DPDP timeline explained: what's due, and when
India's data protection law was passed in 2023 but only switched on in November 2025. Here is the rollout in one page — and why May 2027 is closer than it looks.
Key takeaways
- The DPDP Act received assent on 11 August 2023; MeitY notified the DPDP Rules on 13 November 2025.
- Most obligations on businesses are enforceable from 13 May 2027.
- A January 2026 proposal could pull Significant Data Fiduciaries forward to November 2026.
- Remediation touches product, engineering and vendors — starting now is not early.
How we got here
Parliament enacted the Digital Personal Data Protection Act in August 2023, but left most of the operational detail — how consent must look, how breaches are reported, how long data can be kept — to rules. Draft rules came out on 3 January 2025, drew 6,915 public inputs from consultations across seven cities, and were finalised in November 2025.
The three phases
13 November 2025 — immediate
Definitions and the Data Protection Board of India. The Board is digital-first: complaints are filed and tracked online, and appeals go to TDSAT.
13 November 2026 — 12 months
Consent Manager registration. This binds companies that want to operate as Consent Managers, not ordinary businesses — but expect consent-manager integrations to start appearing in vendor roadmaps.
13 May 2027 — 18 months
Everything else that matters to a Data Fiduciary: notice and consent, security safeguards, breach notification, retention and erasure, children's data, rights requests, and the additional duties of Significant Data Fiduciaries. Penalties apply from here.
The proposal that could change the date
On 23 January 2026, MeitY met industry and proposed compressing the compliance window from 18 to 12 months for Significant Data Fiduciaries, and bringing some provisions — such as cross-border restrictions — into force sooner. As of October 2026 this has not been notified in the Gazette. If it is, the largest data processors would face a November 2026 deadline.
Our view: if you process large volumes of personal or sensitive data, plan to the earlier date. If you don't, plan to May 2027 — but remember your large customers may push their deadline down to you as a vendor.
Working back from the deadline
A typical programme runs in four stages: discovery and data mapping, gap assessment, remediation (systems, notices, contracts, processes), and readiness testing. Remediation is the long pole — consent capture and erasure workflows touch product, engineering and every vendor that holds your data.
| If you start in… | Months to 13 May 2027 | Room for slippage |
|---|---|---|
| November 2026 | 6 | Little to none |
| January 2027 | 4 | None |
| March 2027 | 2 | Triage only |
What to do this quarter
- Name an owner and a budget.
- Build a personal-data inventory: what you collect, why, where it lives, who you share it with.
- Decide whether you could be a Significant Data Fiduciary.
- Run a gap assessment against the Act and Rules.
- Rewrite your breach process to meet both CERT-In's 6 hours and the Board's 72 hours.
Not sure where you stand?
Take the free 3-minute readiness check, or book a scoping call for a full assessment.
Sources: DPDP Act, 2023 and DPDP Rules, 2025 (MeitY); PIB backgrounder, 17 November 2025. General information, not legal advice.