DPDP Act: consent and data principal requests explained
What the DPDP Act asks of a small business, what valid consent has to look like, and what a data principal can request. With the phasing stated plainly.
· 4 min read
The Act everyone has heard of and few have checked the timeline on
A boutique that runs a WhatsApp order list, a clinic that keeps patient phone numbers for appointment reminders, and a small recruiter with a spreadsheet of candidate CVs are all, in the language of the Digital Personal Data Protection Act, 2023 (DPDP Act), Data Fiduciaries — the entities that decide why and how someone's personal data gets processed.
Most of them have heard the Act's name. Fewer have checked when its actual obligations start to bite, which matters more than knowing the Act exists, because a business planning its compliance around a wrong date is planning around nothing.
What 'consent' has to look like under Section 6, once it applies
The Act's consent standard, once in force, requires consent to be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action — not inferred from silence, a pre-ticked box, or continued use of a service. The notice accompanying a request for consent has to be in plain language, itemise what personal data is being collected and for what specific purpose, and give the person a way to withdraw that consent that is at least as easy as the way they gave it.
This is a meaningfully higher bar than 'we mentioned it in the terms and conditions' — a common small-business habit that predates the Act and does not meet it. A clinic collecting a patient's phone number for appointment reminders needs that purpose stated plainly at collection, not buried in a form the patient never read, and needs a genuine way to say no to reminder messages later without that refusal blocking the underlying service.
What a data principal can actually ask you for
The person whose data a business holds — a data principal, under the Act — gets a specific, enforceable set of asks once these provisions are in force: a summary of what personal data about them is being processed and who it has been shared with; correction of inaccurate or incomplete data; erasure of data no longer needed for the purpose it was collected for; a way to nominate someone to exercise these rights on their behalf if they die or become incapacitated; and a grievance-redressal channel with the business itself before any complaint escalates to the Data Protection Board.
A small business receiving a request like this doesn't need a large compliance department to handle it properly — but it does need to actually know what personal data it holds and be able to locate, correct or delete a specific person's record on request, which is a real operational capability, not just a policy statement.
Children's data, and the one bright line that already matters
One provision is worth understanding on its own because it states a clearly checkable rule rather than a general standard: personal data belonging to a child — defined in the Act as anyone under eighteen — cannot be processed without verifiable consent from a parent or lawful guardian, and a Data Fiduciary is barred from processing a child's data in a way that causes detrimental effect to their wellbeing, or from undertaking tracking, behavioural monitoring, or targeted advertising directed at children.
A business whose customer base includes anyone under eighteen — a coaching institute, an edtech product, anything with a school-age audience — should treat this as a specific, distinct compliance question, not something a general adult-facing consent flow happens to also cover.
What's already true today, and what still isn't
Here is the detail worth checking directly rather than assuming: the DPDP Act's core substantive obligations are not fully in force yet. Checked as of 16 August 2026 against reporting from law-firm and industry sources describing the Ministry of Electronics and Information Technology's notifications, the Act commenced in stages — provisions establishing the Data Protection Board took effect around 13–14 November 2025; the framework for registering Consent Managers is reported to follow roughly a year later, around 13–14 November 2026; and the substantive obligations that actually govern day-to-day business conduct — the consent and notice requirements, breach-reporting duties, security-safeguard obligations, the full set of data principal rights described above, and Significant Data Fiduciary obligations — are reported to come into force around 13–14 May 2027, alongside the repeal of the Information Technology Act's Section 43A, the older provision the current sensitive-personal-data rules sit under.
A business reading a headline that says India's data protection law 'is here' in 2025 or 2026 and concluding its day-to-day consent and rights obligations are already legally mandatory would be acting on a date that, per this reporting, has not arrived yet. This is genuinely one of the more consequential gaps between how the Act is talked about and what it currently requires, and it's worth confirming directly against MeitY's own notifications before either delaying preparation or overstating current legal exposure.
A practical posture while the phase-in continues
None of this is a reason to wait. The behaviours the Act will require — knowing what personal data is held and why, getting genuine rather than buried consent, being able to locate and correct or delete one person's record, and treating a child's data with extra care — are good practice regardless of the exact date they become legally mandatory, and the interim period between the 2025 Data Protection Board notification and the 2027 substantive-obligations date is a reasonable window to build these habits before they're a legal requirement rather than after.
What's not worth doing is either extreme: assuming nothing is required until 2027 and doing nothing in the meantime, or assuming the Act is already fully binding today and citing an obligation that, as of this check, has not yet commenced. Where a specific request or dispute is time-sensitive, checking MeitY's current notifications directly, or asking a lawyer who tracks this Act's commencement schedule, is worth more than any single explainer's snapshot of where things stood on the date it was checked.
Common questions
Is the DPDP Act already legally binding on my business today?
Parts of it are — the provisions establishing the Data Protection Board came into force around November 2025. But the obligations that govern everyday business conduct — consent and notice requirements, data principal rights, breach reporting — are reported to commence later, around May 2027, based on the staggered notification schedule checked for this article on 16 August 2026. Confirm the current status directly against the Ministry of Electronics and Information Technology's notifications before treating a specific obligation as already mandatory.
What counts as valid consent under the Act?
The Act's standard requires consent to be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, accompanied by a plain-language notice describing what data is collected and why, with a withdrawal method at least as easy as the consent mechanism itself. Silence, continued use of a service, or a pre-ticked box do not meet this standard.
What has to happen if someone asks us to delete their data?
A data principal can request erasure of personal data no longer needed for the purpose it was originally collected for. Handling this properly requires actually knowing what data you hold about that person and where, and being able to locate and act on it — this is a specific operational answer this article cannot give in general terms; how erasure interacts with other retention obligations a business may have is worth checking with a professional for a specific case.
Do we need special consent to collect a minor's phone number for something like a coaching institute's SMS reminders?
Yes, in principle — the Act requires verifiable consent from a parent or lawful guardian to process a child's (under-eighteen) personal data, and separately bars behavioural tracking or targeted advertising directed at children. Exactly how 'verifiable' parental consent needs to be implemented in practice is a detail worth confirming against the Act's rules and any sector-specific guidance rather than assuming a general adult consent flow covers it.
Related pages