August 5, 2026 · 12 min read
DPDP Rules 2025 Timeline: Every Date and Deadline
India's DPDP framework commences in three phases — 13 November 2025, 13 November 2026 and 13 May 2027. This is the rule-by-rule breakdown of what activates when
DPDP Rules 2025 Timeline: Every Date, Every Rule, and What to Build When
By Yatin Chaudhary, SEO Specialist at ProtectComply · Last updated 5 August 2026 · 12 min read
Quick answer
India's DPDP framework commences in three phases:
13 November 2025 — Rules 1, 2 and 17–21 in force. Data Protection Board of India constituted. Definitions and procedural framework live. Complaints can be filed.
13 November 2026 — Rule 4 in force. Consent Manager registration opens. Enforcement and penalty machinery becomes operative.
13 May 2027 — Rules 3, 5–16, 22 and 23 in force. Full compliance required: notice, consent standards, Data Principal rights, security safeguards, breach reporting, retention and deletion, children's data, cross-border conditions.
Your deadline is 13 May 2027. No grace period is expected, because the Board is already operational and complaints can already be filed.
Two gazette notifications, not one
This trips people up, including several published guides.
G.S.R. 843(E), 13 November 2025 — the commencement notification for the Act, setting which sections take effect immediately, at 12 months, and at 18 months.
G.S.R. 846(E), 13 November 2025 — the DPDP Rules, 2025 themselves: 23 rules and 7 schedules, with their own staggered commencement in Rule 1.
Both dated the same day. They do different jobs. Citing only one when discussing statutory commencement is incomplete, and citing the wrong one in a compliance document is the kind of error a regulator notices.
Dates you will see misreported
Worth stating plainly, because several widely-shared guides carry these errors:
- The Rules were not notified in January 2025. January 2025 was the draft Rules, published for consultation. The final Rules came on 13 November 2025.
- Notification was 13 November 2025, not the 14th.
- Full compliance is 13 May 2027, not the 14th.
- There is no separate "DPDP Act 2025." The Act is the 2023 statute. 2025 is when the Rules operationalised it.
If your internal compliance calendar was built from a secondary source, check it against the gazette.
Phase 1 — 13 November 2025
Rules in force: 1, 2, 17–21
What activated: Rule 1 sets commencement itself. Rule 2 supplies definitions. Rules 17–21 cover the Data Protection Board's constitution, its procedures, and transitional provisions.
What it means for you: no direct operational burden. But the enforcement structure now exists. The Board is constituted, and Data Principals can lodge complaints.
That last point is the one organisations underweight. The absence of a compliance deadline is not the absence of a regulator. A complaint filed today lands with a constituted Board.
What you should have done by now: determined whether you are a Data Fiduciary, whether you might be designated a Significant Data Fiduciary, and scoped which of your processing falls in the Act's ambit.
Phase 2 — 13 November 2026
Rule in force: 4
What activates: registration and obligations of Consent Managers. Alongside this, the Act's enforcement and penalty provisions become operative.
What it means for you: almost certainly nothing directly. Rule 4 governs entities that want to operate as registered consent intermediaries — a high bar involving Indian incorporation, ₹2 crore minimum net worth, independent platform certification and direct accountability to the Board. Most operating businesses will never register.
What does affect you is the second half. From this date the penalty framework is live. An inquiry opened after 13 November 2026 has teeth.
What you should have done by then: consent architecture rebuilt and tested, notices drafted in Eighth Schedule languages, breach response runbook written and rehearsed. Not because Rule 3 has commenced — it hasn't — but because you have six months left and no slack.
Phase 3 — 13 May 2027
Rules in force: 3, 5–16, 22, 23
This is where the substance lands. Broadly:
- Rule 3 — notice to Data Principals: clear, plain-language, itemised
- Rules 5–6 — legitimate uses and security safeguards, including logging
- Rule 7 — personal data breach notification, to the Board and to affected individuals
- Rule 8 — retention and erasure, with prescribed periods for certain classes
- Rule 9 — contact details for the DPO or designated person
- Rule 10 — verifiable consent for children's data and persons with disabilities
- Rules 11–13 — Data Principal rights, and Significant Data Fiduciary obligations including DPIA and audit
- Rules 14–16 — cross-border transfer conditions and related provisions
- Rules 22–23 — Appellate Tribunal and consequential provisions
What it means for you: everything. Notice, consent, rights fulfilment, safeguards, breach reporting, retention, children's data, transfers.
Working backwards from May 2027
Eighteen months sounds generous. Anyone who lived through GDPR implementation knows the programme consumes the runway.
Here is the schedule that leaves margin rather than assuming none is needed.
Now to Q4 2026 — discovery and mapping. Find where personal data actually lives, including the systems nobody names at kickoff. Build a RoPA that reconciles against real systems rather than department interviews. Everything downstream takes this as input, and it is the phase organisations consistently underestimate.
Q4 2026 to Q1 2027 — consent and notice. Rebuild consent around the purposes your register actually shows. Purpose-level granularity, Eighth Schedule language coverage, withdrawal as easy as consent, artefacts that are timestamped and provable. Withdrawal propagation to downstream systems is the piece that takes engineering time.
Q1 2027 — vendors and processors. Data Processing Agreements with every processor, covering third-party risk, security audits, erasure, and breach reporting timelines. This depends on other people's legal teams, which is why it cannot be left late.
Q1 to Q2 2027 — safeguards, breach readiness, rights workflows. Encryption, access control, logging. A breach runbook you have actually rehearsed. Rights request workflows that meet statutory timelines rather than aspiring to.
Q2 2027 — testing and evidence. Run a mock inquiry. Ask your own team to produce the evidence pack a regulator would request. This is where you discover what does not actually work.
13 May 2027 — live.
If you are reading this in August 2026, you are already inside phase one of that schedule.
The deadline may compress
One development most timeline articles miss.
At a MeitY stakeholder consultation in January 2026, the possibility of compressing the 18-month runway to 12 months was raised. It has not been confirmed by gazette notification, so 13 May 2027 remains the operative date.
But the asymmetry matters. Plan against the earlier date and the cost is a few idle months. Plan against the later one and get compressed, and you are rebuilding foundational systems under live enforcement.
Section 1 of the Act permits the Central Government to appoint different dates for different provisions. The timeline is set by notification, and notifications can be issued. Monitor the gazette rather than the commentary.
What the phasing does not delay
Three things are live now, regardless of Phase 3:
The Board exists. Complaints can be filed today.
Breach exposure is real today. The Act's phasing does not pause the reputational and contractual consequences of a leak, nor does it pause sectoral regulators. RBI, IRDAI and SEBI requirements continue on their own timelines.
Your customers are already asking. Enterprise procurement in India increasingly includes DPDP readiness questions. That is a commercial deadline, not a statutory one, and it has already arrived.
Frequently asked questions
When were the DPDP Rules 2025 notified?
13 November 2025, via gazette notification G.S.R. 846(E). The Act's commencement notification, G.S.R. 843(E), was issued the same day. January 2025 was the draft Rules published for consultation, not the final Rules.
What is the DPDP compliance deadline?
13 May 2027 for full compliance. The Data Protection Board has been operational since 13 November 2025, and enforcement and Consent Manager registration begin 13 November 2026.
Which DPDP Rules are in force right now?
Rules 1, 2 and 17–21, in force since 13 November 2025 — commencement, definitions, and the Board's constitution and procedures.
Is there a grace period after May 2027?
None has been indicated, and none should be assumed. The Board has been operational since November 2025, complaints can already be filed, and the 18-month runway was itself the transition period.
What happens on 13 November 2026?
Rule 4 commences, opening Consent Manager registration. The Act's penalty and appeal provisions also become operative — so enforcement machinery is live six months before your compliance deadline.
Could the deadline move?
Section 1 permits the Central Government to appoint different dates for different provisions, and a January 2026 MeitY consultation raised compressing the timeline to 12 months. Nothing has been gazetted. Monitor official notifications rather than secondary commentary.
How long does DPDP compliance actually take to implement?
Three to four quarters for a mid-sized organisation, with discovery and data mapping consuming more of it than teams expect. Vendor contract renegotiation is the other common bottleneck because it depends on external parties.
What are the penalties?
Up to ₹250 crore for failure to maintain reasonable security safeguards, with separate heads for breach notification failures, children's data violations and Significant Data Fiduciary obligations. Assessed per contravention rather than per organisation.
Where to start
If you have not begun, start with scope rather than tooling. A gap analysis tells you which obligations you already meet and which you do not — which tells you what to actually buy.
Then discovery, then your processing register, then consent designed around what the register shows. Not the reverse.
ProtectComply runs discovery into RoPA into DPIA end to end, with a steward review queue so nothing enters your compliance record unreviewed.
Map your obligations against the timeline
About the author
Yatin Chaudhary is an SEO Specialist at ProtectComply, where he writes about India's data protection framework and how organisations operationalise it.
How this article was researched
Dates and rule groupings taken from the gazette notifications of 13 November 2025 and the text of the DPDP Rules, 2025. Where secondary sources disagree with the gazette, we follow the gazette and say so. The January 2026 consultation is reported as a consultation, not as settled law.
Corrections: write to [corrections email] and we will review and update.
Sources
- Digital Personal Data Protection Rules, 2025 — gazette notification G.S.R. 846(E), 13 November 2025; Rule 1 (commencement)
- DPDP Act commencement notification — gazette G.S.R. 843(E), 13 November 2025
- The Digital Personal Data Protection Act, 2023 — Sections 1(2) and 1(3)
- MeitY / PIB press release on the DPDP Rules notification, 13 November 2025
General information, not legal advice. Consult qualified counsel before finalising your compliance position.