The enforcement timeline: what happened and what is coming
The DPDPA’s rollout follows a phased sequence. Here is every confirmed milestone:
| Date | Event | Implication |
|---|---|---|
| 11 Aug 2023 | DPDPA receives Presidential assent | India’s first comprehensive data-protection law enacted |
| Nov 2025 | DPDP Rules 2025 notified | Procedural framework for consent, breach, DPO, DPIA and Board procedure |
| 2025–2026 | Data Protection Board constituted | Board operational but no penalty proceedings initiated |
| May 2027 | Core obligations take full effect | Consent (S.6), notice (S.5), security (S.8(5)), rights (S.11–14), breach notification (S.8(6)) |
| Post-May 2027 | SDF notifications expected | Central Government to notify Significant Data Fiduciaries—triggering DPIA, DPO and audit obligations |
| Ongoing | Section 16 transfer restrictions | Central Government may restrict transfers to specific countries (none restricted as of Oct 2026) |
Practical preparation: working backward from May 2027
A 12–18 month compliance programme working backward from May 2027:
- 01
Phase 1: Assessment (months 1–3)
Conduct a data-processing inventory. Map every category of personal data, the purpose of collection, the lawful basis and the current retention practice. Identify gaps against the DPDPA framework.
- 02
Phase 2: Architecture (months 3–6)
Design the consent-management framework, draft Section 5 notices, build the Data Principal rights fulfilment mechanism and design the breach-notification workflow. If applicable, prepare for SDF designation.
- 03
Phase 3: Implementation (months 6–12)
Implement technical controls—consent-state management, encryption, access controls, automated retention/erasure, breach-detection systems. Train staff. Update vendor contracts (DPAs under Section 8(2)).
- 04
Phase 4: Testing (months 12–15)
Run tabletop exercises for breach notification (72-hour timeline). Test consent-withdrawal workflows end-to-end. Validate that the erasure system deletes data at the right time. Conduct internal audits.
- 05
Phase 5: Go-live (months 15–18)
Activate the compliance programme. Publish updated privacy notices. Activate the Data Principal rights portal. Brief the leadership team. Monitor and iterate.
When will SDF notifications come?
Section 10 empowers the Central Government to notify certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data they process, the risk to the rights of Data Principals and other factors. SDFs face additional obligations: appointment of a DPO based in India (Section 10(2)(a)), an independent data auditor, and a periodic DPIA (Section 10(2)(c), Rule 13).
As of October 2026, no SDF notifications have been issued. The expectation is that notifications will follow shortly after the May 2027 enforcement date, targeting large-scale processors—technology platforms, telecom operators, financial institutions and e-commerce marketplaces.
How AMLEGALS helps with DPDPA readiness
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in building phased compliance programmes, conducting readiness assessments against the May 2027 deadline and preparing for potential SDF designation.

