Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The DPDP Act commencement timeline for India's data protection law

The DPDP Act Timeline: What Applies in 2026 and 2027

The DPDP Act was passed in August 2023 and then did almost nothing for two years, which taught a lot of organisations the wrong lesson. It is now commencing — in three tranches, on dates fixed by notification — and the first of those is three months away.

This guide is read from the Gazette notification and the Rules themselves, because the commencement structure is where most secondary coverage goes wrong.

What the DPDP Act is

The Digital Personal Data Protection Act, 2023 is Act No. 22 of 2023, enacted on 11 August 2023. It is India’s general data protection law, structured across nine chapters: obligations of the Data Fiduciary, rights and duties of the Data Principal, special provisions, the Data Protection Board of India, the Board’s powers and procedure, appeals and alternate dispute resolution, and penalties and adjudication.

The DPDP Act vocabulary is its own. The controller equivalent is a Data Fiduciary; the data subject is a Data Principal; a class of larger or higher-risk entities are designated Significant Data Fiduciaries with additional duties. There is also an institution with no GDPR analogue — the Consent Manager, a registered intermediary through which a Data Principal can give, manage, review and withdraw consent.

The DPDP Act commencement schedule

The DPDP Act commencement timeline set by G.S.R. 843(E)

Notification G.S.R. 843(E), dated 13 November 2025 and published in the Gazette on 14 November 2025, exercises the power in section 1(2) to bring provisions into force on different dates. The Digital Personal Data Protection Rules, 2025 were notified the same day and carry a matching three-part commencement in rule 1.

From publication. Section 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) — the Data Protection Board of India, and the powers to make rules. Rules 1, 2 and 17 to 21 came into force alongside, covering the Board’s functioning as a digital office and the terms for its officers and employees. Two further notifications of the same date establish the Board and settle the number of members.

In other words, the DPDP Act stood the regulator up first and left the obligations until later — the opposite of the sequence most data protection laws follow.

One year — 14 November 2026. Section 6(9) and section 27(1)(d) of the Act, and rule 4: registration and obligations of Consent Managers. This is the tranche now approaching.

Eighteen months — 14 May 2027. Everything that actually governs processing: sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 10, sections 11 to 17, section 27 apart from clause (1)(d), sections 28 to 34, 36 and 37, and section 44(2). On the Rules side that is rules 3, 5 to 16, 22 and 23.

A corrigendum to the Rules followed on 16 December 2025 — worth picking up if you took a copy in November.

What the DPDP Act lands on you in May 2027

The eighteen-month tranche is the one to plan against, because it contains essentially the whole operational regime. The Rules coming into force then cover:

  • Notice given by a Data Fiduciary (rule 3) — and the drafting bar is high. The notice must be understandable independently of any other information, must give a fair account in clear and plain language, and must include at minimum an itemised description of the personal data and a specific description of the goods, services or uses enabled by the processing.
  • Reasonable security safeguards (rule 6).
  • Intimation of a personal data breach (rule 7).
  • Retention — the period after which a specified purpose is deemed no longer served (rule 8).
  • Contact information for questions about processing (rule 9).
  • Verifiable consent for children’s data (rules 10 to 12), with defined exemptions.
  • Additional obligations of Significant Data Fiduciaries (rule 13).
  • Rights of Data Principals (rule 14).
  • Transfer of personal data outside India (rule 15).
  • Research, archiving and statistical exemptions (rule 16).

Rule 3’s notice standard is the single most under-appreciated item in the whole DPDP Act package. A privacy notice that works by cross-referring to a policy elsewhere does not meet “understandable independently of any other information”.

Why 14 November 2026 still matters

If you are not becoming a Consent Manager, the one-year tranche can look irrelevant. It is not.

The DPDP Act requires Consent Managers to be registered with the Board and meet obligations set out in rule 4, and they need to exist and function before the consent machinery they support goes live in May 2027. Organisations planning to rely on a Consent Manager should be identifying one now rather than after the substantive obligations bite.

How the DPDP Act compares with what you may already run

Regime What transfers, and what does not
GDPR The inventory, retention thinking and breach process transfer well. The notice standard, the Consent Manager institution and the Significant Data Fiduciary designation have no GDPR equivalent — a GDPR programme is a head start, not compliance
ISO 27701 A privacy information management system gives you the governance and records discipline the Rules assume, in an auditable form
ISO 27001 The natural home for rule 6’s reasonable security safeguards and for breach detection feeding rule 7
CCPA Similar in requiring documented processing and consumer rights handling, but the consent architecture is fundamentally different

Where to start with the DPDP Act

  1. Work back from 14 May 2027, not from 2023. That is when processing obligations begin.
  2. Rewrite notices against rule 3 specifically — standalone, itemised, plain language.
  3. Decide whether you are a Significant Data Fiduciary and record the reasoning.
  4. Resolve children’s data early. Verifiable consent is the hardest engineering problem in the Rules.
  5. Map cross-border flows against rule 15 before contracts renew.
  6. Pick up the December 2025 corrigendum if your copy of the Rules predates it.

This guide reflects G.S.R. 843(E), the Digital Personal Data Protection Rules, 2025 and the MeitY document set at 15 August 2026. The one-year and eighteen-month dates are calculated from Gazette publication on 14 November 2025 — verify against the notification before relying on them contractually.

The DPDP Act Toolkit provides 91 editable privacy templates covering the notice and consent artefacts, the records of processing, breach intimation, retention schedules, children’s data handling, Significant Data Fiduciary obligations and the data principal rights procedures.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.