# The DPDP clock is running. What Indian startups should test now

Canonical page: https://dxcl.tech/infomedia/dpdp-rules-the-clock-is-running/
Published: 2026-10-05 by DrishtiX Cyber Labs (DXCL). Topic: Compliance.

India's data protection rules give most companies until May 2027. The penalties reach INR 250 crore. Here is what the law asks for, and what to test before the deadline.

For years, data protection in India was something big companies worried about. That changed with the Digital Personal Data Protection Act, 2023, and the rules that put it into practice.

If you collect personal data from Indian users, and almost every startup does, this applies to you. The good news is that there is still time. The bad news is that it is less time than it feels like.

## The dates that matter

The government notified the DPDP Rules on 13 November 2025. Most of the operational duties, including security safeguards and breach reporting, come into force 18 months after that: 13 May 2027.[^1]

In January 2026 the ministry asked industry for views on cutting that window to 12 months, which would have pulled the date forward to November 2026.[^2] As we write, no such change has been notified and May 2027 still stands. Check the latest notification before you lock your roadmap.

Eighteen months sounds like a lot. It is about six release cycles for a fast team, with a fundraise or two in between.

## What the law asks for

Three duties matter most for a product team.

1. **Reasonable security safeguards.** You must take reasonable steps to protect the personal data you hold. Failing to do so, where it leads to a breach, can draw a penalty of up to INR 250 crore, the highest in the Act.[^3]
2. **Breach notification.** If personal data is breached, you must tell the Data Protection Board and the affected people. Under the Rules, a detailed report to the Board is due within 72 hours of becoming aware of the breach.[^1] Failing to notify can draw a penalty of up to INR 200 crore.[^3]
3. **Logs you can rely on.** The Rules ask for logs and monitoring that let you detect and investigate unauthorised access, kept for at least a year.[^1]

This sits on top of CERT-In's 2022 directions, which already require listed cyber incidents to be reported to CERT-In within 6 hours of noticing them.[^4]

## Why this is not paperwork

It is tempting to treat all of this as a policy document and a checkbox. The numbers say otherwise.

CERT-In handled more than 29.44 lakh cyber incidents in 2025.[^5] IBM's 2026 study put the average cost of a data breach in India at a record INR 25.5 crore, before any penalty.[^6]

"Reasonable security safeguards" will be judged after something goes wrong. The question will be simple: did you look for the holes, and did you fix them?

## What to test before May 2027

You do not need to do everything at once. Start where personal data actually lives.

- **Map it.** Know which apps, APIs, databases and third parties hold personal data. You cannot protect what you have not listed.
- **Test the paths to it.** Run a penetration test on the web and mobile apps and APIs that touch personal data. Look hardest at access control: can one user see another user's data?
- **Test your AI features.** If an assistant or agent can read customer data, test whether it can be talked into revealing it.
- **Check your logging.** Confirm that access to personal data is logged, that the logs are kept, and that someone would notice an unusual pattern.
- **Rehearse the 72 hours.** Walk through who decides, who writes the report and who tells customers. Do it before you need it.
- **Retest after big changes.** A test from last year says little about the product you ship this quarter.

## Where we fit

We are not lawyers, and a security test is not a legal opinion. Talk to your counsel about what the Act means for your business.

What we do is the testing that "reasonable security safeguards" depends on. Our VAPT and AI security engagements find the paths to your users' data, explain them in language your engineers can act on, check that the fixes hold, and leave you with a dated, verifiable record of the work. On request, we map findings to the safeguards your lawyers and auditors ask about.

The deadline is fixed. How ready you are when it arrives is not.

## Sources

1. EY India, [DPDP Act 2023 and DPDP Rules 2025: point of view](https://www.ey.com/content/dam/ey-unified-site/ey-com/en-in/pdf/2025/11/ey-india-dpdp-act-2023-and-rules-2025-pov.pdf) (November 2025), summarising Rules 1, 6 and 7.
2. Storyboard18, [MeitY seeks industry views on fast-tracking DPDP Act rollout, proposes 12-month compliance timeline](https://www.storyboard18.com/digital/meity-seeks-industry-views-on-fast-tracking-dpdp-act-rollout-proposes-12-month-compliance-timeline-88332.htm) (January 2026).
3. Press Information Bureau, Government of India, [explainer on the DPDP Act and Rules](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) (17 November 2025).
4. CERT-In, [Directions under section 70B(6) of the IT Act](https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf) (28 April 2022).
5. Press Information Bureau, Government of India, [CERT-In achievements in 2025](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jan/doc2026123764501.pdf) (January 2026).
6. IBM, [Cost of a Data Breach 2026: India](https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026).
