India's data-protection law stopped being a draft on 13 November 2025, when the Digital Personal Data Protection Rules, 2025 were notified and the Government fixed three commencement dates for the Digital Personal Data Protection Act, 2023. Most businesses in Uttar Pradesh that collect personal data, which is to say most businesses, have never mapped what they hold. This article sets out the timeline and what should be ready before each date.
The three phases
| Date | What comes into force | What it means for you |
|---|---|---|
| 14 November 2025 | The Data Protection Board of India; definitions; the rule-making framework | The regulator exists. Complaints and penalties become possible once substantive duties apply. |
| 14 November 2026 | Consent-manager provisions and registration | Platforms that manage consent on behalf of individuals must be registered; businesses that rely on them should have their integrations planned. |
| 13 May 2027 | All remaining provisions: notice, consent, data-fiduciary obligations, rights of data principals, breach intimation, children's data, penalties | Full compliance. Every duty in the Act applies from this date. |
The eighteen-month runway was designed for organisations to prepare. Half of it has already passed.
Who is a data fiduciary
Anyone who decides the purpose and means of processing digital personal data. In practice, in Lucknow: hospitals, clinics and diagnostic labs; schools, colleges and coaching institutes; e-commerce sellers and D2C brands; NBFCs, fintech and lending apps; real-estate developers and housing societies; employers, for the data of their staff. If a form on your website or app collects a name and a phone number, the Act applies.
What to have ready before 13 May 2027
- A data map. What personal data you collect, from whom, for what purpose, where it is stored, who processes it for you, and how long you keep it. Everything else follows from this document.
- A notice. In plain language, in English and Hindi where your customers read Hindi, stating what you collect, why, how consent can be withdrawn and how to complain. The DPDP Rules prescribe the contents.
- A consent mechanism. Free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and as easy to withdraw as to give. Pre-ticked boxes do not qualify.
- Processor agreements. Written contracts with every vendor that processes personal data for you: the laboratory information system, the school ERP, the cloud provider, the marketing agency. The contract must bind the processor to your obligations.
- A breach procedure. Who decides that a breach has occurred, who notifies the Board and the affected persons, within what time, and in what form. The Rules require intimation to affected data principals and to the Board within the prescribed period.
- A children's-data process, if you serve persons under eighteen: verifiable parental consent, and no tracking or targeted advertising directed at children. Schools and coaching institutes are directly affected.
- A retention schedule. Data must be erased when the purpose is served or consent is withdrawn, unless retention is required by law. The Rules set specific periods for certain classes of fiduciary.
- Reasonable security safeguards. Access controls, encryption where appropriate, logs, and a tested backup. Failure here carries the highest penalty in the Act.
Penalties
The Act provides penalties of up to ₹250 crore for failure to take reasonable security safeguards to prevent a breach, up to ₹200 crore for failure to notify a breach or for breach of obligations in relation to children, and lower ceilings for other contraventions. Penalties are imposed by the Board after an inquiry and depend on the nature, gravity and duration of the contravention, and on the steps taken to mitigate it. A documented compliance programme is therefore not only a defence but a factor in any penalty.
Sector notes
Hospitals and clinics. Patient data is sensitive in every practical sense. The priority is the notice at registration, processor agreements with the LIS and TPA vendors, and the breach procedure. Front-desk staff need to know what to say when they collect an Aadhaar copy.
Schools and coaching institutes. Children's data and verifiable parental consent are the hard parts. Marketing to students is restricted. Admission forms and ERP contracts need review.
E-commerce and D2C. Consent for marketing must be separate from consent for fulfilling the order. Cookie and tracking consent should be revisited. Marketplace and logistics vendors are processors.
Employers. Employee data has a legitimate-use basis for employment purposes, but notice is still required and the data of former employees must be retained only as long as the law requires.
Where to start
A readiness assessment that produces a two-page roadmap is the right first step for most organisations; a hundred-page policy manual is not. Sarvā Nyāy Legal's data-protection practice runs these assessments for institutions in Lucknow and across Uttar Pradesh, and drafts the documents in the order of exposure.
This article is general information, not legal advice. Statutory dates and figures are as notified; verify the current position before acting.
When To Call Sarvā Nyāy
You do not have to work this out alone. A short first conversation tells you what to preserve, where to file and whether you need us at all. No obligation, no pressure.
Response within 24 hours · Advocate-client confidentiality · Lucknow

