The Digital Personal Data Protection Act was passed in August 2023 and then sat largely dormant, because a law that depends on rules cannot operate until the rules exist. They now do β and they arrive with a deliberately staggered commencement rather than a single switch.
The DPDP Rules were notified on 13 November 2025. A small set of provisions took effect immediately, Consent Manager registration opens on 13 November 2026, and the substantive compliance obligations bite on 13 May 2027.
That staggering is the most commercially useful fact in the whole regime, and it is the one most coverage skips. It means the enforcement date for the obligations that will actually cost you money is not today β but the work needed to meet them takes longer than the time remaining, which is why starting now matters.
This guide is about the calendar. For what the Act itself requires, start with our DPDP Act compliance guide.
The bottom line
Phase 1 β 13 November 2025: Rules 1, 2 and 17 to 21. Definitions and the machinery of the Data Protection Board.
Phase 2 β 13 November 2026: Rule 4. Consent Manager registration and obligations.
Phase 3 β 13 May 2027: Rules 3, 5 to 16, 22 and 23. The substantive duties: notice, security safeguards, breach notification, retention limits, children's data, data principal rights.
Phase 1: what took effect on 13 November 2025
The provisions that commenced on notification are structural rather than operational. They put the definitions in place and stand up the Data Protection Board of India β the adjudicating body that will eventually hear complaints and impose penalties.
Nothing in this phase requires a business to change how it handles data. What it does is create the institution that will enforce the later phases, which is why it had to come first.
Phase 2: Consent Managers
On 13 November 2026, one year after notification, Rule 4 brings the Consent Manager framework into force.
A Consent Manager is a registered intermediary through which a person can give, manage, review and withdraw consent across different organisations from a single interface. It is one of the genuinely novel features of the Indian regime β there is no direct GDPR equivalent β and it exists because the Act runs almost entirely on consent rather than on multiple lawful bases.
This phase matters directly if you intend to become a Consent Manager, since registration with the Board and the associated obligations begin here. For most businesses, the relevance is indirect: it is the point at which the plumbing for consent withdrawal starts to exist, and you should know whether you will interact with it.
Phase 3: the obligations that actually bite
This is the phase to plan for. On 13 May 2027 the substantive duties come into force together:
- Notice. A clear, standalone, plain-language notice telling people what personal data you collect, for what purpose, how to withdraw consent, and how to complain β not a clause buried in terms of service.
- Security safeguards. Reasonable technical and organisational measures, including encryption or comparable protection, access controls, logging, and contractual obligations on processors.
- Breach notification. Intimation to affected individuals and to the Board, on the prescribed timelines β see our data breach guide for the mechanics.
- Retention and erasure. Data deleted once the purpose is served, with specified retention periods for certain classes of large platform.
- Data principal rights. Access, correction, erasure and grievance redressal, with a published route to exercise them and defined response timelines.
- Children's data. Verifiable parental consent for anyone under 18, and prohibitions on tracking and targeted advertising directed at children.
- Significant Data Fiduciaries. Additional duties for organisations notified as such β a Data Protection Officer based in India, independent audits and periodic impact assessments.
Penalties under the Act run to substantial sums, with the highest bracket reaching βΉ250 crore for failure to take reasonable security safeguards.
What to do in the meantime
May 2027 sounds distant. It is not, because three of these tasks take longer than people expect and none can be done in the final month.
Build a data inventory. You cannot write an accurate notice, honour an erasure request or notify a breach if you do not know what personal data you hold, where it lives, who can reach it, and which vendors touch it. For most organisations this is the single largest piece of work in the whole programme, and it is entirely doable today.
Fix your consent capture. Consent under the Act must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Pre-ticked boxes and bundled consent do not qualify. Most existing Indian signup flows will need rebuilding, and rebuilding a signup flow is a product project, not a legal one.
Paper your processors. If a vendor processes personal data for you, the contract needs to reflect that. Renegotiating a supplier contract takes months.
Worked example
A 30-person Indian SaaS company holds email addresses, names, usage logs and support tickets for its customers' end users, and uses three sub-processors abroad.
Today: no operative obligation, but it begins mapping what it holds and where, and lists every vendor that touches personal data.
Over the following months: it rewrites its signup consent so it is specific and unbundled, builds a self-service route for access and deletion requests, sets a retention rule for support tickets, and adds data-processing terms to its three vendor contracts.
Before 13 May 2027: it publishes a standalone privacy notice, appoints someone accountable, and runs a tabletop exercise on breach notification so the first time it works out who calls the Board is not during an actual incident.
Every one of those steps is available now. None depends on a further notification.
Common mistakes
- Reading May 2027 as "not yet my problem". The data inventory alone takes most organisations several months.
- Assuming the Act is a copy of GDPR. It runs on consent rather than six lawful bases, and it has no direct equivalent of legitimate interests.
- Treating the privacy policy as the notice. The Act contemplates a specific, standalone notice.
- Overlooking the under-18 rule. India's threshold is 18, higher than in many other regimes, and it catches consumer apps that never thought of themselves as children's services.
- Forgetting processors. Your obligations do not stop at your own systems.
- Waiting for perfect clarity. Some operational detail will keep emerging; the inventory and consent work does not depend on it.
Checklist
- Map every category of personal data you hold, its location, and who can access it.
- List every vendor and sub-processor that touches personal data.
- Audit consent capture β remove pre-ticked boxes and unbundle consents.
- Draft a standalone, plain-language notice separate from your terms.
- Build a route for access, correction and erasure requests, with an owner and a response time.
- Set retention periods per data category and a mechanism that actually deletes.
- Add data-processing terms to vendor contracts.
- Write and rehearse a breach response runbook.
- Check whether you handle under-18 data, and design verifiable parental consent if you do.
Frequently asked questions
Is the DPDP Act in force now? The Act is law and the Rules were notified on 13 November 2025, but commencement is staggered. The substantive obligations arrive on 13 May 2027.
When exactly must I comply? 13 May 2027 for almost everything. The exception is Consent Manager registration, which opens a year earlier on 13 November 2026.
Does this apply to a small business? Yes. The Act does not carry a general small-business exemption, though Significant Data Fiduciary duties apply only to organisations notified as such.
Does it apply to companies outside India? It reaches processing outside India where that processing relates to offering goods or services to people in India.
What is a Consent Manager? A registered intermediary letting a person manage and withdraw consent across organisations from one place. Registration begins in the second phase.
What is the maximum penalty? The highest bracket under the Act reaches βΉ250 crore, for failing to take reasonable security safeguards.
What single thing should I start with? The data inventory. Every other obligation depends on knowing what you hold.