DRMLAW · Counsel. Compliance. Evidence.
MeitY Secretary S. Krishnan Said It Again in Aug'2026: DPDPA's May 13, 2027 Deadline Isn't Moving. ₹250 Crore a Violation.
On August 14, 2026, MeitY Secretary S. Krishnan addressed a virtual “Data Privacy Compliance Clinic” convened by the Startup Policy Forum in Bengaluru — a room that included Groww, Razorpay, Pine Labs, Meesho, CRED, Acko, and roughly two dozen other SPF member companies. It wasn’t a new position — it was a reiteration. Krishnan has said it before, at earlier consultations; this time the room was startup founders, and the answer was the same: the notified timelines for the Digital Personal Data Protection Act will hold. No extension is under consideration. Companies that haven’t started should start now.
For two years, corporate India has treated DPDPA as a “when convenient” project. Hearing it twice should end that.
Here’s the number that should be on every board agenda: ₹250 crore for a single failure of reasonable security safeguards. ₹200 crore for failing to report a breach or mishandling a child’s data. ₹150 crore for missing Significant Data Fiduciary obligations. No turnover threshold. No headcount exemption. If you collect a phone number from someone in India, you are a Data Fiduciary — full stop.
Krishnan made one structural point worth sitting with: DPDPA was deliberately built around principles, not prescriptive checklists. That’s a real design choice — it lets a fintech and a school build compliance programmes shaped around their own data and risk, rather than filling out an identical form. But a principle-based law has no fill-in-the-blank template to hand a vendor. It has to be interpreted, into your specific business, by someone who understands both the statute and the system.
The questions the room actually raised prove the point: how to avoid “consent fatigue” without triggering user drop-off, where legitimate processing ends and behavioural monitoring begins, what threshold triggers a breach notification, how personal data used to train AI models should be treated, whether account aggregators can double as paid consent managers, and — the sharpest one — whether years of legacy data now need fresh consent or can be grandfathered. None of those has a software-generated answer. Every one is a judgment call with a ₹250-crore downside if you get it wrong.
One honest caveat worth adding: the government has not yet formally notified which organisations qualify as Significant Data Fiduciaries — that list is expected only after the May 2027 deadline lands. That ambiguity doesn’t lower your risk; it raises it. You have to build as if you might be designated, because you’ll find out after the fact, not before.
Ranked by exposure — sensitivity of data handled, volume of processing, regulatory overlap, and how far behind current practice typically sits:
If your business sits in the top five, the next twelve months aren’t planning time — they’re your only planning time.
Take a mid-sized real estate developer running 40 active sales executives across three project sites. A realistic quarter generates roughly 3,000 site-visit leads. Each lead typically hands over an Aadhaar photocopy, a PAN card, and an income proof — three sensitive documents, times 3,000 leads, times four quarters. That’s upward of 36,000 sensitive-document instances a year, most of them scattered across personal WhatsApp threads, individual sales-executive phones, and a CRM nobody has audited since it was installed.
Now run the exposure math. A single incident — one leaked spreadsheet, one hacked sales-rep phone with 200 client documents on it — is enough to trigger the ₹250 crore security-safeguard penalty ceiling. Against that, a structured DPDPA programme for a business this size typically runs to a low single-digit percentage of that ceiling — the kind of spend a firm would barely notice on its annual compliance line, and would notice enormously on the regulator’s.
True compliance rewires the entire journey, not just the paperwork at the end:
That’s six structural changes, one business function, one mid-sized firm. Multiply it across marketing, HR, and finance, and the real scope of “compliance” comes into focus. It is not a form. It is an operating model.
Here’s the sentence most vendors won’t say out loud: DPDPA compliance is not a Legal deliverable, an IT project, or an HR training module. It is all four — Business, Legal, IT, and HR — moving on the same clock, with each function unable to finish its part until another function finishes theirs. That interdependency is exactly why it takes months, not weeks, and exactly why no single department can shortcut it alone.
Business owns the starting point nobody else can supply: where does personal data actually enter the company, and why is it being collected in the first place? Sales, marketing, and operations teams have to walk their own workflows — the site visit, the onboarding call, the loyalty sign-up — because no outside consultant can invent that map from a policy template. Skip this step and every downstream control is built on guesswork.
Legal takes that map and does the interpretive work a principle-based statute demands: which processing needs consent versus a “legitimate use” ground, what a Section 8(6) breach-notification duty actually requires in your sector, which vendor contracts need a fresh data-processing clause before they’re renewed, and where Section 16 cross-border transfer rules bite. This is judgment, not paperwork — the same clause can be defensible for one business and reckless for another.
IT/Engineering turns that judgment into working systems: consent logging that’s actually queryable, access controls that match the roles Business just mapped, encryption and retention rules enforced in the database rather than described in a PDF, and breach-detection tooling that can hit both the DPDPA and CERT-In notification clocks. Bring IT in first, before Business and Legal have defined the requirement, and you get a technically elegant system that solves the wrong problem.
HR carries the part everyone underestimates: the policy is only as strong as the person applying it at 6 pm on a Friday. That means role-specific training — a sales executive needs to know what “verifiable consent” looks like in the field, not a slide about the Act’s preamble — plus updated employee data-handling policies, since staff records are personal data too, and a workforce that knows the escalation path the moment something looks like a breach.
A realistic programme sequences these four functions over roughly five to seven months: Business-led data discovery and legacy audits in the first two months, Legal- and IT-built consent architecture and rights workflows over the next two, and IT/Legal-driven processor alignment, breach simulation, and governance reporting in the final stretch — with HR training running continuously underneath all three phases, not bolted on at the end. Compress that sequence and you don’t get faster compliance; you get a consent form with no data map behind it, or a breach protocol nobody has ever rehearsed.
This is precisely where DRMLAW’s role sits: not as one more vendor adding a fifth track, but as the single accountable owner running the cross-functional program — chairing the stand-ups between Business and IT, translating Legal’s judgment calls into engineering requirements, and making sure HR’s training reflects what the other three functions actually built, instead of a generic slide deck. Someone has to own the dependencies between four departments that don’t naturally report to each other. Left to run independently, each function optimises its own piece and the seams between them — where regulators and breaches both live — go unmanaged.
Here is the gap, stated plainly: a law firm can write you a policy. A GRC vendor can sell you a dashboard. Neither one owns the outcome when the policy and the dashboard disagree with what’s actually happening on the sales floor — and in a principle-based law, that gap is exactly where the ₹250 crore lives.
DRMLAW closes it by refusing to split the mandate. One firm holds the Section 10 statutory DPO appointment, engineers the technical controls, negotiates the vendor contracts, and stands in front of the Data Protection Board if it ever comes to that — under a single signature, with no handoff between “our lawyer” and “our IT vendor” when a regulator asks who was accountable. That’s not a value-add. For a principle-based law with no fixed template and a nine-figure penalty ceiling, it’s the only structure that actually survives an audit.
Krishnan’s message removed the last excuse for waiting. The businesses that start real work this quarter will spend the deadline verifying, not scrambling. Everyone else will be negotiating with a ₹250-crore ceiling hanging over the room.
Rupak Ranjan Mukherjee is Founder Partner at DRMLAW LLP, a Kolkata-based techno-legal practice specialising in DPDPA compliance, DPO-as-a-Service, and digital forensics. Read more at drmlaw.in/technolegal/dpdpa. Source: Fortune India, August 14, 2026.