Compliance Timelines
Key milestones in the DPDPA's enactment and expected compliance timelines for organisations. Timelines are subject to Government notification and may be updated.
Enactment Timeline
Presidential Assent and Gazette Notification
The Digital Personal Data Protection Act, 2023 received Presidential assent and was published in the Official Gazette, establishing the legislative framework.
Draft DPDP Rules Published
The Ministry of Electronics and Information Technology released the draft Digital Personal Data Protection Rules for public consultation, inviting stakeholder feedback.
DPDP Rules, 2025 Notified
The Central Government notified the final DPDP Rules, 2025 via Gazette Notification S.O. 846(E). The 23 Rules operationalise the Act with a staggered enforcement approach.
Board Provisions in Effect
Rules 1-2 (Short Title, Definitions) and Rules 17-21 (Data Protection Board composition, powers, procedures, and appeals) came into force immediately upon notification.
Consent Manager Registration Opens
Rule 4 (Registration of Consent Managers) comes into force 1 year after notification. Consent Managers must register with the Data Protection Board and meet interoperability, transparency, and accessibility standards.
Full Operational Enforcement
Rules 3, 5-16, and 22-23 come into force 18 months after notification. All operational provisions become enforceable: privacy notices (R.3), consent obligations (R.5), security safeguards (R.6), breach notification (R.7), data retention (R.8), children's data (R.9-12), SDF obligations (R.13), grievance redressal (R.14), cross-border restrictions (R.15), and research exemption (R.16).
Phase-wise Compliance Deadlines
| Obligation | Applicable To | Expected Timeline | Notes |
|---|---|---|---|
| Privacy notice (R.3) | All Data Fiduciaries | By ~May 14, 2027 | Notice must be independent, self-sufficient, itemised by purpose, and include a communication link for consent withdrawal. |
| Consent mechanism alignment (R.5) | All Data Fiduciaries | By ~May 14, 2027 | Review and update all consent collection practices. Consent Managers must meet 7 obligations including interoperability and transparency. |
| Security safeguards (R.6) | All Data Fiduciaries | By ~May 14, 2027 | Implement encryption, obfuscation, masking, virtual tokenisation, access controls, and maintain activity logs for 1 year. |
| Breach notification: Level 1 (R.7) | All Data Fiduciaries | By ~May 14, 2027 | Notify DPB without unreasonable delay upon awareness of a personal data breach. |
| Breach notification: Level 2 (R.7) | All Data Fiduciaries | By ~May 14, 2027 | Submit detailed report to DPB within 72 hours including facts, nature of data, number of Data Principals affected, and remedial measures. |
| Data retention thresholds (R.8) | All Data Fiduciaries | By ~May 14, 2027 | 3-year retention cap for e-commerce, online gaming, social media; 48-hour erasure notice to Data Principals; 1-year retention for State-processed data. |
| Children's data verifiable consent (R.9-12) | All Data Fiduciaries processing children's data | By ~May 14, 2027 | Implement verifiable parental consent mechanisms (R.10). 5 exempt entity types under R.12: healthcare, education, childcare, child safety, parental monitoring. |
| Appointment of DPO (R.13) | Significant Data Fiduciaries | By ~May 14, 2027 | DPO must be based in India. Also requires periodic DPIAs, annual independent audits, and algorithmic software monitoring. |
| Grievance redressal mechanism (R.14) | All Data Fiduciaries | By ~May 14, 2027 | Maximum 90-day resolution timeline. Must designate a responsible person and provide web-based grievance submission mechanism. |
| Consent Manager registration (R.4) | Consent Manager entities | After ~November 14, 2026 | Register with the Data Protection Board. Must maintain interoperability, transparency, accessibility, and data security standards. |
| Vendor/Processor compliance review | All Data Fiduciaries | Ongoing | Ensure contractual obligations with Data Processors reflect DPDPA requirements. R.15 cross-border restrictions also apply to processors. |
Transition Considerations
The DPDP Rules, 2025 provide a staggered enforcement framework. Rules 1-2 and 17-21 (Board provisions) are in immediate effect. Rule 4 (Consent Manager registration) comes into force after 1 year (~November 14, 2026). Rules 3, 5-16, and 22-23 (all operational provisions) come into force after 18 months (~May 14, 2027), providing organisations an 18-month transition runway to achieve compliance.
Organisations should use this transition period to implement required changes, as many requirements, such as R.3 privacy notices, R.6 security safeguards (encryption, masking, 1-year logs), R.7 two-tier breach notification, and R.14 grievance redressal (90-day SLA), require significant lead time for technical and organisational implementation.
Different categories of organisations face different compliance requirements. Significant Data Fiduciaries (SDFs) have enhanced obligations under R.13 including DPO appointment, periodic DPIAs, annual audits, and algorithmic software monitoring. Entities processing children's data must implement verifiable parental consent mechanisms under R.10, though R.12 provides exemptions for healthcare, education, childcare, child safety, and parental monitoring entities.
Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
