InsightsProfessional Finance Insights › DPDP Rules 2025: A Finance-Team Readiness Calendar from 2025 to 2027

DPDP Rules 2025: A Finance-Team Readiness Calendar from 2025 to 2027

By CA Nikhil Gupta · 21 July 2026

India's Digital Personal Data Protection Rules were notified on 14 November 2025 with staggered commencement. That phased timetable should not be read as permission to wait. Finance functions hold high-risk personal data—PAN, bank details, payroll, claims, vendor KYC and payment records—and need time to map systems, correct retention practices and renegotiate processor contracts.

Finin2min Summary

The finance team is often both a major data user and a control owner. It receives employee information from HR, customer data from sales, vendor data from procurement and bank or tax data from external portals. A readiness programme should therefore sit across legal, information security, HR, procurement and finance rather than being delegated to a website team.

Read the commencement schedule obligation by obligation

The notified Rules brought some provisions into force immediately, scheduled another provision one year later and placed a substantial set of operational provisions on an eighteen-month track. Organisations should maintain a legal applicability matrix rather than applying one assumed deadline to everything. Preparatory work—data inventory, contract amendments, system design and training—should be planned backwards from the relevant commencement date.

Map data flows before drafting notices

List the personal data collected, the person category, purpose, legal basis or consent path, source, destination, processor, retention period and deletion event. Finance examples include salary accounts, TDS records, expense claims, customer refunds and vendor due diligence. The map should identify copies in spreadsheets, email attachments and shared drives, not only the core ERP.

Fix retention and access at the system level

A policy saying data will be kept only as long as necessary is ineffective if systems never delete records or every finance employee can download full bank details. Retention must reconcile privacy requirements with tax, company-law, labour, audit and litigation holds. Access should be role-based, reviewed periodically and restricted for bulk export.

Build request and breach workflows

The organisation needs an intake channel, identity verification, task routing, response records and escalation for data-principal requests. The breach process should classify affected data, contain access, preserve evidence, assess notification duties and communicate consistently. Finance should be able to identify payment and payroll exposure quickly rather than waiting for a complete enterprise investigation.

What the Viral Version Usually Misses

A viral countdown may present one universal compliance date. The legal reality is phased and obligation-specific. Another simplification is that consent solves every problem. Consent must be informed and purpose-linked, and it does not eliminate security, accuracy, deletion, rights-handling or processor oversight obligations.

Worked Scenario: Payroll processor readiness review

A company sends employee name, PAN, bank details and salary data to a payroll vendor. The contract mentions confidentiality but says nothing about breach notification, deletion, sub-processors or data export. The readiness project maps the flow, limits fields sent, adds role-based access, requires prompt incident notice, specifies return or deletion at termination and creates a rights-request path. Statutory payroll and tax records are retained for the required period, while duplicate onboarding copies are removed from shared folders.

Practical Decision Checklist

Article-Specific Q&A

Do the DPDP Rules apply only to customer data?

No. Employee, applicant, vendor-contact and other identifiable natural-person data can also fall within scope, subject to the Act and applicable exemptions.

Can tax records be deleted immediately when an employee asks?

Not necessarily. Legal retention, claims and other permitted grounds may justify continued storage. The organisation should retain only what is required and document the reason.

Is a processor contract enough to transfer responsibility?

No. The data fiduciary remains responsible for its obligations and must select, contract with and monitor processors appropriately.

Can old data be used to train an internal AI model?

Only after the original purpose, notice or consent, necessity, security and applicable law are assessed. Historical possession is not automatic permission for a new purpose.

What should finance report to the board?

Coverage of the data inventory, high-risk systems, contract remediation, access exceptions, retention gaps, rights-response performance, breaches and unresolved dependencies.

Should a company wait for its eighteen-month provisions before acting?

No. System changes, contract negotiations and data cleanup can take months. The phased period is implementation time, not idle time.

Sources and Verification Trail

Editorial note: This article is for education and general awareness. Verify the latest primary source and obtain professional advice before acting.