top of page

No DPDP Extension, Startups Told to Comply Now

14 August 2026

I. A Deliberate Refusal to Negotiate on Timing


Secretary Krishnan's statement at the Bengaluru compliance clinic is notable less for its content, no extension is under consideration, than for its context. It was delivered directly to the startup constituency most likely to lobby for relief, at an event organised specifically to surface implementation concerns. Making the no extension position explicit in that room, rather than in a generic press statement, suggests the government anticipated and wanted to foreclose a coordinated extension request before it could gather momentum. Advisors should treat this as a clear signal that further advocacy for timeline relief is unlikely to succeed and should redirect client resources from lobbying toward compliance build out.


II. Principles-Based Framing Is Doing Real Work Here


Krishnan's characterisation of the DPDP framework as deliberately principles-based, allowing proportionate programme design, is not merely reassurance. It shifts interpretive risk onto individual companies. A prescriptive, rules-based framework tells a company exactly what to build; a principles-based one requires the company to defend its own risk based judgment before a regulator after the fact. For startups without dedicated privacy counsel, this framing is more burdensome than it sounds, since it removes the safety of a compliance checklist and replaces it with the need for documented, defensible reasoning about proportionality.


III. The Consent Fatigue Objection Has No Answer Yet


The startup concerns raised at the clinic, consent fatigue and user drop-off in particular, reflect a well documented tension in consent based privacy regimes generally, not a uniquely Indian problem. What is uniquely unresolved in India is the absence of a settled position on whether the Consent Manager framework, once operational, will actually reduce this friction or add a further consent layer on top of existing first party consent flows. Until MeitY publishes clearer guidance on how Consent Manager mediated consent interacts with direct consent capture, startups face genuine design uncertainty about whether to build for a Consent Manager integrated future or a first party consent present.


IV. AI Training Data Remains the Sharpest Open Question


The unresolved question of whether personal data used for AI training requires fresh consent is the single most commercially consequential item raised at this clinic and the one with the least official clarity. If the government eventually requires fresh, purpose specific consent for AI training uses of previously collected data, as a literal reading of the Act's purpose limitation principle would suggest, the compliance cost for any Indian company with existing AI or machine learning products built on legacy datasets would be substantial. The absence of a clear answer here, rather than the topics that dominate press coverage, is the item practitioners should be tracking most closely.


V. Comparative Note


The GDPR's own transition experience offers a useful, if imperfect, precedent. The GDPR provided a two year implementation window between adoption and enforcement, and even then enforcement against smaller entities was demonstrably uneven in the early years, with regulators exercising discretion that was never formally codified as an extension. India's DPDP timeline offers an eighteen month window from Rules notification to full enforcement, shorter than the GDPR's, with a regulator, the Data Protection Board, that is institutionally less mature at the equivalent point in its lifecycle than the various European data protection authorities were in 2018. The "no extension" posture may therefore coexist in practice with uneven early enforcement, even if it is never announced as such. Startups should not confuse this possibility with a safe assumption to plan around; discretionary regulatory forbearance, where it exists, tends to favour entities that can demonstrate documented good-faith compliance efforts, not entities that simply waited for enforcement leniency to materialise. The GDPR's early years rewarded companies that had at least begun implementation, however imperfectly, over companies that had done nothing while hoping for a de facto extension.


VI. Practitioner Guidance


Startups should treat the May 2027 deadline as real and should not structure compliance budgets around an anticipated grace period. On AI training data specifically, clients should adopt a conservative position now, treating fresh consent as likely required for any new AI training use of previously collected personal data, rather than waiting for MeitY guidance that may arrive too close to the compliance deadline to be actionable. Early-stage companies with limited compliance budgets should prioritise the consent and notice architecture over less immediately consequential obligations, such as elaborate internal governance documentation, since consent defects are the exposure most likely to trigger both regulatory and civil consequences under the Act's current design.


bottom of page