DS Consulting logoDS Consulting
Regulatory Dictionary

India’s DPDP Act: what commences when

Digital Personal Data Protection Act 2023, and the DPDP Rules 2025

November 2026 is the consent manager framework. It is not the compliance deadline, whatever you have read. The obligations that bind your business commence on 13 May 2027.

Tejas Dhabalia
Tejas Dhabalia
Co-founder, DS Consulting · 11 September 2026

The DPDP commencement timeline. India's Digital Personal Data Protection framework commences in three phases over eighteen months from 13 November 2025, when the DPDP Rules 2025 were notified. Phase 1 established the Data Protection Board of India and is in force. Phase 2, on 13 November 2026, brings the consent manager framework into effect. Phase 3, on 13 May 2027, commences the obligations that apply to businesses handling personal data: notice, consent, security safeguards, breach notification, data principal rights, retention and erasure, children's data, and the additional duties of a significant data fiduciary.

Key facts at a glance

Legal basis
DPDP Act 2023, DPDP Rules 2025
Rules notified
13 November 2025
In force now
Board and enforcement machinery
Consent managers
13 November 2026
Your obligations commence
13 May 2027
Maximum penalty
₹250 crore

The date most commentary gets wrong

India has had a data protection law on paper since August 2023. It sat unenforced for two years because the rules that operate it had not been made. That changed on 13 November 2025, when the government notified the DPDP Rules 2025 and set an eighteen month phased timetable.

A large amount of published guidance reports that the substantive obligations land at the twelve month mark, in November 2026. They do not. November 2026 commences the consent manager framework, which creates a registered class of intermediary that individuals can use to manage consent across many companies at once. Useful, and not an obligation on you.

Notice, consent, security safeguards, breach notification, rights, retention, children’s data and the significant data fiduciary duties all commence at the eighteen month mark, on 13 May 2027. That is the date to plan against, and it is the one to check any advice you are given against.

Commencement timeline

1
13 November 2025: Phase 1, in force
Definitions, and the establishment, composition and procedure of the Data Protection Board of India. Appeals lie to TDSAT. No operational duty on your business from this date, but the enforcement machinery exists.
2
13 November 2026: Phase 2, the consent manager framework
Consent managers may register with the Data Protection Board of India. They must be companies incorporated in India. This is an ecosystem milestone and is not the date your own obligations commence.
3
13 May 2027: Phase 3, everything that binds you
Notice, consent, security safeguards, breach notification, data principal rights, retention and erasure, children's data, processor arrangements and the additional obligations of a significant data fiduciary.

One live caveat. The government has been reported as considering a shorter compliance timeline than the eighteen months notified. Nothing has been formally amended. Plan against May 2027 and treat an earlier date as a risk rather than a certainty.

Who is in scope?

Scope follows the role you play and whether the processing touches people in India. It does not follow company size, sector or place of incorporation. The law uses two terms that everything else is built on: the data fiduciary decides why and how personal data is used, and the data principal is the person the data is about.

Data fiduciary

MAY 2027

You, if you decide why and how personal data is collected and used. A signup form, a CRM, a payroll system or a customer database makes you one. Size is not a factor.

Data processor

MAY 2027

Anyone processing personal data on a fiduciary's behalf. The fiduciary stays accountable, which is why processor contracts are a live piece of work rather than paperwork.

Companies outside India

MAY 2027

In scope where processing is connected with offering goods or services to individuals in India. Place of incorporation does not decide the question.

Significant data fiduciary

ON DESIGNATION

Designated by the Central Government on volume, sensitivity and risk. Extra structural duties follow: an India-based DPO, impact assessments, independent audits and algorithmic due diligence.

Consent managers

NOV 2026

Registered intermediaries that let individuals manage consent across many fiduciaries at once. Must be companies incorporated in India. A supplier category, not an obligation on you.

What you actually have to do

Strip away the legal language and Phase 3 comes down to six things, plus a separate and non-negotiable rule on children.

Give a real notice

Standalone, separate from your terms of service, in plain language, with an itemised description of the personal data collected and the specific purpose for each. A privacy policy saying data is collected to improve the service does not satisfy this.

Get consent that means something

Free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. No pre-ticked boxes. No bundling with unrelated terms. Withdrawal must be as easy as giving it.

Answer rights requests

Access, correction, completion, updating, erasure, grievance redressal and nomination. The Rules set a maximum of ninety days to respond. Most of a first attempt is spent finding the data rather than deciding what to do with it.

Report breaches to two audiences

Affected individuals must be told promptly and in plain language: what happened, the likely consequences, what you have done about it and who to contact. The Data Protection Board of India must be informed as well.

Set retention limits and honour them

A defined reason for how long you hold data, and a process that actually deletes it when the reason ends. Specified classes of e-commerce, social media and online gaming intermediary face a fixed retention limit, with advance notice to the individual before erasure.

Treat children's data as a separate problem

Verifiable parental consent before processing a child's data, with narrow exemptions for purposes such as healthcare, education and real-time safety. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited.

Where the data can sit

The most common question we get is whether personal data of Indian customers has to stay on Indian servers. It does not, as a general rule. Section 16 of the Act and Rule 15 of the Rules work as a negative list: data may be transferred to any country except those the Central Government restricts by notification. No restricted list has been published.

That is the opposite of an adequacy regime. Running your site, CRM or mail on infrastructure outside India is permitted, and most mid-market Indian companies do exactly that without a problem.

Three qualifications. The government may bar offshore transfer of specified categories for organisations designated as significant data fiduciaries, though no categories have been notified. Sectoral rules survive untouched, so RBI payment data localisation and the equivalent SEBI and IRDAI requirements still bite in those sectors. And this commences on 13 May 2027 with everything else.

The reason the confusion persists is that the 2019 and 2021 drafts of the Bill did propose mandatory localisation for sensitive data. It was dropped. A good deal of published commentary is still describing a version of the law that was never enacted. What you do owe your overseas providers is a processor arrangement that carries your obligations, which is a contract question rather than a hosting one.

What it costs to get wrong

The Schedule to the Act attaches ceilings to specific failures rather than to the law in the abstract. These are maximums and the Data Protection Board of India decides each case after an inquiry, but they establish the scale the government intends.

Failure to take reasonable security safeguardsUp to ₹250 crore
Failure to notify a personal data breachUp to ₹200 crore
Breach of children's data obligationsUp to ₹200 crore
Breach of significant data fiduciary obligationsUp to ₹150 crore
Breach of any other provision of the Act or RulesUp to ₹50 crore

Two points that matter more than the headline number. The ceilings attach per failure, so a single incident handled badly can engage more than one line of the Schedule. And enforcement runs exclusively through that regulator, so your exposure is regulatory rather than litigation driven. There is no private right of action.

What is still unsettled

The Data Protection Board of India is established, with membership set at four, but it has not yet published decisions. Until it rules on cases, everyone is reading the text of the law rather than a body of precedent. That includes us. Where this page says what something is likely to mean in practice, that is a reading and not a settled answer.

Significant data fiduciary designation is made by government notification rather than against a published threshold, so no organisation can confirm its own status in advance. Most mid-market companies will not be designated. That is a judgement rather than a fact, and it is worth a straight conversation instead of an assumption.

Consent manager registration does not open until November 2026. Anyone offering you a registered DPDP consent manager today is offering something that cannot yet exist in that form.

What to do between now and May 2027

Eight months sounds like time. It is, if you start now. Most remediation plans fail because they begin with the privacy policy, which is the output rather than the input.

The starting point is the same in every case: work out what personal data you actually hold, where it lives, who touches it and which vendor operates the system it sits in. Everything else, from rewriting notices to answering a rights request inside ninety days, depends on having that list. Most companies find the gap is wider in the details than in the headline principles, which everyone already agrees with.

Where the fix reaches the data model and the integration layer rather than the policy alone, that is integration work, and it takes longer than a legal review.

Frequently asked questions

Is the DPDP compliance deadline November 2026 or May 2027?

May 2027 for the obligations that apply to your business. The DPDP Rules 2025 set an eighteen month phased timetable from notification on 13 November 2025. The twelve month mark, 13 November 2026, commences the consent manager framework, which creates a registered class of intermediary that individuals can use to manage their consent across many companies. The eighteen month mark, 13 May 2027, commences everything else: notice, consent, security safeguards, breach notification, data principal rights, retention and erasure, children's data obligations and the additional duties of a significant data fiduciary. A great deal of published commentary assigns those to November 2026. It is worth checking any advice you receive against the commencement notification itself.

Does the DPDP Act apply to companies outside India?

Yes, where the processing is connected with offering goods or services to individuals in India. The Act applies to digital personal data processed within India, and it applies outside India where processing relates to offering goods or services to data principals in India. Place of incorporation does not decide the question. A company registered anywhere that runs a signup flow, a support desk or a payment page serving people in India is within scope.

What is a significant data fiduciary and how do I know if I am one?

A significant data fiduciary is a data fiduciary, or a class of them, that the Central Government designates by notification. The factors include the volume and sensitivity of personal data processed, the risk to the rights of data principals, and the risk to the sovereignty and integrity of India, electoral democracy, security of the state and public order. Designation is by government notification rather than by self-assessment against a published threshold, so no organisation can confirm its own status in advance. The additional obligations, once designated, are structural: a Data Protection Officer based in India, periodic data protection impact assessments, periodic independent audits and due diligence on algorithmic software.

Does the DPDP Act require personal data of Indian customers to be stored in India?

No, not as a general rule. Section 16 of the Act and Rule 15 of the Rules use a negative list: personal data may be transferred to any country except those the Central Government restricts by notification, and no restricted list has been published. This is the opposite of an adequacy regime. Hosting with a cloud provider whose infrastructure sits outside India is permitted. Three qualifications matter. The government may bar offshore transfer of specified categories of data for organisations designated as significant data fiduciaries, though no categories have been notified. Sectoral rules survive untouched, so the RBI payment data localisation requirements and equivalent SEBI and IRDAI rules still apply in those sectors. And earlier drafts of the Bill in 2019 and 2021 did propose mandatory localisation for sensitive data, which was dropped, so commentary describing that position is describing a version of the law that was never enacted.

What are the penalties under the DPDP Act?

The Schedule to the Act sets ceilings against specific failures. Failure to take reasonable security safeguards to prevent a personal data breach carries up to INR 250 crore. Failure to notify the Data Protection Board of India and affected individuals of a breach carries up to INR 200 crore, as does breach of the children's data obligations. Breach of the additional obligations of a significant data fiduciary carries up to INR 150 crore. Any other breach of the Act or Rules carries up to INR 50 crore. These are maximums rather than typical outcomes, and that regulator determines each case after an inquiry. Enforcement runs exclusively through it. There is no private right of action, so a data principal cannot sue a data fiduciary directly for a DPDP breach.

How long do we have to respond to a data principal rights request?

The Rules set a maximum of ninety days. That sounds generous until you try it. Most of the ninety days in a first attempt is spent establishing which systems hold data about the person, because the answer usually lives across a CRM, a support tool, a billing system, a marketing platform and at least one spreadsheet. Organisations that can answer quickly are the ones that did the data inventory first.

Can we appoint a registered DPDP consent manager now?

No. The consent manager framework does not commence until 13 November 2026, and registration with the Data Protection Board of India opens with it. A consent manager must be a company incorporated in India and must meet the conditions set out in the Rules. Anyone offering a registered DPDP consent manager service before that date is describing something that cannot yet exist in that form.

Sources

Both primary. Secondary summaries of this timetable disagree with each other and several disagree with the notification, which is the reason this page exists.

  • Government notifies DPDP Rules to empower citizens and protect privacy

    Press Information Bureau, Ministry of Electronics and Information Technology, 14 November 2025. Release ID 2190014. Source for the eighteen month phased timetable, the standalone itemised notice requirement, the ninety day response window for rights requests, and the requirement that consent managers be Indian companies.

  • Ministry of Electronics and Information Technology

    Publisher of the DPDP Act 2023, the DPDP Rules 2025 and the commencement notifications of 13 November 2025. Check the current gazette text here before relying on any date on this page.

Dates and figures verified 11 September 2026. This page is a management summary and not legal advice.

DPDP exposure assessment

Eighteen questions across notice and consent, rights, breach readiness, retention, children’s data and vendors. Scored, with the specific gaps named rather than a single number.

Take the assessment
Tejas Dhabalia
Tejas Dhabalia
Co-founder, DS Consulting

Former IBM mainframe engineer turned operator across Tata and Tata-Tesco. Works at the seam between systems, governance and commercial execution.

More about the team

CRM and revenue operations

Most DPDP exposure sits in the systems that hold customer records. We help mid-market teams work out what personal data they hold, where it lives and which system has to change.

View CRM and revenue operations →