RISKFORTIS
Enforcement092d 01h 44m

DPDP compliance deadlines: what applies when

Reviewed August 2026 · Data Protection Board decisions tracked

India’s DPDP Act is being phased in across three dates. Enforcement powers arrive on 13 November 2026, six months before the full compliance deadline in May 2027.

01 · The three dates

The Act received assent in August 2023 but did not commence on that date. Commencement is staged by the DPDP Rules 2025: some provisions on notification, the enforcement machinery a year later, and the substantive compliance obligations eighteen months after that.

The sequence matters more than the individual dates. Enforcement arrives before the compliance deadline, which is the opposite of the assumption most programmes are built on.

DateWhat takes effect
13 Nov 2025Definitions in force; Data Protection Board constituted.
13 Nov 2026Inquiry and penalty powers; Consent Manager registration.
13 May 2027Notice, consent, rights, retention, transfers, breach duties.

02 · What has applied since November 2025

The definitional architecture is already live. Whether you are a Data Fiduciary, a Data Processor, or both for different datasets, is a settled question of law today, not something that begins in 2027.

The Data Protection Board of India also exists. It cannot yet levy penalties, but it can be approached, and its early practice is worth tracking because it will shape what “reasonable” means when the penalty powers switch on.

03 · Enforcement powers from November 2026

From 13 Nov 2026 the Board may receive complaints, conduct inquiries and impose monetary penalties. Consent Manager registration opens on the same date, which matters if your consent architecture depends on one.

Two duties do not wait for May 2027 in practice. A data principal can complain, and a personal data breach can happen, in the window between the two dates — and both put you in front of a Board that now has powers.

04 · Full compliance from May 2027

From 13 May 2027 every Data Fiduciary must meet the substantive obligations: itemised notice, valid and withdrawable consent, fulfilment of data principal rights, purpose limitation and erasure, processor contracts, security safeguards under Rule 6, breach intimation under Rule 7, verifiable parental consent for children’s data, and the additional Significant Data Fiduciary duties where they apply.

Nothing in the Rules stages these among themselves. On that date they all apply at once, to processing that started years earlier — which is why consent collected under an old privacy policy is the single largest remediation item in most programmes.

05 · Quarter by quarter, from here

A workable sequence for an organisation starting now, with the milestones the Rules impose in mono.

  1. Q3 2026 · NOW

    Know your position

    Gap assessment, processing inventory, processor register, SDF applicability opinion. Three weeks of work that tells you the size of everything else.

  2. Q4 2026 · BY 13 NOV 2026

    Be defensible before enforcement

    Rule 7 breach plan tested against the clock, a rights request workflow that answers inside the window, Rule 6 safeguards and logging in place.

  3. Q1 2027

    Rebuild notice and consent

    Itemised notices, consent capture and withdrawal, consent artefacts retained as evidence, processor agreements repapered, transfers assessed.

  4. Q2 2027 · BY 13 MAY 2027

    Evidence it and rehearse it

    Retention and erasure running, DPO or contact published, training delivered, and a second drill to show the plan improved rather than aged.

06 · Penalties

Penalties are levied by the Board after inquiry, per instance, with regard to the nature and gravity of the breach and any mitigating action taken.

Failure to take reasonable security safeguards
₹250 Cr
Failure to notify a personal data breach
₹200 Cr
Breach of obligations relating to children's data
₹200 Cr
Breach of additional Significant Data Fiduciary duties
₹150 Cr

07 · Questions people ask

In phases. Definitions and the Board from 13 Nov 2025, enforcement powers and penalties from 13 Nov 2026, and the substantive obligations in full from 13 May 2027.

Related

01

Rule 7 breach intimation

What to file, when the clock starts, and the CERT-In overlap.

Read
02

DPDP Breach Clock

Every deadline computed live from one awareness timestamp.

Open the tool
03

DPDP vs GDPR

What a GDPR-mature organisation still has to build for India.

Compare

Find out which of these dates already reaches you — in three weeks, for a fixed fee.

Start a DPDP Gap Assessment

General information, not legal advice.