The DPDP Act was passed in August 2023 and then did almost nothing for two years, which taught a lot of organisations the wrong lesson. It is now commencing — in three tranches, on dates fixed by notification — and the first of those is three months away.
This guide is read from the Gazette notification and the Rules themselves, because the commencement structure is where most secondary coverage goes wrong.
What the DPDP Act is
The Digital Personal Data Protection Act, 2023 is Act No. 22 of 2023, enacted on 11 August 2023. It is India’s general data protection law, structured across nine chapters: obligations of the Data Fiduciary, rights and duties of the Data Principal, special provisions, the Data Protection Board of India, the Board’s powers and procedure, appeals and alternate dispute resolution, and penalties and adjudication.
The DPDP Act vocabulary is its own. The controller equivalent is a Data Fiduciary; the data subject is a Data Principal; a class of larger or higher-risk entities are designated Significant Data Fiduciaries with additional duties. There is also an institution with no GDPR analogue — the Consent Manager, a registered intermediary through which a Data Principal can give, manage, review and withdraw consent.
The DPDP Act commencement schedule

Notification G.S.R. 843(E), dated 13 November 2025 and published in the Gazette on 14 November 2025, exercises the power in section 1(2) to bring provisions into force on different dates. The Digital Personal Data Protection Rules, 2025 were notified the same day and carry a matching three-part commencement in rule 1.
From publication. Section 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) — the Data Protection Board of India, and the powers to make rules. Rules 1, 2 and 17 to 21 came into force alongside, covering the Board’s functioning as a digital office and the terms for its officers and employees. Two further notifications of the same date establish the Board and settle the number of members.
In other words, the DPDP Act stood the regulator up first and left the obligations until later — the opposite of the sequence most data protection laws follow.
One year — 14 November 2026. Section 6(9) and section 27(1)(d) of the Act, and rule 4: registration and obligations of Consent Managers. This is the tranche now approaching.
Eighteen months — 14 May 2027. Everything that actually governs processing: sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 10, sections 11 to 17, section 27 apart from clause (1)(d), sections 28 to 34, 36 and 37, and section 44(2). On the Rules side that is rules 3, 5 to 16, 22 and 23.
A corrigendum to the Rules followed on 16 December 2025 — worth picking up if you took a copy in November.
What the DPDP Act lands on you in May 2027
The eighteen-month tranche is the one to plan against, because it contains essentially the whole operational regime. The Rules coming into force then cover:
- Notice given by a Data Fiduciary (rule 3) — and the drafting bar is high. The notice must be understandable independently of any other information, must give a fair account in clear and plain language, and must include at minimum an itemised description of the personal data and a specific description of the goods, services or uses enabled by the processing.
- Reasonable security safeguards (rule 6).
- Intimation of a personal data breach (rule 7).
- Retention — the period after which a specified purpose is deemed no longer served (rule 8).
- Contact information for questions about processing (rule 9).
- Verifiable consent for children’s data (rules 10 to 12), with defined exemptions.
- Additional obligations of Significant Data Fiduciaries (rule 13).
- Rights of Data Principals (rule 14).
- Transfer of personal data outside India (rule 15).
- Research, archiving and statistical exemptions (rule 16).
Rule 3’s notice standard is the single most under-appreciated item in the whole DPDP Act package. A privacy notice that works by cross-referring to a policy elsewhere does not meet “understandable independently of any other information”.
Why 14 November 2026 still matters
If you are not becoming a Consent Manager, the one-year tranche can look irrelevant. It is not.
The DPDP Act requires Consent Managers to be registered with the Board and meet obligations set out in rule 4, and they need to exist and function before the consent machinery they support goes live in May 2027. Organisations planning to rely on a Consent Manager should be identifying one now rather than after the substantive obligations bite.
How the DPDP Act compares with what you may already run
| Regime | What transfers, and what does not |
|---|---|
| GDPR | The inventory, retention thinking and breach process transfer well. The notice standard, the Consent Manager institution and the Significant Data Fiduciary designation have no GDPR equivalent — a GDPR programme is a head start, not compliance |
| ISO 27701 | A privacy information management system gives you the governance and records discipline the Rules assume, in an auditable form |
| ISO 27001 | The natural home for rule 6’s reasonable security safeguards and for breach detection feeding rule 7 |
| CCPA | Similar in requiring documented processing and consumer rights handling, but the consent architecture is fundamentally different |
Where to start with the DPDP Act
- Work back from 14 May 2027, not from 2023. That is when processing obligations begin.
- Rewrite notices against rule 3 specifically — standalone, itemised, plain language.
- Decide whether you are a Significant Data Fiduciary and record the reasoning.
- Resolve children’s data early. Verifiable consent is the hardest engineering problem in the Rules.
- Map cross-border flows against rule 15 before contracts renew.
- Pick up the December 2025 corrigendum if your copy of the Rules predates it.
This guide reflects G.S.R. 843(E), the Digital Personal Data Protection Rules, 2025 and the MeitY document set at 15 August 2026. The one-year and eighteen-month dates are calculated from Gazette publication on 14 November 2025 — verify against the notification before relying on them contractually.
The DPDP Act Toolkit provides 91 editable privacy templates covering the notice and consent artefacts, the records of processing, breach intimation, retention schedules, children’s data handling, Significant Data Fiduciary obligations and the data principal rights procedures.