DPDP compliance deadlines: what applies when
Reviewed August 2026 · Data Protection Board decisions tracked
India’s DPDP Act is being phased in across three dates. Enforcement powers arrive on 13 November 2026, six months before the full compliance deadline in May 2027.
01 · The three dates
The Act received assent in August 2023 but did not commence on that date. Commencement is staged by the DPDP Rules 2025: some provisions on notification, the enforcement machinery a year later, and the substantive compliance obligations eighteen months after that.
The sequence matters more than the individual dates. Enforcement arrives before the compliance deadline, which is the opposite of the assumption most programmes are built on.
| Date | What takes effect |
|---|---|
| 13 Nov 2025 | Definitions in force; Data Protection Board constituted. |
| 13 Nov 2026 | Inquiry and penalty powers; Consent Manager registration. |
| 13 May 2027 | Notice, consent, rights, retention, transfers, breach duties. |
02 · What has applied since November 2025
The definitional architecture is already live. Whether you are a Data Fiduciary, a Data Processor, or both for different datasets, is a settled question of law today, not something that begins in 2027.
The Data Protection Board of India also exists. It cannot yet levy penalties, but it can be approached, and its early practice is worth tracking because it will shape what “reasonable” means when the penalty powers switch on.
03 · Enforcement powers from November 2026
From 13 Nov 2026 the Board may receive complaints, conduct inquiries and impose monetary penalties. Consent Manager registration opens on the same date, which matters if your consent architecture depends on one.
Two duties do not wait for May 2027 in practice. A data principal can complain, and a personal data breach can happen, in the window between the two dates — and both put you in front of a Board that now has powers.
04 · Full compliance from May 2027
From 13 May 2027 every Data Fiduciary must meet the substantive obligations: itemised notice, valid and withdrawable consent, fulfilment of data principal rights, purpose limitation and erasure, processor contracts, security safeguards under Rule 6, breach intimation under Rule 7, verifiable parental consent for children’s data, and the additional Significant Data Fiduciary duties where they apply.
Nothing in the Rules stages these among themselves. On that date they all apply at once, to processing that started years earlier — which is why consent collected under an old privacy policy is the single largest remediation item in most programmes.
05 · Quarter by quarter, from here
A workable sequence for an organisation starting now, with the milestones the Rules impose in mono.
Q3 2026 · NOW
Know your position
Gap assessment, processing inventory, processor register, SDF applicability opinion. Three weeks of work that tells you the size of everything else.
Q4 2026 · BY 13 NOV 2026
Be defensible before enforcement
Rule 7 breach plan tested against the clock, a rights request workflow that answers inside the window, Rule 6 safeguards and logging in place.
Q1 2027
Rebuild notice and consent
Itemised notices, consent capture and withdrawal, consent artefacts retained as evidence, processor agreements repapered, transfers assessed.
Q2 2027 · BY 13 MAY 2027
Evidence it and rehearse it
Retention and erasure running, DPO or contact published, training delivered, and a second drill to show the plan improved rather than aged.
06 · Penalties
Penalties are levied by the Board after inquiry, per instance, with regard to the nature and gravity of the breach and any mitigating action taken.
- Failure to take reasonable security safeguards
- ₹250 Cr
- Failure to notify a personal data breach
- ₹200 Cr
- Breach of obligations relating to children's data
- ₹200 Cr
- Breach of additional Significant Data Fiduciary duties
- ₹150 Cr
07 · Questions people ask
In phases. Definitions and the Board from 13 Nov 2025, enforcement powers and penalties from 13 Nov 2026, and the substantive obligations in full from 13 May 2027.
Related
Rule 7 breach intimation
What to file, when the clock starts, and the CERT-In overlap.
ReadDPDP Breach Clock
Every deadline computed live from one awareness timestamp.
Open the toolDPDP vs GDPR
What a GDPR-mature organisation still has to build for India.
Compare