What businesses must complete before 13 May 2027
The Digital Personal Data Protection framework follows a phased commencement. This page sets out the three commencement dates, the obligations attached to each, and a stage-by-stage roadmap to reach readiness before the principal Data Fiduciary obligations commence on 13 May 2027.
When is the DPDPA compliance deadline?
The DPDPA has a phased commencement. Certain institutional provisions took effect on 13 November 2025, the Consent Manager framework commences on 13 November 2026, and the principal substantive obligations for Data Fiduciaries commence on 13 May 2027. Organisations should complete implementation, testing and evidence validation before that date.
The DPDP Rules, 2025 were notified in the Gazette (G.S.R. 846(E)) on 13 November 2025. Commencement is staggered across three dates so that institutions, consent infrastructure and substantive obligations come into force in sequence. The operative compliance date for most businesses is 13 May 2027.
Three commencement dates
Institutional provisions
Preliminary provisions, definitions and the constitution and functioning of the Data Protection Board of India.
No operational filing is required of most businesses at this stage, but the enforcement institution now exists.
Consent Manager framework
Registration and obligations of Consent Managers (read with the First Schedule).
Organisations relying on consent should confirm how consent will be captured, recorded and withdrawn through a registered Consent Manager.
Principal Data Fiduciary obligations
Notice, security safeguards, breach intimation, Data Principal rights, Significant Data Fiduciary obligations, cross-border processing, erasure and enforcement machinery.
This is the operative compliance date. Programmes should be built, tested and evidenced before it.
Not every organisation can wait until 2027
The 13 May 2027 date is when obligations commence, not when work should begin. The build effort that precedes it — data mapping, contract remediation, consent and rights engineering, and breach readiness — typically takes several months. Organisations in the following positions should begin immediately.
A stage-by-stage path to 13 May 2027
Accountability and discovery
- ■Appoint a programme owner and, where required, a Data Protection Officer function.
- ■Commission a data inventory and flow mapping across applications, vendors and locations.
- ■Identify cross-border transfers and possible Significant Data Fiduciary status under Section 10.
- ■Establish a Board-level reporting line for the programme.
Notice, consent and contracts
- ■Draft Data Principal notices in clear language and in the required Eighth Schedule languages.
- ■Design the consent capture, record and withdrawal architecture (Rule 3 read with Rule 4).
- ■Remediate processor and vendor contracts to allocate DPDPA responsibilities.
- ■Design Data Principal rights workflows for access, correction, erasure and grievance redressal (Rule 14).
Controls, security and breach readiness
- ■Implement reasonable security safeguards (Rule 6).
- ■Stand up breach detection, logging and the staged intimation process (Rule 7 read with Section 8(6)).
- ■For Significant Data Fiduciaries, plan DPIA, independent audit, algorithmic due diligence and the DPO (Rule 13).
- ■Configure erasure and retention against the specified time periods (Rule 8).
Testing, evidence and governance
- ■Run end-to-end tests of consent, rights fulfilment and erasure within statutory windows.
- ■Conduct tabletop breach exercises against the intimation timelines.
- ■Validate that every control produces retained, auditable evidence.
- ■Place the operating model under continuing Board and management review.
Eight questions for the Board
- 01Has the Board been briefed on the phased commencement and the 13 May 2027 operative date?
- 02Is there a named accountable owner and an approved budget and timeline?
- 03Has a data inventory and gap assessment been completed or commissioned?
- 04Is the organisation likely to be notified as a Significant Data Fiduciary under Section 10?
- 05Are cross-border transfer arrangements identified and being remediated?
- 06Is there a documented breach-response plan aligned to the staged intimation requirement?
- 07Does each control produce evidence that can withstand regulatory scrutiny?
- 08Is there a continuing review cadence rather than a one-time project close?
What each control must be able to show
Compliance is demonstrated through retained, auditable evidence. Each obligation should produce a record capable of withstanding regulatory scrutiny.
The cost of a late start
- 01Data mapping and contract remediation routinely take longer than expected; a late start compresses the highest-risk work into the final weeks.
- 02Consent and rights systems require engineering and testing time that cannot be shortened by drafting alone.
- 03Breach-response readiness cannot be demonstrated without prior exercises and retained evidence.
- 04The Schedule provides for financial penalties determined by the Data Protection Board of up to ₹250 crore; children’s-data breaches carry exposure up to ₹200 crore.
Where the deadline bites hardest
Financial services & fintech
High data volume, sensitive financial data, and likely Significant Data Fiduciary status raise both control effort and penalty exposure.
Healthcare & pharma
Health data, consent complexity and long retention obligations require early data mapping and erasure design.
E-commerce & consumer tech
Large user bases, children’s access and extensive vendor ecosystems demand consent and rights systems at scale.
SaaS & data processors
Processor obligations, contract remediation and cross-border flows require early contractual and technical work.
EdTech
Children’s data and verifiable parental consent (Rule 10) create heightened design and penalty considerations.
Request a Deadline Readiness Review
Tell us where your organisation stands today. A senior practitioner will respond with a time-bound plan to reach readiness before 13 May 2027.
Request a Deadline Readiness Review
A senior practitioner will respond within one working day.
What practitioners and boards are asking
When is the DPDPA compliance deadline?
The DPDP Rules, 2025 were notified on 13 November 2025 and follow a phased commencement. Institutional and Data Protection Board provisions took effect on 13 November 2025, the Consent Manager framework commences on 13 November 2026, and the principal substantive obligations for Data Fiduciaries — notice, security safeguards, breach intimation, Data Principal rights, Significant Data Fiduciary obligations, cross-border processing and enforcement — commence on 13 May 2027.
When does the DPDP Act become fully enforceable?
The principal Data Fiduciary obligations commence on 13 May 2027, eighteen months after the Rules were notified. Organisations should complete implementation, testing and evidence validation before that date rather than on it.
Do any DPDPA obligations apply before 13 May 2027?
Yes. Preliminary provisions, definitions and the constitution and functioning of the Data Protection Board of India (Rules 1, 2 and 17–21) took effect on 13 November 2025, and the Consent Manager registration and obligations (Rule 4) commence on 13 November 2026.
Who should begin DPDPA implementation now?
Organisations with large user bases, children's data, cross-border transfers, complex vendor ecosystems, or likely Significant Data Fiduciary status under Section 10 should begin immediately, because data mapping, contract remediation and technical control build typically require several months.
