Most Indian businesses still treat data protection as a legal footnote. That window is closing. The Digital Personal Data Protection (DPDP) Act, 2023, paired with the DPDP Rules notified in November 2025, is now a live regulatory system with real deadlines and real penalties — up to ₹250 crore per violation. If your business collects a customer's name, phone number, or email address digitally, you are a "Data Fiduciary" under the Act, and the clock is already running.
This isn't a one-time filing. DPDP compliance touches your consent flows, your breach response process, your vendor contracts, and how your engineering team stores and deletes personal data. Getting DPDP readiness right means treating it as an operational build, not a checkbox exercise. Here's what the law actually requires, what's changing through 2026 and 2027, and how to approach DPDP Act compliance without derailing your product roadmap.

The DPDP Rules 2025 rolled out enforcement in three phases. Phase one took effect in November 2025 with the constitution of the Data Protection Board of India. Phase two lands on 13 November 2026, when the Consent Manager framework becomes operational, a system that lets users manage and withdraw consent across services through interoperable platforms. Phase three, the hard deadline, is 13 May 2027, when full substantive compliance across notice, consent, breach reporting, and data principal rights becomes enforceable with no announced grace period.
The DPDP Rules 2025 rolled out enforcement in three phases. Phase one took effect in November 2025 with the constitution of the Data Protection Board of India. Phase two lands on 13 November 2026, when the Consent Manager framework becomes operational, a system that lets users manage and withdraw consent across services through interoperable platforms. Phase three, the hard deadline, is 13 May 2027, when full substantive compliance across notice, consent, breach reporting, and data principal rights becomes enforceable with no announced grace period.
Strip away the legal language, and DPDP compliance comes down to seven operational buckets:
Historical data isn't exempt either. Regulators expect legacy datasets collected before the Act to be backed by valid consent or a lawful basis, a gap that trips up more companies than the day-to-day flows do.
Two patterns show up repeatedly. First, treating DPDP as a legal-team problem instead of an engineering one. Consent capture, breach detection, and data deletion are code, not clauses, they live in your application architecture, your database retention jobs, and your incident response runbooks. Second, underestimating legacy data. Auditing years of accumulated customer records for lawful basis is slower and messier than building new-user consent flows from scratch, and it's exactly the area regulators are watching first as the "soft enforcement" phase ends.
Start with a data inventory: what personal data you hold, where it lives, who touches it, and why. Map that against the seven obligation buckets above to find your real gaps, not assumed ones. From there, prioritize by risk and deadline: consent and notice infrastructure first, Consent Manager compatibility ahead of November 2026, then breach response and retention automation. Build the technical controls into your existing systems rather than bolting on a separate "compliance layer" that engineering will quietly ignore. Finally, document everything, audits, DPO appointments, and impact assessments aren't just internal hygiene; they're what you'll need to show the Data Protection Board if it comes calling.
DPDP compliance fails most often at the handoff between legal requirements and actual systems, the consent banner that doesn't talk to the database, the deletion policy with no automation behind it, the breach plan nobody has tested. Leapcodes closes that gap directly. Our DPDP compliance consulting services start with a full data inventory and gap assessment, then our engineering and infrastructure teams build the consent management, breach detection, and data rights workflows into your actual product, not as a separate layer bolted on before an audit. Whether you need a one-time DPDP readiness assessment or ongoing managed support through the 2027 deadline, Leapcodes builds the systems, not just the paperwork.
It is the process of administering and optimising cloud-based computing, storage, and networking resources to ensure efficiency, security, and alignment with business needs.
It ensures that cloud services deliver consistent performance, adhere to SLAs, and support strategic business outcomes through automation and analytics.
IT strategy consulting ensures cloud investments are aligned with overall business priorities, risk posture, and future scalability needs.
AI brings automation, predictive analytics, and self-healing capabilities, allowing enterprises to operate more efficiently and reduce downtime.
Leapcodes combines deep technical expertise with consultative strategy, enabling businesses to modernise operations, improve resilience, and maximise ROI.