The Digital Personal Data Protection Act was passed in 2023 and then sat there, unusable, because the rules underneath it did not exist. That changed on 13–14 November 2025, when MeitY notified the DPDP Rules, 2025.
There is an implementation runway: full compliance is required by 13 May 2027, eighteen months from notification. Penalties run to ₹250 crore per violation.
Does this apply to a small business site?
If your website collects personal data from people in India, yes. And a contact form asking for a name, phone number and email is personal data. There is no small-business carve-out that makes a contact form exempt.
What actually changes on the site
| Requirement | What it means in the build |
|---|---|
| Itemised notice | A standalone, plain-language notice saying specifically what you collect and what each item is used for. Not a wall of legalese, and not buried inside your terms. |
| Real consent | Consent has to be a free, specific, informed act. No pre-ticked boxes. No 'by using this site you agree'. |
| Withdrawal | Withdrawing consent must be as easy as giving it. That is a real UI you have to build, not a line of text. |
| Retention limits | Purpose-based deletion timelines. You cannot keep enquiry form submissions forever because nobody got round to clearing the inbox. |
| Breach notification | Affected people notified within 72 hours, in plain language: what happened, what data, what they should do, who to contact. |
| Children | Verifiable parental consent for under-18s. If your site can attract minors — coaching, gaming, edtech — this is a design problem, not a checkbox. |
| A contact point | A published contact for data questions. This is a page, and it needs to be monitored. |
The part most sites will fail
Not the privacy policy. Most businesses will paste something adequate. The failures will be operational:
- Nobody can actually delete a person's data on request, because it is scattered across a CRM, a Google Sheet, a WhatsApp thread and someone's inbox.
- There is no retention rule, so data from 2019 is still sitting in a form-submissions table.
- There is no breach process, so the 72-hour clock would be missed on day one.
Which means the honest first step is not writing a policy. It is listing every place your website drops personal data — form handler, email inbox, analytics, chat widget, CRM, spreadsheet — and deciding who owns deletion for each one.
What we would do this quarter
- Map where form data currently lands. All of it.
- Delete what has no reason to still exist.
- Add a specific consent line at the point of collection, not a site-wide banner.
- Set a retention period per purpose and automate the deletion.
- Publish a data contact and make sure someone reads it.
- Then get the policy text reviewed.
Eighteen months sounds long. It is roughly the time it takes a busy business to do the six things above properly.
Want this handled properly?
Tell us what your business needs. You'll get a straight answer on whether we can help and what it would take — before you commit to anything.
Tell us what you need