For two years India's Digital Personal Data Protection Act, 2023 was law without a deadline. It received assent in August 2023, and then nothing was enforceable because the Rules that give it dates, procedures and a Board had not been made. That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025. The clock is now running, and for most obligations it runs out in the first half of 2027.
This post is about what that means if you run business email, which is every organisation with customers or employees. It is the news-and-timeline companion to our evergreen guide, DPDP compliant email: what the law asks of your mailboxes, which has the full duty-by-duty walk-through and a checklist you can download.
What the Rules added that the Act only implied
- A breach clock. The Act said a Data Fiduciary must intimate the Data Protection Board and affected individuals of a personal data breach. The Rules put a number on it: the Board within 72 hours, with the nature, extent, timing and remedial steps; affected individuals without delay. A compromised mailbox holding customer data is a breach, so the 72 hours starts the moment you know a mailbox has been taken over.
- What "reasonable security safeguards" means. The Act used the phrase; the Rules list the minimum: encryption, obfuscation or masking of personal data, access control, monitoring and logging to detect unauthorised access, and retention of logs and related data for long enough to detect and investigate a breach, at least a year. Every one of those lands on email: TLS and S/MIME, MFA and role-based admin, audit trails, log retention.
- Erasure mechanics. Erase personal data once the purpose is served or consent is withdrawn, with defined notice periods for certain large platforms. For email that means an archive policy rather than keeping everything forever.
- A published contact. The business contact of the person who answers data questions, and a grievance route with a response time. Your customers will find it on your website, and they will email it.
- Consent Managers, registered with the Board, as a way for individuals to give, manage and withdraw consent across services; registration opens 12 months after notification.
The one thing the Rules did not add
A localisation mandate. The Act permits transfer of personal data outside India except to countries the Central Government notifies as restricted (s. 16), and the Rules did not turn that into a requirement to keep data, or your mail server, in India. If a vendor tells you "DPDP requires Indian hosting", they are wrong, and a compliance head will know it. Localisation duties for email come from elsewhere: RBI's 2018 direction on payment system data, CERT-In's 2022 requirement to keep ICT logs for 180 days within India, and sector frameworks from SEBI and IRDAI. Indian hosting or an on-premise server makes DPDP accountability easier to evidence, and that is the honest reason to choose it.
The timeline, and what to do in which order
- 13 November 2025: Rules notified. The Data Protection Board provisions took effect immediately.
- +12 months (November 2026): Consent Manager registration provisions.
- +18 months (first half of 2027): the remaining obligations on Data Fiduciaries: notice and consent, security safeguards, breach intimation, erasure, individual rights, grievance handling.
Work backwards from the 18-month mark. The three items that take longest and that the Board will look at first after a breach are access control (MFA everywhere, role-based admin, same-day leaver removal), logging (retained, monitored, on synchronised clocks) and the breach playbook (from "mailbox compromised" to a Board notification in 72 hours, with named owners). Start those now. Consent records for marketing lists, the erasure policy and the published contact can follow in early 2027, but not later.
Penalties, briefly
The Schedule to the Act sets the ceilings: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for the duties around children's data, up to ₹150 crore for a Significant Data Fiduciary's additional obligations, and up to ₹50 crore for any other breach. Penalties are per instance, decided by the Board after inquiry.
Where to go from here
The DPDP compliant email page has the six duties in detail, a ten-point readiness checklist you can tick through, and a downloadable PDF version with the section of the Act or the Rules behind every line. If you are regulated, the sector overlays are on our RBI, SEBI CSCRF and IRDAI checklists. Guidance, not legal advice; the texts govern.


