Two of India's data rules already bite, and neither is DPDP
GuruPrakash SampathKumar · ·India's data rules
Most conversations about India’s data law start with ₹250 crore. The number is real. It is the ceiling for one particular failure, and it is the largest of four.
What the Schedule actually says
The Schedule to the DPDP Act sets four ceilings rather than one.
| Failure | Ceiling |
|---|---|
| Failing to secure personal data, §8(5) | ₹250 crore |
| Breach notice, and children’s data, §§8(6) and 9 | ₹200 crore |
| Significant Data Fiduciary duties, §10 | ₹150 crore |
| Most other violations | ₹50 crore |
Every figure there is a ceiling. The Data Protection Board decides the actual amount case by case.
The shape of that table is the part worth keeping. The largest exposure sits on the security failure that causes a breach, not on the paperwork filed after it.
Who the Act reaches
If you have no entity in India, §3(b) still reaches you when you offer goods or services to people in India. There is no physical presence test in it.
Two rules already bite
DPDP’s consent, breach notice and cross-border rules bind on 13 May 2027. That is when the fines become collectable. Two obligations do not wait for it.
CERT-In has required a report within six hours of noticing an incident since June 2022. There is no size threshold. A ten-person company is covered on the same terms as a bank.
Section 43A of the IT Act still carries a security duty, and compensation for failing it. It lapses when DPDP takes over on 13 May 2027, not before.
November 2026 adds the Consent Manager framework. That is part of the machinery arriving early, not the law arriving early.
Eight months is not eight months
There are about eight months left. Three pieces of work set the critical path, and none of them compresses.
Consent flows have to be redesigned. Notice, purpose limitation and withdrawal have to work as something a person can operate, not as a paragraph on a policy page.
Breach playbooks have to be tested. A six-hour clock is met by rehearsal or it is not met.
Vendor contracts have to be reopened. That timeline sits with the counterparty, which makes it the one you control least and the one to start first.
Each of those is a document, a date, and evidence that the thing was done. That is the part Pulan is being built for. It does not make the obligation go away.
The organisations that are ready in May 2027 will not be the ones that read the Act first. They will be the ones that started rewriting contracts first.