← All articles

DPDP Rules 2025 Are Notified: Your New Compliance Timeline

For two years, the Digital Personal Data Protection Act, 2023 was a law without an operating manual — real obligations, but no notified rules to say exactly how or when. That changed on November 13, 2025, when the Ministry of Electronics and IT notified the DPDP Rules, 2025 via Gazette G.S.R. 846(E). If you run a business that touches personal data of anyone in India — which is most businesses — this is the point where "we'll get to DPDP eventually" stops being a viable plan.

The timeline, concretely

The Rules take effect in phases rather than all at once:

  • Immediately (November 2025): the Data Protection Board of India became operational, able to receive complaints and hear cases.
  • November 13, 2026: Consent Manager registration opens, and the Board's penalty powers become active — this is when non-compliance starts having real financial consequences, not just legal exposure on paper.
  • May 13, 2027: full compliance is required across consent, notice, security safeguards, and data-principal rights handling. This is the hard deadline every enterprise DPDP programme should be working backward from.

That gives most organisations roughly 18 months from notification to full enforcement — which sounds like a lot until you remember that a proper gap assessment, control implementation, and audit-readiness pass typically takes 9–12 months on its own. 2026 is the year this actually gets built, not planned.

What the Rules actually add on top of the 2023 Act

The Act set out principles; the Rules set out mechanics. A few of the operational details that now have real shape:

Consent Managers become a real registration category

Entities that want to operate as Consent Managers — intermediaries that let individuals manage consent across multiple data fiduciaries — now have a defined registration process opening in November 2026. If your product touches this space, or you're evaluating a Consent Manager vendor, the registration list is where you verify legitimacy.

Breach notification gets a clock

The Rules specify the mechanics of notifying the Data Protection Board and affected individuals — this is no longer just "without undue delay" as an abstract phrase. If you don't already have a written incident-response plan that names who notifies whom and within what window, this is the moment to write one, before it's tested by a real incident.

Significant Data Fiduciaries get named obligations

Organisations classified as Significant Data Fiduciaries (based on volume and sensitivity of data processed) face additional requirements — a India-based Data Protection Officer, periodic Data Protection Impact Assessments, and independent data auditor engagement. If you're a large fintech, healthtech, or platform business, this classification is worth confirming early rather than assuming it doesn't apply to you.

What to actually do in 2026

Skip the temptation to wait for more clarity — the Rules are about as clear as this framework is going to get before enforcement starts. A realistic build-year sequence looks like:

  1. Run a gap assessment against the Rules' consent, notice, and security-safeguard requirements — not a generic privacy audit, one scoped to this specific law.
  2. Fix the highest-exposure findings first: trackers firing before consent, bundled/pre-ticked consent flows, and a privacy policy that's vague about specific purposes.
  3. Write (or finalise) the breach-notification runbook — who, how, and within how many hours.
  4. Confirm whether you're a Significant Data Fiduciary, and if so, start the DPO and DPIA process now rather than in early 2027.

Our free DPDP scanner checks the most common gaps automatically — consent-before-tracking, missing disclosures, and policy language issues — in a couple of minutes, no signup required for the basic report.

Run a free DPDP scan →