Compliance & Regulation

DPDP Act Compliance Timeline and Deadlines Explained

The three phases of the DPDP Rules, 2025: what took effect in November 2025, what starts in November 2026 and what businesses must have in place by 13 May 2027.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
6 min read
Calendar and planning notes on a desk

The Digital Personal Data Protection Act was passed in August 2023, but it needed rules to operate. Those rules were notified on 13 November 2025 and come into force in three phases over eighteen months. As of October 2026, the first phase is in force, the second begins next month and the third is a little over seven months away.

01

The three phases

Each phase switches on a different part of the Rules.

13 Nov 2025
Phase 1: Data Protection Board set up; definitions and Board procedures in force
13 Nov 2026
Phase 2: registration and obligations of Consent Managers
13 May 2027
Phase 3: notice, consent, security, breach, retention, children's data and user rights
02

Phase 1: the Board

The rules that took effect immediately concern the Data Protection Board of India: its constitution, the appointment and service conditions of its members, and its functioning as a digital office. Nothing in this phase requires action from businesses, but it means the body that will receive breach reports and complaints exists.

03

Phase 2: Consent Managers

From 13 November 2026, companies can register with the Board as Consent Managers. A Consent Manager gives individuals one place to give, manage, review and withdraw consent across businesses. The Rules set conditions for registration, including being a company incorporated in India with a minimum net worth of two crore rupees, and obligations such as not seeing the personal data that passes through. Most businesses will not become Consent Managers, but may later need to accept consents through them.

04

Phase 3: everything that affects your product

On 13 May 2027 the substantive obligations begin. This is the deadline that matters for product and engineering teams.

NoticesItemised, standalone and in plain language
Security safeguardsEncryption or equivalent, access control, logs and backups
Breach notificationTo users and the Board without delay; detailed report within 72 hours
Retention and erasureIncluding the three-year inactivity rule for large platforms
Children's dataVerifiable parental consent and no tracking or targeted ads
Significant Data FiduciariesAnnual impact assessment and audit
User rightsAccess, correction, erasure, nomination and grievance redressal
05

A working plan for the months left

Compliance projects take longer than expected because they touch every system that holds personal data. A reasonable sequence from October 2026:

Start with the data inventory. Everything else is derived from it.

October to December 2026Data inventory, vendor list, gap assessment and budget
January to February 2027Rewrite notices and consent flows; begin consent logging
February to March 2027Security work: access control, logging, encryption gaps, backups
March to April 2027Privacy centre, deletion jobs, retention rules, vendor contracts
April 2027Breach drill, grievance process, staff training
Before 13 May 2027Notices to existing users; go live
06

Penalties and what is still open

The Board can impose penalties up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach or for breaching children's data obligations, and lower amounts for other failures. Several matters still depend on future government notifications: which businesses are designated Significant Data Fiduciaries, any countries to which transfers are restricted, and any categories of data that must stay in India. Check for those notifications before finalising your plan.

Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact