The DPDP Act Isn't One 2027 Deadline, It's Three

DPDP is usually called a "2027 law." It actually commences in three phases, and the second one, the Consent Manager framework, lands 13 November 2026, less than two months from now.

The DPDP Act Isn't One 2027 Deadline, It's Three

MeitY notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025, and with them, a staggered commencement schedule most compliance content flattens into a single "2027" date. It isn't one date. It's three: 14 November 2025, when the Data Protection Board of India itself came into existence; 13 November 2026, when the Consent Manager registration framework activates; and 14 May 2027, when the remaining substantive obligations, and the penalty provisions, actually come into force. The middle date is the one most businesses haven't clocked, and it's less than two months out.

DPDP Act's real 3-phase timeline and full 4-tier penalty schedule, from Rs 50 crore to Rs 250 crore

The DPDP Act's core mechanism is narrower than Europe's GDPR, which most Indian compliance advice gets modeled on. GDPR lets companies process personal data under several lawful bases, and "legitimate interest" is the one most businesses lean on for everyday things like analytics, fraud checks, and B2B marketing, without asking permission first. DPDP has no equivalent. Its "legitimate uses" carve-out is a closed list, state functions, legal compliance, medical emergencies, employment, and public health, not a general business-interest basis. Outside that list, every use of personal data needs consent, collected for one specific, stated purpose. A newsletter sign-up authorises a newsletter. It doesn't authorise a product email, a discount offer, or a retargeting campaign, each of those needs its own separate, specific permission, collected through a box that isn't pre-checked.

That single design choice forces the second big change: every tracking tag on a website, Google Analytics, Meta Pixel, Google Ads, Microsoft Clarity, Hotjar, has to stay unfired until the visitor actively consents. A GDPR-style banner with granular toggles becomes standard, and "reject" has to be exactly as easy to click as "accept."

What that does to a site's own analytics

That last requirement is where the real cost shows up. Published rejection-rate data from consent-platform studies (Usercentrics, OneTrust) puts the cross-geography average cookie-rejection rate at around 42%, rising to 50-55% in Germany, Austria, and Switzerland. The gap between a compliant and a manipulative banner is large: "Reject all" on the same first screen as "Accept" runs roughly 60% rejection; buried behind a "Manage preferences" click, acceptance climbs to around 90%. DPDP's equal-prominence rule rules out the second design, and mobile visitors, most of India's traffic, reject at a further 10-15% higher rate than desktop. A meaningful share of GA4 sessions, plausibly 40-50% on some sites, will stop reporting once the banner goes live, with no change in actual traffic or revenue.

Google's answer is Consent Mode v2, which estimates the lost data rather than restoring it. In basic mode, a rejected tag simply doesn't fire. In advanced mode, it still loads but sends a cookieless signal for statistical modeling instead of a real user record, and that modeling only kicks in past specific volume thresholds: GA4 needs at least 1,000 daily events with consent denied for seven straight days, plus 1,000 daily users with consent granted for seven of the last 28. Google Ads conversion modeling has a separate, lower bar, around 700 ad clicks in seven days per country. A high-traffic e-commerce site clears both easily. A clinic's booking page or a local service business generally never will, so their rejected-consent data never gets modeled back. It's just gone, permanently.

The "₹2 crore" claim, and what it's actually about

A specific number has been circulating as a loophole: that DPDP only applies to companies with a net worth above ₹2 crore. I traced that figure back to its actual source, and it isn't an applicability threshold at all. Under Part A of the First Schedule to the DPDP Rules, ₹2 crore is the minimum net worth a company needs to register as a Consent Manager, the licensed intermediary role (effective from the 13 November 2026 phase) that manages consent on behalf of data principals across platforms. It has nothing to do with whether an ordinary business is covered by the Act. The DPDP Act applies by what a business does, collecting and processing personal data digitally, not by its turnover or company size. A two-page salon website and a national e-commerce platform sit under the identical set of obligations.

The penalty schedule, in full

The Act's Schedule sets four tiers of maximum penalty, all discretionary ceilings decided case by case by the Data Protection Board, not automatic or minimum fines, and none of them enforceable until the 14 May 2027 phase commences:

  • Up to ₹250 crore for failing to take reasonable security safeguards against a personal data breach.
  • Up to ₹200 crore for failing to notify the Board and affected users after a breach, or for violating children's-data obligations.
  • Up to ₹150 crore for a Significant Data Fiduciary that skips a required DPO appointment, DPIA, or independent audit.
  • Up to ₹50 crore, the residual tier, for any other breach of the Act or Rules.

Most compliance content quotes only the ₹250 crore and ₹50 crore ends of that range and skips the ₹150 crore Significant Data Fiduciary tier entirely.

Children's data has the tightest rules in the Act

Anyone under 18 is legally a child under DPDP, and processing their data requires verifiable parental consent, actual verification of the guardian's identity, not a checkbox. Beyond consent, the Act separately bans targeted advertising to anyone identified or suspected to be under 18: no interest-based ads, no retargeting, no lookalike or customer-match audiences, regardless of whether a parent has consented to something else. Consent doesn't unlock ad targeting here; it's switched off by default.

What to actually do before 13 November

Two obligations are already live in principle, worth acting on now rather than waiting for 2027. First, Section 5(2) requires a one-time notice to anyone whose data was collected before the Act took effect and is still in use, covering what data is held, what it's used for, and how to withdraw consent or complain to the Board, sent as soon as reasonably practicable. Second, any list that wasn't built through proper consent, purchased lists, scraped addresses, business cards collected at events, doesn't qualify for that legacy-notice path at all and needs to be deleted, since it never had valid consent to begin with. Waiting for May 2027 to start on either doesn't reduce the work; it just compresses it into less time.


If you have information related to this story, contact us through StartupTalky's tips line. Anonymity is the default.