Update
On 14 August 2026, MeitY Secretary S. Krishnan stated that no extension of DPDP Act compliance timelines is under consideration, and urged startups to begin compliance work immediately ahead of the 13 May 2027 deadline for substantive obligations. The statement was reported by Fortune India and other outlets covering a startup-focused compliance event. Krishnan described the DPDP framework as deliberately principles-based, intended to let companies design compliance programmes proportionate to their own data-processing risk rather than follow a fixed prescriptive checklist.
Coverage of the event reported that startup representatives raised several concerns, including the risk of "consent fatigue" and user drop-off from repeated consent requests, uncertainty over where the line falls between behavioural monitoring and legitimate data processing, unresolved questions about breach-notification thresholds, and whether personal data used to train AI models requires fresh, purpose-specific consent. Questions about how legacy data collected before the Act's rules came into force should be treated, and whether account aggregators could function as Consent Managers, were also raised.
Analysis
Krishnan's statement is consistent with earlier public remarks by MeitY officials describing the May 2027 deadline as fixed. It does not, on its own, resolve the specific compliance questions startups have raised, several of which remain without published government guidance as of this writing, including the AI training data consent question, which has significant cost implications for companies with AI products built on data collected before the DPDP framework was finalised.
The "principles-based" description of the DPDP framework has been characterised differently by different stakeholders. Government officials frame it as flexibility that avoids imposing one-size-fits-all rules on a diverse economy. Some industry compliance professionals have described it as shifting interpretive burden onto companies, particularly smaller ones without dedicated privacy counsel, who must justify their own risk-based judgments rather than follow a prescriptive standard.
Comparisons to the European Union's General Data Protection Regulation, which had a two-year gap between adoption and enforcement, show a similar pattern of early uneven enforcement against smaller entities in the GDPR's first years, even though no formal extension was ever granted. Whether India's Data Protection Board, whose leadership was still being recruited as of June 2026, will exercise comparable enforcement discretion once the May 2027 deadline arrives has not been addressed by government statements to date.
Comments
0 commentsNo comments yet — be the first.