DPDP Act & Rules Timeline: What Applies Now, 2026 & 2027

30 Aug 2026 16 min read Joginder Poswal
DPDP Act & Rules Timeline: What Applies Now, 2026 & 2027

Confused by India's DPDP Act timeline? Learn what applies now, what starts in November 2026 (Consent Managers), and what changes in May 2027 (full enforcement).

DPDP Act 2023 and DPDP Rules 2025: what applies now, what starts in November 2026, and what changes in May 2027

Most business owners I meet know about India’s data protection law, but not many are sure which parts apply to them right now.

It’s easy to see why there’s confusion. The government is rolling out the law in stages, and different sources give different dates. Here’s a simple timeline from the Gazette, with section and rule numbers so you can check yourself.

First, you need to keep two documents separate.

The Digital Personal Data Protection Act, 2023 received the President's assent on 11 August 2023. It is the parent law. It tells you what the obligations are.

The Digital Personal Data Protection Rules, 2025 were made under Section 40 of the Act and notified by MeitY through Gazette notification G.S.R. 846(E), dated 13 November 2025. The Rules tell you how to do what the Act says: what a notice must contain, how a breach is reported, how a parent's consent for a child is verified, and so on.

People often mix these two up. If someone talks about "DPDP compliance," check if they mean the Act, the Rules, or both. This is important because they started at different times, and the Rules refer to Schedules with many details.

The three dates

  • Rule 1 of the DPDP Rules explains when things start.

  • Rules 1, 2, and 17 to 21 take effect on the publication date.

  • Rule 4 starts one year after publication.

  • Rules 3, 5 to 16, 22, and 23 begin eighteen months after publication.

A separate commencement notification issued by MeitY on the same day brings the corresponding sections of the Act into force on matching dates.

This part can be confusing. The notification is dated 13 November 2025, but the Rules use the publication date in the Official Gazette, usually 14 November 2025, to count the one-year and eighteen-month periods. That’s why some firms use 13 November 2026 and 13 May 2027, while others use 14 November 2026 and 14 May 2027.

So the working calendar is:

Phase 1: November 2025. Already in force. Phase 2: 13 or 14 November 2026. Twelve months from publication. Phase 3: 13 or 14 May 2027. Eighteen months from publication.

I can’t say which date is "correct" because it depends on the Gazette record and any later changes. But your compliance plan shouldn’t depend on just one day. If you’re ready by April 2027, you won’t need to worry about this.

Phase 1: what is already live

This phase set up the basic structure, but your daily obligations under the DPDP Act have not started yet.

The Data Protection Board of India has been established as a four-member body in the National Capital Region. Rules 17 to 21 cover how its Chairperson and Members are selected, their terms of service, how meetings run, and, under Rule 20, that the Board functions as a digital office. Rule 19(9) is worth noting: the Board's inquiry into a complaint is to be completed within six months, extendable in blocks of up to three months with reasons recorded.

The definitions in Section 2 of the Act and Rule 2 of the Rules now apply, so the terms are set. You are a Data Fiduciary if you decide why and how personal data is used. The individual is referred to as the Data Principal. A vendor that processes data on your behalf is a Data Processor. A child is anyone under eighteen, which is stricter than in most other countries.

Section 44 of the Act, which amends the Right to Information Act, 2005 and the TRAI Act, 1997, has also been brought into effect in this tranche. The RTI change narrows the personal information exemption in Section 8(1)(j) of that Act. That is a separate debate, but it is live.

The main DPDP duties, such as notice, consent, safeguards, breach reporting, children’s data, and Data Principal rights, are not active yet. Right now, the Board cannot penalise you under the DPDP Act for a faulty privacy notice or an unreported breach.

But this doesn’t mean nothing applies. Section 43A of the IT Act and the SPDI Rules of 2011 are still in force. CERT-In’s incident reporting rules from April 2022 also still apply. Regulators such as the RBI, SEBI, and IRDAI have their own data and cybersecurity rules that remain in force. If a business mishandles customer data today, it can still face action under these laws, contracts, or consumer protection rules. The DPDP Act is being added to these, not replacing them yet.

Phase 2: November 2026, the Consent Manager regime

Rule 4 and the First Schedule come into force on this date. This is the framework for Consent Managers: registered intermediaries who let an individual give, manage, review and withdraw consent across multiple Data Fiduciaries from one place.

For most businesses, this date does not create any direct obligation. You do not need to register as a Consent Manager or use one unless you want to.

Part A of the First Schedule says, among other things, that the applicant must be a company incorporated in India with a net worth of at least two crore rupees, and its platform must be independently certified against standards the Board will publish.

Part B lists the obligations, including keeping consent records for at least seven years and not being able to read the personal data it routes.

The Board’s power under Rule 4(4) and 4(5) to direct, suspend, or cancel a Consent Manager also begins at this point.

There’s another reason to pay attention to this date, which I’ll explain later under "the proposal that may move things."

Phase 3: May 2027, the real compliance date

This is when the law actually starts to apply. From this date, all the following requirements come into force simultaneously.

Notice and consent. Section 5 requires a notice before or at the time you seek consent. Rule 3 sets out the minimum content: an itemised description of the personal data, the specified purpose, a specific description of the goods, services or uses it enables, and the link and other means by which the individual can withdraw consent, exercise rights and complain to the Board.

Rule 3(c)(i) adds a detail that product teams often miss: it must be just as easy for someone to withdraw consent as it is to give it.

Section 6 sets the consent standard: free, specific, informed, unconditional and unambiguous, with a clear affirmative action.

Pre-ticked boxes and hidden consent in terms will not be allowed under these rules.

Legitimate uses. Section 7 lists the situations in which you can process data without consent, including when the individual voluntarily provided the data for a specified purpose and has not objected; for employment-related purposes; in medical emergencies; and for compliance with the law. The list is closed.

Unlike the GDPR, there is no general "legitimate interest" reason for processing data. This is the biggest change for companies that used European templates.

Security safeguards. Section 8(5) requires reasonable security safeguards. Rule 6(1) sets the floor: measures such as encryption, obfuscation, masking or virtual tokens; access controls; logs, monitoring and review to detect unauthorised access; backups for continuity; security terms in your contracts with Data Processors where applicable; and technical and organisational measures to make all of it stick.

Rule 6(1)(e) also requires you to retain logs and personal data for one year so that unauthorised access can be detected and investigated, unless another law requires otherwise.

Retention. Rule 8 is often misquoted, so read it carefully. Rule 8(1) and the Third Schedule set erasure timelines for large e-commerce entities, online gaming intermediaries and social media intermediaries above user thresholds.

Rule 8(3) is broader: every Data Fiduciary must retain personal data, associated traffic data and other processing logs for at least one year from the date of processing, for the purposes in the Seventh Schedule, then erase them unless another law requires longer.

The examples for Rule 8 show that an e-book platform must keep order and payment logs for a year, even if the customer deletes their account. This does not mean you can keep all records forever. You must erase them after one year unless another law says otherwise.

Breach reporting. Section 8(6) and Rule 7. Rule 7 applies when you become aware of "any personal data breach". You must notify each affected Data Principal without delay, in plain language, via their user account or registered contact details.

The notice must cover the nature of the breach, its likely consequences, what you have done to mitigate, what they can do, and whom to contact.

You must notify the Board right away with a description of the breach. Then, within seventy-two hours, or a longer period if the Board allows in writing, you must provide detailed information, including the causes, mitigation steps, findings on who caused it, what you have done to fix it, and a report on the notifications sent to individuals.

The Rules do not exclude minor breaches. Whether a security incident counts as a "personal data breach" as defined in Section 2(u) is a question you must answer quickly and document, because once it does, the duty applies.

Contact person. Rule 9 states that every Data Fiduciary must clearly display the business contact details of its Data Protection Officer on its website or app. If there is no officer, you must list someone who can answer questions about data processing. This may seem like a small change, but it is the first thing a complainant or the Board will check.

Children's data. Section 9 and Rule 10. Verifiable consent from a parent is required before processing a child's personal data, with due diligence to ensure that the person consenting is an identifiable adult, either from reliable details already held or from identity and age details supplied by the individual, or through a virtual token issued by an authorised entity, including via DigiLocker.

Tracking, behavioural monitoring and targeted advertising directed at children are prohibited under Section 9(3).

Rule 12 and the Fourth Schedule carve out exemptions for specific classes, such as clinical establishments, educational institutions, crèches and school transport providers, and for specific purposes, such as tracking a child's real-time location for safety.

The exemptions are limited and come with conditions. Always check the specific conditions for each exemption before relying on it.

Data Principal rights. Sections 11 to 14 give the right to access a summary of processing, to correction and erasure, to grievance redressal, and to nominate someone to exercise rights on death or incapacity.

Rule 14(1) says you must publish how people can make requests. Rule 14(3) says you must also publish how long you will take to respond to grievances, and this cannot be more than ninety days. Remember, ninety days is the maximum, not the goal.

Significant Data Fiduciaries. Section 10 and Rule 13. Once the Central Government notifies an entity or class as an SDF, it must appoint a Data Protection Officer based in India and an independent data auditor, and, under Rule 13(1), conduct a Data Protection Impact Assessment and an audit every twelve months, with significant findings reported to the Board.

Rule 13(3) requires due diligence that its technical measures, including algorithmic software, do not pose a risk to Data Principals' rights.

Rule 13(4) allows the government, on a committee's recommendation, to specify personal data that SDFs may not transfer outside India.

Cross-border transfers. Section 16 and Rule 15. Personal data may be transferred outside India, subject to any restriction the Central Government notifies on specific countries and any requirements it specifies about making data available to a foreign State or its agencies. This is a negative-list model, not Europe's adequacy model.

Penalties. Section 33 and the Schedule to the Act. The ceilings are up to 250 crore rupees for failing to maintain reasonable security safeguards; up to 200 crore for failing to notify a breach and for breaches of the children's provisions; up to 150 crore for SDF failures; and up to 50 crore for any other violation.

A Data Principal who breaches her own duties, for example by filing a false complaint, can be fined up to ten thousand rupees.

Appeals. Rule 22. An appeal from a Board order goes to the Appellate Tribunal (TDSAT) and is filed digitally, with a fee mirroring the TRAI Act appeal fee unless reduced or waived.

After setting up your process, test it by sending yourself an erasure request and timing how long it takes to complete.

The proposal that may move things

In late January 2026, MeitY held stakeholder consultations at which, according to reports from several law firms, it proposed compressing the eighteen-month window to twelve months for Significant Data Fiduciaries, which would pull their compliance date forward to November 2026. Comments were reportedly sought by 4 February 2026.

There was also talk of enforcing the cross-border restrictions for SDFs sooner.

I want to be precise about the status of this. I have not found an official MeitY consultation paper, press release or Gazette notification giving effect to the proposal; what exists in the public domain is professional commentary on a stakeholder meeting. So, as of the date I am writing, the legal position is still eighteen months, and this is an unconfirmed policy development, not a change in law.

If your organisation is likely to be named as an SDF, which usually means large platforms, banks, insurers, big fintech companies, and similar businesses—you should plan for a compliance date of November 2026. For everyone else, keep an eye on the Gazette and MeitY's website for updates, not just the news.

What this means for a typical Indian business

Let me give some real examples based on the businesses I work with.

A coaching institute in Chandigarh that takes online admissions is collecting data of students under eighteen.

From May 2027, it needs verifiable parental consent under Section 9 and Rule 10 before processing that data. It may be tempted to rely on the "educational institution" entry in the Fourth Schedule, but that exemption is confined to tracking and behavioural monitoring for educational activities or safety.

The exemption does not cover admissions data or allow targeted advertising to students. This requires changes to your product, not just paperwork, and it can take several months.

A garment exporter in Ludhiana with buyers in Europe is mostly a processor for its buyers' data but a fiduciary for its own employees and Indian customers.

Its employee data largely falls under Section 7(i), but its HR policies still need to state this, and its contracts with the payroll provider and the CRM vendor need to include security terms under Rule 6(1)(f).

A D2C brand on Shopify with a WhatsApp marketing list needs to take a hard look at how that list was built. If numbers were collected at checkout for delivery and then used for promotions, the Section 7(a) argument that the data was "voluntarily provided for a specified purpose" is weak for the marketing use, because the purpose communicated was delivering an order.

Whether you can keep the list depends on what notice you gave, what consent you actually got, and whether you can collect new, specific consent before May 2027. This means you need to review your process, not just delete the list automatically.

A chartered accountancy firm holds PAN, Aadhaar, bank statements and income details of hundreds of clients. It is a Data Fiduciary for that data, whatever the engagement letter says. Rule 6 logging, a breach process under Rule 7, a published contact under Rule 9, and a grievance channel under Section 13 and Rule 14 are the immediate gaps.

None of these examples are unusual. They show the typical challenges businesses face.

A practical order of work between now and May 2027

If you are starting from zero with about eight months in hand, I would sequence it like this.

First, find out what personal data you have, where it is stored, and who can access it. Separate employee, customer, marketing, children's, and vendor data, since each type needs a different approach. You cannot do anything else until you have this inventory.

Second, update your privacy notice to meet Rule 3 and redesign how you collect consent to meet Section 6. Customers and the Board will see this first, so it is the main thing people will check.

Third, add security terms to every processor contract and make sure you have the logs required by Rule 6 and Rule 8(3). If you cannot provide a year's worth of access logs, you risk a penalty of up to 250 crore rupees.

Fourth, create a breach response plan. Decide now who contacts whom in the first hour, and who will decide if an incident counts as a "personal data breach." Remember, you have only seventy-two hours to act, so you cannot wait for a board meeting.

Fifth, publish the Rule 9 contact details and the Rule 14 grievance process with a named person. If your business serves children, establish a process to obtain parental consent.

Sixth, keep complying with the IT Act, SPDI Rules, CERT-In directions and your sector regulator until the DPDP tranche that repeals Section 43A actually commences.

Then test it. Send yourself an erasure request and see how long it takes.

Where to check the primary sources

Do not rely on this article or any other for the actual text of the law. You can find the Act on the India Code portal and MeitY's website. The Rules are in Gazette notification G.S.R. 846(E) dated 13 November 2025, also on MeitY's site with the commencement notifications for the Act. The Board's website will publish its procedures and orders as they come out.

I will update this page when a notification changes any of the dates above.


This article is for general educational purposes only and does not constitute legal advice. Reading it does not create an advocate-client relationship.

← Back to all articles

Have a legal question?

These articles are for awareness. For advice specific to your situation, start a conversation.

Request a Consultation