DPDP enforcement India 2027: what actually arrives first
A 260-person staffing firm in Jaipur received its first DPDP letter eleven months before the law bites. It came from a man they did not hire.

DPDP enforcement in India 2027 will not open with an inspection. It opens with one person writing to you about their own data. Section 13 of the Digital Personal Data Protection Act, 2023 gives every data principal a right of grievance redressal, and requires you to publish how they reach you.
Section 13(3) then says the person must exhaust your route before approaching the Data Protection Board. Your inbox is therefore the first line of enforcement, and the Digital Personal Data Protection Rules, 2025 cap your response window at 90 days (Rule 14). A request that dies unanswered in a shared mailbox is exactly what escalates.
The substantive obligations commence on 13 May 2027, under the phased notification of 13 November 2025. The commercial clock is well ahead of the legal one, because enterprise and BFSI buyers are already asking for this in vendor paperwork.
11:52 AM on a Wednesday, and the email had already been forwarded four times before it reached me. Recruitment desk to the HR head, HR head to the founder, founder to the IT lead, IT lead to us, each forward adding one line and no decision. A 260-person recruitment and staffing firm in Jaipur, seventeen recruiters, four verticals, the kind of business whose entire asset is other people’s personal data.
The original was six sentences long and very calm. A man had interviewed with them in 2023 for a role he did not get. He had since seen his own CV forwarded to a company he had never applied to. He wanted to know what they still held about him, on what basis they held it, and he wanted it deleted. He signed off politely and asked for a reply within a fortnight.
Meenal, who runs HR there, called me before I had finished reading. Is this a legal notice, she asked. No, I said. It is worse than that in one specific way. It is the exact thing the law is built around, and you have replied to nothing yet.
The email had been forwarded four times before it reached me
The thread told me more about their compliance posture than any questionnaire would have. Four forwards, three departments, no owner. Nobody in that chain believed the email belonged to them, and everyone assumed the person after them would take it.
Dev, the IT lead, sent me the practical answer inside an hour, which I will say to his credit. Candidate records lived in the recruitment platform. Older ones, from before the platform, lived in a shared drive folder per recruiter. Some lived in individual mailboxes as attachments, because that is how CVs travel in this industry. Salary slips and identity documents collected during offer stages were in a fourth place, an onboarding folder, which had never been cleaned after candidates dropped out.
So what it came to was this. The firm could not say what it held about one named person without a manual search across four systems, two of which had no search worth the name. Achha. That is not unusual. We have seen this shape in staffing, healthcare and education repeatedly, and the tooling is never the reason it happens.
What the thread was actually testing
Here is the part buyers get wrong. They read DPDP as a security law and prepare for an attacker. The first contact almost never involves an attacker. It involves a person exercising an ordinary right, in writing, with a date on it.
Section 11 of the Act gives a data principal the right to ask what personal data you hold and to whom you have shared it. Section 12 gives them correction and erasure. Section 13 gives them a right to grievance redressal, and this is the one that decides your week, because it requires you to have a published means of contact and a stated response period. The Rules cap that period at 90 days for both data fiduciaries and consent managers, per the Digital Personal Data Protection Rules, 2025.
Section 13(3) requires the data principal to exhaust your grievance route before approaching the Data Protection Board. Read that as a warning rather than a shield. It means the Board will only ever see the cases you failed to answer. Every complaint that reaches a regulator has your unanswered email attached to it as page one.
That is the trigger chain in full. Somebody writes. You do not reply, or you reply with a sentence that does not address the request. They escalate. The Board decides whether there are sufficient grounds for an inquiry, and if it proceeds, it examines your affairs. At no point in that sequence did anyone break into anything.
Where DPDP enforcement in India 2027 actually starts
I want to be honest about a mistake, because the mistake is the lesson. For most of last year I told clients that the substantive obligations commence on 13 May 2027, so they had time, and I let that sentence do too much work. Clients heard it as permission to start in 2027. What I should have said is that the date governs when the Board can act, and nothing in it stops a candidate or an ex-employee from writing to you tomorrow with a request you cannot answer.
One of those firms then received a request in March and replied with a line about it being under review. That reply is now the first document in a file that has their name on it. I wrote the guidance that produced it. Bas, no way around that one.
The commencement itself is a phased thing. The Rules were notified on 13 November 2025. Provisions constituting the Data Protection Board took effect straight away. Consent manager provisions follow in November 2026. The obligations most businesses think of as DPDP, notice, security safeguards, breach intimation and data principal rights, land on 13 May 2027. Legislative history and the surrounding text of the Act sit on the PRS legislative tracker if you want the original wording rather than a vendor summary.
Four shapes the first letter takes
Across the mid-market engagements we run, the first DPDP contact has arrived in four recognisable forms. None of them is a hacker. Three of the four come from people who were once inside your building.
| Who writes | What they ask for | What it really tests | What usually breaks |
|---|---|---|---|
| A candidate you did not hire | What you still hold, why, and deletion of it | Whether your retention has an end date | Onboarding folders that were never cleared after a drop-out |
| An employee who resigned badly | Access to their own records and correction of one field | Whether HR data has a single home | Copies in personal mailboxes and on a returned laptop nobody wiped |
| A customer who saw their data somewhere else | The list of parties you shared it with | Whether you track downstream sharing | Vendor and sub-processor lists that live in someone’s memory |
| Your client’s vendor risk team | Evidence of your grievance mechanism and response times | Whether any of this is documented | A published contact that routes to an unmonitored shared inbox |
Rights and the grievance duty above follow Sections 11 to 13 of the Digital Personal Data Protection Act, 2023 and the response period in the Rules of 2025.
The fourth row is the one arriving fastest right now, and it has nothing to do with the Board. Procurement teams at banks and large enterprises have started putting data protection questions into vendor onboarding packs, well ahead of the statutory date. A staffing firm loses that deal on a form, not on a fine.
The Schedule to the Act prices a failure to take reasonable security safeguards at up to ₹250 crore, and a failure to give breach intimation at up to ₹200 crore, per the Act text. Those are ceilings for the worst cases, and quoting them at a 260-person firm is the kind of fear-selling we try to avoid. The realistic cost of the Jaipur thread was a fortnight of three people’s time and one uncomfortable conversation with a client.
What I told Meenal to do in the next thirty days
The reply to the candidate went out on the Friday, and it was short. What we hold, where, on what basis, what we deleted, what we are keeping and why. She did not need a policy document to send it. She needed the search to be possible, which took Dev four days.
Then the structural work, in this order.
Publish a real contact and a real period. One named role, one monitored address, and a stated response window on your website. Do not publish care-of-everyone. A published contact that nobody owns is worse than none, because it proves you knew the duty existed.
Give the inbox an owner and a service standard shorter than the statutory ceiling. Ninety days is a legal maximum, not a target. Answering inside a fortnight is what keeps a person from escalating, and escalation is the only mechanism that puts you in front of the Board.
Write the retention rule for candidate data before you build anything. How long a CV survives a rejection, and what happens to identity documents when an offer lapses. This is the same discipline as the deletion side we walked through in the erasure request a Pune insurer got wrong, and it is the step that quietly shrinks every other problem on this page.
Then find where personal data actually sits, which is an inventory job and not a security job. Four systems and seventeen recruiters is a mapping exercise, and it is the same one we run in a data mapping day at an NBFC. Until it exists, every request costs you four days.
Last, close the exits. Data-movement monitoring and discovery, the part that tells you a CV left for a personal drive, sits in Secure Data Guard. Returned laptops are the quiet one here, because a recruiter’s machine that leaves unwiped carries the whole candidate database with it. That belongs with device lifecycle management, and if you are buying 50 or more machines this year, ask us about DaaS in the same conversation.
Then the objection, which arrived from the founder on the same thread. DPDP is not even being enforced yet, we will deal with it later. Enforcement timing is a gamble, and even before a single fine your clients’ RFPs are already starting to ask about it. The companies scrambling after the first big penalty will pay a premium and move badly. The ones who set this up quietly now will just tick the box. Later is more expensive and more panicked, which is the only reliable thing about later.
Where our pitch loses, and I would rather write it here than defend it in a proposal. If you already have a named data protection officer, a live record of processing and a ticketed rights-request queue, you do not need Sirius Star for this part. Ask us for the endpoint and data-movement layer, or do not ask us at all. A firm that can already answer a candidate in a week has bought itself most of what this article is about.
What to take away
- Enforcement begins in your inbox. Section 13(3) requires a data principal to exhaust your grievance route first, so the only cases the Data Protection Board ever sees are the ones you failed to answer.
- Ninety days is a ceiling, not a plan. The Rules of 2025 cap your response window. Set an internal standard of a fortnight and you remove the reason anybody escalates.
- The first letter usually comes from someone who was inside. A rejected candidate, a resigned employee, a customer who spotted their data elsewhere. Prepare for a request, not a raid.
- Retention rules shrink every other problem. Most of what the Jaipur firm was asked to account for should never have still existed. Decide what dies and when, before you buy a tool.
- The commercial deadline is ahead of the legal one. Substantive obligations land on 13 May 2027, but vendor risk teams at your clients are asking for evidence of a grievance mechanism today.
Four words in this piece, in plain English
- DPDP Act 2023
- India’s national data protection law. If your business holds personal information about people in India, names, phone numbers, identity documents, salary records, the Act sets out what you may do with it and what you owe those people. The Rules under it, notified in November 2025, add the operating detail, including the grievance response window in this article.
- Data principal
- The person the data is about. Your candidate, your employee, your customer. The law gives that person rights over their own information, and the whole grievance mechanism exists so they can use those rights without hiring a lawyer.
- Data fiduciary
- Your business, when it decides why and how personal data gets used. If you choose what to collect and what to do with it, you are the fiduciary and the duties in this article are yours. We wrote a longer plain-English version of this in who counts as a data fiduciary under DPDP.
- DaaS, or Device-as-a-Service
- Renting your laptops instead of buying them. One monthly cost per device covers supply, support, replacement and a certified wipe when the machine comes back. It matters here because a recruiter’s unwiped laptop walks out with every CV on it.
Questions Meenal wishes she had asked in 2023
When does DPDP enforcement actually start in India?
The Rules were notified on 13 November 2025 with a phased commencement. Provisions constituting the Data Protection Board took effect immediately, consent manager provisions from November 2026, and the substantive obligations including notice, security safeguards, breach intimation and data principal rights from 13 May 2027. What is already live is the commercial pressure. Enterprise and BFSI procurement teams are asking vendors for evidence of a grievance mechanism now, and a lost tender does not wait for a statutory date.
Can a data principal complain straight to the Data Protection Board?
Not as a first step. Section 13(3) of the Act requires them to exhaust the grievance route offered by the data fiduciary or consent manager before approaching the Board. In practice that makes your published contact and your response time the real control. The Board sees the request you ignored, along with whatever you did reply, which is why a holding line about the matter being under review is a poor thing to have on file.
How long do we have to answer a data protection grievance?
The Digital Personal Data Protection Rules, 2025 cap the response period at 90 days (Rule 14) for data fiduciaries and consent managers, and you have to publish the period you will work to. Treat that as an outer limit. Every firm we have helped through a first request found that answering inside two weeks changed the tone of the exchange completely, and nobody escalates a matter that has already been dealt with.
We are a 200-person company with no regulated data. Does this apply to us?
If you hold information that identifies a living person in India, yes. There is no headcount exemption in the Act. Employee records, candidate CVs, customer contact details and identity documents all count. What changes with size is proportionality, not applicability. A 200-person firm needs a named owner, a published contact, a retention rule and a way to search. It does not need the apparatus a bank builds, and any vendor telling you otherwise is selling licences rather than advice.
Still deciding? These are the pages we send clients next.
Two weeks after the reply went out, the candidate wrote back. One line, no complaint in it. He said he had asked three companies the same question and theirs was the only answer he received. Meenal forwarded it to me with a shrug in the subject line. Theek hai, I told her, that is the whole product. Nobody escalates a company that writes back.
We send you a live rights request against your own estate, time how long it takes you to answer it, and hand back a one-page grievance runbook with the published contact wording and retention rules already drafted.
Get my free rights-request readiness check
Sections, timings and penalty ceilings above are drawn from the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they stood at the time of writing, with commencement following the phased notification of 13 November 2025. Confirm the current text and any amendment before relying on a date. The Jaipur engagement is one anonymised client matter, not a published benchmark. This is a practitioner note on operating practice, not legal advice.





