The DPDP Act timeline: what switches on 13 Nov 2025, 13 Nov 2026 and 13 May 2027
This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.
The Digital Personal Data Protection Act, 2023 received the President’s assent on 11 August 2023, but its provisions take effect only on dates the Central Government appoints. Section 1(2) allows different dates for different provisions. The government used that power on 13 November 2025, in G.S.R. 843(E). The DPDP Rules, 2025 are dated the same day and carry their own staggered start.
The two notifications
G.S.R. 843(E) is the commencement notification for the Act, issued under Section 1(2). It sorts the Act’s sections into three groups, in clauses (a), (b) and (c).
G.S.R. 846(E), dated 13 November 2025, is the Digital Personal Data Protection Rules, 2025, made under Section 40. The notified Rules have 23 rules and seven Schedules. Rule 1 sets their own staggered start, in sub-rules (2), (3) and (4).
(G.S.R. 843(E) and G.S.R. 846(E) are the Gazette reference numbers of the two notifications.) Both instruments use the same three steps: the date of publication, one year after it, and eighteen months after it. The notifications do not print the later two dates. Counted from 13 November 2025 (the publication date of G.S.R. 843(E), and the date the Rules carry), they are 13 November 2026 and 13 May 2027.
What switches on when
13 Nov 2025 publication
Act provisions (G.S.R. 843(E)): Section 1(2), Section 2, Sections 18 to 26, Section 35, Sections 38 to 43, Section 44(1) and Section 44(3). Clause (a).
Rules (Rule 1): Rules 1, 2 and 17 to 21. Rule 1(2).
13 Nov 2026 + one year
Act provisions (G.S.R. 843(E)): Section 6(9) and Section 27(1)(d). Clause (b).
Rules (Rule 1): Rule 4. Rule 1(3).
13 May 2027 + eighteen months
Act provisions (G.S.R. 843(E)): Sections 3 to 5, Section 6(1) to 6(8) and 6(10), Sections 7 to 17, Section 27 except clause (d) of Section 27(1), Sections 28 to 34, Sections 36 and 37, and Section 44(2). Clause (c).
Rules (Rule 1): Rules 3, 5 to 16, 22 and 23. Rule 1(4).
13 November 2025: the machinery
The first group sets up the framework rather than duties on businesses. Section 2 brings the definitions into force. Sections 18 to 26 cover the establishment and composition of the Data Protection Board of India, its members’ terms, and its officers. Sections 38 to 43 cover how the Act sits with other laws, the bar on civil court jurisdiction, and the government’s powers to make rules and amend the Schedule.
On the Rules side, Rules 17 to 21 deal with the Board itself: selecting its Chairperson and Members, their pay, how the Board meets, its working as a digital office, and its staff. Rule 19(9) already sets a time limit for the Board’s future inquiries: six months from receiving an intimation, complaint, reference or direction, extendable by up to three months at a time for recorded reasons.
The Board’s provisions being in force does not by itself mean the Board has been constituted. Check the Gazette for appointment notifications rather than assuming either way.
13 November 2026: Consent Managers
Section 6(9) requires every Consent Manager to be registered with the Board. A Consent Manager is a person registered with the Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent through an interoperable platform (Section 2(g)).
Rule 4 sets out how registration works, and Part A of the First Schedule lists the conditions. They include being a company incorporated in India and having a net worth of not less than two crore rupees. Section 27(1)(d), which lets the Board inquire into a breach of a registration condition, starts the same day.
If you are not planning to become a Consent Manager, this date changes little for you directly.
13 May 2027: the duties on businesses
The third group is the one most businesses need to plan around. From this date:
the Act starts to apply under Section 3, and processing needs a lawful ground under Section 4;
notice and consent apply under Sections 5 and 6, with the notice contents in Rule 3;
the Data Fiduciary’s general obligations apply under Section 8, with security safeguards in Rule 6, breach intimation in Rule 7, and retention and erasure in Rule 8;
children’s data rules apply under Section 9 and Rule 10, and Significant Data Fiduciary duties under Section 10 and Rule 13;
Data Principals’ rights and duties apply under Sections 11 to 15, with Rule 14 on how requests and grievances are handled;
transfers outside India are governed by Section 16 and Rule 15;
the Board’s inquiry powers under Section 27 (other than Section 27(1)(d), already in force from 13 November 2026) and Section 28, appeals under Section 29, and penalties under Section 33 all start.
Section 44(2) also starts on this date. It amends the Information Technology Act, 2000, including omitting its section 43A.
One consequence people miss: consent you already hold
Section 1(2) says that a reference in a provision to “the commencement of this Act” means the date that provision comes into force. Section 5(2) deals with consent given “before the date of commencement of this Act”. Section 5 comes into force on 13 May 2027. On a plain reading of Section 1(2), consents collected before that date fall under Section 5(2).
For those, Section 5(2)(a) requires a notice as soon as reasonably practicable, telling the person what data was processed and for what purpose, how to withdraw consent and use your grievance process (Sections 6(4) and 13), and how to complain to the Board. Section 5(2)(b) lets you keep processing until they withdraw consent. On that reading, every consent you collect before 13 May 2027 adds to the list of people you must notify. See what a consent notice must contain.
Planning backwards from 13 May 2027
The Act’s substantive duties and the penalty regime start on the same day, so there is no grace period after that date written into either notification. A workable plan starts with a data map, then the documents the duties require: notices, a breach procedure, a retention schedule, a rights process and processor contracts. Each needs an owner and a finish date that leaves time for review before 13 May 2027.
Sources
Every section, rule and date above was checked against the official text on 4 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Section 1(2): Different dates for different provisions; "commencement" means that provision's date
Section 2: Definitions, in force from 13 November 2025
Section 2(g): Consent Manager
Sections 3 to 17 (except 6(9)), 27 (except 27(1)(d)), 28 to 34, 36 and 37: Application of the Act, and the other sections listed in clause (c), from 13 May 2027
Section 5(2): Notice for consent given before commencement
Section 6(9): Consent Manager registration, from 13 November 2026
Sections 18 to 26: The Board: establishment, composition, terms, officers
Section 27(1)(d): Board inquiry into breach of a Consent Manager registration condition
Section 35: Protection of action taken in good faith; in force from 13 November 2025
Sections 38 to 43: Relationship with other laws, rule-making, amending the Schedule
Section 44: Section 44(1) and (3) from 13 November 2025; Section 44(2), amending the IT Act, 2000, from 13 May 2027
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
Rule 1(2), 1(3), 1(4): Staggered commencement of the Rules
Rule 3: Notice contents
Rule 4: Consent Manager registration and obligations, with Part A and Part B of the First Schedule
Rule 6: Security safeguards
Rule 7: Breach intimation
Rule 8: Retention and erasure
Rule 10: Children
Rule 13: Significant Data Fiduciaries
Rule 14: Rights and grievances
Rule 15: Transfers outside India
Rules 17 to 21: Board selection, pay, meetings, digital office and staff
Rule 19(9): Board inquiries: six months, extendable by up to three months at a time
First Schedule, Part A: Consent Manager registration conditions, including incorporation in India and net worth of at least two crore rupees
Notifications
G.S.R. 843(E), clauses (a), (b) and (c): Commencement of the Act in three groups
G.S.R. 846(E): The DPDP Rules, 2025: 23 rules and seven Schedules
Turn 13 May 2027 into a dated plan
How-to 02 turns your gaps into a compliance timeline, with most tasks tied to a document and a suggested target date worked back from the legal date by a live formula.
The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.
Drafting aid, not legal advice.




Comments