An insurer's vendor questionnaire arrived at a 40-person Indian SaaS company in March. Question fourteen asked where personal data of Indian customers is stored and processed, listing every sub-processor. The engineering lead answered in a day: AWS Mumbai. Then someone remembered the analytics tool, the transcription API a support engineer had wired in, the marketing platform holding every contact record, and a nightly export landing in a shared drive owned by a US parent. The honest answer took three weeks and cost the renewal a quarter.
Nothing in that story is a breach or a fine. It is the ordinary shape of DPDP Act compliance failure in 2026: not a dramatic enforcement action, but an inability to describe your own data flows when a customer, an insurer or an acquirer asks. The law's May 2027 deadline is the forcing function, and the work it demands is inventory work long before it is legal work.
What DPDP Act Compliance Requires, and When
The Digital Personal Data Protection Act was passed in 2023 and sat dormant until the Government notified the Digital Personal Data Protection Rules, 2025 in November 2025, alongside a staggered commencement schedule and the constitution of the Data Protection Board of India. The phased rollout runs 18 months:
| Stage | Effective | What comes into force |
|---|---|---|
| Immediate | 13 November 2025 | Definitions, the Data Protection Board's constitution and powers, the bar on civil court jurisdiction, the Government's rule-making powers |
| One year | 12 November 2026 | Consent manager registration and the Board's jurisdiction over consent managers |
| Eighteen months | 12 May 2027 | Notice and consent, legitimate uses, obligations of data fiduciaries, children's data, data principal rights, security safeguards, breach notification, retention and erasure, Significant Data Fiduciary duties, cross-border conditions |
As of late August 2026 the middle stage is eleven weeks away and matters only if you intend to operate as a consent manager. The stage that matters to everyone else is eight and a half months out. That sounds comfortable until you notice what sits inside it: notice, consent, retention, erasure, security and breach reporting all commence on the same day, and every one of them depends on knowing what data you hold and where it goes.
Data Residency Is Narrower Than the Panic Suggests
The most persistent misreading of the Act is that it mandates storing Indian personal data in India. It does not.
Section 16, operationalised by Rule 15, uses a negative list. A data fiduciary may transfer personal data outside India to any country except those the Central Government restricts by notification. No restricted-country list has been published. There is no adequacy assessment to pass, no standard contractual clauses to sign, no transfer impact assessment to file — none of the machinery a GDPR-trained compliance lead expects. Compared with the EU regime, India's default position is permissive.
Three qualifications keep that from being the whole story.
Significant Data Fiduciaries carry a real localisation duty. Rule 13 requires an SDF to ensure that personal data specified by the Central Government, and the traffic data describing its flow, is not transferred outside India. It also requires an annual Data Protection Impact Assessment and audit, plus due diligence on algorithmic software. SDFs are designated by notification based on volume and sensitivity of processing; most small and mid-sized businesses will never be one, but a consumer platform with millions of users should assume it might be.
Sectoral rules outrank the Act and are stricter. The RBI's payment data storage direction, the IRDAI's requirements for insurers, telecom licence conditions — none of these were relaxed by the DPDP framework. If you handle payment data in India, that circular, not Section 16, decides where your database lives.
The Government kept a discretionary lever. Rule 15 preserves the power to specify requirements for making personal data available to a foreign State or an entity under its control. That targets foreign government access rather than your hosting choice, but the permissive default can be narrowed by notification without a new statute.
What residency actually costs to get wrong
The practical risk is not a fine for hosting in Frankfurt. It is that you cannot answer question fourteen. Enterprise procurement, insurers underwriting cyber cover and acquirers running diligence all ask for a data flow map now, and the DPDP framework has made that request routine rather than exotic.
The Baseline That Carries the Largest Penalty
Read the Schedule to the Act and the priorities become obvious. The maximum penalty for failing to implement reasonable security safeguards is 250 crore rupees. Failing to notify a breach carries up to 200 crore. Both can be applied to the same incident, because they are two distinct failures.
Rule 6 turns "reasonable" into something specific enough to build against: encryption, obfuscation, masking or the use of virtual tokens for personal data; access controls limiting who can reach it; logs and monitoring retained for at least one year to support investigation; backups; and contractual pass-through of these obligations to any data processor you use.
Rule 7 sets the breach clock in two stages. On becoming aware of a personal data breach you notify the Data Protection Board without delay, with a description of the breach, the categories and approximate number of people affected, likely consequences and the measures taken. A fuller report follows within 72 hours. Affected individuals must be told too.
Notice the trigger. The clock starts at awareness, not at intrusion. Most organisations that miss this deadline do so because nobody noticed for six weeks — which is what the one-year log retention requirement in Rule 6 exists to prevent, and why the two rules should be one project rather than two.
The Cheapest Compliance Is the Data You Never Collected
Every obligation above attaches to personal data you hold. Retention limits, erasure duties, breach notification, processor contracts, the security baseline: each one is a function of volume and spread. Reduce either and the compliance surface shrinks with it.
This is where architecture does more for you than policy. A file processed in the user's browser and never uploaded creates no storage, no transfer, no sub-processor relationship and nothing to disclose in a breach. We have written before about why client-side processing beats cloud upload on performance grounds; under DPDP the same choice removes an entire category of paperwork.
The processor relationship you did not sign
The document tools nobody audited
Contracts, KYC packets and signed forms get dragged into whatever free converter came top of a search result, which quietly makes an unknown vendor a processor of your customers' data. Pro PDF Edit runs compression, merging and conversion in the browser, so the file never reaches a server and never enters your transfer inventory. It is not a compliance product and does not pretend to be one — it simply removes a step that would otherwise need documenting.
Our piece on document workflows that quietly cost small teams ten hours a week covers the same ground from the productivity side. The overlap is no coincidence: the workflows nobody owns are the ones nobody has mapped.
What to Do Between Now and May 2027
Sequenced so that each step makes the next one cheaper:
- Build the inventory. Every system holding personal data, what it holds, why, who can reach it, where it is hosted, how long it is kept. Two weeks of unglamorous work that every later step depends on. Include the shadow tools — analytics scripts, browser extensions, the spreadsheet on someone's laptop.
- Kill what you do not need. Fields collected because a form template had them. Exports nobody reads. Accounts for departed staff. This is the only step that reduces obligations rather than adding process.
- Fix the Rule 6 baseline. Encryption at rest and in transit, role-based access, and logging retained for a year. Treat log retention as a detection capability, not a filing requirement.
- Write the breach runbook and rehearse it once. Who declares a breach, who notifies the Board, what the initial notice says. A tabletop exercise takes an afternoon and is the difference between the 72-hour report and an improvisation.
- Paper the processors. Every vendor touching personal data needs a contract carrying the Rule 6 obligations through. Start with the ones you found in step one and did not expect.
- Then decide about residency. With a real inventory this becomes a short list of flows to evaluate against sectoral rules and customer commitments, not an anxious blanket migration.
Where This Advice Stops
We build software; we are not your lawyers, and none of the above is legal advice. Three situations need proper counsel rather than a checklist:
- You are likely to be designated a Significant Data Fiduciary. The annual DPIA, audit and algorithmic due diligence obligations are a programme, not a project.
- You are in a regulated sector. Banking, insurance, health and telecom carry storage and reporting rules that predate the DPDP framework and are stricter than it.
- You already comply with the GDPR and assume you are covered. You are ahead on security and documentation, but the consent, notice and children's data provisions differ in ways that matter.
The deadline is 12 May 2027, and the Data Protection Board is already constituted and taking complaints. The organisations that will find that date uneventful are the ones spending this quarter on an inventory rather than on an opinion about localisation.
If you want that map built quickly, our consultancy team runs a data-flow audit in about two weeks — tell us what you are working with and we will tell you which flows create obligations and which ones you can simply stop.
Frequently Asked Questions
Does the DPDP Act require Indian businesses to store data in India?
No, not as a general rule. Section 16 and Rule 15 of the DPDP Rules take a negative-list approach: personal data may be transferred to any country except one the Central Government specifically restricts by notification. No such restriction list has been issued. Two narrower localisation obligations do exist — the Government may bar offshore transfer of specified categories of data held by Significant Data Fiduciaries, and sectoral regulators like the RBI impose their own storage requirements that are stricter than the Act and continue to apply.
When is the DPDP Act compliance deadline?
12 May 2027 for almost everything that affects an ordinary business. The framework commenced in three stages from the November 2025 notifications: institutional provisions and the Data Protection Board took effect immediately, consent manager registration follows on 12 November 2026, and the substantive obligations — notice and consent, security safeguards, breach notification, retention limits, children's data and cross-border conditions — all commence on 12 May 2027.
What are the penalties for failing DPDP Act compliance?
The Schedule sets maximum penalties per instance rather than a percentage of turnover. Failure to implement reasonable security safeguards carries up to 250 crore rupees; failure to notify the Data Protection Board or affected individuals of a breach carries up to 200 crore. Both can be levied for the same incident, because they are separate failures.
How quickly must a data breach be reported under the DPDP Rules?
In two stages. You notify the Data Protection Board without delay once you become aware of a breach, with a description of what happened, the categories and approximate number of people affected, likely consequences and steps taken. A fuller report follows within 72 hours, and affected individuals must be informed. The clock starts at awareness, which is why most organisations fail this through weak detection rather than slow paperwork.
Do startups get an exemption from the DPDP Act?
Section 17(3) lets the Government notify classes of data fiduciaries, expressly including recognised startups, as exempt from some provisions — notice requirements, certain accuracy and retention duties, and the Significant Data Fiduciary obligations. That power has not been exercised. Until a notification names your class, plan for full compliance. An exemption would also not touch the security safeguard obligation, where the largest penalty sits.