Compliance Timelines

Key milestones in the DPDPA's enactment and expected compliance timelines for organisations. Timelines are subject to Government notification and may be updated.

6 min read

Enactment Timeline

  1. Presidential Assent and Gazette Notification

    The Digital Personal Data Protection Act, 2023 received Presidential assent and was published in the Official Gazette, establishing the legislative framework.

  2. Draft DPDP Rules Published

    The Ministry of Electronics and Information Technology released the draft Digital Personal Data Protection Rules for public consultation, inviting stakeholder feedback.

  3. DPDP Rules, 2025 Notified

    The Central Government notified the final DPDP Rules, 2025 via Gazette Notification S.O. 846(E). The 23 Rules operationalise the Act with a staggered enforcement approach.

  4. Board Provisions in Effect

    Rules 1-2 (Short Title, Definitions) and Rules 17-21 (Data Protection Board composition, powers, procedures, and appeals) came into force immediately upon notification.

  5. Consent Manager Registration Opens

    Rule 4 (Registration of Consent Managers) comes into force 1 year after notification. Consent Managers must register with the Data Protection Board and meet interoperability, transparency, and accessibility standards.

  6. Full Operational Enforcement

    Rules 3, 5-16, and 22-23 come into force 18 months after notification. All operational provisions become enforceable: privacy notices (R.3), consent obligations (R.5), security safeguards (R.6), breach notification (R.7), data retention (R.8), children's data (R.9-12), SDF obligations (R.13), grievance redressal (R.14), cross-border restrictions (R.15), and research exemption (R.16).

Phase-wise Compliance Deadlines

ObligationApplicable ToExpected TimelineNotes
Privacy notice (R.3)All Data FiduciariesBy ~May 14, 2027Notice must be independent, self-sufficient, itemised by purpose, and include a communication link for consent withdrawal.
Consent mechanism alignment (R.5)All Data FiduciariesBy ~May 14, 2027Review and update all consent collection practices. Consent Managers must meet 7 obligations including interoperability and transparency.
Security safeguards (R.6)All Data FiduciariesBy ~May 14, 2027Implement encryption, obfuscation, masking, virtual tokenisation, access controls, and maintain activity logs for 1 year.
Breach notification: Level 1 (R.7)All Data FiduciariesBy ~May 14, 2027Notify DPB without unreasonable delay upon awareness of a personal data breach.
Breach notification: Level 2 (R.7)All Data FiduciariesBy ~May 14, 2027Submit detailed report to DPB within 72 hours including facts, nature of data, number of Data Principals affected, and remedial measures.
Data retention thresholds (R.8)All Data FiduciariesBy ~May 14, 20273-year retention cap for e-commerce, online gaming, social media; 48-hour erasure notice to Data Principals; 1-year retention for State-processed data.
Children's data verifiable consent (R.9-12)All Data Fiduciaries processing children's dataBy ~May 14, 2027Implement verifiable parental consent mechanisms (R.10). 5 exempt entity types under R.12: healthcare, education, childcare, child safety, parental monitoring.
Appointment of DPO (R.13)Significant Data FiduciariesBy ~May 14, 2027DPO must be based in India. Also requires periodic DPIAs, annual independent audits, and algorithmic software monitoring.
Grievance redressal mechanism (R.14)All Data FiduciariesBy ~May 14, 2027Maximum 90-day resolution timeline. Must designate a responsible person and provide web-based grievance submission mechanism.
Consent Manager registration (R.4)Consent Manager entitiesAfter ~November 14, 2026Register with the Data Protection Board. Must maintain interoperability, transparency, accessibility, and data security standards.
Vendor/Processor compliance reviewAll Data FiduciariesOngoingEnsure contractual obligations with Data Processors reflect DPDPA requirements. R.15 cross-border restrictions also apply to processors.

Transition Considerations

The DPDP Rules, 2025 provide a staggered enforcement framework. Rules 1-2 and 17-21 (Board provisions) are in immediate effect. Rule 4 (Consent Manager registration) comes into force after 1 year (~November 14, 2026). Rules 3, 5-16, and 22-23 (all operational provisions) come into force after 18 months (~May 14, 2027), providing organisations an 18-month transition runway to achieve compliance.

Organisations should use this transition period to implement required changes, as many requirements, such as R.3 privacy notices, R.6 security safeguards (encryption, masking, 1-year logs), R.7 two-tier breach notification, and R.14 grievance redressal (90-day SLA), require significant lead time for technical and organisational implementation.

Different categories of organisations face different compliance requirements. Significant Data Fiduciaries (SDFs) have enhanced obligations under R.13 including DPO appointment, periodic DPIAs, annual audits, and algorithmic software monitoring. Entities processing children's data must implement verifiable parental consent mechanisms under R.10, though R.12 provides exemptions for healthcare, education, childcare, child safety, and parental monitoring entities.

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.