← All posts
DPDP ActIndia IncEnforcementCompliance StrategyData Protection Board

Has the DPDP law been taken seriously by India Inc?

By Autocops Desk·7 Aug 2026·8 min read

Nine months after the DPDP Rules were notified, the honest answer is: in pockets. BFSI and the big technology firms are building real programmes; most of India Inc is waiting to see whether the Board bites. Here's what the readiness surveys actually show, why the ₹250-crore penalty hasn't moved boards yet, and what changes the day the first enforcement order lands.

Ask a compliance vendor whether India Inc has taken the DPDP Act seriously and you'll get an enthusiastic yes, followed by a pitch. Ask a privacy lawyer and you'll get a weary no, followed by war stories. Having spent the last year inside both kinds of conversation, I think the honest answer is more uncomfortable than either: India Inc has taken the DPDP Act seriously in pockets, and the pockets are exactly where you'd predict — the sectors where a regulator already carries a stick. Everywhere else, the dominant strategy is wait-and-watch, and it's a deliberate strategy, not ignorance.

Let me lay out the evidence for both halves of that claim, and then get to the question that actually matters: what would change it.

What the readiness numbers actually say

Start with the timeline, because everything else hangs off it. MeitY notified the DPDP Rules in November 2025, with a phased schedule that pushes most substantive obligations — consent notices, breach notification, data-principal rights, the security safeguards — to May 2027. That's the deadline the country is working against. Eighteen months sounded generous in November. Nine of them are already gone.

Against that clock, the survey data is blunt. EY India's 2026 readiness study — a survey of around 150 professionals across financial services, technology, retail, healthcare, manufacturing and telecom, published as India moved from policy to implementation — found that close to 71% of respondents had only a limited understanding of the Act and the Rules. Not limited implementation. Limited understanding, and EY noted the gap ran into leadership cohorts, not just operations. The same study found roughly 80% of organisations hadn't yet updated or drafted privacy policies aligned to the Act, and about 77% pointed to their inability to deploy privacy technology — consent management, data discovery, rights fulfilment — inside legacy environments.

The budget numbers are the tell. Coverage of the same EY survey put the share of organisations with no dedicated DPDP budget at 64%. A board that believed enforcement was coming would fund the programme. A board that has allocated nothing eighteen months out has made a probability judgment, and the judgment is "not yet."

And the demand side isn't pushing either. A PwC India consumer survey found that only 16% of Indian consumers understand the DPDP law, with more than half unaware of their rights over their personal data. In Europe, GDPR compliance was propelled partly by customers and activists filing complaints from day one. In India, the complainant base barely knows the statute exists. Companies have noticed.

Where the seriousness is real

Now the other half, because the wait-and-watch story isn't the whole story.

Walk into a large private bank's compliance function and you'll find a DPDP programme with named owners, a data inventory in progress, and a breach-notification runbook being drilled. Not because the bank suddenly discovered privacy, but because its regulators got there first. RBI has required banks to run serious cyber and incident-response operations since its 2016 framework. CERT-In's 2022 directions put a six-hour incident-reporting clock on essentially everyone, and BFSI actually built to it. SEBI's Cybersecurity and Cyber Resilience Framework of August 2024 made a functioning SOC an explicit obligation for its regulated entities. For these firms, the DPDP Act isn't a new discipline — it's a new reporting obligation bolted onto an existing operational muscle. EY's survey confirms the pattern: compliance maturity concentrates in financial services and technology, the regulated and the globally exposed.

The second pocket is big tech and the GCC economy. Companies that went through GDPR between 2016 and 2018 — the IT majors, the global capability centres, the SaaS exporters — already own consent tooling, data maps, DPO functions and breach playbooks. For them DPDP is a localisation exercise: new notice languages, a new board to notify, Indian grievance timelines. Meaningful work, but incremental.

The third pocket is quieter: the consent-manager and privacy-tech ecosystem the Rules deliberately created, which is building ahead of demand on the bet that demand arrives in 2027. EY's sector data suggests only about half of consumer, retail and e-commerce firms have even begun adoption — which tells you where that bet's risk sits.

Everyone else — the mid-market manufacturer, the hospital chain, the regional NBFC's vendors, the edtech that holds data on a few million children — is mostly watching. Their reasoning deserves to be taken seriously rather than mocked, because it's coherent. Which brings us to the penalty question.

Why ₹250 crore hasn't moved a single board

The Act's headline number — penalties up to ₹250 crore for failing to maintain reasonable security safeguards — was supposed to be the board-level attention mechanism. It hasn't been, and there are three reasons.

First, for most of the Act's life there was no enforcer. The Data Protection Board existed on paper from 2023; MeitY only invited applications for its chairperson and members in May 2026, and the appointments landed in June — barely two months ago. Commentary through early 2026 ran under headlines like "the enforcer that isn't there yet," and the commentary was right. Boards of directors are very good at distinguishing a law from an agency. A penalty with no adjudicator is a forecast, not a risk.

Second, ₹250 crore is a ceiling, not a base rate. Every general counsel in the country has read the Act's factors for determining penalty quantum and concluded, reasonably, that first-round penalties against ordinary companies will be far smaller, and that the truly large numbers are reserved for egregious, repeated, large-scale failures. The expected-value calculation — modest probability of action, multiplied by a modest likely penalty, discounted over a timeline that starts in May 2027 — comes out below the cost of a serious compliance programme. That's not negligence. That's arithmetic. It happens to be arithmetic with a fat tail the spreadsheet doesn't capture, but you won't convince a CFO of a fat tail with a hypothetical.

Third, there's no reputational amplifier yet. GDPR fines hurt partly because European media, customers and B2B procurement teams treated them as news. Until an Indian enforcement order gets a company's name into the business press and its enterprise customers' vendor-risk questionnaires, the reputational term in the equation is zero.

What changes when the first order lands

Here's my actual prediction, and it's the reason I don't think the wait-and-watch camp is being clever — I think it's being late.

The Board is now staffed, its grievance portal is live, and complaints are accumulating in a queue that the Board will eventually have to work through publicly. Its first significant orders will almost certainly come from the easiest cases: breaches that were notified late or not at all, because a missed 72-hour clock is objectively provable in a way that "inadequate safeguards" is not. The first respondent probably won't be a bank — banks have the muscle — it'll be a consumer-facing company with a public breach, a slow notification, and no documented decision trail.

The day that order publishes, three things happen fast. The penalty number becomes a base rate, and every risk model in the country gets re-run with a non-zero probability. Enterprise procurement teams add DPDP compliance attestations to vendor onboarding — this is how GDPR actually propagated, contract by contract, and it reaches the mid-market long before the Board does. And boards that allocated nothing discover that an eighteen-month programme doesn't compress into the six months of runway they'll have left. The wait-and-watch strategy was rational right up until the moment it wasn't, and the moment moves without notice.

What taking it seriously actually looks like

One last thing, because "take it seriously" has been co-opted to mean "buy a policy template." The gap between the pockets of seriousness and everyone else isn't paperwork — the 80% who haven't updated their policies can fix that in a quarter. The gap is operational.

A serious programme, in my experience, has five properties. It knows where personal data lives — an actual inventory, queryable, not a spreadsheet from a one-time discovery exercise. It can start the 72-hour breach clock, meaning awareness capture is wired from the SOC and support channels into the privacy function, and someone has drilled the notification end-to-end before the first real incident. It treats consent as a system with records and withdrawal handling, not a banner. It can fulfil a data-principal request — access, correction, erasure — inside the Rules' timelines against production systems, not by email archaeology. And it produces evidence continuously, so that when the Board asks "what did you know and when," the answer is retrieved rather than reconstructed.

None of that is achievable in the last six months before May 2027, which is precisely why the pockets that started in 2024 look so different from everyone else today. It's also, for what it's worth, the operational layer we build AutoCops around — because we think the companies that treat DPDP as an engineering problem rather than a documentation problem are the ones that will find the first enforcement season boring.

Has India Inc taken the DPDP law seriously? The regulated have, the burned-before have, and the rest are betting on the Board's patience. It's a bet with decent odds this quarter and terrible odds over the life of the Act. The window to switch sides cheaply is still open. It closes with the first published order — and nobody gets told the date in advance.

Want help putting this into action?

Run the free DPDP assessment

5 minutes, 40 questions, a posture score, and a PDF report. No signup. No marketing chase.