Trust, Ethics & Regulation · established evidence

India's DPDPA and the Cross-Border AI-Services Firm: A 2025 to 2027 Compliance Timeline

Last reviewed 2026-07-20. Written by Chandranshu Kumar, Founder, Raveneye Global. · 10 min read

The DPDPA compliance timeline is now concrete rather than prospective. India's Digital Personal Data Protection Act was passed in 2023, but the implementing DPDP Rules were notified only in November 2025, which started an eighteen-month phased rollout concluding in May 2027. For an India-based firm that delivers AI-marketing services to businesses in the United States, this is not a distant or foreign concern. It is the law of the firm's own jurisdiction, and it governs the personal data such a firm inevitably handles: its own staff records, its India-side leads, and the client data it processes under contract. The Act also created the Data Protection Board of India, with authority to levy penalties up to 250 crore rupees for significant breaches. This piece reads the timeline literally, separates what is settled from what is still forming, and locates precisely where a cross-border services structure sits within it.

What the DPDPA is, and why 2025 is the year it acquired teeth

The Digital Personal Data Protection Act, 2023 was India's first horizontal, cross-sectoral data-protection statute. For two years it existed largely on paper: the primary Act had been passed and published, but the operative machinery, the detailed rules that tell a firm what notice to give, how to record consent, how fast to report a breach, and how the regulator will function, had not been notified. A statute without its implementing rules is a set of principles without a manual.

That changed in November 2025, when the government notified the DPDP Rules 2025. Notification is the legal event that converts a dormant Act into an operable compliance regime. It is also what started the clock that this article is about. From that point, the obligations stop being aspirational and begin to phase into force on a fixed schedule.

The Act established a dedicated regulator, the Data Protection Board of India, and gave it real financial authority. For significant breaches the Board may impose penalties up to 250 crore rupees, roughly 2.5 billion rupees when the Indian numbering unit is converted. That ceiling is what distinguishes the DPDPA from earlier, advisory-only Indian data guidance: non-compliance now carries a quantified, enforceable cost.

The phased rollout to May 2027, read as a timeline

The single most useful fact for a firm planning its compliance work is that the DPDPA did not switch on all at once. The DPDP Rules 2025 established a phased rollout, an eighteen-month sequence measured from the November 2025 notification and concluding in May 2027.

Notification is the starting gun, not the finish line

It is tempting to read a notified rule as an immediate obligation. The phased structure is deliberately the opposite: it grants a transition window so that data fiduciaries can build consent mechanisms, notice flows, breach-reporting processes, and processor contracts before those obligations are enforced against them. The transition is a feature of the design, not a loophole.

For a small services firm, the practical reading is that the window between late 2025 and May 2027 is the period in which compliance infrastructure is expected to be stood up, not the period in which it can be safely ignored. A regime that phases in over eighteen months is a regime that expects to find you ready at the end of it.

What "concluding in May 2027" actually means

The end of the rollout is the point at which the full operative obligations of the Act are in force and the transition allowances have expired. A firm that treats May 2027 as the deadline to be fully compliant, rather than the date after which it is exposed if it is not, has read the timeline correctly.

The cross-border structure this Act actually governs

This is the genuinely under-covered intersection. Most public commentary on the DPDPA addresses Indian companies serving Indian consumers, or foreign companies serving Indians. The specific case of an Indian-registered firm delivering services to businesses in the United States is discussed far less, even though it is a common structure for AI and marketing services.

The clarifying move is to separate the two data flows such a firm handles. First, there is the personal data the firm generates and processes about people in India: its own employees, its India-side contractors, and any Indian prospects or leads it collects. That data is squarely within the DPDPA regardless of who the firm's paying clients are. A firm cannot place itself outside its home data-protection law by pointing at an overseas customer base.

Second, there is the client data the firm handles on behalf of a US business, typically the personal data of that client's own customers. Here the firm is acting as a service provider, and its obligations are shaped by the contract with the client and by the data-protection laws that govern that client. The DPDPA's protections are written for data principals in India; they do not convert every US consumer record into an Indian regulatory matter. But the firm's conduct as a processor, its security practices, its breach discipline, its retention hygiene, is exactly what a well-drafted client contract will require, and exactly what the DPDPA trains the firm to do at home.

In short, a cross-border services structure does not escape data-protection law by straddling two countries. It inherits obligations from both sides at once, and the DPDPA is the half of that pair that is arriving on a fresh, fixed timeline.

Data Fiduciary or Data Processor: which role the firm occupies

The DPDPA borrows the same functional distinction that anchors most modern data-protection law. A Data Fiduciary is the entity that determines the purpose and means of processing personal data. A Data Processor is an entity that processes personal data on behalf of a fiduciary, under its instructions. The roles are not job titles; they are determined by what the firm actually does with the data in each flow.

For its own operational data, its staff, its India-side marketing, an AI-services firm is a Data Fiduciary and carries the fuller set of obligations: giving notice, obtaining and recording consent, honoring data-principal rights, and reporting breaches to the Board. For the client data it handles under instruction, the same firm is usually a Data Processor, and its duties run primarily through its contract with the client fiduciary rather than directly to the individuals.

Getting this classification right, flow by flow, is the first substantive compliance task, because it determines which obligations attach. A firm that assumes it is only ever a processor will under-build; a firm that assumes it is always a fiduciary will over-scope its own client work. The DPDPA rewards the firm that maps its data flows precisely.

The US client's own obligations sit on top of the Indian firm's

A firm reading only the DPDPA sees half the picture. The US clients it serves face their own, entirely separate stack of obligations, and because the firm's work touches those clients' customers, the firm is drawn into that stack contractually.

The clearest illustration is the wave of AI-transparency law now landing on a 2026 timeline. The European Union's AI Act, Regulation (EU) 2024/1689, makes its Article 50 transparency obligations enforceable from August 2, 2026, with fines up to fifteen million euros or three percent of global annual turnover. Alongside it sits a growing patchwork of US state disclosure laws with similar 2026 effective dates. None of these are Indian law, but a services firm whose deliverables are published by a client operating across these jurisdictions has a direct, contractual interest in getting the disclosure posture right.

The point is not that a small AI-services firm must personally comply with every regime its clients touch. It is that the firm sits at a junction where its home law (the DPDPA) and its clients' laws (US federal and state rules, and in some cases European rules) converge on the same deliverables. A firm that understands both halves is a materially safer vendor than one that understands neither.

The compliance burden is regressive by firm size

There is a structural fairness problem buried in all of this, and the evidence for it is worth stating carefully because it is emerging rather than settled. Research on the earlier European regime, the GDPR, finds that compliance cost is regressive by firm size: smaller firms bear a disproportionately larger share of compliance cost relative to revenue than large firms, even though large firms spend more in absolute terms.

The specific dollar figures that circulate for this, small-business GDPR programs commonly estimated in the range of roughly 20,500 to 102,500 US dollars, and CCPA compliance commonly estimated from about 5,000 to over 100,000 US dollars depending on data footprint, come from industry compliance-cost aggregators rather than peer-reviewed or government sources. They should be read as directional, not precise. But the direction is consistent across independent sources and it matters: the smallest firms, including the local-service businesses an AI-marketing firm typically serves, are the least equipped to absorb overlapping compliance regimes.

The DPDPA's eighteen-month phase-in is, in part, a response to exactly this asymmetry. A transition window is a concession to the reality that not every regulated entity has a compliance department. It does not remove the burden; it spreads it over time.

The timeline: settled, emerging, and still moving

Rigor here means distinguishing what is fixed from what is still forming. Three things are settled and documented: the Act was passed in 2023, the DPDP Rules were notified in November 2025, and the phased rollout concludes in May 2027, with the Data Protection Board of India holding penalty authority up to 250 crore rupees. These are matters of statutory text and official notification.

Several things are genuinely still moving. Detailed operational guidance, Board precedent, and the practical interpretation of the Rules will develop across the transition window, because that is what always happens between a rule's notification and its mature enforcement. A firm building its compliance program in 2026 is building against a regime whose text is fixed but whose practice is not yet fully written. That is a reason to build conservatively and revisit, not a reason to wait.

The temptation, in any regulatory explainer, is to project false precision about how enforcement will feel. The defensible position is narrower and more useful: the obligations and the deadline are real and dated; the enforcement culture around them is still being established. Plan for the former, watch the latter.

Why transparency about your own structure is the credible response

There is a strategic reading of this timeline that goes beyond avoiding penalties. For a services firm, the arrival of a serious home-country data-protection regime is an opportunity to be legibly, documentably compliant, and to say so plainly. In a market where many vendors are vague about where they are based, how they handle data, and which laws govern them, structural transparency is itself a trust signal.

A firm that can state its structure clearly, an Indian company serving US clients, operating under the DPDPA at home and contracting responsibly for the data it processes abroad, is easier to trust than one that obscures the question. The same discipline the DPDPA demands, mapping data flows, documenting purpose, honoring rights, reporting honestly, is the discipline that produces a credible institution. Compliance and credibility are, in this case, the same work.

The evidence

Key findings, with their sources

  • India's Digital Personal Data Protection Act was passed in 2023, and its implementing DPDP Rules were notified in November 2025, converting the Act into an operable compliance regime.

    established Digital Personal Data Protection Act, 2023, and DPDP Rules 2025 (notified November 2025), Gazette of India notification.

  • The DPDP Rules 2025 established a phased compliance rollout of roughly eighteen months, concluding in May 2027.

    established DPDP Rules 2025 (notified November 2025), Gazette of India notification.

  • The Act created the Data Protection Board of India, which may impose penalties up to 250 crore rupees for significant breaches.

    established Digital Personal Data Protection Act, 2023, Gazette of India.

  • GDPR compliance cost is regressive by firm size: smaller firms bear a disproportionately larger share of cost relative to revenue than large firms, with small-business GDPR programs commonly estimated at roughly 20,500 to 102,500 US dollars and CCPA compliance at about 5,000 to over 100,000 US dollars depending on data footprint.

    emerging Aggregated industry compliance-cost estimates (ComplyDog, PoliWriter, Internet for Growth 2026 guides); MIT Sloan reporting on GDPR effects. Industry-estimate tier, not peer-reviewed.

  • The EU AI Act's Article 50 transparency obligations become enforceable August 2, 2026, with fines up to fifteen million euros or three percent of global annual turnover.

    established EU Artificial Intelligence Act, Regulation (EU) 2024/1689, Article 50; European Commission AI Act Service Desk.

Calibration

What is proven, what is promising, what is unproven

Evidence tierTacticsWhat the evidence says
establishedThe Act (2023), the DPDP Rules notification (November 2025), the phased rollout to May 2027, the Data Protection Board of India, the 250 crore rupee penalty ceiling, and the EU AI Act Article 50 dates.Statutory text and official gazette / regulator notifications.
emergingThe regressive-by-firm-size compliance-cost figures for GDPR and CCPA and the specific dollar ranges quoted.Industry compliance-cost aggregators, directionally consistent but not peer-reviewed or government-sourced.
contestedHow enforcement will feel in practice: Board precedent, detailed operational guidance, and interpretation across the transition window.Not yet written; forms across the 2025 to 2027 phase-in, so treat any confident enforcement prediction as speculative.

Reference

Glossary

DPDPA
India's Digital Personal Data Protection Act, 2023, the country's horizontal, cross-sectoral personal-data-protection statute.
DPDP Rules 2025
The implementing rules notified in November 2025 that operationalize the Act, specifying notice, consent, breach-reporting, and Board procedure, and setting the phased rollout.
Data Fiduciary
The entity that determines the purpose and means of processing personal data. It carries the fuller set of obligations under the Act.
Data Processor
An entity that processes personal data on behalf of a Data Fiduciary, under its instructions. Its duties run primarily through its contract with the fiduciary.
Data Principal
The individual to whom the personal data relates, that is, the person whose data is being processed.
Data Protection Board of India
The regulator created by the Act, with authority to adjudicate breaches and impose penalties up to 250 crore rupees for significant violations.

Straight answers

Frequently asked questions

When does the DPDPA take full effect?

The Act was passed in 2023, but it became operable when the DPDP Rules 2025 were notified in November 2025. Those rules set a phased rollout of roughly eighteen months, concluding in May 2027, which is the point at which the full operative obligations are in force and the transition allowances have expired.

Does the DPDPA apply to an Indian firm that only serves US clients?

Yes, for the personal data the firm handles about people in India, such as its own staff, contractors, and India-side leads. That data is within the Act regardless of where the firm's paying clients are. A firm cannot place itself outside its home data-protection law by pointing at an overseas customer base. For the client data it processes on behalf of a US business, its obligations are shaped mainly by its contract and by the laws governing that client.

What is the difference between a Data Fiduciary and a Data Processor under the DPDPA?

A Data Fiduciary determines the purpose and means of processing and carries the fuller obligations, including notice, consent, and breach reporting. A Data Processor processes data on behalf of a fiduciary under its instructions, with duties running primarily through the contract. The same firm can be a fiduciary for its own data and a processor for its clients' data, so the classification has to be made flow by flow.

What are the penalties under the DPDPA?

The Act created the Data Protection Board of India, which may impose penalties up to 250 crore rupees, roughly 2.5 billion rupees, for significant breaches. That quantified, enforceable ceiling is what distinguishes the DPDPA from earlier advisory-only Indian data guidance.

How does the DPDPA interact with the US laws my provider faces?

They stack rather than overlap. The DPDPA is the provider's home law, arriving on a fresh timeline to May 2027. Its US clients separately face US federal and state rules, and in some cases the EU AI Act, whose Article 50 transparency obligations become enforceable in August 2026. A cross-border firm sits at the junction of both, so a vendor that understands both halves is materially safer than one that understands neither.

Provenance

Sources

  1. Digital Personal Data Protection Act, 2023 (India), and DPDP Rules 2025 (notified November 2025), Gazette of India notification (established)
  2. Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023, penalty authority up to 250 crore rupees (established)
  3. EU Artificial Intelligence Act, Regulation (EU) 2024/1689, Article 50 (transparency obligations enforceable August 2, 2026); European Commission AI Act Service Desk (established)
  4. GDPR/CCPA small-firm compliance-cost estimates aggregated via ComplyDog, PoliWriter, and Internet for Growth 2026 guides; MIT Sloan reporting on GDPR effects on firm data use (emerging, industry-estimate tier)

Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.

What this means for your business

A firm that can state its own structure plainly, where it is based, how it handles data, and which laws govern it, is easier to trust than one that keeps the question vague. Before any work is scoped, a clear read of where your business actually stands across the surfaces buyers now use, classic search, the local map pack, AI answers, and reputation, is the starting point.

diagnostic Surface Intelligence Audit A measured read of where you stand across all four surfaces, benchmarked against the competitors surfacing above you, with a ranked list of the corrections that move you first. See how it works

Start free with a Machine-Readiness Score, a specialist-reviewed read of where you stand across search and AI answers. No guaranteed number, and no obligation.