Corporate India’s level of preparedness for Digital Personal Data Protection Rules (DPDP) remains uneven as it gets closer to the deadline with small and medium-sized entities stuck at understanding the routes in which they collect personal data and how it flows across their entity.
With 9 months to go for the May 2027 deadline, large companies seem better positioned, given their resources and experience with overseas clients, but smaller businesses are still evaluating requirements, consultants and tech providers working on DPDP, told businessline. Further, Consent Managers need to register by November 2026, so organisations wanting to work with such intermediaries must get their consent platform in place by then.
This comes at a time when the Government sources have stressed that there is “no chance of an extension of the deadline,” as companies have gone through sufficient rounds of consultation.
However, MEITY itself has not yet set up a key adjudicating body- the Data Protection Board (DPB). “Work is on, applications have been called to staff the DPB, and it will be completed soon,” a government official said.
Experts note that besides consent framework, the Data Processing Agreement and other processess should also be ideally in place by November to allow six or seven months for testing. However, this is turning out to be aspirational given current progress.
Kalindhi Bhatia, Partner at BTG Advaya says smaller businesses are moving more cautiously because compliance involves substantial investment in processes and systems. Some companies appear to be taking a wait-and-watch approach in the expectation of an extension, she said. Larger companies and MNCs are considerably more prepared, she adds.
Mayuran Palanisamy, Partner, Deloitte India, says financial services companies are among the most well-prepared with private banks having begun the journey earlier. Other large companies are now between operational implementation and technology implementation, he said. “SMEs, I don’t think many of them have really started the journey; they have just identified some basic risks and gaps,” he adds.
Malcom Gomes, Chief Operating Officer at IDfy, says that SMEs and start-ups have limited resources for dedicated privacy teams and depend heavily on third-party SaaS platforms for their operations. As a result the third-party data flows makes things complicated, he notes.
Experts stress that the DPB’s absence is not a reason to wait for companies, but it would have been ideal to have the Board running by now.
The DPB will be important because, beyond enforcing the law, it is expected to provide guidance on how companies should implement several provisions, says Bhatia.
With inputs from Rohan Das
Published on August 18, 2026



