision is easier to make in Q4 2026 than in Q2 2027.
Conclusion
The DPDP Act is one of the few Indian regulations of the last decade where the commencement dates are truly fixed and the primary text is truly public. The uncertainty sits not in what the law says but in how the enforcement architecture is being built around it. An MSME that spends the next nine months mapping its own data touchpoints, tightening its vendor contracts, and drafting a defensible consent flow will be in a materially stronger position on 14 May 2027 than one waiting for a MeitY circular that names its industry. The law will not make an exception for size. Plan accordingly.
Need help getting your paper published?
PaperFoundry provides PhD-led research writing, editing, and journal submission support for Indian scholars.
Get Help With Your Paper