Where India's Digital Personal Data Protection Act stands right now, what binds in November 2026 and May 2027, and what your organisation should actually be doing in the window between. A living tracker, kept current against the gazette.
The DPDP Rules 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The commencement notification split the Act into three phases, timed from that date.
| Phase | Effective | What commences |
|---|---|---|
| 1 · Machinery | 13 Nov 2025 | Definitions (s.2); Data Protection Board establishment and functioning (ss.18 to 26); good-faith protection (s.35); rule-making and miscellaneous (ss.38 to 43, 44(1)); the s.44(3) amendment to the RTI Act; Rules on Board appointments, salaries and digital-office functioning. |
| 2 · Consent Managers | 13 Nov 2026 | Section 6(9) and s.27(1)(d); Rule 4, the registration and obligations of Consent Managers. First Schedule conditions include incorporation in India and a net worth of at least Rs 2 crore. |
| 3 · Substantive duties | 13 May 2027 | Consent and notice (ss.4 to 7, Rule 3); security safeguards (s.8(5), Rule 6); breach notification (s.8(6), Rule 7, a detailed report to the Board within 72 hours); retention and erasure (Rule 8); children's data (s.9, Rules 10 to 12); Significant Data Fiduciary duties (s.10, Rule 13); data-principal rights (ss.11 to 14, Rule 14); cross-border conditions (s.16, Rule 15); inquiries and penalties (ss.27 to 28, 33 with the Schedule). |
Dates in the gazette are expressed as twelve and eighteen months from publication; most trackers render these as 13 November 2026 and 13 May 2027.
Four moving parts decide how much of the timeline is real today. This is the part most compliance calendars leave out.
The Board was established with effect from 13 November 2025, with a strength of a chairperson and four members. Recruitment for those posts was only invited by MeitY on 6 May 2026, and no appointments had been announced by mid-2026.
What it means: there is no functioning forum. No complaints are adjudicated, no penalty orders issued, and no enforcement posture published. Watch: the appointment of the chairperson and members.
The Consent Manager is a registered intermediary through which individuals give, manage and withdraw consent across fiduciaries. Registration under Rule 4 does not open until 13 November 2026, and no entity is registered yet.
What it means: for almost every business the correct step is a compliant consent platform for the May 2027 standard, not applying to become a Consent Manager. Watch: the Board opening registration and publishing technical standards.
No organisation has been notified as an SDF, and the designation criteria are not yet notified. A January 2026 proposal to compress the SDF window from eighteen months to twelve (to November 2026) has not been gazetted.
What it means: treat the acceleration as a proposal, not law. If you are likely to be designated, prudently plan to the earlier date. Watch: any gazette notification of SDF criteria or a shortened window.
The one substantive change already in force, s.44(3), rewrote the RTI Act's personal-information exemption. Writ petitions challenging it were referred to a five-judge Constitution Bench on 16 February 2026, with no interim stay, and remained pending in mid-2026.
What it means: the framework's architecture could still shift mid-rollout. Watch: the Constitution Bench's hearings and any order.
The Schedule sets per-violation maximums, applied at the Board's discretion after inquiry, with no minimums and no criminal sanctions. They can only be imposed once Phase 3 commences.
| Violation | Provision | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards | s.8(5) | Rs 250 crore |
| Failure to notify a personal data breach | s.8(6) | Rs 200 crore |
| Breach of children's-data obligations | s.9 | Rs 200 crore |
| Breach of Significant Data Fiduciary obligations | s.10 | Rs 150 crore |
| Any other breach of the Act or Rules | general | Rs 50 crore |
| Breach of a data principal's duties | s.15 | Rs 10,000 |
The same journey every data fiduciary runs between now and May 2027. Each stage feeds the next, and none of it compresses into the final weeks.
Ordered by what unblocks the most work and what takes the longest to build. This is a hub, not a dead end: each priority links straight to where the detail lives.
Everything downstream depends on it.
You cannot write purpose-specific notices, honour erasure timelines or fulfil rights requests without knowing what personal data you hold, where it sits and why. In most Indian organisations that inventory does not exist yet, and building it takes quarters.
Follow the implementation roadmap →The primary legal basis, live from May 2027.
Consent must be free, specific, informed, unconditional and unambiguous, with no bundling, and withdrawal as easy as giving it. Settle one thing early: almost no business needs to register as a Consent Manager. Most need a compliant consent platform, not the statutory role.
Go to the consent guide →Access, correction, erasure, grievance, nomination.
Data principals gain enforceable rights with response timelines set by the Rules. A request intake, an identity check, a fulfilment workflow and a grievance route need to exist and be tested before the duties bind, not designed on the day a request lands.
Understand data-principal rights →Heavier duties, and a possibly earlier clock.
If you are likely to be designated a Significant Data Fiduciary, the extra duties are a DPO based in India, periodic Data Protection Impact Assessments and an independent audit. These carry lead time and, if the acceleration is gazetted, a shorter runway.
Check what SDF status means →Two clocks on one incident.
The Rules require a detailed breach report to the Board within 72 hours and notice to affected individuals, with no materiality threshold. Fold this into a single runbook alongside the separate CERT-In six-hour reporting duty so one incident does not trigger two uncoordinated scrambles.
See breach notification →Liability sits with you, not the processor.
Processor contracts, breach flow-downs and retention terms take procurement cycles to land. Cross-border transfers follow a negative-list model under Rule 15, with stricter sectoral rules such as RBI localisation preserved. Scope the remediation across the vendor estate now.
See the implementation framework →Plenty of time.
Inventory → decisions → engineering → vendors → testing → remediation → evidence
Under the GDPR, obligations applied about 25 months after adoption, to regulators that already existed, and the first major fine landed within a year. India's Board is still being staffed, but once it is, enforcement tends to follow readiness quickly. A GDPR programme is a head start, not a pass: DPDP centres on consent with no legitimate-interests route, notices in the languages of the Eighth Schedule, breach notification to every affected person without a risk threshold, and a distinct cross-border model.
This page is the map. Each destination below is the depth behind a priority above.
Partly. The commencement notification of 13 November 2025 brought definitions, the Data Protection Board's establishment provisions, rule-making powers and the Section 44(3) RTI amendment into force. The substantive obligations on data fiduciaries, consent, notice, security, breach notification and data-principal rights, commence on 13 May 2027, with Consent Manager registration opening on 13 November 2026.
November 2026 opens Consent Manager registration under Section 6(9) and Rule 4, which matters mainly to entities intending to operate as registered Consent Managers. May 2027 is when the full set of duties, consent and notice, security, breach reporting, retention, children's data, SDF obligations, rights and cross-border conditions, and the penalty regime all become enforceable.
No. As of mid-2026 there are no penalty orders or public enforcement actions. The Data Protection Board has no chairperson or members yet, recruitment opened only in May 2026, and the inquiry and penalty provisions do not commence until May 2027.
Almost certainly not. A Consent Manager is a specific registered entity, incorporated in India with a net worth of at least Rs 2 crore, that acts as a neutral interface for individuals to manage consent across many fiduciaries. For the overwhelming majority of businesses the correct step is deploying a compliant consent platform against the May 2027 standard, not applying for the statutory role.
May 2027, on the current law. A January 2026 proposal to compress the Significant Data Fiduciary window to twelve months, moving it to November 2026, has not been gazetted. If your organisation is likely to be designated an SDF, the prudent planning assumption is the earlier date, but the enforceable deadline today is May 2027.
It helps but does not suffice. DPDP centres on consent as the primary basis with no legitimate-interests route, requires notices in the languages of the Eighth Schedule, mandates breach notification to every affected person without a risk threshold, and follows a different cross-border model. A GDPR programme needs adaptation, not relabelling.
Data mapping first, because notice, rights and erasure all depend on it. Then consent and withdrawal design, rights operations, an SDF-exposure assessment, a breach runbook, and vendor and cross-border contract work. The priorities section above orders these and links each to the detail.
Every date and figure on this page is keyed to a primary source: the DPDP Act 2023 and its Schedule; the DPDP Rules 2025 (G.S.R. 846(E), 13 November 2025) and the commencement notification; the notifications establishing the Data Protection Board and fixing its strength; MeitY's recruitment circular of 6 May 2026; and the Supreme Court's reference of the Section 44(3) challenge to a Constitution Bench. Proposals, such as the SDF acceleration, are labelled as proposals. Absences, such as no Board members and no registered Consent Managers, are verified as absences rather than assumed.
This page is legal information for orientation, not legal advice. Confirm anything you rely on with qualified counsel.
Answer a short assessment and see which controls your organisation should address first, based on your size, sector, data and current readiness.