Verdict Watch

India’s data law raises stakes for enterprise risk

By Sherin Prasetyo · · 4 min read
India's data law raises stakes for enterprise risk - india data law
India aims to build a $1 trillion digital economy by 2030.

India is targeting a $1 trillion digital economy by 2030. To support that growth, the Digital Personal Data Protection (DPDP) Act, 2023, and the new DPDP Rules, 2025, have fundamentally shifted legal liability for corporate India. The regulatory environment has moved beyond simple policy compliance to strict statutory fiduciary accountability. Companies can no longer treat data governance as a back-office task. It is now a board-level legal obligation.

The principal operational rules take full effect on 13 May 2027. This date is not a distant milestone. It is a hard legal boundary. Boardrooms face immediate operational duties. Treating this date as a deferred deadline exposes firms to significant regulatory risk. The work required—enterprise-wide data mapping, vendor contract amendments, and building audit trails—needs extended lead time.

Compliance Deadlines and Operational Shifts

The rollout is phased. Initial administrative and framework rules commenced on 13 November 2025. Next, Rule 4, which covers the Consent Manager Framework, goes live on 13 November 2026. The entire regime becomes fully enforceable on 13 May 2027.

These dates dictate the pace of corporate preparation. Legal teams must align workflows with these statutory deadlines to avoid gaps in protection. For many enterprises, the transition from bundled agreements to specific statutory consent obligations is the most complex hurdle. The framework replaces broad, vague terms of service with precise legal requirements. This shift demands a complete overhaul of how companies collect and process user information. It’s a move that changes the fundamental relationship between a business and its customer.

In practice, this means the era of vague “I agree” boxes is ending. Users will now have granular control over their data. Companies that fail to adapt this level of specificity risk not just fines, but a loss of consumer trust in a market where digital adoption is the primary driver of growth. The legal structure now mirrors the user’s expectation of transparency.

Consent Mechanics and Legacy Data

The Rule 3 notice mandate requires a specific action before consent is requested. A Data Fiduciary must issue an itemised, standalone notice. This document must detail the exact categories of personal data collected and their specific processing purposes. Accessibility is also mandated. Under the Eighth Schedule, this notice must be available in English and any of the 22 scheduled Indian languages.

Legacy data presents a distinct challenge. Section 6 mandates clear, affirmative action for datasets collected prior to the Act. Data Fiduciaries must issue retrospective notices to existing Data Principals before the operational deadline. This ensures that old data is brought under the new legal umbrella. It prevents companies from hiding behind historical collection methods.

A new intermediary role has been introduced. Under Rule 4, Data Principals may grant, review, or withdraw consent using Board-registered Consent Managers. These are statutory intermediaries acting as agents for the individual. The flow is direct: the Data Principal interacts with the Consent Manager, who then interfaces with the Data Fiduciary. This structure adds a layer of verification and user agency.

Financial Penalties and Risk Mitigation

The DPDP Schedule establishes statutory financial penalties for non-compliance. The numbers are substantial. Failure to implement reasonable security safeguards under Section 8(5) carries a statutory maximum of up to ₹250 crore. Failure to notify the Board and affected principals of a breach under Section 8(6) can result in penalties up to ₹200 crore.

Contraventions relating to children’s personal data under Section 9 also carry a maximum penalty of ₹200 crore. Breach of Significant Data Fiduciary duties under Section 10 can lead to fines up to ₹150 crore. These ceilings are not fixed amounts. They are evaluated under the Data Protection Board’s adjudicatory discretion. The Board takes into account mitigating factors and contemporaneous evidence.

Protecting the enterprise requires documented risk assessments. Companies must implement continuous system logging under Rule 6. They also need tested breach-notification playbooks. The legal framework leaves little room for ambiguity in these areas. Compliance is not just about avoiding fines; it is about demonstrating a defensible posture of accountability. The deadline is set. The rules are clear. The responsibility now lies with the executive leadership.

Leave a Reply

Your email address will not be published.