Readiness assessment
DPDP Act 2023 · Status and priorities

DPDP Compliance Timeline and Implementation Priorities

Where India's Digital Personal Data Protection Act stands right now, what binds in November 2026 and May 2027, and what your organisation should actually be doing in the window between. A living tracker, kept current against the gazette.

Where things stand · August 2026
About 9 months until the major substantive obligations commence
Full duties and penalties begin 13 May 2027, with no grace period.

Where DPDP stands, in short

In force todayOnly the machinery. The Board still has no members, so no complaint can be heard and no penalty issued.
The date that bites13 May 2027, when consent, security, breach, rights and penalties all begin together, with no grace period.
The common trapAlmost no business needs to register as a Consent Manager. Most need a compliant consent platform.
Where to startMap your personal data first. It gates notices, rights and erasure, and it takes quarters to build.
The phased timeline

What binds when

The DPDP Rules 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The commencement notification split the Act into three phases, timed from that date.

AUG 2026 · NOW 13 Nov 2025 13 Nov 2026 13 May 2027
Phase 1 · MachineryIn force. Definitions, the Board, rule-making powers, and the s.44(3) RTI amendment.
Phase 2 · Consent ManagersRegistration of Consent Managers under s.6(9) and Rule 4. A registered entity, not software.
Phase 3 · Substantive dutiesConsent, security, breach, retention, children, SDF, rights, cross-border, and penalties.
Phase detail, keyed to the Act and the DPDP Rules 2025.
PhaseEffectiveWhat commences
1 · Machinery13 Nov 2025Definitions (s.2); Data Protection Board establishment and functioning (ss.18 to 26); good-faith protection (s.35); rule-making and miscellaneous (ss.38 to 43, 44(1)); the s.44(3) amendment to the RTI Act; Rules on Board appointments, salaries and digital-office functioning.
2 · Consent Managers13 Nov 2026Section 6(9) and s.27(1)(d); Rule 4, the registration and obligations of Consent Managers. First Schedule conditions include incorporation in India and a net worth of at least Rs 2 crore.
3 · Substantive duties13 May 2027Consent and notice (ss.4 to 7, Rule 3); security safeguards (s.8(5), Rule 6); breach notification (s.8(6), Rule 7, a detailed report to the Board within 72 hours); retention and erasure (Rule 8); children's data (s.9, Rules 10 to 12); Significant Data Fiduciary duties (s.10, Rule 13); data-principal rights (ss.11 to 14, Rule 14); cross-border conditions (s.16, Rule 15); inquiries and penalties (ss.27 to 28, 33 with the Schedule).

Dates in the gazette are expressed as twelve and eighteen months from publication; most trackers render these as 13 November 2026 and 13 May 2027.

Living tracker

Where enforcement actually stands

Four moving parts decide how much of the timeline is real today. This is the part most compliance calendars leave out.

Data Protection Board Unstaffed

The Board was established with effect from 13 November 2025, with a strength of a chairperson and four members. Recruitment for those posts was only invited by MeitY on 6 May 2026, and no appointments had been announced by mid-2026.

What it means: there is no functioning forum. No complaints are adjudicated, no penalty orders issued, and no enforcement posture published. Watch: the appointment of the chairperson and members.

Consent Managers None registered

The Consent Manager is a registered intermediary through which individuals give, manage and withdraw consent across fiduciaries. Registration under Rule 4 does not open until 13 November 2026, and no entity is registered yet.

What it means: for almost every business the correct step is a compliant consent platform for the May 2027 standard, not applying to become a Consent Manager. Watch: the Board opening registration and publishing technical standards.

Significant Data Fiduciaries None designated

No organisation has been notified as an SDF, and the designation criteria are not yet notified. A January 2026 proposal to compress the SDF window from eighteen months to twelve (to November 2026) has not been gazetted.

What it means: treat the acceleration as a proposal, not law. If you are likely to be designated, prudently plan to the earlier date. Watch: any gazette notification of SDF criteria or a shortened window.

Section 44(3) RTI amendment In court

The one substantive change already in force, s.44(3), rewrote the RTI Act's personal-information exemption. Writ petitions challenging it were referred to a five-judge Constitution Bench on 16 February 2026, with no interim stay, and remained pending in mid-2026.

What it means: the framework's architecture could still shift mid-rollout. Watch: the Constitution Bench's hearings and any order.

What is at stake

The penalty exposure

The Schedule sets per-violation maximums, applied at the Board's discretion after inquiry, with no minimums and no criminal sanctions. They can only be imposed once Phase 3 commences.

ViolationProvisionMaximum penalty
Failure to take reasonable security safeguardss.8(5)Rs 250 crore
Failure to notify a personal data breachs.8(6)Rs 200 crore
Breach of children's-data obligationss.9Rs 200 crore
Breach of Significant Data Fiduciary obligationss.10Rs 150 crore
Any other breach of the Act or RulesgeneralRs 50 crore
Breach of a data principal's dutiess.15Rs 10,000
The scale behind the numbers. India counted 1,028.61 million internet subscribers at the end of 2025. That is the base of data principals these duties will run to, which is why reading the long runway as low urgency is a timing bet, not a safe default.

The DPDP implementation runway

The same journey every data fiduciary runs between now and May 2027. Each stage feeds the next, and none of it compresses into the final weeks.

Discover
Data inventory: what you hold, where it sits, and why.
Design
Notices · consent · rights.
Operationalise
Deletion · vendors · breach response.
Prove
Evidence · testing · DPIA and audit.
13 May 2027
Operational readiness.
Implementation priorities

What to prioritise in this window

Ordered by what unblocks the most work and what takes the longest to build. This is a hub, not a dead end: each priority links straight to where the detail lives.

Start here
1

Map your personal data first

Everything downstream depends on it.

You cannot write purpose-specific notices, honour erasure timelines or fulfil rights requests without knowing what personal data you hold, where it sits and why. In most Indian organisations that inventory does not exist yet, and building it takes quarters.

Follow the implementation roadmap →
Then, in order
2

Design consent and withdrawal

The primary legal basis, live from May 2027.

Consent must be free, specific, informed, unconditional and unambiguous, with no bundling, and withdrawal as easy as giving it. Settle one thing early: almost no business needs to register as a Consent Manager. Most need a compliant consent platform, not the statutory role.

Go to the consent guide →
3

Stand up rights operations

Access, correction, erasure, grievance, nomination.

Data principals gain enforceable rights with response timelines set by the Rules. A request intake, an identity check, a fulfilment workflow and a grievance route need to exist and be tested before the duties bind, not designed on the day a request lands.

Understand data-principal rights →
4

Assess your SDF exposure

Heavier duties, and a possibly earlier clock.

If you are likely to be designated a Significant Data Fiduciary, the extra duties are a DPO based in India, periodic Data Protection Impact Assessments and an independent audit. These carry lead time and, if the acceleration is gazetted, a shorter runway.

Check what SDF status means →
5

Build a breach runbook

Two clocks on one incident.

The Rules require a detailed breach report to the Board within 72 hours and notice to affected individuals, with no materiality threshold. Fold this into a single runbook alongside the separate CERT-In six-hour reporting duty so one incident does not trigger two uncoordinated scrambles.

See breach notification →
6

Fix vendor paper and transfers

Liability sits with you, not the processor.

Processor contracts, breach flow-downs and retention terms take procurement cycles to land. Cross-border transfers follow a negative-list model under Rule 15, with stricter sectoral rules such as RBI localisation preserved. Scope the remediation across the vendor estate now.

See the implementation framework →
Not sure where you stand? The free DPDP readiness assessment scores your organisation across these areas in a few minutes and returns a prioritised gap list. Start the assessment →
Calibrating urgency

A long runway is not low urgency

What nine months sounds like

Plenty of time.

What implementation actually involves

Inventory decisions engineering vendors testing remediation evidence

Under the GDPR, obligations applied about 25 months after adoption, to regulators that already existed, and the first major fine landed within a year. India's Board is still being staffed, but once it is, enforcement tends to follow readiness quickly. A GDPR programme is a head start, not a pass: DPDP centres on consent with no legitimate-interests route, notices in the languages of the Eighth Schedule, breach notification to every affected person without a risk threshold, and a distinct cross-border model.

Frequently asked questions

Is the DPDP Act in force in 2026?

Partly. The commencement notification of 13 November 2025 brought definitions, the Data Protection Board's establishment provisions, rule-making powers and the Section 44(3) RTI amendment into force. The substantive obligations on data fiduciaries, consent, notice, security, breach notification and data-principal rights, commence on 13 May 2027, with Consent Manager registration opening on 13 November 2026.

What is due in November 2026 versus May 2027?

November 2026 opens Consent Manager registration under Section 6(9) and Rule 4, which matters mainly to entities intending to operate as registered Consent Managers. May 2027 is when the full set of duties, consent and notice, security, breach reporting, retention, children's data, SDF obligations, rights and cross-border conditions, and the penalty regime all become enforceable.

Has anyone been fined under the DPDP Act yet?

No. As of mid-2026 there are no penalty orders or public enforcement actions. The Data Protection Board has no chairperson or members yet, recruitment opened only in May 2026, and the inquiry and penalty provisions do not commence until May 2027.

Do we need to register as a Consent Manager?

Almost certainly not. A Consent Manager is a specific registered entity, incorporated in India with a net worth of at least Rs 2 crore, that acts as a neutral interface for individuals to manage consent across many fiduciaries. For the overwhelming majority of businesses the correct step is deploying a compliant consent platform against the May 2027 standard, not applying for the statutory role.

Is the SDF deadline November 2026 or May 2027?

May 2027, on the current law. A January 2026 proposal to compress the Significant Data Fiduciary window to twelve months, moving it to November 2026, has not been gazetted. If your organisation is likely to be designated an SDF, the prudent planning assumption is the earlier date, but the enforceable deadline today is May 2027.

Does GDPR compliance make us DPDP-ready?

It helps but does not suffice. DPDP centres on consent as the primary basis with no legitimate-interests route, requires notices in the languages of the Eighth Schedule, mandates breach notification to every affected person without a risk threshold, and follows a different cross-border model. A GDPR programme needs adaptation, not relabelling.

What should we prioritise right now?

Data mapping first, because notice, rights and erasure all depend on it. Then consent and withdrawal design, rights operations, an SDF-exposure assessment, a breach runbook, and vendor and cross-border contract work. The priorities section above orders these and links each to the detail.

Sources and methodology

Every date and figure on this page is keyed to a primary source: the DPDP Act 2023 and its Schedule; the DPDP Rules 2025 (G.S.R. 846(E), 13 November 2025) and the commencement notification; the notifications establishing the Data Protection Board and fixing its strength; MeitY's recruitment circular of 6 May 2026; and the Supreme Court's reference of the Section 44(3) challenge to a Constitution Bench. Proposals, such as the SDF acceleration, are labelled as proposals. Absences, such as no Board members and no registered Consent Managers, are verified as absences rather than assumed.

Status as of August 2026. This tracker is refreshed quarterly, and sooner if a commencement-changing notification issues. If you spot something out of date, tell us.

This page is legal information for orientation, not legal advice. Confirm anything you rely on with qualified counsel.

Find your DPDP implementation priorities

Answer a short assessment and see which controls your organisation should address first, based on your size, sector, data and current readiness.