Back to all posts

September 24, 2026

DPDP Compliance Timeline: What Businesses Need to Prepare Before May 2027

A clear guide to the phased DPDP compliance timeline, covering what is already in force, the November 2026 milestone and the May 2027 requirements.


India’s Digital Personal Data Protection (DPDP) Act, 2023 does not follow a single compliance deadline. The DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology in November 2025, follow a phased commencement timeline. 

For businesses, understanding these phases matters. Some provisions establish the regulatory framework, while others introduce operational requirements around consent, security, personal data breaches, and individual rights. Treating May 2027 as the only date that matters can leave organizations overlooking earlier provisions relevant to them. 

If you haven’t yet explored what the law requires, our DPDP Act & Rules complete guide covers the full framework, while our 25-point DPDP compliance checklist explains what to build. This article focuses on the calendar and how to plan your preparation. 


Where We Stand Right Now  

The first phase has already commenced, the next milestone relating to Consent Manager provisions, falls in November 2026. The remaining Rules are scheduled to come into force in May 2027. 

Businesses should use this period to identify their applicable obligations, assign responsibility and build the processes needed to meet them. Data mapping, consent redesign, vendor reviews and incident response testing require coordination across teams. Leaving them until the final weeks creates unnecessary pressure. 


Phase 1: 13 November 2025 | Initial Provisions Come Into Force

The first phase brought the initial provisions and regulatory framework into force, including definitions and Rules relating to the Data Protection Board of India’s administration and functioning. 

This phase primarily established the institutional foundation for implementing the law. It should not be interpreted as meaning that every business obligation, complaint procedure or penalty became applicable from this date. 

The broader obligations and associated enforcement provisions follow their respective commencement dates. Businesses therefore need to distinguish between the establishment of the regulatory framework and the commencement of specific operational duties.  


Phase 2: 13 November 2026 | Consent Manager Provisions Come Into Force 

Twelve months after notification, the provisions governing Consent Manager registration and obligations come into force. 

A Consent Manager is a registered intermediary that enables individuals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. 

What this means in practice: 


  • Registration is subject to eligibility conditions. Applicants must meet the prescribed requirements, including incorporation in India and a minimum net worth threshold.  


  • Foreign entities cannot register directly without meeting the Indian incorporation requirements.  


  • Businesses considering Consent Manager integration can assess their technical and operational needs, including how consent choices and withdrawal requests would move between systems.  


November 2026 should not be treated as a mandatory infrastructure-readiness deadline for businesses generally. This milestone specifically concerns Consent Manager provisions. 

For organisations that do not intend to operate as Consent Managers, it is an opportunity to review future integration needs and strengthen their own consent processes.


Phase 3: 13 May 2027 | Remaining Rules Come Into Force 

Eighteen months after notification, the Rules scheduled for the 18-month commencement period will come into force. Businesses should prepare to meet the requirements applicable to their activities by the relevant commencement dates. 

Depending on the organisation’s role, processing activities and applicable exemptions, preparation should cover the following areas. 


Clear, Itemised Consent Notices 

Review notices across relevant data collection touchpoints. These should clearly explain the personal data being collected, the purposes of processing and the ways individuals can withdraw consent or exercise their rights. 

The objective is to help people understand what they are agreeing to, using clear language rather than relying on a broad, difficult-to-read privacy statement. 


Working Consent Management Processes 

Ensure that consent can be obtained, recorded and withdrawn appropriately. Withdrawing consent should be as easy as giving it. 

Teams should also understand what happens after withdrawal, including how the request reaches relevant systems and processors. 


Data Principal Rights Workflows 

Establish workflows for access, correction, erasure, grievance redressal and nomination, operating as required under the Act and Rules. 

Assign responsibility for receiving, verifying, routing and responding to requests. Avoid applying a general 90-day response window to every right, as the requirements should be assessed separately. 


Reasonable Security Safeguards 

Review safeguards such as encryption, access controls, monitoring and incident response procedures. 

The review should consider how personal data is protected across internal systems and processing carried out on the organisation’s behalf. 


Breach Notification Procedures 

Build a process to notify affected Data Principals and the Data Protection Board without delay upon becoming aware of a personal data breach. 

The prescribed detailed information must then be provided to the Board within 72 hours of becoming aware of the breach, unless the Board permits a longer period following a written request. 

The 72-hour period should not be presented as a blanket deadline for notifying both the Board and affected individuals.  


Children’s Data Safeguards 

Where children’s personal data is processed, assess the requirements for verifiable parental consent and other applicable safeguards, taking account of prescribed exemptions. 

Identify whether existing collection, verification and processing practices need to change. 


Processor Contracts 

Review contracts with vendors and processors handling personal data on your behalf. 

Update relevant terms to support applicable obligations, including security safeguards, incident reporting and cooperation with requests relating to personal data. 


Additional Significant Data Fiduciary Requirements 

Organisations designated as Significant Data Fiduciaries should prepare for additional obligations, including a Data Protection Officer, audits and Data Protection Impact Assessments. 

These requirements should be assessed based on the organisation’s designation and the applicable provisions, rather than assumed to apply to every business. 

The relevant obligations and enforcement provisions apply according to their respective commencement dates. May 2027 should therefore not be described as a single, universal deadline covering every organisation and every provision.


A Practical Timeline From Here to May 2027 

The following is a suggested implementation plan to help sequence the work. It is not a separate statutory timetable. 


Now Through the End of 2026: Map Your Data and Identify Gaps 

Start by understanding what personal data your organisation holds and how it moves. 


Identify: 

  • What personal data you collect and why.  

  • Where it is stored and which teams can access it.  

  • Which vendors or processors receive it.  

  • How long it is retained.  

  • Which notices, consent processes and safeguards already exist.  


Confirm your role for each processing activity and identify the requirements that apply. Begin updating consent notices, reviewing security controls and assigning owners across legal, engineering, HR, marketing and support. 

If you intend to operate as a Consent Manager, assess the registration requirements associated with the November 2026 milestone. Other businesses can review potential integration needs without treating November as a general integration deadline. 

January to March 2027: Build and Test the Processes 

Turn the gap assessment into working processes. 

Build and test Data Principal rights workflows. Finalise breach response procedures and run a simulation to check whether teams can identify, escalate and report an incident. 

Implement parental consent processes where applicable. Review retention and deletion practices, and update contracts with processors handling personal data on your behalf. 

Testing should answer practical questions: Who receives a request? Who approves the response? Which systems need updating? What happens if the responsible person is unavailable? 

A documented process is useful only when teams can follow it. 

Before the May 2027 Commencement: Review Readiness and Close Gaps 

Run an internal readiness review against the requirements applicable to your organisation. 

Check whether notices are ready, consent withdrawal works, requests reach the right teams and incident response procedures can be followed under pressure. 

Train employees who handle personal data and close outstanding gaps before the relevant provisions commence. Keep records of implementation, testing and remediation to support your compliance programme. 

What Happens If You Miss an Applicable Requirement? 

Failure to meet an applicable obligation can lead to proceedings and penalties under the relevant provisions of the Act. 

The Act provides different maximum penalties for specified contraventions. The maximum of ₹250 crore relates to failure to take reasonable security safeguards to prevent a personal data breach. It should not be presented as a standard penalty applicable to every provision of the Rules. 

Businesses should map their obligations to the relevant commencement dates and prepare accordingly, rather than assuming that every requirement starts at the same time. 

FAQ

Got Questions? We've Got Answers

A quick, practical guide to the DPDP compliance timeline, key deadlines, and what businesses need to prepare before May 2027.

A quick, practical guide to the DPDP compliance timeline, key deadlines, and what businesses need to prepare before May 2027.

When do the different DPDP Rules come into force?

What happens on 13 November 2026?

Is any part of the DPDP framework already in force?

Should businesses assume there will be a grace period after May 2027?

Should smaller businesses wait until closer to May 2027 to start?

Related resources

Related resources

Explore More

Explore More