India’s government has ruled out extending the implementation timeline for the Digital Personal Data Protection (DPDP) Act, with MeitY Secretary S. Krishnan urging startups to begin compliance preparations immediately.
Speaking at a Data Privacy Compliance Clinic organized by the Startup Policy Forum, Krishnan said the notified deadlines would remain unchanged. The framework is deliberately principle-based, allowing organizations to tailor compliance to their data and associated risks.
Startups, however, highlighted practical challenges around consent fatigue, breach notification, behavioral monitoring, access and erasure requests, legacy data and consent management.
AI is adding another layer of complexity. Companies sought clarity on using personal data for AI model training, particularly how consent and data-erasure obligations can be implemented at scale.
The message for businesses is clear: waiting is no longer an option. Organizations need to start building privacy systems, governance processes and compliance workflows now. With timelines fixed, DPDP readiness is shifting from a legal discussion to an urgent technology and operational priority.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




