Somewhere between the Gazette notification and the compliance deadline, most Indian companies looking for a DPDP Compliance Solution in India lose the plot on the Digital Personal Data Protection Act. Not because the law is unreasonable. Because operationalizing it, across consent banners, vendor contracts, breach drills, and a dozen spreadsheets nobody quite owns, turns out to be a genuinely different problem than reading the law.
That gap between “we understand the DPDP Act” and “we can prove compliance on demand” is exactly where a dedicated DPDP compliance solution earns its keep. This guide walks through what that actually means in practice, and how RuleExpert, an AI-powered DPDP compliance infrastructure platform, closes that gap for Indian organisations of every size.
If you’re a founder, compliance manager, CFO, or Company Secretary trying to figure out where to even start, this is written for you.
Where India’s DPDP Deadline Actually Stands Right Now
Most DPDP content on the internet either treats the law as still hypothetical or assumes it’s already fully enforced. Neither is accurate as of today. Here’s the real, current picture.
The DPDP Rules, 2025 commence in three distinct phases, and each phase unlocks a different set of obligations:
| Phase | Effective date | What kicks in |
|---|---|---|
| Phase 1 | 13 November 2025 | Rules 1, 2 and 17–21 – the Data Protection Board’s constitution, procedure, and terms of service take immediate effect |
| Phase 2 | 13 November 2026 | Rule 4 – Consent Manager registration and obligations become operational |
| Phase 3 | 13 May 2027 | Rules 3, 5–16, 22–23 – the substantive obligations: notice requirements, security safeguards, breach reporting, children’s data protections, Significant Data Fiduciary duties, and Data Principal rights |
That’s directly from the official MeitY/PIB backgrounder on the DPDP Rules, 2025, published to explain the notification to the public.
A detail that surprises a lot of business owners: the Data Protection Board of India exists in law, but as of mid-2026, legal press including LiveLaw reported that it had not yet had a Chairperson or Members appointed, even though the Search-cum-Selection Committee process (chaired by the Cabinet Secretary, per Rule 17) had been underway since late 2025.
Government officials have since confirmed the appointment process and the Board’s digital infrastructure are actively being built out. In plain terms: the regulator is being assembled while the compliance clock is already running.
Here’s why that timeline matters more than it might look like on paper. Eighteen months sounds generous until you map it against what “compliance” under Phase 3 actually demands: a live personal data inventory, a working consent architecture, vendor contracts rewritten with DPDP-specific clauses, a tested breach response process, and audit trails for all of it going back months, not weeks.
None of that gets built in the final quarter before 13 May 2027. It gets built now, or it gets built in a panic later, usually right after a customer complaint or a vendor incident forces the issue.
This is the practical argument for starting with a DPDP compliance solution well before enforcement bites: readiness isn’t a switch you flip, it’s a record you accumulate.
What a DPDP Compliance Solution in India Is
A genuine DPDP compliance solution is not a policy template pack, and it isn’t a single dashboard bolted onto your existing tools. It’s operational infrastructure – the connective tissue between what the law requires and what your teams actually do every day.
Three things separate a real compliance solution from a compliance-adjacent tool:
It runs continuously, not once a year. A DPIA done in January is a snapshot. Consent captured today, tracked and honoured through every subsequent interaction, is a living record. The Act’s obligations (notice, consent, breach reporting, data principal rights) aren’t one-time filings; they’re standing operational duties.
It produces evidence, not just policy. When the Data Protection Board or an auditor asks “show me,” a folder of Word documents drafted eighteen months ago doesn’t answer the question. Timestamped logs of who consented to what, when a Data Subject Request was actioned, and which vendor was reviewed and when, do.
It connects the dots across functions. DPDP compliance touches legal, IT, HR, marketing, and vendor management simultaneously. A spreadsheet in Legal’s shared drive that nobody in Marketing has seen isn’t compliance infrastructure – it’s a liability with a filename.
This is precisely the gap RuleExpert is built to close: DPDP documentation automation and workflow, not just DPDP documentation.
DPDP Compliance, in Plain Terms
Strip away the acronyms and “DPDP compliance meaning” comes down to one operational question: can you show, at any moment, that personal data in your custody is collected with valid consent, used only for the purpose it was collected for, protected with reasonable safeguards, and deletable or correctable on request? If the honest answer involves phrases like “we’d have to check with three different people,” that’s the gap a compliance solution exists to close.
What Is RuleExpert?
RuleExpert is an AI-powered DPDP compliance platform that helps organisations operationalise compliance with the Digital Personal Data Protection Act, 2023, through centralised workflows, automation, and audit-ready documentation.
The distinction RuleExpert draws – and the one worth understanding before you evaluate any DPDP compliance tool in India – is between a documentation platform and a compliance infrastructure platform. A lot of tools in this space help you write policies faster. RuleExpert is built to make compliance something your organisation does, continuously, with automation doing the tracking, reminding, and evidencing that used to fall on an overworked compliance manager and a shared drive.
That shows up in how the platform is structured. Instead of one generic “compliance dashboard,” RuleExpert is organised around the actual operational surfaces where DPDP risk lives: consent, data subject requests, the data inventory itself, breach response, and third-party vendors, each with its own workflow engine, all feeding one central audit trail.
RuleExpert’s compliance strategy and product direction are led by Nitin Ray, the platform’s Compliance Manager, whose work centres on bridging the gap between regulatory requirements under the DPDP Act and how organisations actually implement them day to day, from consent lifecycle management to Data Subject Request workflows and audit readiness.
See the platform in action – book a RuleExpert demo.
Inside the RuleExpert Platform: Module by Module
DPDP Readiness Assessment (DPDP Scorecard)
Before you can fix a compliance gap, you need to know it exists. The DPDP Scorecard evaluates an organisation’s current readiness against the Act’s requirements: a compliance maturity assessment, gap identification, a readiness score, and actionable recommendations, rolled into an executive dashboard with a practical compliance roadmap attached. This is usually where a RuleExpert engagement starts, because it turns “we should probably look into DPDP” into a prioritised, ranked list of what to fix first.
Consent Management
Consent under the DPDP Act isn’t a one-time checkbox; it’s a lifecycle. RuleExpert’s Consent Manager handles the full arc: consent collection, purpose management, consent records management, withdrawal, consent history, and a complete audit trail of every consent event. When a Data Principal asks “what did I actually agree to, and when did I withdraw it,” the answer needs to be immediate and exact, not reconstructed from memory.
Data Subject Request (DSR) Automation
Every request a Data Principal files (access, correction, erasure) comes with an implicit clock and an explicit expectation of a documented process. RuleExpert automates request intake, workflow routing, responsibility assignment, approval steps, SLA monitoring, and status tracking, and produces audit-ready documentation for every request as it closes. Nothing sits in an inbox waiting for someone to notice it’s overdue.
Data Registry
You cannot protect data you haven’t mapped. The Data Registry maintains a centralised, living inventory of personal data across the organisation: what’s collected, where it sits, which business systems touch it, who owns it, and why it was collected in the first place. This is the foundation almost every other module depends on, because consent, DSR fulfilment, and breach scoping all require knowing exactly what data exists and where.
Breach Management
Under Rule 7 of the DPDP Rules, 2025, a Data Fiduciary that becomes aware of a personal data breach must intimate affected Data Principals and the Data Protection Board without delay, followed by a more detailed report to the Board within 72 hours (or a longer period if the Board permits it in writing).
RuleExpert’s Breach Management module is built around that exact cadence: incident reporting, investigation workflows, risk assessment, evidence management, corrective action tracking, and breach documentation that’s audit-ready from the moment the incident is logged, not reconstructed under pressure after the fact.
Vendor Governance
Most personal data breaches don’t originate inside the organisation that gets fined for them – they originate with a vendor. RuleExpert’s Vendor Governance module maintains a vendor inventory, runs structured vendor risk assessments, tracks due diligence and compliance reviews, stores vendor documentation, and sets review reminders so third-party oversight doesn’t quietly lapse between audits.
Workflow Automation, AI-Powered Assistance, and Role-Based Access
Underneath every module above, RuleExpert replaces manual, spreadsheet-driven processes with structured task assignment, approvals, notifications, and escalation management, so nothing depends on someone remembering to follow up.
An AI-powered compliance assistance layer adds intelligent workflow support, documentation help, and operational recommendations on top. Role-based access control makes sure the right people, and only the right people, can see and act on sensitive compliance data, with a clear approval hierarchy for secure cross-department collaboration.
Audit-Ready Documentation and Dashboards
Every action taken inside RuleExpert (a consent captured, a request closed, a vendor reviewed, a breach logged) feeds a centralised documentation layer: activity logs, version history, an evidence repository, and compliance reports that are ready to hand over the moment an auditor, a client’s due diligence team, or eventually the Data Protection Board asks to see them.
Executive dashboards then translate all of that into a live view of compliance status, incident tracking, risk reporting, and operational metrics, so leadership isn’t waiting on a quarterly report to know where the organisation stands.
How RuleExpert Solves Compliance Problems by Role
DPDP compliance isn’t owned by one department, and it doesn’t look like the same problem to everyone in the building. Here’s what RuleExpert actually solves depending on your seat at the table.
Founders and Managing Directors carry the ultimate liability, and the Act’s penalty Schedule doesn’t care about company size. What RuleExpert gives you is a single source of truth: one dashboard that answers “are we compliant” honestly, instead of a patchwork of assurances from different teams who each think someone else owns the risk.
COOs need compliance to run as a process, not a project. RuleExpert’s workflow automation turns DPDP obligations into standard operating procedure: assigned owners, SLAs, and escalation paths that function whether or not any one person remembers to check.
CFOs are increasingly the ones asked to model regulatory exposure. With penalties running up to ₹250 crore for a single failure to implement reasonable security safeguards, DPDP risk belongs on the same risk register as any other material financial exposure. RuleExpert’s audit trail and readiness scoring give CFOs a defensible number to point to, and evidence of active mitigation if that number ever gets questioned.
CHROs own a category of personal data that’s uniquely sensitive: employee records, biometric attendance, background checks, health declarations. RuleExpert’s Data Registry and Consent Management modules extend the same governance to HR-held data that customer-facing teams get, closing a gap that’s easy to overlook internally.
Chief Compliance Officers and Compliance Managers are the primary daily users of the platform, and the ones who feel the difference between “compliance on paper” and “compliance in practice” most acutely. RuleExpert is built to be the operational backbone for this role: DSR queues that don’t require manual chasing, breach workflows that trigger themselves, and documentation that assembles itself as work happens rather than needing to be recreated before an audit.
Company Secretaries and Legal/Admin Managers are frequently the ones fielding board questions about regulatory exposure and drafting the board resolutions and disclosures that follow. RuleExpert’s executive dashboards and compliance reports are built to be board-presentation-ready, not just internally useful.
Chartered Accountants and statutory auditors increasingly need to factor DPDP exposure into audit opinions and risk disclosures. A platform that maintains continuous, timestamped evidence makes that assessment materially faster and more defensible than a client that “believes” it’s compliant.
DPDP Act Compliance Checklist for Indian Businesses
If you’re starting from zero, here’s a practical, sequenced checklist. This isn’t exhaustive legal advice – it’s the operational starting point most organisations need, in the order it usually makes sense to tackle it.
- Map your personal data. Build an inventory of what personal data you collect, where it’s stored, which systems touch it, and who’s responsible for it. You cannot comply with an Act you can’t see the shape of.
- Classify your role. Determine whether you’re a Data Fiduciary, a Joint Data Fiduciary, a Data Processor, or a Significant Data Fiduciary. Obligations under Section 10 of the DPDP Act scale up meaningfully if you’re classified as an SDF, based on qualitative factors like the volume and sensitivity of data processed, not a fixed numeric threshold.
- Rebuild your consent architecture. Notices need to be clear, itemised, and standalone, with an equally easy path to withdraw consent as to give it.
- Stand up a Data Subject Request process. Have a defined, timed workflow for access, correction, and erasure requests before the first one arrives, not after.
- Implement reasonable security safeguards. This is the highest-penalty provision in the Act – up to ₹250 crore under the Schedule to Section 33 for a failure that leads to a breach.
- Build (and rehearse) your breach response plan. Rule 7’s “without delay” initial intimation and 72-hour detailed report to the Board is not a timeline you want to be improvising under pressure.
- Audit every vendor with data access. Contracts need DPDP-specific clauses, and vendor risk needs periodic, documented review, not a one-time onboarding check.
- Appoint accountable owners. Significant Data Fiduciaries have additional obligations, including data protection officer-level accountability, under Rule 13.
- Document everything, continuously. Policies alone aren’t a defence. Timestamped, retrievable evidence of ongoing compliance is.
- Reassess on a fixed cadence. DPDP compliance isn’t a project with an end date; treat it like any other standing operational risk, with periodic scorecard reviews.
Every one of these ten steps maps directly to a RuleExpert module – which is precisely the point of building a platform around the checklist rather than leaving it as a document nobody revisits.
DPDP Compliance for Startups vs Enterprises vs Significant Data Fiduciaries
Startups and MSMEs often assume DPDP compliance is an enterprise problem. It isn’t – the Act applies regardless of company size, and the DPDP Rules, 2025’s own consultation record shows the government explicitly consulted startups and MSMEs while drafting the phased compliance window precisely because smaller organisations need it.
What a lean team needs from a DPDP compliance solution is speed to baseline: get a readiness score, fix the highest-risk gaps first, and avoid building an in-house compliance function from scratch. RuleExpert’s Scorecard-first approach is built for exactly that starting position.
SaaS companies face a specific complication: personal data usually flows through their product, not just their internal operations, which means DPDP compliance has to be embedded into product and engineering workflows, not bolted on as an afterthought in Legal. Data Registry mapping and Consent Management matter more here because the “data” in question is often a customer’s customer data too.
Enterprises and Significant Data Fiduciaries carry the heaviest obligations under Rule 13 of the DPDP Rules – Data Protection Impact Assessments, independent data audits, and appointed accountability roles. At this scale, manual tracking across business units simply doesn’t hold up under audit scrutiny, which is where RuleExpert’s role-based access, multi-department workflows, and centralised audit trail earn their keep.
What to Look for in DPDP Compliance Software (and Where RuleExpert Fits)
Search for “best DPDP compliance software in India” or “top DPDP compliance tools 2026” and you’ll find no shortage of options claiming the title. Most buyers evaluating a DPDP compliance tool in India are really comparing across three very different starting points, and it’s worth being clear-eyed about which one you’re actually choosing between.
Spreadsheets and shared drives work fine for a policy document. They fall apart the moment you need to answer “show me every consent withdrawal from the last quarter” or “which vendors haven’t been reviewed in 12 months” under time pressure. Nothing is timestamped automatically, nothing escalates itself, and version control is a matter of file-naming discipline.
Consultants and one-time audits are genuinely valuable for interpretation and strategy, but a compliance audit is a snapshot, not a system. Six months after the engagement ends, the org chart has changed, three new vendors have been onboarded, and nobody’s tracking whether the recommendations actually got implemented.
Point tools (a consent banner here, a DSAR form there) solve one problem while leaving the others disconnected. A DPDP consent management software that doesn’t talk to your vendor register or your breach workflow still leaves you assembling the full compliance picture manually when it matters most.
Whichever category of DPDP compliance software you’re evaluating, a few criteria tend to separate the tools that hold up under real audit pressure from the ones that look good in a sales demo and thin out afterward:
| What to check | Why it matters |
|---|---|
| Does it function as a DPDP risk assessment tool from day one, or only after setup? | You need a baseline readiness score before you can prioritise fixes – not after months of configuration |
| Does it double as DPDP audit software, generating evidence automatically? | Evidence created after the fact, under audit pressure, is far weaker than evidence timestamped as work happens |
| Does it cover consent, DSR, breach, and vendor risk in one system? | Disconnected point tools recreate the spreadsheet problem, just with better UI |
| Is it built specifically for the DPDP Act, or adapted from a GDPR or CCPA product? | India-specific timelines (72-hour breach reports, the Section 33 Schedule, SDF thresholds) don’t map cleanly onto foreign frameworks |
| Does it scale from startup to Significant Data Fiduciary without a platform switch? | Re-platforming mid-growth is expensive and creates compliance gaps of its own |
RuleExpert was built as a privacy automation platform for the Indian market specifically, not adapted from a global product, which is why its workflows map directly onto DPDP Rule numbers, Section 33 penalty categories, and India-specific obligations like Consent Manager interoperability.
As an AI compliance automation platform, it connects the DPDP Scorecard, Consent Manager, DSR Automation, Data Registry, Breach Management, and Vendor Governance modules to one audit trail, instead of leaving them as six disconnected tools that don’t talk to each other.
Common DPDP Compliance Mistakes Indian Businesses Make
Anyone researching how to comply with the DPDP Act in India eventually runs into the same handful of avoidable mistakes. Here are the ones that show up most often.
Treating consent as a one-time banner, not a lifecycle. A cookie banner that captures consent once, with no mechanism to track withdrawal or update purpose, satisfies the letter of nothing. Consent needs to be as easy to withdraw as it was to give, and every state change needs a timestamp.
Assuming DPDP is an IT problem. Personal data lives in HR systems, marketing automation, customer support tools, and vendor platforms, not just the core product database. Compliance programmes that stay siloed in IT routinely miss entire categories of exposure sitting in other departments.
Skipping the vendor audit. As covered in the section below, a huge share of real-world exposure sits with third parties, not the organisation that ultimately answers to the Data Protection Board.
Writing a breach response policy and never rehearsing it. A document that says “notify the Board within 72 hours” is not the same as an organisation that actually knows who does what in the first hour after a breach is discovered. The gap between the two is usually measured in real financial exposure.
Confusing “we have a policy” with “we have evidence.” Auditors, clients running due diligence, and eventually the Data Protection Board don’t ask whether a policy exists. They ask for proof it’s being followed – logs, timestamps, and records, not PDFs.
Waiting for the enforcement deadline. The 13 May 2027 date feels distant until you map backward from it: data mapping, consent rebuild, vendor re-papering, and breach rehearsal all take real time. Starting the week before enforcement isn’t a plan.
Vendor Risk Management Under DPDP: Where Most Companies Are Exposed
Ask most compliance teams where their DPDP exposure actually sits, and the honest answer, once you dig past the internal policies, is usually: in a vendor contract nobody’s reviewed since it was signed. Cloud storage providers, marketing automation platforms, payment processors, HR software, customer support tools – every one of them potentially touches personal data your organisation is accountable for, whether or not they’re the ones who ultimately mishandle it.
RuleExpert’s Vendor Governance module treats this as a standing discipline rather than a one-time onboarding checkbox: a centralised vendor inventory, structured risk assessments per vendor, tracked due diligence, scheduled compliance reviews, and automatic review reminders so a vendor relationship that was low-risk at signing doesn’t quietly become high-risk two product updates later without anyone noticing.
This matters more than it might seem for one specific reason: under the Act, accountability for personal data doesn’t transfer away just because a vendor is the one who actually processes it. A gap in vendor oversight is still your compliance gap.
Breach Management and the Data Protection Board: What Readiness Looks Like
If your organisation is compliance-mature enough to have DPDP on the radar, breach readiness is usually the item that gets the most anxious attention, and for good reason. The Schedule to Section 33 of the DPDP Act sets a penalty of up to ₹250 crore for a failure to implement reasonable security safeguards that leads to a breach, and up to ₹200 crore separately for failing to notify the Board and affected Data Principals about a breach that does occur.
The mechanics that matter, under Rule 7:
- Initial intimation to affected Data Principals and the Board must happen without delay upon becoming aware of the breach – not once the investigation is complete.
- A detailed follow-up report to the Board is due within 72 hours, unless the Board grants a longer period on a written request.
- Notices to Data Principals must be in plain, concise language, describing the nature and extent of the breach and what’s being done about it.
The Data Protection Board’s own status is worth tracking too. It was constituted in law from 13 November 2025 under Section 18, but as of mid-2026, was still in the process of having its Chairperson and Members formally appointed – a gap the government has been actively working to close. That doesn’t mean breach obligations are optional in the meantime; the notification and safeguard duties apply regardless of whether the Board’s bench is fully staffed on the day an incident occurs.
This is exactly the scenario RuleExpert’s Breach Management module is built around: a workflow that starts the moment an incident is flagged, routes investigation and evidence capture automatically, and keeps the Rule 7 clock visible so “without delay” and “72 hours” are tracked deadlines, not aspirational language in a policy document nobody re-reads during an actual incident.
For a deeper look at the Board’s structure, powers, and what audit-readiness for a DPB inquiry actually involves, see our companion piece on the Data Protection Board of India.
How to Get Started with RuleExpert
Most organisations that reach out to RuleExpert aren’t starting from “we’ve read the Act.” They’re starting from “we know we’re exposed and we don’t know how big the gap is.” That’s the right starting point, and it’s exactly what the DPDP Scorecard is built to answer first.
A typical path looks like this:
- Readiness assessment – run the DPDP Scorecard to get a maturity score and a prioritised gap list.
- Foundational setup – stand up the Data Registry (what data exists, where) and Consent Manager (how it’s collected and tracked going forward).
- Operational rollout – activate DSR Automation, Breach Management, and Vendor Governance as live workflows, not policy documents.
- Continuous monitoring – use the executive dashboards to track readiness, incidents, and vendor risk on an ongoing basis, with the audit trail building automatically underneath.
There’s no reason to wait for the 13 May 2027 deadline to start step one. The organisations in the strongest position when enforcement fully lands will be the ones who treated the current window as build time, not grace period.
If you’re at the stage of comparing DPDP compliance software before you buy, the honest advice is to start with the Scorecard regardless of which vendor you eventually choose. A readiness number changes what you’re buying from a guess into a scoped decision.
Book a RuleExpert demo and get a clear picture of where your organisation stands today, with a roadmap for what to fix first.
Nitin Ray is a Compliance Manager at RuleExpert with expertise in DPDP compliance, data privacy, consent management, and governance. He helps organizations implement practical compliance frameworks and automation strategies to meet the requirements of India’s Digital Personal Data Protection Act, 2023.
Follow: Medium · Patreon · Pinterest · Quora · Reddit · Tumblr
Frequently Asked Questions
1. What is a DPDP compliance solution? A DPDP compliance solution is a software platform that helps organisations operationalise the obligations under India’s Digital Personal Data Protection Act, 2023 – consent management, data subject request handling, breach response, vendor oversight, and audit documentation – as ongoing, automated processes rather than one-time policy exercises.
2. Is RuleExpert suitable for startups, or only large enterprises? RuleExpert is built to scale across company sizes. Startups typically start with the DPDP Scorecard to identify the highest-priority gaps quickly, while enterprises and Significant Data Fiduciaries use the full suite, including role-based access control and multi-department workflows, to manage more complex compliance obligations.
3. How is RuleExpert different from hiring a compliance consultant? A consultant provides a point-in-time assessment and recommendations. RuleExpert provides the operational infrastructure to implement and continuously maintain those recommendations, generating timestamped, audit-ready evidence as work actually happens, rather than needing to be reconstructed later.
4. Do I need to comply with the DPDP Act if my company is small? Yes. The DPDP Act, 2023 does not exempt organisations based on size in the way some other jurisdictions’ privacy laws do. Obligations do scale up for organisations classified as Significant Data Fiduciaries under Section 10, based on qualitative factors such as the volume and sensitivity of personal data processed, not a fixed headcount or revenue threshold.
5. What happens if my organisation doesn’t comply with the DPDP Act? The Schedule to Section 33 of the Act sets monetary penalties of up to ₹250 crore for failing to implement reasonable security safeguards leading to a breach, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for violations involving children’s data, up to ₹150 crore for Significant Data Fiduciary obligation failures, and up to ₹50 crore for other violations, imposed by the Data Protection Board of India after an inquiry.
6. When do I actually need to be compliant by? The substantive obligations under the DPDP Rules, 2025 – notice, security safeguards, breach reporting, and Data Principal rights – come into force on 13 May 2027. Consent Manager registration obligations under Rule 4 become operational earlier, on 13 November 2026. Waiting until either deadline to begin preparation is not advisable given how much operational groundwork compliance requires.
7. What is a Data Subject Request (DSR), and does my business need a formal process for it? A Data Subject Request (referred to as a Data Principal’s rights under the Act) is when an individual asks to access, correct, or erase their personal data, or exercises other rights under Chapter III of the DPDP Act. Yes – organisations need a defined, timed, and documented process to handle these requests, which RuleExpert’s DSR Automation module manages end to end.
8. Does RuleExpert help with vendor and third-party risk under DPDP? Yes. RuleExpert’s Vendor Governance module maintains a vendor inventory, runs structured risk assessments, tracks due diligence and compliance reviews, and sets recurring review reminders, since accountability for personal data doesn’t transfer away from your organisation just because a vendor processes it.
9. Is the Data Protection Board of India currently operational? The Board was constituted in law from 13 November 2025 under Section 18 of the DPDP Act. As of mid-2026, legal press reported it had not yet had its Chairperson and Members formally appointed, though the government’s selection process was actively underway. Breach notification and other statutory obligations apply regardless of the Board’s staffing status.
10. How long does it take to become DPDP-ready with RuleExpert? It depends on your starting point and organisational complexity, but most organisations can complete an initial DPDP Scorecard assessment and have foundational modules (Data Registry and Consent Manager) operational within weeks, not months. Book a demo for a timeline specific to your organisation.