Programmers Studio.
← All writing7 min read

India's DPDP Rules are notified. What your website has to do now.

The Digital Personal Data Protection Rules were notified in November 2025 with an 18-month runway. A plain-English list of what actually changes on your website.

The Digital Personal Data Protection Act was passed in 2023 and then sat there, unusable, because the rules underneath it did not exist. That changed on 13–14 November 2025, when MeitY notified the DPDP Rules, 2025.

There is an implementation runway: full compliance is required by 13 May 2027, eighteen months from notification. Penalties run to ₹250 crore per violation.

Does this apply to a small business site?

If your website collects personal data from people in India, yes. And a contact form asking for a name, phone number and email is personal data. There is no small-business carve-out that makes a contact form exempt.

What actually changes on the site

RequirementWhat it means in the build
Itemised noticeA standalone, plain-language notice saying specifically what you collect and what each item is used for. Not a wall of legalese, and not buried inside your terms.
Real consentConsent has to be a free, specific, informed act. No pre-ticked boxes. No 'by using this site you agree'.
WithdrawalWithdrawing consent must be as easy as giving it. That is a real UI you have to build, not a line of text.
Retention limitsPurpose-based deletion timelines. You cannot keep enquiry form submissions forever because nobody got round to clearing the inbox.
Breach notificationAffected people notified within 72 hours, in plain language: what happened, what data, what they should do, who to contact.
ChildrenVerifiable parental consent for under-18s. If your site can attract minors — coaching, gaming, edtech — this is a design problem, not a checkbox.
A contact pointA published contact for data questions. This is a page, and it needs to be monitored.

The part most sites will fail

Not the privacy policy. Most businesses will paste something adequate. The failures will be operational:

  • Nobody can actually delete a person's data on request, because it is scattered across a CRM, a Google Sheet, a WhatsApp thread and someone's inbox.
  • There is no retention rule, so data from 2019 is still sitting in a form-submissions table.
  • There is no breach process, so the 72-hour clock would be missed on day one.

Which means the honest first step is not writing a policy. It is listing every place your website drops personal data — form handler, email inbox, analytics, chat widget, CRM, spreadsheet — and deciding who owns deletion for each one.

What we would do this quarter

  1. Map where form data currently lands. All of it.
  2. Delete what has no reason to still exist.
  3. Add a specific consent line at the point of collection, not a site-wide banner.
  4. Set a retention period per purpose and automate the deletion.
  5. Publish a data contact and make sure someone reads it.
  6. Then get the policy text reviewed.

Eighteen months sounds long. It is roughly the time it takes a busy business to do the six things above properly.

Sources

Want this handled properly?

Tell us what your business needs. You'll get a straight answer on whether we can help and what it would take — before you commit to anything.

Tell us what you need