The DPDPA deadline 2027 is 13 May 2027. Indian SMB founders who feel that clock usually buy the wrong pack. The Digital Personal Data Protection Act, 2023 wants a sequence: inventory, grounds, notices, rights, dual-clock SOP, then evidence.
TL;DR
- The DPDPA deadline 2027 for remaining substantive DPDP Rules, 2025 duties is 13 May 2027, not a vendor certificate date. From this article’s date that is under eight months, not an eleven-month slogan.
- Do the work in order: personal-data inventory, then Section 6 / Section 7 grounds, then Section 5 notices, then rights and grievance, then the CERT-In (6 hours) plus Data Protection Board of India (DPB) Rule 7 (72 hours) runbook, then evidence.
- Rule 13 annual DPIA and audit remain Significant Data Fiduciary only, after a Section 10 Gazette notice. Most SMBs still owe Sections 4-9 and 11-14. They do not owe a pre-notification auditor logo.
- Consent is Section 6: free, specific, informed, unconditional, unambiguous, clear affirmative action. Employment-necessary processing can sit under Section 7(i). Processor copies are still personal data.
- Section 8(5) security failures sit under the ₹250 crore Schedule slab. Architecture that can reconstruct a record beats a policy PDF. The week-by-week container is the 90-day DPDPA readiness roadmap. This piece is the cut: what first, what later, what not to buy.
What should an Indian SMB do first for the DPDPA deadline 2027?
DPDPA deadline 2027 work starts with a sheet, not a purchase order.
The SMB is already a Data Fiduciary under Section 2(i) once it determines purpose and means for digital personal data of people in India. Size is not a carve-out. The baseline stack is in DPDPA compliance for Indian SMBs. This article is the order you run it in when the calendar is loud.
Write every place a person can still be named: CRM, Tally, HRMS, payroll vendor, WhatsApp Business, Google Forms, the shared drive labelled old_leads_final_v2.xlsx, the laptop folder, the agency export. For each row: system, dataset, purpose in plain language, who else sees it, how long you keep it, who owns it. Empty owner = future incident.
Do not skip this to “get to consent.” You cannot assign a ground to a purpose you have not written. You cannot itemise a Section 5 notice for fields you cannot name. You cannot honour Section 12 erasure across systems you never mapped.
The DPDPA does not revive the old SPDI sensitive personal data category. Phones, Aadhaar copies, and vendor emails are personal data under Section 2(t). There is no extra SMB tier because a field “feels financial.”
| Do first | Typical source | Why it is first | Owner |
|---|---|---|---|
| Named systems + shadow copies | CRM, HRMS, Tally, WhatsApp, shared drive | Everything else depends on the row existing | Founder + ops |
| Purpose in business language | Same sheet | A purpose you cannot put in a notice is a habit | Ops |
| Processor list | Payroll, email, cloud, collections | Section 8(2) contract; copies stay personal data | Legal / ops |
| Retention trigger | Each dataset | Section 8(7) erasure needs a “done” date | Ops |
Which DPDPA jobs can wait until after the inventory exists?
Not “never.” After.
| Buy / task now | Wait until the sheet exists | Skip unless notified SDF |
|---|---|---|
| Inventory + owner per row | Fancy consent widget with no purpose register | Rule 13 annual DPIA / statutory audit pack |
| Ground per purpose: Section 6 or named Section 7 | Multi-language pack covering all 22 Eighth Schedule languages as a duty | Self-declared DPO because a vendor slide said so |
| Section 8(9) contact who actually answers | Tool bake-off before you know which records to reconstruct | SDF extras without a Section 10 notice |
A GDPR “legitimate interests” row has nowhere to land. The Act has no balancing test. Marketing and optional analytics sit on Section 6. The walk-in number for a delivery update can sit on Section 7(a) if it was voluntarily provided for that specified purpose and they have not objected. Payroll, PF, ESI, and necessary attendance can sit on Section 7(i); do not route them through consent you cannot survive withdrawing. Employment detail: when the employer is a Data Fiduciary.
Rule 4 Consent Manager registration from 13 November 2026 is a date for entities that want to be registered Consent Managers. It is not a duty for an SMB founder to buy a “Consent Manager” banner. Software is not your Section 10(2)(b) auditor.
Does an SMB need a Rule 13 audit before 13 May 2027?
No, unless and until the Central Government notifies you, or a class that includes you, under Section 10.
SDF extras: Significant Data Fiduciary under DPDPA. Until that Gazette notice, you still owe the baseline: notices, grounds, security, dual-clock, erasure, rights, processor contracts. You do not owe an annual statutory DPIA because a consultant bundled it with “2027 readiness.”
If you already self-declared, write the Gazette date you last checked. If you have not checked, that is this week’s job, not a purchase.
How should founders sequence notices, rights, and the dual-clock SOP?
After grounds, not before.
| Step | Statute hook | What “done” looks like |
|---|---|---|
| 1. Inventory | Section 8(1) accountability | One sheet; no empty owner |
| 2. Grounds | Section 6 or named Section 7 | Every purpose has a citation |
| 3. Notices | Section 5; Rule 3 | Itemised, stand-alone, at the collection point |
| 4. Rights + grievance | Sections 8(9), 8(10), 11-13; Rule 14 | Named contact; a request that actually reaches CRM |
| 5. Dual-clock SOP | Section 8(6); Rule 7; CERT-In 28 Apr 2022 | Named owners; 6 hours and 72 hours |
| 6. Evidence | Section 8(5) | Reconstruct one customer and one staff file |
Section 5 notice itemises personal data and purpose, and tells the person how to exercise rights and complain to the Board. Rule 3 wants that notice to stand on its own, in clear language, English or any Eighth Schedule language you actually use - not a duty to ship all twenty-two on day one.
Section 6(4) withdrawal must be as easy as giving consent. Test one record through the front door. Count how many systems still hold it an hour later.
A leak still starts two clocks: CERT-In 6 hours and the DPB under Rule 7 72 hours. Name who picks up at 6pm Friday. Processor copies do not leave the Act; the Section 8(2) contract needs an hours-based SLA that lets you hit both clocks.
Architecture that stops identifiers cloning into every tool is the Privigo platform argument for this cohort: sealed PII vault, immutable consent records, evidentiary trail. Software is not the sequence.
What counts as evidence when the Board asks?
A find-replaced policy is narrative.
Pick one live customer and one staff file. Pull: notice version shown that day, purpose granted or refused, ground (Section 6 or which Section 7 limb), processor who still holds a copy, last withdrawal or erasure date. If that pull lives on a shared drive, you have a story. The Board will want a record that was not edited after the complaint arrived.
Do not invent a tenth keep-year from a Limitation Act slide. Do not freeze a marketing list because “KYC is five years” - that slogan belongs to a different cohort and a named RBI class, not to every SMB spreadsheet.
What should the founder put in this month’s pack?
A map the MD can sign. Not a countdown graphic.
| Area | Owner | Status ☐ |
|---|---|---|
| Inventory sheet: systems, purposes, processors, retention, owner | Ops | ☐ |
| Ground per purpose: Section 6 or named Section 7 (incl. 7(i) for necessary HR) | Founder + ops | ☐ |
| Section 5 notice at one live collection point | Product / ops | ☐ |
| Section 8(9) contact who answers; one rights request tested | Ops | ☐ |
| Dual-clock drill: CERT-In 6h + DPB 72h | Founder + whoever holds the keys | ☐ |
| One customer file reconstructed (notice + purpose + processor) | Ops | ☐ |
| Do not buy a Rule 13 pack unless and until notified as an SDF | Finance | ☐ |
Three moves, in order:
- Write the six-line sequence on one page - inventory, grounds, notices, rights, dual-clock, evidence. Put it in this week’s pack.
- Finish the inventory sheet this fortnight - every row an owner. Skipping it to buy software is the 2027 failure mode.
- Reconstruct one customer file - if you cannot, that is the gap, not the missing certificate.
If you want that sequence mapped to your actual CRM, HRMS, and vendors rather than a generic checklist, use the 90-day roadmap as the calendar and this page as the cut.
Book a 30-minute DPDPA discovery call →
Sources
- Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), MeitY - Sections 2, 4-13, 33 and the Schedule: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY - Rules 3, 4, 6, 7, 13, 14: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- DPDP Act commencement, G.S.R. 843(E), 13 November 2025, MeitY: https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
- Press Information Bureau - Digital Personal Data Protection (DPDP) Rules, 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
- CERT-In - Directions under section 70B(6) of the IT Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
This article is operational commentary for Indian SMB founders and ops leads, not legal advice and not a determination that any named company’s programme is lawful. Confirm positions with qualified Indian counsel. Other laws in force continue in parallel with the DPDPA.
FAQ
Is 13 May 2027 the DPDPA deadline 2027 for Indian SMBs?
Yes. Substantive DPDP Rules, 2025 duties - notice, consent, security safeguards, breach intimation, erasure and rights - commence on 13 May 2027, eighteen months after the Rules were notified on 13 November 2025. Consent Manager registration under Rule 4 starts earlier, on 13 November 2026. That date is for registered Consent Managers, not a duty for an ordinary SMB to buy a banner.
Does every SMB need a DPO and a Rule 13 audit before May 2027?
No. Rule 13 annual DPIA and independent audit, and the Section 10(2)(a) Data Protection Officer, start only after a Section 10 Significant Data Fiduciary notification. Most SMBs still need a Section 8(9) contact, Sections 4-9 and 11-14, and a dual-clock runbook. They do not need a pre-notification Rule 13 pack.
Do SMBs need employee consent for payroll under DPDPA?
No. Processing necessary for employment purposes can sit under Section 7(i). Routing payroll through Section 6 consent creates a withdrawal problem you cannot honour. Notice, security, and processor contracts still apply. Optional staff tools still need Section 6: free, specific, informed, unconditional, unambiguous, by clear affirmative action.
Does DPDPA keep the old SPDI sensitive personal data category for SMBs?
No. The DPDPA does not revive the old SPDI sensitive personal data category. Customer phones, employee Aadhaar copies, and vendor emails are personal data under Section 2(t). There is no heavier SMB tier. Sequence the work; do not sort fields into a dead category.


