AMLEGALS — Strategic Lawyering
DPDPA Compliance Deadline · India

What businesses must complete before 13 May 2027

The Digital Personal Data Protection framework follows a phased commencement. This page sets out the three commencement dates, the obligations attached to each, and a stage-by-stage roadmap to reach readiness before the principal Data Fiduciary obligations commence on 13 May 2027.

Direct Answer

When is the DPDPA compliance deadline?

The DPDPA has a phased commencement. Certain institutional provisions took effect on 13 November 2025, the Consent Manager framework commences on 13 November 2026, and the principal substantive obligations for Data Fiduciaries commence on 13 May 2027. Organisations should complete implementation, testing and evidence validation before that date.

The DPDP Rules, 2025 were notified in the Gazette (G.S.R. 846(E)) on 13 November 2025. Commencement is staggered across three dates so that institutions, consent infrastructure and substantive obligations come into force in sequence. The operative compliance date for most businesses is 13 May 2027.

Phased Commencement

Three commencement dates

Commenced13 November 2025Rules 1, 2 and 17–21

Institutional provisions

Preliminary provisions, definitions and the constitution and functioning of the Data Protection Board of India.

No operational filing is required of most businesses at this stage, but the enforcement institution now exists.

12 months after notification13 November 2026Rule 4

Consent Manager framework

Registration and obligations of Consent Managers (read with the First Schedule).

Organisations relying on consent should confirm how consent will be captured, recorded and withdrawn through a registered Consent Manager.

18 months after notification13 May 2027Rules 3, 5–16, 22 and 23

Principal Data Fiduciary obligations

Notice, security safeguards, breach intimation, Data Principal rights, Significant Data Fiduciary obligations, cross-border processing, erasure and enforcement machinery.

This is the operative compliance date. Programmes should be built, tested and evidenced before it.

Who Should Start Now

Not every organisation can wait until 2027

The 13 May 2027 date is when obligations commence, not when work should begin. The build effort that precedes it — data mapping, contract remediation, consent and rights engineering, and breach readiness — typically takes several months. Organisations in the following positions should begin immediately.

Large user bases or high data volume
Children’s data or verifiable parental consent (Rule 10)
Cross-border transfers (Rule 15)
Complex vendor and processor ecosystems
Likely Significant Data Fiduciary status (Section 10, Rule 13)
Legacy systems with limited existing security controls
Implementation Roadmap

A stage-by-stage path to 13 May 2027

01First 30 days

Accountability and discovery

  • Appoint a programme owner and, where required, a Data Protection Officer function.
  • Commission a data inventory and flow mapping across applications, vendors and locations.
  • Identify cross-border transfers and possible Significant Data Fiduciary status under Section 10.
  • Establish a Board-level reporting line for the programme.
02Days 31–90

Notice, consent and contracts

  • Draft Data Principal notices in clear language and in the required Eighth Schedule languages.
  • Design the consent capture, record and withdrawal architecture (Rule 3 read with Rule 4).
  • Remediate processor and vendor contracts to allocate DPDPA responsibilities.
  • Design Data Principal rights workflows for access, correction, erasure and grievance redressal (Rule 14).
03Days 91–180

Controls, security and breach readiness

  • Implement reasonable security safeguards (Rule 6).
  • Stand up breach detection, logging and the staged intimation process (Rule 7 read with Section 8(6)).
  • For Significant Data Fiduciaries, plan DPIA, independent audit, algorithmic due diligence and the DPO (Rule 13).
  • Configure erasure and retention against the specified time periods (Rule 8).
04Final phase to 13 May 2027

Testing, evidence and governance

  • Run end-to-end tests of consent, rights fulfilment and erasure within statutory windows.
  • Conduct tabletop breach exercises against the intimation timelines.
  • Validate that every control produces retained, auditable evidence.
  • Place the operating model under continuing Board and management review.
Board & Management Checklist

Eight questions for the Board

  • 01Has the Board been briefed on the phased commencement and the 13 May 2027 operative date?
  • 02Is there a named accountable owner and an approved budget and timeline?
  • 03Has a data inventory and gap assessment been completed or commissioned?
  • 04Is the organisation likely to be notified as a Significant Data Fiduciary under Section 10?
  • 05Are cross-border transfer arrangements identified and being remediated?
  • 06Is there a documented breach-response plan aligned to the staged intimation requirement?
  • 07Does each control produce evidence that can withstand regulatory scrutiny?
  • 08Is there a continuing review cadence rather than a one-time project close?
Documents & Evidence

What each control must be able to show

Compliance is demonstrated through retained, auditable evidence. Each obligation should produce a record capable of withstanding regulatory scrutiny.

Notice (Rule 3)
Versioned notice text, language variants, and records of when and how notice was served.
Consent (Rule 3 / Rule 4)
Consent logs showing purpose, timestamp, and withdrawal, capable of Consent Manager integration.
Data Principal rights (Rule 14)
Request register with fulfilment timestamps against statutory windows and grievance outcomes.
Security safeguards (Rule 6)
Documented technical and organisational measures, access controls and encryption posture.
Breach intimation (Rule 7)
Incident log, principal intimation records and Board intimation within the staged timelines.
Erasure and retention (Rule 8)
Retention schedule and deletion logs against the specified time periods.
SDF obligations (Rule 13)
DPIA reports, independent audit reports, algorithmic due-diligence records and DPO appointment.
Why Timing Matters

The cost of a late start

  • 01Data mapping and contract remediation routinely take longer than expected; a late start compresses the highest-risk work into the final weeks.
  • 02Consent and rights systems require engineering and testing time that cannot be shortened by drafting alone.
  • 03Breach-response readiness cannot be demonstrated without prior exercises and retained evidence.
  • 04The Schedule provides for financial penalties determined by the Data Protection Board of up to ₹250 crore; children’s-data breaches carry exposure up to ₹200 crore.
Sector Considerations

Where the deadline bites hardest

Financial services & fintech

High data volume, sensitive financial data, and likely Significant Data Fiduciary status raise both control effort and penalty exposure.

Healthcare & pharma

Health data, consent complexity and long retention obligations require early data mapping and erasure design.

E-commerce & consumer tech

Large user bases, children’s access and extensive vendor ecosystems demand consent and rights systems at scale.

SaaS & data processors

Processor obligations, contract remediation and cross-border flows require early contractual and technical work.

EdTech

Children’s data and verifiable parental consent (Rule 10) create heightened design and penalty considerations.

Start Here

Request a Deadline Readiness Review

Tell us where your organisation stands today. A senior practitioner will respond with a time-bound plan to reach readiness before 13 May 2027.

Request a Deadline Readiness Review

A senior practitioner will respond within one working day.

Your information is handled in accordance with our privacy obligations. No spam, ever.

Insights & Answers

What practitioners and boards are asking

When is the DPDPA compliance deadline?

The DPDP Rules, 2025 were notified on 13 November 2025 and follow a phased commencement. Institutional and Data Protection Board provisions took effect on 13 November 2025, the Consent Manager framework commences on 13 November 2026, and the principal substantive obligations for Data Fiduciaries — notice, security safeguards, breach intimation, Data Principal rights, Significant Data Fiduciary obligations, cross-border processing and enforcement — commence on 13 May 2027.

When does the DPDP Act become fully enforceable?

The principal Data Fiduciary obligations commence on 13 May 2027, eighteen months after the Rules were notified. Organisations should complete implementation, testing and evidence validation before that date rather than on it.

Do any DPDPA obligations apply before 13 May 2027?

Yes. Preliminary provisions, definitions and the constitution and functioning of the Data Protection Board of India (Rules 1, 2 and 17–21) took effect on 13 November 2025, and the Consent Manager registration and obligations (Rule 4) commence on 13 November 2026.

Who should begin DPDPA implementation now?

Organisations with large user bases, children's data, cross-border transfers, complex vendor ecosystems, or likely Significant Data Fiduciary status under Section 10 should begin immediately, because data mapping, contract remediation and technical control build typically require several months.