India's data protection rules reach your website by May 2027
India's Digital Personal Data Protection rules phase in over 18 months, with a consent deadline in November 2026 and full enforcement in May 2027. Here is what a small business website needs before then.

The short version
India’s DPDP Act now has Rules, and they phase in over 18 months: historical consent records need revalidating by 13-14 November 2026, and full enforcement with penalties starts 13-14 May 2027 (India Briefing, 2026). A small business website needs four things: a plain privacy notice, a consent tick box that is not pre-ticked, an email address for deletion requests, and a named contact for complaints. Ask whoever built your site to add them, and check old customer lists before November.
This one is for India only. If your business is in the US, Ireland or the euro area, the rules here do not apply to you, though the habits are good ones anywhere.
India’s Digital Personal Data Protection Act was passed in 2023, and the Rules that make it work were notified in November 2025 and phase in over 18 months. So the deadlines fall within the next year rather than in some distant one.
A café taking bookings, a dentist with a patient form, a salon with a WhatsApp list: all of them collect personal data, and all of them are covered. This article is about what a basic small business website should have in place. It is not legal advice, and anything beyond a basic site needs a lawyer who knows the Act.
The dates, in one table.
| When | What | What it means for you |
|---|---|---|
| June to August 2026 | The central government was expected to operationalise the Consent Manager framework | Noted for completeness. If a tool you use mentions it, ask a lawyer. |
| 13-14 November 2026 | Legacy data revalidation deadline: historical consent and notice records revalidated | Your existing customer lists need consent you can show. |
| November 2026 | Soft enforcement ends; the Data Protection Board of India shifts toward active supervision | Have the basics on your site by then. |
| 13-14 May 2027 | Full enforcement: the 18-month transition ends; full adjudicatory power and penalties active | Everything should be done. |
The two dates to write down are the November one and the May one. In November 2026 the soft enforcement period ends and the Data Protection Board of India, the body that supervises the Act, moves toward active supervision; in May 2027 the transition finishes and penalties are live. Between now and then is the time to do the small amount of work this article describes.
The November date is the one people miss, because it is about data you already hold rather than data you collect from now on. That gets its own section below.
It covers any business that collects a name and a phone number.
The Act is about digital personal data, and a small business collects it every day. A name and phone number on a booking form. An email address in a newsletter box. An appointment time next to a patient’s name. A saved address for a delivery. If it identifies a person and it sits on a computer, a phone or a website, it counts.
Law-firm commentary on the 2026 milestones describes the shape of what is expected: a notice that says what you collect and why, consent from the person before you collect it, and a way for them to raise a grievance and be heard (Mondaq, 2026). Those three ideas, notice, consent and complaints, run through the rest of this article.
As reported, the Rules do not appear to contain a size-based exemption. If you think one applies to you, ask a lawyer rather than assuming. A small salon and a hospital chain collect the same kind of data, and the Act is written around the data, not the size of the business.
Your website needs a privacy notice, a tick box and a way to delete.
A basic small business website needs four things, and none of them is expensive.
- A privacy notice page. One plain page saying what you collect (name, phone, email, appointment details), why you collect it, and how long you keep it. Link to it from the footer and from every form.
- A consent tick box on every form. It sits next to the link to the notice, and it is empty until the customer ticks it. A box that is already ticked is not consent.
- A way to ask for deletion. An email address on the notice page where a customer can ask what you hold about them and ask for it to be deleted. Then act on the request.
- A named contact for complaints. A person, with an email address, who answers when something goes wrong. In a small business that is usually the owner.
Nothing here needs a lawyer to write the first draft. The notice should read like the rest of your site: short sentences, no legal padding. If your booking form belongs to a booking tool rather than your own site, check that the tool lets you add a tick box and a notice link. Most do. The bookings article covers what a good booking flow looks like, and this fits inside it.
Try this now
Open your own website on your phone and fill in the contact or booking form. Count the pieces of personal data it asks for. Then look for a privacy notice link and a tick box. If either is missing, that is the first job.
Old lists need looking at before November.
The November deadline is about data you already hold. The timeline calls it “legacy data revalidation”: historical consent and notice records need revalidating by 13-14 November 2026 (India Briefing, 2026).
For a small business that means the customer lists built up over years. The WhatsApp broadcast list started long ago. The spreadsheet of every patient. The booking tool’s export with everyone who ever made an appointment. If you cannot show that those people agreed to hear from you, the safe course is to ask them again, or to stop using the list.
Customers who booked recently and ticked a box
A list bought or copied from somewhere else
A WhatsApp chat where the customer messaged you first and you are answering their enquiry
A broadcast list of numbers collected from a counter sheet years ago
Appointment records you need to deliver the service or to keep your accounts
Booking data for people who have not returned and whom you have no reason to contact
Keeping less is the easiest form of compliance. Data you have deleted cannot leak, cannot be asked about, and cannot be the subject of a complaint. Go through the lists once, decide which column each one belongs in, and delete what is in the second column. The WhatsApp Business article explains how broadcast lists work in the free app, which helps when deciding what to keep.
What to ask whoever built your site.
Most of this is an afternoon’s work for whoever built your site, and a new site should be planned with it from the start. If you are about to build one, the planning article has the questions to settle before a designer starts, and the privacy notice belongs on that list.
- A privacy notice page exists, in plain words, and is linked from the footer.
- It says what is collected, why, and how long it is kept.
- Every form has a consent tick box that is empty by default.
- The notice gives an email address for asking to see or delete data.
- One named person handles complaints, and their contact is on the notice.
- Old customer lists have been checked, re-consented or deleted before 13-14 November 2026 (India Briefing, 2026).
- Booking and messaging tools have been checked for the same tick box and notice link.
- Anything beyond a basic site has been put to a lawyer who knows the Act.
0 of 8 checked
Then leave it alone. The Data Protection Board of India and the penalties that switch on in May 2027 matter most to businesses that ignored the basics. A site with a notice, a tick box and a working deletion address is most of the way there.
A few common questions.
Does the DPDP Act apply to a one-person business?
As reported, the Rules do not appear to include a size-based exemption, so assume yes. The Act is about the data, not the size of the business. If you believe an exemption applies to you, ask a lawyer rather than relying on this article.
What is the deadline?
There are two dates to note. Historical consent and notice records need revalidating by 13-14 November 2026, and full enforcement with penalties starts on 13-14 May 2027. The soft enforcement period ends in November 2026. The Rules were notified in November 2025 and phase in over 18 months.
Do I need a consent tick box on my contact form?
The safe course is yes, for any form that collects a name, phone number or email address. The Act allows some data a person volunteers for a stated purpose to be used without separate consent, so a lawyer may tell you a plain contact form can do without one. Until you have that advice, a tick box costs nothing. It should be empty until the customer ticks it, and sit next to a link to your privacy notice.
What about my WhatsApp broadcast list?
Treat it as personal data you hold. If the people on it messaged you first and you are replying to their enquiries, that is one thing. If it is a list of numbers gathered over years without a clear yes, the safe course is to ask again or stop sending to it before November 2026.
What is the Data Protection Board of India?
The body the Act sets up to supervise it and decide cases. During the soft enforcement period it is not yet using its full powers. From November 2026 it shifts toward active supervision, and from May 2027 it has full adjudicatory power and penalties are active.
Do I need a lawyer for this?
For a basic site with a contact or booking form, the four things in this article are within reach of whoever built the site. For anything beyond that, or if you are not sure how the Act applies to what you collect, talk to a lawyer who knows it. This article describes what a basic site should have; it does not replace that conversation.