← All articles

August 12, 2026 · 5 min read

DPDP Decoded: Free Webinar on Obligations & Timelines

A free live session on 13 August 2026 covering what India's DPDP Act obliges organisations to do — consent, notices, data-principal rights, breach — plus what to prioritise given the 13 May 2027 deadline, and live Q&A with the ProtectComply and Auxiliary DigiTech teams.

DPDP Decoded: What the Act Obliges You to Do, and What to Prioritise Before May 2027

By Yatin Chaudhary, SEO Specialist at ProtectComply · Reviewed by Jupinder Singh Bedi · Published 12 August 2026 · 6 min read

Free live webinar · Thursday, 13 August 2026 · 3:00 PM IST · OnlineRegister here →

The short version

We're running a live session tomorrow on what India's DPDP Act actually obliges organisations to do — consent, notices, data-principal rights, breach response and grievance handling — plus what to prioritise given the compliance deadline is 13 May 2027 and a real programme takes three to four quarters.

It's free, it's an hour, and roughly a third of it is live Q&A. If you're the person who owns this problem and you're not certain where to start, that Q&A is the part worth showing up for.

Register: https://intellowork.com/c/dpdpwebinar

Why we're running it now

Most organisations we speak to are working from one of two positions, and both are uncomfortable.

The first is that DPDP is a 2027 problem. The maths doesn't support that. The Rules were notified on 13 November 2025 via gazette G.S.R. 846(E), and the Data Protection Board of India was constituted the same day — so complaints can already be filed. Penalty provisions become operative 13 November 2026. Full compliance is due 13 May 2027.

An eighteen-month runway sounds comfortable until you attempt the work. Discovery alone runs weeks. Vendor contract renegotiation depends on other people's legal teams. Start in early 2027 and you'll be building foundational systems while enforcement is already live.

The second position is worse: a cookie banner has been deployed and DPDP has been marked done. A banner is roughly three percent of the obligation. The Act also wants records of processing, rights fulfilment within statutory timelines, grievance redressal, retention limits, breach notification to both the Board and affected individuals, processor contracts and security safeguards.

The session is aimed squarely at both groups.

What we'll cover

What the DPDP Act obliges your organisation to do. The actual obligation set, mapped to the sections and rules they come from — not a summary of the summary.

Consent, privacy notices and data-principal rights. Where consent must be purpose-linked rather than bundled, what notice in Eighth Schedule languages means in practice, and why withdrawal has to propagate to downstream systems rather than flip a flag in one.

Compliance timelines and what to prioritise now. The three commencement dates, and a working-backwards schedule that leaves margin rather than assuming none is needed.

Breach response and grievance redressal. The dual notification obligation — the Board and every affected Data Principal — and why the risk-based filter GDPR gives you isn't available here.

Live Q&A. Bring the specific problem you're stuck on.

Who's speaking

Jupinder Bedi — CEO & Co-Founder, ProtectComplyDinkar Singh — Chief Data Privacy Officer & Co-Founder, ProtectComplyTarun Gupta — CTO & Co-Founder, ProtectComplyNikhil Gupta — CEO & Founder, Auxiliary DigiTech

Run in association with Auxiliary DigiTech.

Who should attend

Compliance and legal leads who own the obligation. CTOs and engineering leads who'll implement it. Founders at companies without a dedicated privacy function — which is most companies, and the Act has no small-business exemption.

It's a leadership session, so it assumes you can follow a regulatory argument. It doesn't assume you've read the Rules.

Three questions worth bringing

The Q&A is better when people arrive with something specific. Ones we get asked most:

Do we need to register as a Consent Manager? Almost certainly not — that's a registered intermediary category with a ₹2 crore net worth requirement. You need a consent management capability, which is a different thing. More on that distinction here.

Does GDPR compliance cover us? Partially. Your RoPA discipline and DPIA methodology transfer. Your legitimate-interest processing does not — the DPDP Act has no such basis. The full delta is here.

Where do we actually start? Scope the data estate, build a processing record that reconciles against real systems, then design consent around what that record shows. Not the reverse — that's the sequencing error that costs the most to unwind.

If you can't make it

Register anyway. We'll send the recording and the slides to everyone on the list.

In the meantime, three things worth reading:

Register

Thursday, 13 August 2026 · 3:00 PM IST · Online · Free

Secure your seat →

About the authorYatin Chaudhary is an SEO Specialist at ProtectComply, where he writes about India's data protection framework and how organisations operationalise it.

Reviewed by Jupinder Singh Bedi, CEO & Co-Founder, ProtectComply.

General information, not legal advice. Consult qualified counsel before finalising your compliance position.

← Back to all articles