DPDP Act Compliance Timeline and Deadlines Explained
The three phases of the DPDP Rules, 2025: what took effect in November 2025, what starts in November 2026 and what businesses must have in place by 13 May 2027.

The Digital Personal Data Protection Act was passed in August 2023, but it needed rules to operate. Those rules were notified on 13 November 2025 and come into force in three phases over eighteen months. As of October 2026, the first phase is in force, the second begins next month and the third is a little over seven months away.
The three phases
Each phase switches on a different part of the Rules.
Phase 1: the Board
The rules that took effect immediately concern the Data Protection Board of India: its constitution, the appointment and service conditions of its members, and its functioning as a digital office. Nothing in this phase requires action from businesses, but it means the body that will receive breach reports and complaints exists.
Phase 2: Consent Managers
From 13 November 2026, companies can register with the Board as Consent Managers. A Consent Manager gives individuals one place to give, manage, review and withdraw consent across businesses. The Rules set conditions for registration, including being a company incorporated in India with a minimum net worth of two crore rupees, and obligations such as not seeing the personal data that passes through. Most businesses will not become Consent Managers, but may later need to accept consents through them.
Phase 3: everything that affects your product
On 13 May 2027 the substantive obligations begin. This is the deadline that matters for product and engineering teams.
A working plan for the months left
Compliance projects take longer than expected because they touch every system that holds personal data. A reasonable sequence from October 2026:
Start with the data inventory. Everything else is derived from it.
Penalties and what is still open
The Board can impose penalties up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach or for breaching children's data obligations, and lower amounts for other failures. Several matters still depend on future government notifications: which businesses are designated Significant Data Fiduciaries, any countries to which transfers are restricted, and any categories of data that must stay in India. Check for those notifications before finalising your plan.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





