Timelines · 5 min read · Updated October 2026

DPDP timeline explained: what's due, and when

India's data protection law was passed in 2023 but only switched on in November 2025. Here is the rollout in one page — and why May 2027 is closer than it looks.

Key takeaways

  • The DPDP Act received assent on 11 August 2023; MeitY notified the DPDP Rules on 13 November 2025.
  • Most obligations on businesses are enforceable from 13 May 2027.
  • A January 2026 proposal could pull Significant Data Fiduciaries forward to November 2026.
  • Remediation touches product, engineering and vendors — starting now is not early.

How we got here

Parliament enacted the Digital Personal Data Protection Act in August 2023, but left most of the operational detail — how consent must look, how breaches are reported, how long data can be kept — to rules. Draft rules came out on 3 January 2025, drew 6,915 public inputs from consultations across seven cities, and were finalised in November 2025.

The three phases

13 November 2025 — immediate

Definitions and the Data Protection Board of India. The Board is digital-first: complaints are filed and tracked online, and appeals go to TDSAT.

13 November 2026 — 12 months

Consent Manager registration. This binds companies that want to operate as Consent Managers, not ordinary businesses — but expect consent-manager integrations to start appearing in vendor roadmaps.

13 May 2027 — 18 months

Everything else that matters to a Data Fiduciary: notice and consent, security safeguards, breach notification, retention and erasure, children's data, rights requests, and the additional duties of Significant Data Fiduciaries. Penalties apply from here.

The proposal that could change the date

On 23 January 2026, MeitY met industry and proposed compressing the compliance window from 18 to 12 months for Significant Data Fiduciaries, and bringing some provisions — such as cross-border restrictions — into force sooner. As of October 2026 this has not been notified in the Gazette. If it is, the largest data processors would face a November 2026 deadline.

Our view: if you process large volumes of personal or sensitive data, plan to the earlier date. If you don't, plan to May 2027 — but remember your large customers may push their deadline down to you as a vendor.

Working back from the deadline

A typical programme runs in four stages: discovery and data mapping, gap assessment, remediation (systems, notices, contracts, processes), and readiness testing. Remediation is the long pole — consent capture and erasure workflows touch product, engineering and every vendor that holds your data.

Months remaining to 13 May 2027 by start date
If you start in…Months to 13 May 2027Room for slippage
November 20266Little to none
January 20274None
March 20272Triage only

What to do this quarter

  1. Name an owner and a budget.
  2. Build a personal-data inventory: what you collect, why, where it lives, who you share it with.
  3. Decide whether you could be a Significant Data Fiduciary.
  4. Run a gap assessment against the Act and Rules.
  5. Rewrite your breach process to meet both CERT-In's 6 hours and the Board's 72 hours.

Not sure where you stand?

Take the free 3-minute readiness check, or book a scoping call for a full assessment.

Sources: DPDP Act, 2023 and DPDP Rules, 2025 (MeitY); PIB backgrounder, 17 November 2025. General information, not legal advice.