Short answer
India's Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and phase in over 18 months. Data Protection Board provisions applied immediately, consent manager registration applies from 13 November 2026, and the core obligations for data fiduciaries, including notice, consent, security safeguards and breach reporting, apply from 13 May 2027.
Key takeaways
- Phase 1 (13 Nov 2025): the Data Protection Board is set up.
- Phase 2 (13 Nov 2026): consent managers can register and operate.
- Phase 3 (13 May 2027): notice, consent, security, breach reporting and rights obligations apply.
- Seven months remain before core obligations bite: most programmes need all of it.
Three phases, eighteen months
Timeline
DPDP Rules, 2025 commencement
- Rules notified; Board provisions applyRules 1, 2 and 17 to 21.
- Consent managersRule 4: registration and obligations of consent managers.
- Core obligations applyRules 3, 5 to 16, 22 and 23.
What each phase means for you
| Phase | In force | What to do |
|---|---|---|
| 1 | Data Protection Board constituted and able to act | Nothing enforceable against fiduciaries yet; use the time to plan |
| 2 | Consent manager framework | Decide whether you will accept consent through registered consent managers |
| 3 | Notice, consent, security safeguards, breach reporting, retention and erasure, data principal rights | Have processes running and evidenced by 13 May 2027 |
Work back from May 2027
Seven months is short for a programme that touches every system holding personal data. The order that works for most organisations is data discovery first, then notices and consent, then security and breach response, then rights handling, because each step depends on knowing what data you hold and why.
Checklist
DPDP readiness by May 2027
0 of 8 done
If you are already GDPR-compliant
GDPR programmes give you a head start on data mapping, security and breach response, but do not assume they carry over. Consent, notices, children's data and the role of consent managers work differently under the DPDP framework, so review each area against the Rules instead of relying on your GDPR documentation.
Frequently asked questions
When do DPDP Act obligations apply to businesses?
The core obligations for data fiduciaries under the DPDP Rules, 2025, including notice, consent, security safeguards, breach reporting and data principal rights, apply from 13 May 2027.
Sources
- Digital Personal Data Protection Rules, 2025 notified, Press Information Bureau, Government of India
- DPDP Act 2023 and Rules 2025: phased implementation timeline, Sansa Legal