DPDP final rules set off a compliance stress test for India’s MSMEs and startups

  • jsa
  • November 17, 2025

India’s newly notified Digital Personal Data Protection (DPDP) Rules have triggered a moment of reckoning for the country’s micro, small and medium businesses- many of whom rely heavily on digital customer acquisition, third-party tech tools, and low-cost data infrastructure. While the law marks a long-awaited shift toward global-grade privacy protections, its operational demands pose the steepest challenge for the smallest players in the ecosystem. JSA Partner Raj Ramachandran says stakeholders “have about 12–18 months to comply… a welcome move,” but for MSMEs with no existing data frameworks, even 18 months will require accelerated execution. Read more

POST TAGS