Back to Thinking & Perspectives
Brand Ecosystems·Aug 8, 2026·48 min read

DPDP Act for Small Businesses: The Complete Marketing Compliance Guide (2026)

DPDP Act for Small Businesses: The Complete Marketing Compliance Guide (2026)

India's data protection regulator has issued zero orders. It has no chairperson and no members. In April 2026 the Madhya Pradesh High Court directed a petitioner to take a complaint to that regulator and ordered it to pass a reasoned order within fifteen days. There was nobody there to write one.

Meanwhile, a different Indian regulator issued 7,31,120 notices to telemarketers in 2025 and disconnected 1,84,482 telecom connections. That regulator is TRAI, it has been enforcing for years, and almost nothing written about "DPDP compliance for small business" mentions it.

This is the gap between the law everyone is worried about and the rules that are actually binding your marketing today. Most articles on this subject get the deadline wrong, quote the wrong penalty, and sell you a product for a problem you do not have yet — while ignoring the two regimes that can cost you your WhatsApp account or your SMS route this month.

Here is what is genuinely in force, what changes in 2027, what breaks in an ordinary Indian small business's funnel, and what is worth doing now. Where sources disagree, that is said plainly rather than averaged away. Where the law is untested, that is said too.

Key Takeaways

  • DPDP's consent and notice rules are not enforceable yet. Sections 3 to 17 and Rules 3 and 5 to 16 commence eighteen months after the Gazette — May 2027. Anyone telling you to comply "now" or quoting a November 2026 deadline for an ordinary business is wrong.
  • But the deadline may move earlier, not later. MeitY held stakeholder discussions in January 2026 on cutting the window from eighteen months to twelve — which would land it in November 2026. No amendment has been notified as of 7 August 2026. This is the single biggest planning risk in this article.
  • The ₹250 crore figure is the wrong number for marketing. That tier covers security failures causing a breach. A defective consent notice falls in the residual bucket: ₹50 crore. Children's data is ₹200 crore, not the ₹150 crore widely reported.
  • There is no "legitimate interest" basis in India. Section 7 is a closed list of nine grounds and marketing is not among them. A number given for a delivery receipt may be used for the receipt — the Act says so in its own illustration — and nothing else.
  • The law you are actually breaking today is the old one. Section 43A of the IT Act and the SPDI Rules 2011 stay in force until May 2027, because the provision deleting them commences with everything else. That liability is uncapped compensation payable to the affected person.
  • A bought database has no repair path. Consent is not transferable, and Meta's own policy already prohibits messaging people who did not give you their number. That list is not a compliance problem to fix in 2027; it is a dead asset today.
  • If you market to anyone under 18, stop reading and check section 8. Targeted advertising directed at children is banned outright, and a parent cannot consent around it. Coaching centres are the most exposed businesses in this city.

1. What is actually in force today, and what is not

The Digital Personal Data Protection Act was passed in 2023 and then sat dormant for over two years because it needed rules. Those arrived as G.S.R. 846(E), notified by the Ministry of Electronics and Information Technology on 13 November 2025 and published in the Gazette the following day.

The Rules do not switch on at once. Rule 1(2) splits commencement into three tranches, keyed to the date of Gazette publication:

  • Immediately. Rules 1, 2 and 17 to 21 — the machinery for constituting the Data Protection Board, appointing its members, paying them and running it as a digital office. On the Act side: definitions, the Board provisions in sections 18 to 26, and sections 44(1) and 44(3).
  • After twelve months. Rule 4 only — registration and obligations of Consent Managers.
  • After eighteen months. Rules 3 and 5 to 16, 22 and 23, plus Act sections 3 to 17 and 28 to 34.

That last tranche is the entire substance. Notice. Consent. Legitimate uses. Security safeguards. Breach reporting. Children's data. Data principal rights. Penalties. None of it binds anyone today.

So on 7 August 2026, the honest answer to "am I breaking the DPDP Act?" is: you cannot be. The obligations have not commenced, the penalty sections have not commenced, and the Board that would hear a complaint has no members. Writing published on 1 August 2026 by LiveLaw put it precisely: the Board "has no appointed Chairperson and no appointed Members," and exists "only as a statutory possibility" (retrieved 7 August 2026). MeitY did not even advertise the posts until 6 May 2026, roughly nine months after notifying the Rules.

The ICLG India chapter for 2026, written by Singhania & Partners and published 20 July 2026, records that there are "no recent cases to be cited as examples" of enforcement (retrieved 7 August 2026). Not few. None.

A note on dates, because they are genuinely contested. The notifications bear 13 November 2025; the Gazette carries 14 November. Rule 1(2) keys commencement to publication, which points to May 2027 falling on the 14th — and the government's own PIB release and Shardul Amarchand Mangaldas both compute from the 14th. IAPP, Bar & Bench and several other firms compute from the 13th. It is a one-day spread among serious sources, so this article writes "May 2027" and leaves the day open. For planning, assume the earlier date.

2. Two regulators, and only one of them is enforcing

Here is the part almost no coverage puts side by side.

The Telecom Regulatory Authority of India has regulated commercial communication since the TCCCPR came into force in 2018, amended most recently in February 2025. It governs SMS and voice: registration of the sender on the DLT platform, registration of your six-character header, registration of every content template, scrubbing against subscriber preferences, and the 9 AM to 9 PM window for promotional traffic.

And unlike the data regulator, it acts. Figures reported by DD News and The Tribune in January 2026 record that during 2025 TRAI issued 7,31,120 notices to unregistered telemarketers, imposed 4,73,075 one-month communication bans, imposed 89,936 six-month bans on repeat offenders, and disconnected 1,84,482 telecom resources (retrieved 7 August 2026).

Enforcement activity in 2025: the data regulator versus the telecom regulator You are watching the wrong regulator Enforcement actions during calendar 2025 Data Protection Board of India 0 notices · 0 orders · 0 penalties · 0 members TRAI, under rules already in force 7,31,120 notices to unregistered telemarketers 4,73,075 one-month bans 1,84,482 disconnected 89,936 six-month bans DPDP's substantive duties do not commence until May 2027. TRAI's already have.

Sources: DD News and The Tribune reporting TRAI enforcement figures for 2025, January 2026; LiveLaw, 1 August 2026, on the composition of the Data Protection Board; ICLG India chapter, 20 July 2026, on the absence of enforcement actions. Retrieved 7 August 2026.

The distinction that matters, and the one most guides get wrong: TRAI regulates the channel. DPDP regulates the data. TRAI asks whether you are permitted to transmit on the telecom network. DPDP asks whether you were ever entitled to hold that phone number at all.

They are not alternatives, and passing one does not pass the other. A campaign that is perfectly DLT-registered, template-approved and preference-scrubbed, sent to a database you bought from a broker, is clean under TRAI and unlawful under DPDP from May 2027. Most Indian small businesses have been taught to think about the first question and have never been asked the second.

There is a third rulebook, and it binds you fastest of all: Meta's. More on that in section 5.

3. The pharmacy rule: India has no "legitimate interest" for marketing

If you have read anything about GDPR, you may have absorbed the idea that businesses can process personal data for marketing on a "legitimate interests" basis, balancing their commercial need against the individual's privacy. European marketers lean on this constantly.

That basis does not exist in Indian law. Section 4 of the DPDP Act permits processing on exactly two grounds: consent, or one of the "certain legitimate uses" in section 7. Section 7 is a closed list of nine clauses, and seven of them concern the State, legal compulsion, medical emergencies, epidemics, disasters and public order. For a private business, only two are realistically available: clause (a), and clause (i) for employment purposes.

Clause 7(a) is the one that matters, and it reads:

"for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data."

Read the first six words again. For the specified purpose. The Act then illustrates it, and the illustration is the single most useful paragraph in the statute for anyone doing marketing:

"X, an individual, makes a purchase at Y, a pharmacy. She voluntarily provides Y her personal data and requests Y to acknowledge receipt of the payment made for the purchase by sending a message to her mobile phone. Y may process the personal data of X for the purpose of sending the receipt."

For the purpose of sending the receipt. Not for a Diwali offer. Not for a "we miss you" broadcast in March. Not for a lookalike audience. A second illustration makes the ceiling even clearer: a broker helping someone find a rental may process her data to tell her about available accommodation, and when she says she no longer needs help, "Y shall cease to process the personal data."

This is the rule that quietly invalidates the most common Indian marketing habit there is: taking a number for one reason and using it for another. Every walk-in customer who gave you a number for a bill, every enquirer who wanted a quotation, every person who filled a form to download a price list — under section 7(a) you may serve the purpose they gave it for, and you need separate, specific consent under section 6 for anything else.

Section 6(1) sets that consent standard: it must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action," and be "limited to such personal data as is necessary for such specified purpose." A single checkbox covering "updates, offers and partner offers" fails the specificity limb. A pre-ticked box fails the affirmative-action limb — the Act does not say "pre-ticked boxes are banned" in those words, but a box you did not tick is not an action you took.

And section 6(10) puts the burden on you: the Data Fiduciary "shall be obliged to prove" that notice was given and consent was given. Consent you cannot evidence is consent you do not have.

4. What actually breaks in an ordinary funnel

Set the statute aside and walk through a normal small business. Here is what stops working, what rule stops it, and when.

The practice What stops it Bites
Broadcasting to a bought list on WhatsAppMeta policy requires that they gave you the number and opted in. Neither is true. Ladder ends in account lockToday
Running a bought list through SMSTCCCPR. Your header and template are traceable to you; complaints trigger actionToday
Uploading that list as a Meta Custom AudienceMeta's terms make you warrant "all necessary rights, permissions and legal basis." You cannot truthfully do soToday
The same list in Google Customer MatchGoogle restricts uploads to data "collected in the first-party context"Today
Promotional SMS at 10 PMTCCCPR restricts promotional traffic to 9 AM–9 PMToday
Marketing to an ex-customer "because they bought once"Under the 2025 TCCCPR amendment, inferred consent lasts only for the contractual relationshipToday
Taking a number for a quote, then marketing to itSection 7(a) is purpose-locked. New purpose, new consentMay 2027
One checkbox for "updates and offers"Rule 3(b) requires itemised data and specific purposes; s.6(1) requires specificityMay 2027
Consent buried in your terms or privacy policyRule 3(a): the notice must be understandable "independently of any other information"May 2027
One broadcast list mixing order updates and festival offersTransactional and marketing consent are different purposes and must be separableMay 2027
The customer sheet shared by link with your agencySection 8(2): a processor may be engaged "only under a valid contract." A shared link is not oneMay 2027
The staff WhatsApp on a personal phone that leaves with the employeeRule 6: access control, logging, one-year log retention. This is the security tierMay 2027
Deleting a complainant from your CRM but not from your ad audienceMeta requires removal on opt-out; s.6(6) requires you to make processors cease tooMeta: today

Notice how much of that column says "today." The compliance conversation in India has been framed entirely around a 2027 date, and in the process has skipped every rule that is already live.

5. The bought list has no repair path

There is an open market in Indian contact databases — city-wise, pin-code-wise, sold as pre-filtered. Plenty of businesses in this city have bought one. It is worth being blunt about what happens to it, because most compliance content dodges this.

Consent is not transferable. Under section 6 the consent must be given by the individual to you, for your specified purpose. A broker cannot pass one along, because what the broker holds is not a thing that can be assigned. There is no provision in the Act for transferring a lawful basis, and section 7 offers no ground that covers it.

Nor does the "publicly available data" carve-out help, though it is the most commonly abused provision in Indian commentary. Section 3(c)(ii) takes the Act off data "made or caused to be made publicly available by the Data Principal to whom such personal data relates." The individual herself must have published it. A number scraped from a directory, lifted from a WhatsApp group, or extracted from somebody else's customer list does not qualify — she did not make it public, someone else did.

And you do not have to wait until 2027 for this to hurt. Meta's Business Messaging Policy already states that you may contact people only if "they have given you their mobile phone number" and "you have received opt-in permission" (retrieved 7 August 2026). A purchased list satisfies neither condition. Meta's published enforcement ladder runs from a one or three-day block on template messages, to blocks of five, seven or thirty days on all messages, to "an account lock, which is an indefinite block on sending any messages" removable only by appeal.

So the practical answer, which is harder than the one most guides give:

  • Segment the list by provenance. People who transacted with you and gave you the number themselves are one group. Everything bought, scraped or of unknown origin is another.
  • For the second group, there is no lawful re-permission route, because any re-permission message is itself an unsolicited message to someone who never gave you their number. You cannot fix an unlawful list by sending it one more unlawful message. If you hold an email address they gave you, or a registered consent-seeking SMS template, use that. Otherwise the list is finished.
  • For the first group, run a re-permission campaign now, while it is cheap: name your business, state exactly what you will send, offer one-tap in and one-tap out, and log the response with a timestamp. Treat silence as a no for marketing.

The uncomfortable arithmetic is that a 50,000-number blast costs real money in template fees and risks the account that carries your genuine customers. Cost per lawful contact is the only version of that metric worth tracking — the same discipline as knowing your maximum cost per enquiry before you spend, which we worked through in what digital marketing actually costs a small business in India.

6. Your existing list needs a notice, not a re-consent

This is the question that determines whether compliance costs you a weekend or a quarter, and it is the one consultants most often answer expensively.

Section 5(2) deals with data you already hold, where consent was given before the Act commenced. It requires two things:

"(a) the Data Fiduciary shall, as soon as it is reasonably practicable, give to the Data Principal a notice informing her,— (i) the personal data and the purpose for which the same has been processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board … (b) the Data Fiduciary may continue to process the personal data until and unless the Data Principal withdraws her consent."

Read clause (b). You may keep processing. You owe those people a notice, not a fresh opt-in, and you may continue until someone withdraws. That is dramatically cheaper than the re-consent campaigns being sold to Indian businesses, and it is what the statute says.

Two honest caveats. First, this reading is textually straightforward but entirely untested — there is no Board guidance and no case law, because there is no Board. Second, it only helps for data where consent was genuinely given. It does nothing for a bought list, because there was never any consent to carry forward.

7. The number everyone quotes is the wrong number

Search for DPDP and you will be told about ₹250 crore. That figure is real, and for a marketing conversation it is almost entirely irrelevant.

The Schedule to the Act sets seven entries, and each maps to a specific failure. The ₹250 crore ceiling attaches to one of them: breach of the obligation under section 8(5) to take reasonable security safeguards to prevent a personal data breach. Failing to notify a breach is ₹200 crore. Children's data obligations are ₹200 crore — not the ₹150 crore that circulates widely, which is the Significant Data Fiduciary tier and does not apply to a small business at all.

Notice and consent have no dedicated entry. Sections 5, 6 and 7 fall into entry 7: "breach of any other provision of this Act or the rules," capped at ₹50 crore.

DPDP penalty ceilings by type of breach Where a marketing failure actually sits Maximum penalty by breach type — these are ceilings, not standard fines Security safeguards, s.8(5) ₹250cr Breach not notified, s.8(6) ₹200cr Children's data, s.9 ₹200cr Significant Data Fiduciary, s.10 ₹150cr · not you Notice & consent — residual ₹50cr Duties of the individual, s.15 ₹10,000 Imposed to date: nil Sections 33 and 34 have not commenced, and the Board has no members. Section 33(1) also requires a breach to be "significant" before any penalty stage.

Source: the Schedule to the Digital Personal Data Protection Act, 2023, read with sections 33 and 34. Retrieved 7 August 2026.

Two more features of section 33 deserve more attention than they get, because together they are the best answer to "could this destroy my business?"

Section 33(1) permits a penalty only where the Board "determines on conclusion of an inquiry that breach … is significant," after giving an opportunity to be heard. Significance is a threshold, and a minor, remedied, one-off lapse does not obviously clear it.

Section 33(2) then lists seven factors the Board shall weigh. Two matter to a small business. Clause (e) credits "whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action" — note that it rewards a fast, effective response, not a policy binder written in advance and never used. Clause (g) requires the Board to consider "the likely impact of the imposition of the monetary penalty on the person." That is a statutory instruction to look at who is paying. GDPR has no direct equivalent.

What the Act does not give is compensation. Section 34 sends every rupee collected to the Consolidated Fund of India. An individual harmed by your breach gets nothing under this statute — which brings us to the liability nobody is discussing.

8. The law that actually binds you today is the one everyone says was repealed

Section 44(2) of the DPDP Act omits section 43A of the Information Technology Act, 2000, and with it the SPDI Rules of 2011 — India's existing data-security regime.

Section 44(2) is in the eighteen-month tranche. It has not commenced. Section 43A and the SPDI Rules are fully in force today and stay in force until May 2027, which is precisely the point: the drafters staggered it so there would be no gap in protection during the transition. Shardul Amarchand Mangaldas records the repeal of section 43A in the eighteen-month list, and the ICLG India chapter of 20 July 2026 confirms the SPDI regime "continue[s] to survive during the transition period."

This inverts the standard advice. You have probably read that your old IT Act compliance will not save you. Right now it is the only compliance that legally bites — and the exposure under it is worse-shaped than DPDP's for a small business, in three ways:

  • Section 43A creates a liability to pay compensation to the affected person, not a penalty to the State. The money comes out of your business and goes to the claimant.
  • That compensation is uncapped. There is no schedule of ceilings.
  • There is no equivalent of section 33(2)(g) — nothing requiring anyone to weigh what the award would do to you.

There is also a trap in the handover. Section 43A disappears at the same moment DPDP's security obligation under section 8(5) — the ₹250 crore row — switches on. There is no gap and no grace period. A business that treats SPDI as "the old thing we can drop" and DPDP as "the new thing starting in 2027" will drop its only live control regime early, and sit exposed under both.

The practical consequence is genuinely useful: the security work satisfies both regimes. Access controls, encryption or masking, logs, backups and a written contract with anyone who touches your data are the SPDI answer and the Rule 6 answer. It is the one investment that is not premature.

9. If you market to anyone under 18, read this twice

Section 2(f) defines a child as anyone who has not completed eighteen years. That is the highest threshold in the world — GDPR sets it between thirteen and sixteen — and in a city with as many coaching centres, schools and student-facing businesses as this one, it catches far more organisations than people expect.

Section 9 imposes three duties. Section 9(1) requires verifiable parental or guardian consent before processing a child's data at all. Section 9(2) bars processing "likely to cause any detrimental effect on the well-being of a child." And section 9(3) is the one to underline:

"A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children."

That is a prohibition, not a consent requirement. A parent cannot authorise around it. There is no version of a signed form that makes targeted advertising to a fifteen-year-old lawful.

The Fourth Schedule does exempt some organisations, and educational institutions are among them — but the exemption is narrower than the relief people assume. It permits tracking and behavioural monitoring for educational activities or for the child's safety within the institution, and it lifts only sections 9(1) and 9(3) for that purpose. It does not authorise targeted advertising to students, does not permit sharing or selling student contact lists, and cannot cure a breach of section 9(2), which is not exemptible at all.

So a coaching centre running a retargeting pixel against a leads list of school students, or building a lookalike audience from enquiries by minors, is inside the section 9(3) prohibition. The Schedule puts children's breaches at ₹200 crore — the second-highest tier in the Act, above Significant Data Fiduciary obligations. Of everything in this article, this is the item with the widest gap between how common the practice is and how seriously the statute treats it.

10. Your agency and your freelancer are Data Processors

Section 2(i) makes you the Data Fiduciary: you determine the purpose and means. Anyone processing on your behalf — an agency, a freelance media buyer, a CRM, an email tool, a WhatsApp solution provider — is a Data Processor under section 2(k).

Section 8(2) permits you to engage one "only under a valid contract." A shared Google Sheet link is not a contract. A WhatsApp conversation agreeing scope is not a contract. This is the single most common gap in Indian small-business arrangements, and it is also the cheapest to close.

Helpfully, the Act prescribes no mandatory clauses — the ICLG India chapter notes it "does not envisage specific formalities or delineate mandatory clauses." A short written agreement covering scope of data, purpose limitation, no onward transfer, security obligations mirroring Rule 6, breach notification to you within a fixed window, and deletion on termination will do the job. One page is enough.

What you cannot do is push the liability across. Section 8(1) is explicit that a Data Fiduciary is responsible "irrespective of any agreement to the contrary." If your agency leaks your customer list, it is your breach. The contract governs what you can recover from them; it does not change who answers to the regulator.

And section 6(6) requires that when someone withdraws consent you must "cease and cause its Data Processors to cease" processing. Withdrawal has to propagate — out of your CRM, out of your broadcast list, and out of any ad audience you uploaded. Meta's own Customer List Custom Audiences Terms, effective 3 December 2025, already require you to remove people who opt out after an audience is built (retrieved 7 August 2026).

11. What a compliant lead form looks like

There is no official government template. MeitY has published no model notice, and any vendor claiming to sell you "the official format" is selling something that does not exist. What follows is assembled directly from Rule 3, section 5 and section 6.

Rule 3 requires that the notice:

"be presented and be understandable independently of any other information that has been, is or may be made available"

and that it give, at minimum, "an itemised description of such personal data" and "the specified purpose or purposes." It must also carry a link by which the person may withdraw consent "with the ease of doing so being comparable to that with which such consent was given," exercise their rights, and "make a complaint to the Board."

In practice, that means:

  • A standalone notice, not a line in your terms. Rule 3(a) is the clause that kills consent-by-privacy-policy.
  • An itemised list of what you collect. Actually name them: name, mobile number, city.
  • Purposes stated separately, one line each. "To send you a quotation" is one purpose. "To send you offers on WhatsApp" is another.
  • Separate, unticked boxes for transactional and marketing, and ideally per channel — someone may accept WhatsApp and refuse SMS.
  • A working withdrawal link that is as easy as the original tick.
  • Links to exercise rights and to complain to the Board.
  • A named human who answers. Section 8(9) requires you to publish contact information for a person able to answer questions; Rule 9 requires it prominently on your site and in every response. A small business does not need a Data Protection Officer — that is a Significant Data Fiduciary obligation under section 10 — but it does need someone who replies.
  • A language option. Section 5(3) gives the individual the right to access the notice in English or any language in the Eighth Schedule. That is 22 scheduled languages plus English, so 23 options — sources that say "22 languages" are miscounting.
  • A timestamped consent record, because section 6(10) puts the burden of proof on you.

Section 13 then requires "readily available means of grievance redressal," with Rule 14(3) setting a response period "not exceeding ninety days." And section 13(3) requires the individual to exhaust your grievance process before approaching the Board. A working complaints inbox is therefore not just good manners — structurally, it is the thing that intercepts a complaint before it becomes a regulatory matter. For a small business it is the highest-value control in the entire Act.

How far is Indian practice from this? A dipstick study of India's fifty most-visited websites, conducted by Tsaaro Consulting for the ASCI Academy with PSA Legal and published on 28 January 2025, found that just three met the granular consent standard the Act contemplates.

Consent readiness among India's fifty most-visited websites Nearly nobody is ready, including the biggest India's 50 most-visited websites, assessed against a granular consent standard 3 of 50 3 sites met the standard Granular, specific, revocable consent 47 sites did not Bundled, implied or absent consent If the largest sites in the country are not there yet, the standard is not obvious. Start early.

Source: "Navigating Cookies," ASCI Academy with PSA Legal and Tsaaro Consulting, 28 January 2025; sample drawn from Semrush's ranking of India's fifty most-visited websites, December 2024. Reported by ThePrint. Retrieved 7 August 2026.

12. Four things being sold to you that are not true

The compliance market got to this topic before the regulator did. These four claims are in wide circulation and each is wrong.

"The deadline is November 2026." For an ordinary business, no. The twelve-month tranche contains exactly one rule — Rule 4, on Consent Managers. A Consent Manager is a licensed intermediary that must be a company incorporated in India with a net worth of at least ₹2 crore, registered with the Board. It is a category for banks, telcos and funded consent-tech firms. Section 6(7) says a Data Principal may manage consent through one; nothing obliges you to integrate with one. Candour Legal reported on 3 July 2026 that no Consent Manager has registered and the registration facility is not live — because the Board that would process applications has no members (retrieved 7 August 2026).

"You need a GDPR-style cookie banner." Not established. The ICLG India chapter for 2026 states plainly that "the DPDPA does not explicitly regulate the use of cookies, and therefore, does not distinguish between different categories," while adding that "where cookies or similar technologies involve the collection or processing of personal data, the requirements of the DPDPA would apply." India has no ePrivacy equivalent and no "storage on terminal equipment" concept. The honest position: a Meta Pixel with advanced matching, hashing and transmitting an email or phone number, is unambiguously processing personal data and needs consent. A first-party analytics cookie holding a random ID is a genuinely grey area. Every vendor asserting total certainty here sells banners.

"Google Consent Mode v2 is mandatory in India." No Google policy document says so. Consent Mode v2 exists to satisfy the EU's Digital Markets Act and is EEA-scoped. It may still be sensible to implement for measurement continuity. Sensible is not the same as required, and the sources claiming otherwise are consent-management vendors and SEO blogs.

"There is a startup or small-business exemption." There is not. No turnover threshold, no headcount threshold, no MSME carve-out appears anywhere in the Act or the Rules. Section 17(3) empowers the government to notify exemptions for classes of fiduciaries "including startups" — but it is an enabling power, and no notification has been issued as of 7 August 2026. Even a generous one would only relieve sections 5, 8(3), 8(7), 10 and 11. Consent under section 6, security under 8(5), breach notification under 8(6), children under section 9 and grievance redressal under section 13 would all survive it. The marketing spine is untouched either way.

One more that is not a myth but a genuine caution: do not trust the Wikipedia entry for the Data Protection Board. It currently names a chairperson that no press release, ministry notification or news report corroborates, in a format that does not match any Indian civil service. It contradicts LiveLaw, Candour Legal and Khurana & Khurana. It appears to be vandalism, and it is being repeated by vendor blogs and surfacing in AI-generated search summaries.

13. The deadline may move — and the risk is that it moves closer

Every plan in this article assumes May 2027. That assumption has a live threat against it, and it runs in the direction most businesses are not braced for.

Following the notification, the government signalled it would revisit the eighteen-month window. S.S. Rana & Co. reported in February 2026 that MeitY held stakeholder discussions on 23 January 2026 proposing to cut the compliance timeline from eighteen months to twelve, with feedback due by 4 February 2026 (retrieved 7 August 2026). Twelve months from the Gazette is November 2026 — roughly three months from now.

No such amendment has been notified as of 7 August 2026, and nothing suggests one is imminent. But the asymmetry is worth naming: the usual assumption with Indian compliance deadlines is that they slip later. Here the only documented proposal moves it earlier.

What commences when under the DPDP Rules 2025 Roughly 280 days of runway left And the only proposal on the table shortens it no regulator appointed Nov 2025 Rules notified; Board provisions Today no members, no orders Nov 2026 Consent Managers only — not you May 2027 everything else, and s.43A ends MeitY discussed cutting 18 months to 12 at a stakeholder meeting on 23 January 2026, which would move the deadline to November 2026. No amendment notified as of 7 August 2026. Dates shown to the month: sources split between the 13th and 14th. See section 1.

Sources: DPDP Rules 2025, Rule 1(2); Shardul Amarchand Mangaldas commencement note, 21 November 2025; S.S. Rana & Co. on the proposed shortening, February 2026; LiveLaw, 1 August 2026. Retrieved 7 August 2026.

How ready is anyone? An EY India survey of 150-plus professionals, published 27 January 2026, found roughly 70% were "not very familiar" with the Act and Rules, and more than 83% had not begun comprehensive implementation. That is a small sample, drawn from enterprises rather than small businesses — which means it is the optimistic bound. Nobody has measured MSME readiness at all; no survey of it exists.

14. What it costs, and why every number you have been quoted is marketing

There is no credible independent estimate of DPDP compliance cost for an Indian micro or small business. Not from MeitY, not from NASSCOM, not from DSCI, not from FICCI.

What exists instead: consultants quoting anywhere from ₹15 lakh to ₹2 crore, and vendors publishing counter-estimates of ₹3 to 8 lakh to make their own product look reasonable. Both come from firms selling compliance services. One law firm briefing states that around 30% of respondents expect compliance to exceed 10% of turnover, and does not cite a source for the figure even while conceding elsewhere that "concrete data on SMEs is limited."

Indian advertising executives quoted by Storyboard18 on 15 November 2025 estimated a 10 to 15% short-term increase in operational and compliance costs — attributed to unnamed industry sources, and reflecting agencies and adtech firms rather than a shop with a lead form (retrieved 7 August 2026).

The honest position is that nobody has measured this, and the figures being quoted to Indian small businesses are sales collateral rather than research. What can be said with confidence is which items are cheap and which are not. Rewriting a lead form is cheap. Writing a one-page processor agreement is cheap. Setting up a grievance inbox and naming a person to answer it is cheap. Building access control, logging and one-year log retention across a business that currently runs on shared spreadsheets and personal phones is not cheap, and it is the one that takes months rather than weeks.

15. What to do, in order

Sequenced by what bites soonest rather than what sounds most urgent.

This month, because these rules are already live:

  • Audit your WhatsApp list by provenance. Separate people who gave you their number from everything bought, scraped or unknown. The second group is a live risk to your account under Meta's policy today, not a 2027 problem.
  • Check your SMS route. Sender registration, header, content templates, the 9 AM to 9 PM window. TRAI issued over seven lakh notices last year; this is the enforcement that actually exists.
  • Stop uploading anything you did not collect yourself to Meta Custom Audiences or Google Customer Match. Both platforms make you warrant provenance you do not have, and both have already moved the legal risk onto you.
  • If you market to under-18s, stop targeted advertising to them now. Section 9(3) is an outright ban with a ₹200 crore ceiling, and there is no consent that cures it.

This quarter, because it serves both the old regime and the new:

  • Get the security basics documented. Who can access customer data, on what devices, with what logging, backed up where. This satisfies the SPDI Rules that bind you today and Rule 6 that binds you in 2027, and it is the only item on this list that is not premature.
  • Put every processor on a one-page contract. Your agency, your freelancer, your CRM, your WhatsApp provider. Scope, purpose limitation, no onward transfer, security, breach notification to you, deletion on exit.
  • Name the human who answers privacy questions, publish their contact details, and give them an inbox that is actually monitored. Section 13(3) makes your grievance process the first stop — it is what stops a complaint becoming a regulatory matter.

Before the deadline, whichever month it lands in:

  • Rebuild your lead forms to the section 11 pattern above: standalone notice, itemised data, separate purposes, unticked boxes, working withdrawal, timestamped records.
  • Send the section 5(2) notice to your legacy list. A notice, not a re-consent campaign.
  • Make withdrawal propagate. One opt-out should clear the person from your CRM, your broadcast list and your uploaded ad audiences. Test it by actually doing it.

None of this is exotic, and most of it improves the marketing regardless. A list built on consent you can evidence outperforms a bought one on every metric that matters — which is roughly the argument we made about channel discipline in how to promote a small business in Varanasi, arrived at from a completely different direction.

Frequently asked questions

Is my business too small for the DPDP Act to apply?
No. There is no turnover threshold, no headcount threshold and no MSME exemption anywhere in the Act or Rules. Section 2(s) defines "person" to include individuals, Hindu undivided families, companies, firms and associations — a sole proprietor with a lead form is a Data Fiduciary. The only exclusions are purely personal or domestic processing, and data the individual herself made public.

Am I breaking the law right now?
Not under the DPDP Act — its substantive obligations and its penalty sections have not commenced. You may well be breaking TRAI's rules on commercial communication, Meta's WhatsApp policy, or your obligations under Section 43A of the IT Act and the SPDI Rules 2011, all of which are in force today.

Do I have to re-collect consent from my existing customers?
Where consent was genuinely given before commencement, no. Section 5(2) requires a notice covering what data you hold and why, how to exercise rights, and how to complain to the Board — and clause (b) lets you continue processing until the person withdraws. This reading is textually clear but untested. It does not help for lists you bought, where no consent ever existed.

Can I still use a customer's number for marketing if they gave it to me at the counter?
Only for the purpose they gave it for. Section 7(a) is purpose-locked, and the Act's own illustration confines a pharmacy to sending the receipt. Marketing is a new purpose and needs separate consent under section 6.

Is the fine really ₹250 crore?
That is the ceiling for failing to take reasonable security safeguards where a breach follows. Notice and consent failures fall in the residual entry at ₹50 crore. Children's data is ₹200 crore. All are maximums — section 33(1) requires a breach to be "significant" before any penalty stage, and section 33(2)(g) requires the Board to weigh the likely impact of the penalty on the person paying it.

Do I need to hire a Data Protection Officer?
No. That obligation attaches to Significant Data Fiduciaries under section 10, a category the government designates. But section 8(9) requires every business to publish contact details for a person who can answer data questions, and Rule 9 requires it prominently on your site and in every reply.

Does DLT or DND compliance mean I am DPDP compliant?
No, and this is the most consequential confusion in the market. TRAI governs whether you may transmit on the telecom network. DPDP governs whether you may hold the data at all. A perfectly DLT-compliant campaign to a purchased database passes the first test and fails the second.

What happens on 13 November 2026?
For an ordinary business, nothing. That date brings Rule 4 into force, covering registration of Consent Managers — licensed intermediaries requiring Indian incorporation and ₹2 crore net worth. Using one is optional for you. Anyone marketing that date to a small business as a compliance deadline is misrepresenting it.

Can I claim compensation if a company leaks my data?
Under the DPDP Act, no — section 34 sends all penalties to the Consolidated Fund of India, and the Act creates no compensation right. Under Section 43A of the IT Act, which remains in force until May 2027, an affected person can claim compensation directly. That route narrows when section 44(2) commences.

Where to start

If you do one thing after reading this, make it the provenance audit. Open your WhatsApp broadcast list and your customer database and answer a single question for each entry: did this person give me this number, for something?

Everything else follows from that answer. The names where it is yes are an asset that survives 2027 and needs a better form and a notice. The names where it is no are already a liability under rules that are live today, and no amount of 2027 preparation will convert them.

The businesses that will find May 2027 painless are not the ones that bought a compliance product. They are the ones that spent the intervening months collecting fewer, better-sourced contacts and writing down who touches them. That work is unglamorous, it is cheap, and unusually for compliance, it makes the marketing better on its own terms.

Sources

All sources retrieved 7 August 2026. Where a claim rests on a reproduction of statutory text rather than the Gazette itself, that is noted.

Statute and rules

  • Digital Personal Data Protection Act, 2023 (Act 22 of 2023) — sections 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 17, 18, 29, 33, 34, 44 and the Schedule. India Code.
  • Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E), Ministry of Electronics and Information Technology, dated 13 November 2025, published 14 November 2025. Rules 1, 3, 4, 6, 7, 8, 9, 10, 12, 14, and the Third and Fourth Schedules. MeitY.
  • Statutory text and illustrations for sections 5, 6, 7, 8 and 33, and Rules 3, 6, 7 and 8, consulted via bare-act reproductions at dpdpa.com, cross-checked against the law-firm summaries below.
  • Information Technology Act, 2000, Section 43A, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. WIPO Lex.
  • Telecom Commercial Communications Customer Preference Regulations, 2018, as amended 12 February 2025. TRAI.

Commencement, enforcement and regulator status

  • Shardul Amarchand Mangaldas, "Enforcement of the DPDP Act and notification of the DPDP Rules," 21 November 2025 — amsshardul.com. Used for the three-tranche commencement schedule and the deferral of Section 43A's repeal.
  • Singhania & Partners, "Data Protection Laws and Regulations 2026 — India," ICLG, 20 July 2026 — iclg.com. Used for the absence of enforcement actions, the survival of the SPDI regime, the cookie position, and processor contracts.
  • LiveLaw, "India's Data Protection Board: Established In Law, Absent In Fact," 1 August 2026 — livelaw.in.
  • LiveLaw, on the Madhya Pradesh High Court's April 2026 direction to the Data Protection Board — livelaw.in.
  • Khurana & Khurana, "India's Data Protection Board: The Enforcer That Isn't There Yet," 17 April 2026 — Mondaq.
  • Candour Legal, "DPDP Consent Managers: A November 2026 Deadline, But No Regulator Yet," 3 July 2026 — candourlegal.com.
  • S.S. Rana & Co., on MeitY's proposal to shorten the compliance timeline, February 2026 — ssrana.in.
  • Bar & Bench, "MeitY notifies final Digital Personal Data Protection Rules 2025," 17 November 2025 — barandbench.com.
  • IAPP, "With rules finalized, India's DPDPA takes force," 14 November 2025 — iapp.org. Cited for the competing 13 November computation.

Platform policies

Enforcement figures, readiness and industry data

  • DD News, "TRAI cracks down on spam telemarketers, issues over 7 lakh notices in 2025," January 2026 — ddnews.gov.in.
  • The Tribune, on TRAI notices and restrictions, January 2026 — tribuneindia.com.
  • Khaitan & Co, "Efforts to Curb Spam Continue: TRAI Releases Second Amendment to the TCCCPR 2018," 2 April 2025 — khaitanco.com. Cited for the duration limit on inferred consent.
  • ASCI Academy with PSA Legal and Tsaaro Consulting, "Navigating Cookies," 28 January 2025 — ascionline.in; reported by ThePrint.
  • EY India, "India's digital privacy shift: steering DPDP compliance and readiness," 27 January 2026 — ey.com. Sample of 150-plus professionals, enterprise-weighted.
  • Storyboard18, "DPDP Rules trigger a ground-up reset for India's advertising industry," 15 November 2025 — storyboard18.com.
  • PSA Legal, "India's adtech reckoning: what the DPDPA means for digital advertising" — psalegal.com. Cited for the non-transferability of consent across an adtech chain.

This article describes the law as published and is written for marketing decision-makers, not as legal advice. Where provisions are untested — notably the Section 5(2) legacy-notice reading and the treatment of first-party analytics cookies — that is stated in the text. Commencement dates are given to the month because sources divide between the 13th and 14th; see section 1. If a decision turns on a specific provision, take advice on it.

“In a world older and more complete than ours they move finished and complete, gifted with extensions of the senses we have lost or never attained, living by voices we shall never hear.”

Srijan Kumar

Srijan Kumar

Founding Partner & Strategy

Follow Vision Wings on Google

Add us as a preferred source to see our work more often in Top Stories and AI Overviews.

Add as preferred source
Verified by Vision Wings Editorial Board

Read more like this

More perspectives from the Vision Wings editorial desk.

All insights