You hold client data: DPDP applies to freelancers too
The obligations under the Digital Personal Data Protection Rules commence in May 2027, with no phase-in for small operators. The contractual version of them will reach you well before that.
Want this checked against your own position? We prepare the documentation and handle the filing.
If you run a client's mailing list, build the app their customers sign into, manage their CRM, or hold a spreadsheet of survey respondents, you are handling personal data that belongs to people who have never heard of you. India's data protection regime has something to say about that, and freelancers have largely assumed it is a big-company problem.
Note
First, the part every scare piece leaves out. The substantive obligations discussed here are not yet in force. Rule 1(4) of the Rules puts Rules 3, 5 to 16, 22 and 23 into force eighteen months after publication of the gazette, which lands in May 2027. Nobody is in breach of them today, and nobody is exposed to a penalty under them today. Anyone telling you otherwise is selling on fear.
What was actually notified, and when it bites
The Digital Personal Data Protection Rules were notified as G.S.R. 846(E) on 13 November 2025. The commencement is staged. Rules 1, 2 and 17 to 21 took effect on publication. Rule 4, the Consent Manager registration regime, takes effect a year after publication, in November 2026. Everything that creates a working obligation for an ordinary business sits in the eighteen-month tranche, in May 2027.
The Act's own commencement notification, G.S.R. 843(E) of the same date, puts sections 3 to 5, most of section 6, sections 7 to 17, sections 28 to 34 and others into the same eighteen-month tranche. Sections 28 to 34 are the ones that give the Data Protection Board its powers. That is why there is no penalty exposure before then, and it is also why the date is worth marking rather than ignoring.
Note
We write the deadline as May 2027 rather than a specific day. Both notifications carry the dateline 13 November 2025 and key their later tranches to the date of publication, while the ministry's own explainer gives the notification date as 14 November 2025. Until something resolves that, a specific day would be false precision.
There is no small-operator exemption to wait for
Two things people are quietly hoping for do not exist. There is no turnover or headcount floor below which these rules stop applying. And section 17(3) of the Act, which lets the Central Government exempt certain Data Fiduciaries including DPIIT-recognised startups, is a power the Government has not used. No notification under it has been issued. Startup recognition, on its own, currently changes nothing about what the Act asks of you.
A commencement date with no phase-in and no size threshold is a rare thing in Indian compliance. It means a two-person studio and a bank arrive at the same line on the same morning.
Your clients' obligation arrives inside your contract
This is the part that matters most for a freelancer's timeline. Rule 6(1) requires a Data Fiduciary to protect personal data in its possession or control, including where processing is carried out on its behalf by a Data Processor, through security safeguards that include at a minimum:
| Clause | What Rule 6(1) requires |
|---|---|
| (a) | Encryption, obfuscation, masking, or virtual tokens mapped to the personal data |
| (b) | Measures controlling access to the computer resources used |
| (c) | Visibility on access through logs, monitoring and review |
| (d) | Reasonable measures for continued processing if confidentiality, integrity or availability is compromised, such as backups |
| (e) | Retention of such logs and personal data for a period of one year, unless another law requires otherwise |
| (f) | Appropriate provision in the contract between the Data Fiduciary and the Data Processor for taking reasonable security safeguards |
| (g) | Appropriate technical and organisational measures to ensure effective observance of the safeguards |
Cite this as Rule 6(1)(f) and so on. Rule 6 has sub-rules, so a bare "Rule 6(f)" is malformed.
Clause (f) is the one that reaches you. When your client becomes obliged to carry security terms in their contract with anyone processing data on their behalf, that contract is the one they have with you. Enterprise procurement teams do not wait for a commencement date to update their standard templates. The clause lands in your next renewal, and it lands with a security questionnaire attached.
What the rules ask for, in the plainest terms
- Rule 9 requires a Data Fiduciary to publish, prominently on its website or app, the business contact information of a Data Protection Officer where applicable, or of a person able to answer a Data Principal's questions about the processing of her personal data, and to repeat that in every response to a rights request.
- Rule 14(3) sets the grievance response period at ninety days and requires appropriate technical and organisational measures to make the system actually respond within it.
- Rule 7 covers breaches. Intimation to each affected person without delay, in concise, clear and plain language, and a description to the Data Protection Board without delay followed by detailed information within seventy-two hours of becoming aware. Nothing in Rule 7 sets a materiality floor, so as drafted every personal data breach is intimable.
- Rule 8(3) fixes a minimum retention period of one year for personal data, associated traffic data and other logs of the processing, and it applies to every Data Fiduciary rather than only to the large classes listed in the Third Schedule.
- Rule 15 permits transfer of personal data outside India, subject to requirements the Central Government may specify about making that data available to a foreign State or its agencies. Section 16(1) of the Act is the separate power to restrict transfers to a notified country. As far as we have been able to verify, no country has been notified.
Note
Rule 15 is not the GDPR's Chapter V. There is no adequacy test, no standard contractual clause requirement and no approval step in it. If a vendor is selling you a data transfer assessment on that basis, ask them to show you the provision.
The regime that is in force meanwhile
One detail almost nobody mentions. Section 44(2) of the Act, the sub-section that omits section 43A of the Information Technology Act, 2000 and the rule-making power behind the SPDI Rules of 2011, sits in the eighteen-month tranche as well. Section 43A and the SPDI Rules therefore remain in force until the substantive DPDP obligations commence. Any data assessment written today is measuring against a regime that has not been switched off yet, which is worth knowing before you buy one.
What a freelancer should do with a deadline this far out
Very little, urgently. Know the date, know that nothing softens before it, and keep a record of what client data you hold and where it sits, because that inventory is the input to every other step and it is much harder to reconstruct later. When a client's new contract arrives with a security schedule bolted on, read it against Rule 6(1) rather than signing whatever their template says. BuildWright can do that read with you, and can prepare the processor terms and the notice-and-consent documentation when it is time.
- 1.Digital Personal Data Protection Rules, notified as G.S.R. 846(E) on 13 November 2025, Gazette of India Extraordinary, Part II Section 3(i)
- 2.Digital Personal Data Protection Act, 2023, commencement notification G.S.R. 843(E) dated 13 November 2025
- 3.Digital Personal Data Protection Act, 2023, sections 16 and 17(3)
Sources read on 11 August 2026. These provisions get revised, so we re-confirm every figure against the current text before it goes into a filing.
Read next
Getting paid
buildwright.co.in
Getting paid on time: the 45-day rule freelancers already have
One registration turns your payment terms into a statutory deadline that the client's own contract cannot push out, with compound interest running the day after it passes.
7 min read
Entity and tax
buildwright.co.in
Sole proprietor, OPC or LLP: what a freelancer actually needs
You are already a sole proprietor, because no filing was ever required to make you one. The question is when limited liability starts earning the paperwork it costs.
8 min read
Entity and tax
buildwright.co.in
Signing a client agreement: what actually makes it binding
Freelancers routinely assume a contract needs a witness, a notary stamp or a particular kind of paper to count. Mostly it doesn't. The exceptions that do exist are narrow, and worth knowing precisely because they're so easy to miss.
7 min read