India compliance

DPDP Rules timeline: which obligations apply when

India's DPDP Rules, 2025 phase in over 18 months. The Data Protection Board is already running; consent managers start in November 2026 and core obligations in May 2027.

Short answer

India's Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and phase in over 18 months. Data Protection Board provisions applied immediately, consent manager registration applies from 13 November 2026, and the core obligations for data fiduciaries, including notice, consent, security safeguards and breach reporting, apply from 13 May 2027.

Key takeaways

  • Phase 1 (13 Nov 2025): the Data Protection Board is set up.
  • Phase 2 (13 Nov 2026): consent managers can register and operate.
  • Phase 3 (13 May 2027): notice, consent, security, breach reporting and rights obligations apply.
  • Seven months remain before core obligations bite: most programmes need all of it.

Three phases, eighteen months

Timeline

DPDP Rules, 2025 commencement

  1. Rules notified; Board provisions applyRules 1, 2 and 17 to 21.
  2. Consent managersRule 4: registration and obligations of consent managers.
  3. Core obligations applyRules 3, 5 to 16, 22 and 23.

What each phase means for you

PhaseIn forceWhat to do
1Data Protection Board constituted and able to actNothing enforceable against fiduciaries yet; use the time to plan
2Consent manager frameworkDecide whether you will accept consent through registered consent managers
3Notice, consent, security safeguards, breach reporting, retention and erasure, data principal rightsHave processes running and evidenced by 13 May 2027

Work back from May 2027

Seven months is short for a programme that touches every system holding personal data. The order that works for most organisations is data discovery first, then notices and consent, then security and breach response, then rights handling, because each step depends on knowing what data you hold and why.

Checklist

DPDP readiness by May 2027

0 of 8 done

If you are already GDPR-compliant

GDPR programmes give you a head start on data mapping, security and breach response, but do not assume they carry over. Consent, notices, children's data and the role of consent managers work differently under the DPDP framework, so review each area against the Rules instead of relying on your GDPR documentation.

Frequently asked questions

When do DPDP Act obligations apply to businesses?

The core obligations for data fiduciaries under the DPDP Rules, 2025, including notice, consent, security safeguards, breach reporting and data principal rights, apply from 13 May 2027.

Sources

  1. Digital Personal Data Protection Rules, 2025 notified, Press Information Bureau, Government of India
  2. DPDP Act 2023 and Rules 2025: phased implementation timeline, Sansa Legal