Why legacy IT systems will become a DPDP compliance challenge

https://cdn1.expresscomputer.in/wp-content/uploads/2026/09/21144428/EC_Ashok_Kumar_MD_Founder_RAH_Infotech_750.jpg

By Ashok Kumar, Founder & MD, RAH Infotech

India’s Digital Personal Data Protection (DPDP) Act, 2023, has moved from statute-book theory to operational reality. With the DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology in November 2025, the country now has a firm, phased implementation timeline: foundational provisions and the formal establishment of the Data Protection Board of India took effect immediately; provisions relating to the Consent Manager framework come into force one year after publication; and most substantive obligations covering notice, consent, data principal rights, security safeguards, breach reporting, retention and cross-border transfers come into force 18 months after publication, by May 13, 2027. For enterprises, that phased timeline should not be mistaken for spare time. The technology and data remediation needed for compliance can take months.

For most large Indian enterprises like banks, insurers, telecom operators, PSUs, hospitals and government departments, the biggest obstacle...

Copyright of this story solely belongs to www.expresscomputer.in. To see the full text click HERE

Read more