AMLEGALS — Strategic Lawyering
Compliance Tasks

DPDPA compliance timeline: phases, deadlines and preparation milestones

The Digital Personal Data Protection Act received Presidential assent on 11 August 2023, but full enforcement does not begin until May 2027. The DPDP Rules were notified in November 2025. This phased rollout gives organisations a defined window to prepare—but the window is closing. This guide maps every known milestone, identifies what must be ready by when and outlines a practical preparation sequence.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 3 min read

Abstract flowing timeline ribbon with milestone nodes along a structured path on navy and gold background
Short answer

The DPDPA was enacted in August 2023. The DPDP Rules were notified in November 2025. Core obligations—consent, notice, security safeguards, Data Principal rights, breach notification—take effect from May 2027. The Data Protection Board has been constituted but has not issued penalty orders as of October 2026. Organisations should treat May 2027 as the hard deadline and work backward to build compliance infrastructure now.

  • Compliance Timeline
  • DPDPA
  • May 2027
  • Enforcement
  • Implementation
  • Deadlines
Act enacted
11 August 2023
Rules notified
November 2025
Full enforcement
May 2027
Penalty orders issued
None (as of Oct 2026)

The enforcement timeline: what happened and what is coming

The DPDPA’s rollout follows a phased sequence. Here is every confirmed milestone:

DPDPA enforcement timeline
DateEventImplication
11 Aug 2023DPDPA receives Presidential assentIndia’s first comprehensive data-protection law enacted
Nov 2025DPDP Rules 2025 notifiedProcedural framework for consent, breach, DPO, DPIA and Board procedure
2025–2026Data Protection Board constitutedBoard operational but no penalty proceedings initiated
May 2027Core obligations take full effectConsent (S.6), notice (S.5), security (S.8(5)), rights (S.11–14), breach notification (S.8(6))
Post-May 2027SDF notifications expectedCentral Government to notify Significant Data Fiduciaries—triggering DPIA, DPO and audit obligations
OngoingSection 16 transfer restrictionsCentral Government may restrict transfers to specific countries (none restricted as of Oct 2026)

Practical preparation: working backward from May 2027

A 12–18 month compliance programme working backward from May 2027:

  1. 01

    Phase 1: Assessment (months 1–3)

    Conduct a data-processing inventory. Map every category of personal data, the purpose of collection, the lawful basis and the current retention practice. Identify gaps against the DPDPA framework.

  2. 02

    Phase 2: Architecture (months 3–6)

    Design the consent-management framework, draft Section 5 notices, build the Data Principal rights fulfilment mechanism and design the breach-notification workflow. If applicable, prepare for SDF designation.

  3. 03

    Phase 3: Implementation (months 6–12)

    Implement technical controls—consent-state management, encryption, access controls, automated retention/erasure, breach-detection systems. Train staff. Update vendor contracts (DPAs under Section 8(2)).

  4. 04

    Phase 4: Testing (months 12–15)

    Run tabletop exercises for breach notification (72-hour timeline). Test consent-withdrawal workflows end-to-end. Validate that the erasure system deletes data at the right time. Conduct internal audits.

  5. 05

    Phase 5: Go-live (months 15–18)

    Activate the compliance programme. Publish updated privacy notices. Activate the Data Principal rights portal. Brief the leadership team. Monitor and iterate.

When will SDF notifications come?

Section 10 empowers the Central Government to notify certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data they process, the risk to the rights of Data Principals and other factors. SDFs face additional obligations: appointment of a DPO based in India (Section 10(2)(a)), an independent data auditor, and a periodic DPIA (Section 10(2)(c), Rule 13).

As of October 2026, no SDF notifications have been issued. The expectation is that notifications will follow shortly after the May 2027 enforcement date, targeting large-scale processors—technology platforms, telecom operators, financial institutions and e-commerce marketplaces.

How AMLEGALS helps with DPDPA readiness

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in building phased compliance programmes, conducting readiness assessments against the May 2027 deadline and preparing for potential SDF designation.

Bottom line

May 2027 is the hard enforcement date. A 12–18 month compliance programme starting now is not early—it is on schedule.

Key terms
Core obligations (May 2027)
The full set of DPDPA requirements that take effect in May 2027: consent (S.6), notice (S.5), security safeguards (S.8(5)), Data Principal rights (S.11–14), breach notification (S.8(6)).
SDF notification
A Central Government order designating a Data Fiduciary as a Significant Data Fiduciary under Section 10—triggering DPO, DPIA and audit obligations.
Questions and answers

DPDPA Compliance Timeline: common questions

When does the DPDPA fully take effect?

Core obligations take effect from May 2027. The Act was enacted in August 2023 and the Rules were notified in November 2025. The Data Protection Board has been constituted but has not issued penalty orders as of October 2026.

Is the DPDPA already enforceable?

The Act is law, but core obligations (consent, notice, rights, breach notification) take full effect from May 2027. Before that date, the Board is being operationalised and the enforcement infrastructure is being built.

How long does a compliance programme take?

A thorough programme takes 12–18 months: 3 months for assessment, 3 for architecture, 6 for implementation, 3 for testing and go-live. Starting in late 2025 or early 2026 is advisable.

What if I am not compliant by May 2027?

The Board will have the power to inquire into contraventions and impose penalties (up to ₹250 crore for security-safeguard failures). Non-compliance after the enforcement date is a legal risk, not a grace-period situation.

Contact

Is your organisation ready for May 2027?

Submit a question about DPDPA preparation timelines and readiness.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPDPA Compliance Timeline: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Compliance Timeline?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Compliance Timeline under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Compliance Timeline under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Compliance Timeline?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Compliance Timeline rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Compliance Timeline?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Compliance Timeline · DPDPA Exposure Assessment