The DPDP Act Is "In Force." Here's What That Actually Means for Your Codebase
A three-person startup ships an MVP. It stores user phone numbers, email addresses and rough location data in a shared Postgres instance. There is no consent banner, no data retention job, no documented breach process. When a co-founder raises the Digital Personal Data Protection Act, the answer from the team is: "relax, it's not even fully in force yet." That answer is half right and half…
The Digital Personal Data Protection Act, 2023, took effect in India on November 13, 2025. This act applies to how companies handle user data, including phone numbers, emails, and location information. Before this date, the act was pending rules and lacked a clear enforcement timeline. The DPDP Act defines key roles, such as the Data Fiduciary, Data Processor, and Data Principal, and outlines procedural details for data protection.
The enforcement of the act's provisions is staggered, with some rules taking effect as early as November 13, 2026, while the majority become enforceable on May 13, 2027. This means that developers need to understand which obligations are currently in effect and which are postponed, allowing them to build necessary compliance measures now rather than face last-minute scrambling.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.